A security context generation method, device and computer-readable storage medium
By generating and isolating security contexts for different communication services in terminal devices, the security issues caused by the shared security contexts for public and private network services are resolved, and the security and isolation effects of communication services are improved.
Patent Information
- Application Number
- CN202080107902.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-25
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2040-12-25
AI Technical Summary
In PNI-NPN, public network services and private network services share the same security context. This allows attackers to obtain the security context of private network services by cracking the security context of public network services, reducing the security of communication services.
After the terminal device obtains the first security context, it obtains the second security context by additionally generating instructions, which is used to protect different communication services and isolate the security contexts of different services, including generating security keys and/or security algorithms, and using derived parameters and secondary authentication to ensure the difference of the contexts.
By isolating the security contexts of different communication services, attacks are prevented from affecting other communication services, thereby improving the security of public and private network services and the overall security of communication services.
Smart Images

Figure CN116601985B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of communication technologies, and in particular to a security context generation method, device, and computer-readable storage medium. Background Art
[0002] A public network is a communication network built by network service providers for public use. To meet the network resource needs of certain individuals, businesses, and companies, operators can allocate network resources to these users, forming a private network. This private network is called a public network integrated non-public network (PNI-NPN). In a PNI-NPN, user equipment (UE) can connect to the public land mobile network (PLMN) for public network services or to a non-public / private network (NPN) for private network services. Currently, UEs can connect to the same radio access network (RAN) for both public and private network services. These services communicate using the same security context. If an attacker compromises the security context used by public network services, they gain access to the corresponding security context for the private network services. Conversely, if an attacker compromises the algorithms used by private network services, they also gain access to the security context for the public network services. Therefore, security attacks against public network services or private network services may affect the corresponding private network services or public network services, thereby reducing the security of communication services. Summary of the Invention
[0003] The embodiments of the present invention disclose a security context generation method, device and computer-readable storage medium for improving the security of communication services.
[0004] In a first aspect, a security context generation method is disclosed, which can be applied to a terminal device or a module (e.g., a chip) in the terminal device. The following description will be made using the terminal device as an example. The security context generation method may include: the terminal device obtains a first security context, the first security context is used to protect the first communication service of the terminal device; the terminal device sends a session request message to a session management function network element, the session request message is used to request the establishment of a session for a second communication service, the second communication service being different from the first communication service; the terminal device receives a session acceptance message from the session management function network element, the session acceptance message is used to complete the establishment of the session for the second communication service; the terminal device obtains an additional generation indication; the terminal device obtains a second security context according to the additional generation indication, the second security context being used to protect the second communication service.
[0005] In an embodiment of the present application, a terminal device can obtain a second security context based on the first security context. The first security context and the second security context can respectively protect different communication services. This allows the protection of different services to be isolated to prevent an attack on one communication service from affecting another, thereby improving the security of the communication service.
[0006] As a possible implementation manner, the session request message includes first indication information, where the first indication information is used to indicate that the terminal device supports generating the second security context.
[0007] In an embodiment of the present application, when the session request message includes the first indication information, the session management function network element can directly determine the second security context based on this indication information, which can reduce the processing process of the session management function network element and thus improve the efficiency of generating the second security context.
[0008] As a possible implementation, the terminal device obtains a second security context according to the additional generation indication, including: the terminal device obtains a security key based on the first key according to the additional generation indication; and / or the terminal device obtains a security algorithm according to the additional generation indication.
[0009] In the embodiment of the present application, the security context may include a security key and / or a security algorithm. The security context may perform encryption and integrity protection on data, thereby ensuring the security and reliability of data in the communication service.
[0010] As a possible implementation manner, the terminal device obtains a security key based on the first key according to the additional generation indication, including: the terminal device obtains the first key based on the access stratum (AS) root key of the first security context according to the additional generation indication; the terminal device generates the security key based on the first key.
[0011] In the embodiment of the present application, when the terminal device generates a security key, the first key can be generated by generating the AS root key of the first security context. Since the AS root key is known and does not need to be generated, the process of generating the second security context can be reduced, thereby improving the efficiency of generating the second security context.
[0012] As a possible implementation, the additional generation indication includes an indication of a first derived parameter, and the terminal device obtains the first key based on the AS root key of the first security context according to the additional generation indication, including: the terminal device generates the first key based on the AS root key of the first security context and the first derived parameter.
[0013] In an embodiment of the present application, since the first key is generated based on the first derived parameter, and the first derived parameter is different, the generated key is different. Therefore, it is possible to prevent the security key included in the second security context from being the same as the security key included in the first security context, and to ensure that the security contexts used by different communication services are different, thereby ensuring the effectiveness of security isolation and improving the security of communication services.
[0014] As a possible implementation manner, the first derived parameter is a downlink packet data convergence protocol (PDCP) count COUNT, and the indication of the first derived parameter is a portion of bits of the downlink PDCP COUNT.
[0015] In an embodiment of the present application, when the first derived parameter is a downlink PDCP COUNT, the corresponding COUNT value may change as the number of security contexts generated continuously changes. The change in COUNT value can prevent the generation of identical first keys, thereby preventing the generation of identical security keys, and thus ensuring that the generated security contexts are different. Different security contexts are used to protect different communication services, ensuring the effectiveness of communication service security isolation, thereby improving the security of the communication services.
[0016] As a possible implementation manner, after the terminal device sends the session request message to the session management function network element and before the terminal device receives the additional generation indication, the security context generation method also includes: the terminal device performs secondary authentication; the terminal device generates a secondary authentication key during the secondary authentication process; the terminal device obtains a security key based on the first key according to the additional generation indication, including: the terminal device obtains the first key based on the secondary authentication key according to the additional generation indication; the terminal device generates a security key based on the first key.
[0017] In an embodiment of the present application, the terminal device can perform secondary authentication, and then generate a first key using the authentication key obtained through the secondary authentication. Since different authentication keys generate different first keys, the security key included in the second security context generated using the first key is also different from the security key included in the first security context, thereby ensuring that the generated security contexts are different. Different security contexts are used to protect different communication services, which can ensure the effectiveness of the security isolation of communication services, thereby improving the security of communication services.
[0018] As a possible implementation, the additional generation indication includes an indication of a second derived parameter, and the terminal device obtains the first key based on the secondary authentication key according to the additional generation indication, including: the terminal device generates the first key based on the secondary authentication key and the second derived parameter according to the indication of the second derived parameter.
[0019] In the embodiment of the present application, the terminal device can generate the first key based on the second derived parameter. Different second derived parameters result in different generated first keys. Therefore, it is possible to prevent the generated second security context from including the same security key as the first security context, thereby ensuring that different communication services use different security contexts, ensuring the effectiveness of security isolation, and thus improving the security of communication services.
[0020] As a possible implementation manner, the second derived parameter is one or more of the following parameters: downlink non-access stratum (NAS) number COUNT, protocol data unit (PDU) session identity document (ID), network slice selection assistance information (NSSAI) and data network name (DNN).
[0021] In an embodiment of the present application, when NAS COUNT is used as a parameter for deriving the first key, since the COUNT value of each derivation will change, the derived first keys can be different. When PDU session ID, NSSAI or DNN is used as a parameter for deriving the first key, since the terminal device PDU session, access slice and data network are different, the derived first keys can also be different. Different first keys can generate different security keys, and different security keys can ensure that the generated security contexts are different. Different security contexts can be used to protect different communication services, which can ensure the effectiveness of the security isolation of communication services, thereby improving the security of communication services.
[0022] As a possible implementation manner, the terminal device generates the security key according to the first key, including: the terminal device generates the security key according to the first key and a third derived parameter.
[0023] In the embodiment of the present application, the terminal device can generate a security key based on the first key and the third derived parameter. Since different third derived parameters generate different security keys, it is possible to prevent the generated security key from being the same as an existing security key, thereby ensuring that the generated security contexts are different. By protecting different communication services with different security contexts, the effectiveness of communication service security isolation can be ensured, thereby improving the security of the communication services.
[0024] As a possible implementation, the additional generation indication includes an identifier of the security algorithm, and the terminal device generates the security key based on the first key and the third derived parameter, including: the terminal device generates the security key based on the first key and the identifier and type of the security algorithm.
[0025] In the embodiment of the present application, since the type and length of the security key in the second security context are both determined, the security key can be determined by the identifier and type of the corresponding security algorithm, thereby ensuring the validity of the generated security key.
[0026] As a possible implementation manner, the additional generation indication includes an identifier of the security algorithm.
[0027] In an embodiment of the present application, after the terminal device obtains the identifier of the security algorithm, it can directly determine the security algorithm based on the identifier, thereby ensuring the consistency of the security algorithms generated by the terminal device and the data transmission network element, reducing the process of determining the security algorithm by the terminal device, and improving the efficiency of generating the security context.
[0028] As a possible implementation manner, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.
[0029] In an embodiment of the present application, the first communication service and the second communication service are different communication services. When one communication service is a private network service and the other communication service is a public network service, different communication services can be protected using different security contexts, and the security isolation between the public network service and the private network service can be guaranteed, thereby improving the security of the public network service and the private network service.
[0030] A second aspect discloses a security context generation method, which can be applied to a session management function network element, or to a module (e.g., a chip) in the session management function network element. The following description will be made using the session management function network element as an example. The security context generation method may include: the session management function network element receiving a session request message from a terminal device, the session request message being used to request establishment of a session for a second communication service; the session management function network element sending an additional security context indication to a data transmission network element, the additional security context indication being used to instruct generation of a second security context, the second security context being used to protect the second communication service; and the session management function network element sending a session accept message to the terminal device, the session accept message being used to complete establishment of a session for the second communication service.
[0031] In an embodiment of the present application, after receiving a session request message, the session management function network element may respond to a request to generate a second security context. The session management function network element may send an additional security context indication, and the data transmission network element may generate a second security context based on the additional security context. The session management function network element may coordinate the terminal device and the data transmission network element to generate the second security context, thereby ensuring the generation of the second security context.
[0032] As a possible implementation method, the session request message includes first indication information, and the first indication information is used to indicate that the terminal device supports the generation of a second security context, and the session management function network element sends an additional security context indication to the data transmission network element, including: when the first indication information indicates that the terminal device supports the generation of the second security context, the session management function network element sends the additional security context indication to the data transmission network element.
[0033] In an embodiment of the present application, when the session request message includes the first indication information, the session management function network element can directly determine to generate the second security context based on this indication information, which can reduce the processing process of the session management function network element and thus improve the efficiency of generating the second security context.
[0034] As a possible implementation method, the session management function network element sends an additional security context indication to the data transmission network element, including: the session management function network element obtains the contract information of the terminal device based on the session request message; when the contract information of the terminal device indicates that the second security context needs to be generated, the session management function network element sends the additional security context indication to the data transmission network element.
[0035] In an embodiment of the present application, the session management function network element may also determine whether to send an additional security context indication based on the subscription information, and the session request message may not carry indication information for determining whether to generate a second security context, thereby reducing information transmission and saving communication resources.
[0036] As a possible implementation method, the session management function network element sends an additional security context indication to the data transmission network element, including: when the local policy configured by the session management function network element indicates that the second security context needs to be generated, the session management function network element sends the additional security context indication to the data transmission network element.
[0037] In an embodiment of the present application, the session management function network element may determine whether to send an additional security context indication based on a local policy. In this case, the session request message may not carry indication information for determining whether to generate a second security context, thereby reducing information transmission and saving communication resources.
[0038] As a possible implementation manner, the additional security context indication includes an identifier of a security algorithm, and the method further includes: the session management function network element obtaining the security algorithm.
[0039] In an embodiment of the present application, after the session management function network element can determine the security algorithm, the terminal device and the data transmission network element can receive the identifier of the security algorithm determined by the session management function network element. The terminal device and the data transmission network element can directly determine the security algorithm based on the identifier, so as to reduce the process of determining the security algorithm by the terminal device and the data transmission network element and save processing resources, thereby improving the efficiency of generating the security context.
[0040] As a possible implementation, the additional security context indication includes a first key, and the method further includes: the session management function network element triggers secondary authentication; after the secondary authentication is successful, the session management function network element receives the secondary authentication key from the authentication, authorization and billing network element; the session management function network element obtains the first key based on the secondary authentication key.
[0041] In an embodiment of the present application, the session management function network element can trigger secondary authentication to obtain an authentication key, and then generate a first key using the secondary authentication key. Because different authentication keys generate different first keys, the security key included in the second security context generated using the first key is also different from the security key included in the first security context, thereby ensuring that the generated security contexts are different. Different security contexts are used to protect different communication services, which can ensure the effectiveness of communication service security isolation, thereby improving the security of communication services.
[0042] As a possible implementation manner, the session management function network element obtaining the first key according to the secondary authentication key includes: the session management function network element obtaining the first key according to the secondary authentication key and a second derived parameter.
[0043] In this embodiment of the present application, the session management network element can generate a first key based on a second derived parameter. Different second derived parameters result in different generated first keys. This prevents the generated second security context from including the same security key as the first security context, ensuring that different communication services use different security contexts. This ensures the effectiveness of security isolation, thereby improving the security of communication services.
[0044] As a possible implementation manner, the second derived parameter is one or more of the following parameters: downlink NASCOUNT, PDU session ID, NSSAI and DNN.
[0045] In an embodiment of the present application, when NAS COUNT is used as a parameter for deriving the first key, since the COUNT value of each derivation will change, the derived first keys can be different. When one or more of PDU session ID, NSSAI and DNN are used as parameters for deriving the first key, since the terminal device PDU session, access slice and data network are different, the derived first keys can also be different. Different first keys can generate different security keys, and different security keys can ensure that the generated security contexts are different. Different security contexts can be used to protect different communication services, which can ensure the effectiveness of the security isolation of communication services, thereby improving the security of communication services.
[0046] As a possible implementation, the session accept message includes an indication of a second derived parameter, where the indication of the second derived parameter is used to instruct to obtain a security key according to the secondary authentication key.
[0047] In this embodiment of the present application, when the session management function network element receives an indication of a second derived parameter, the session management network element may generate a first key based on the secondary authentication key and the second derived parameter. Different second derived parameters result in different generated security keys. This may result in different generated security contexts. These different security contexts can ensure the effectiveness of secure isolation of communication services, thereby improving the security of communication services.
[0048] A third aspect discloses a security context generation method, which can be applied to a data transmission network element or a module (e.g., a chip) in the data transmission network element. The data transmission network element is used as an example for illustration below. The security context generation method may include: the data transmission network element receiving an additional security context indication from a session management function network element; the data transmission network element obtaining a second security context based on the additional security context indication, where the second security context is used to protect a second communication service; and the data transmission network element sending an additional generation indication to a terminal device, where the additional generation indication is used to instruct the generation of the second security context.
[0049] In the embodiment of the present application, the data transmission network element can obtain the second security context, and the second security context can protect the second communication service, thereby improving the security of the second communication service.
[0050] As a possible implementation manner, the data transmission network element obtains a second security context according to the additional security context indication, including: the data transmission network element obtains a security key based on the first key according to the additional security context indication; and / or the data transmission network element obtains a security algorithm according to the additional security context indication.
[0051] In the embodiment of the present application, the security context may include a security key and / or a security algorithm. The security context may perform encryption and integrity protection on data, thereby ensuring the security and reliability of data in the communication service.
[0052] As a possible implementation manner, before the data transmission network element receives an additional security context indication from the session management function network element, the security context generation also includes: the data transmission network element obtains a first security context, and the first security context is used to protect a first communication service, and the first communication service is different from the second communication service.
[0053] In this embodiment of the present application, a data transmission network element can obtain a second security context based on the first security context. The first security context and the second security context can respectively protect different communication services. This allows for isolation of protection for different services, preventing an attack on one communication service from affecting another. This improves the security of communication services.
[0054] As a possible implementation manner, the data transmission network element generates the security key based on the first key according to the additional security context indication, including: the data transmission network element obtains the first key based on the AS root key of the first security context according to the additional security context indication; the data transmission network element generates the security key based on the first key.
[0055] In the embodiment of the present application, when the data transmission network element generates a security key, the first key can be generated by generating the AS root key of the first security context. Since the AS root key is known and does not need to be generated, the process of generating the second security context can be reduced, thereby improving the efficiency of generating the second security context.
[0056] As a possible implementation manner, the additional generation indication includes an indication of a first derived parameter, and the data transmission network element obtains the first key based on the AS root key of the first security context according to the additional security context indication, including: the data transmission network element generates the first key based on the AS root key of the first security context and the first derived parameter.
[0057] In an embodiment of the present application, since the first key is generated based on the first derived parameter, and the generated first key is different depending on the first derived parameter, it is possible to prevent the security key included in the generated second security context from being the same as the security key included in the first security context, and to ensure that the security contexts used by different communication services are different, thereby ensuring the effectiveness of security isolation and improving the security of communication services.
[0058] As a possible implementation manner, the first derived parameter is a downlink PDCP COUNT, and the indication of the first derived parameter is part of bits of the downlink PDCP COUNT.
[0059] In an embodiment of the present application, when the first derived parameter is a downlink PDCP COUNT, the corresponding COUNT value may change as the number of security contexts generated continuously changes. The change in COUNT value can prevent the generation of identical first keys, thereby preventing the generation of identical security keys, and thus ensuring that the generated security contexts are different. Different security contexts are used to protect different communication services, ensuring the effectiveness of communication service security isolation, thereby improving the security of the communication services.
[0060] As a possible implementation manner, the additional security context indication includes the first key, and the data transmission network element obtains the security key based on the first key according to the additional security context indication, including: the data transmission network element generates the security key based on the first key.
[0061] In an embodiment of the present application, the data transmission network element can generate a security key based on a received first key. The first key can be a key generated by a session management function network element based on an authentication key of secondary authentication. Because different authentication keys generate different first keys, the security key included in the second security context generated using the first key is also different from the security key included in the first security context, thereby ensuring that the generated security contexts are different. Different security contexts are used to protect different communication services, which can ensure the effectiveness of communication service security isolation, thereby improving the security of communication services.
[0062] As a possible implementation manner, the data transmission network element generates the security key according to the first key, including: the data transmission network element generates the security key according to the first key and a third derived parameter.
[0063] In this embodiment of the present application, a data transmission network element can generate a security key based on the first key and the third derived parameter. Because different third derived parameters generate different security keys, different communication services are protected by different security contexts. This ensures the effectiveness of secure isolation of communication services, thereby improving the security of communication services.
[0064] As a possible implementation method, the additional security context indication includes an identifier of a security algorithm, and the data transmission network element generates the security key based on the first key and a third derived parameter, including: the data transmission network element generates the security key based on the first key and the identifier and type of the security algorithm.
[0065] In the embodiment of the present application, since the type and length of the security key in the second security context are both determined, the security key can be determined by the identifier and type of the corresponding security algorithm, thereby ensuring the validity of the generated security key.
[0066] As a possible implementation manner, the additional generation indication includes an identifier of the security algorithm.
[0067] In the embodiment of the present application, after the terminal device obtains the identifier of the security algorithm, it can directly determine the security algorithm based on the identifier, thereby ensuring the consistency of the security algorithm generated by the terminal device and the data transmission network element, reducing the process of determining the security algorithm by the data transmission network element, and improving the efficiency of generating the security context. In addition, the data transmission network element can determine the security algorithm and send the identifier of the security algorithm to the terminal device.
[0068] As a possible implementation, the additional security context indication includes an identifier of the security algorithm.
[0069] In an embodiment of the present application, after the data transmission network element obtains the identifier of the security algorithm, it can directly determine the security algorithm based on the identifier, thereby ensuring the consistency of the security algorithms generated by the terminal device and the data transmission network element, reducing the process of the data transmission network element determining the security algorithm, and improving the efficiency of generating the security context.
[0070] As a possible implementation method, the data transmission network element obtains the security algorithm according to the additional security context indication, including: the data transmission network element obtains the security algorithm based on the security capabilities of the terminal device and a preconfigured algorithm priority list according to the additional security context indication, and the security capabilities of the terminal device are used to indicate all security algorithms supported by the terminal device.
[0071] In an embodiment of the present application, a data transmission network element may obtain a security algorithm based on the security capabilities of the corresponding terminal device and a preconfigured algorithm priority list. The algorithm priority list is preconfigured by the data transmission network element, and the corresponding terminal device may preconfigure its own corresponding security algorithm. The data transmission network element may determine the security algorithms of all corresponding terminal devices based on the algorithm priority list. When a terminal device is subjected to a security attack, the security algorithm of the corresponding terminal device may be leaked without leaking the security algorithms of all terminal devices, thereby improving the security of communication services for different terminal devices.
[0072] As a possible implementation manner, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.
[0073] In an embodiment of the present application, the first communication service and the second communication service are different communication services. When one communication service is a private network service and the other communication service is a public network service, different communication services can be protected using different security contexts, and the security isolation between the public network service and the private network service can be guaranteed, thereby improving the security of the public network service and the private network service.
[0074] A fourth aspect discloses a security context generation device, which may be a terminal device or a module (e.g., a chip) in the terminal device. The device may include:
[0075] an acquiring unit, configured to acquire a first security context, where the first security context is used to protect a first communication service of the terminal device;
[0076] a sending unit, configured to send a session request message to a session management function network element, wherein the session request message is used to request establishment of a session for a second communication service, where the second communication service is different from the first communication service;
[0077] a receiving unit, configured to receive a session accept message from the session management function network element, wherein the session accept message is used to complete the establishment of the session for the second communication service;
[0078] The acquisition unit is further used to obtain additional generation instructions;
[0079] The acquiring unit is further configured to acquire a second security context according to the additional generation indication, where the second security context is used to protect the second communication service.
[0080] As a possible implementation manner, the session request message includes first indication information, where the first indication information is used to indicate that the terminal device supports generating the second security context.
[0081] As a possible implementation manner, the acquiring unit acquires a second security context according to the additional generation indication, where the second security context is used to protect the second communication service, including:
[0082] Obtaining a security key based on the first key according to the additional generation instruction; and / or
[0083] A security algorithm is obtained according to the additional generation instruction.
[0084] As a possible implementation manner, the acquiring unit acquiring the security key based on the first key according to the additional generation indication includes:
[0085] acquiring the first key based on the AS root key of the first security context according to the additional generation indication;
[0086] The security key is generated according to the first key.
[0087] As a possible implementation manner, the additional generation indication includes an indication of a first derived parameter, and the obtaining unit obtains the first key based on the AS root key of the first security context according to the additional generation indication, including:
[0088] The first key is generated according to the AS root key of the first security context and the first derivative parameter.
[0089] As a possible implementation manner, the first derived parameter is a downlink PDCP COUNT, and the indication of the first derived parameter is part of bits of the downlink PDCP COUNT.
[0090] As a possible implementation manner, the device may further include:
[0091] An execution unit, configured to execute secondary authentication;
[0092] A generating unit, configured to generate a secondary authentication key during the secondary authentication process;
[0093] The acquiring unit acquiring the security key based on the first key according to the additional generation instruction includes:
[0094] acquiring the first key based on the secondary authentication key according to the additional generation instruction;
[0095] A security key is generated according to the first key.
[0096] As a possible implementation manner, the additional generation indication includes an indication of a second derived parameter, and the obtaining unit obtains the first key based on the secondary authentication key according to the additional generation indication, including:
[0097] According to an instruction of the second derived parameter, the first key is generated based on the secondary authentication key and the second derived parameter.
[0098] As a possible implementation manner, the second derived parameter is one or more of the following parameters: downlink NASCOUNT, PDU session ID, NSSAI and DNN.
[0099] As a possible implementation manner, the acquiring unit generating a security key according to the first key includes:
[0100] The security key is generated according to the first key and a third derived parameter.
[0101] As a possible implementation manner, the additional generation indication includes an identifier of the security algorithm, and the acquiring unit generates the security key according to the first key and the third derived parameter, including:
[0102] The security key is generated according to the first key and the identifier and type of the security algorithm.
[0103] As a possible implementation manner, the additional generation indication includes an identifier of the security algorithm.
[0104] As a possible implementation manner, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.
[0105] A fifth aspect discloses a security context generation device, which may be a session management function network element or a module (e.g., a chip) in a session management function network element. The device may include:
[0106] a receiving unit, configured to receive a session request message from a terminal device, wherein the session request message is used to request establishment of a session for a second communication service;
[0107] a sending unit, configured to send an additional security context indication to a data transmission network element, where the additional security context indication is used to instruct generation of a second security context, where the second security context is used to protect the second communication service;
[0108] The sending unit is further configured to send a session acceptance message to the terminal device, where the session acceptance message is used to complete the establishment of the session for the second communication service.
[0109] As a possible implementation manner, the session request message includes first indication information, where the first indication information is used to indicate that the terminal device supports generating a second security context, and the sending unit sends an additional security context indication to the data transmission network element, including:
[0110] When the first indication information indicates that the terminal device supports generating the second security context, the additional security context indication is sent to the data transmission network element.
[0111] As a possible implementation manner, the sending unit sending the additional security context indication to the data transmission network element includes:
[0112] Acquiring the contract information of the terminal device according to the session request message;
[0113] When the subscription information of the terminal device indicates that the second security context needs to be generated, the additional security context indication is sent to the data transmission network element.
[0114] As a possible implementation manner, the sending unit sending the additional security context indication to the data transmission network element includes:
[0115] When the local policy configured by the session management function network element indicates that the second security context needs to be generated, the additional security context indication is sent to the data transmission network element.
[0116] As a possible implementation manner, the additional security context indication includes an identifier of a security algorithm, and the apparatus may further include an acquisition unit, wherein:
[0117] An acquiring unit is configured to acquire the security algorithm.
[0118] As a possible implementation manner, the additional security context indication includes a first key, and the apparatus may further include:
[0119] A trigger unit, used to trigger secondary authentication;
[0120] The receiving unit is further configured to receive a secondary authentication key from the authentication, authorization and billing network element after the secondary authentication is successful;
[0121] The acquiring unit is further configured to acquire the first key according to the secondary authentication key.
[0122] As a possible implementation manner, the acquiring unit acquiring the first key according to the secondary authentication key includes:
[0123] The first key is obtained according to the secondary authentication key and a second derived parameter.
[0124] As a possible implementation manner, the second derived parameter is one or more of the following parameters: downlink NASCOUNT, PDU session ID, NSSAI and DNN.
[0125] As a possible implementation, the session accept message includes an indication of a second derived parameter, where the indication of the second derived parameter is used to instruct to obtain a security key according to the secondary authentication key.
[0126] A sixth aspect discloses a security context generation device, which may be a data transmission network element or a module (e.g., a chip) in the data transmission network element. The device may include:
[0127] a receiving unit, configured to receive an additional security context indication from a session management function network element;
[0128] an acquiring unit, configured to acquire a second security context according to the additional security context indication, where the second security context is used to protect a second communication service;
[0129] A sending unit is used to send an additional generation indication to the terminal device, where the additional generation indication is used to instruct the generation of the second security context.
[0130] As a possible implementation manner, the acquiring unit is specifically configured to:
[0131] Obtaining a security key based on the first key according to the additional security context indication; and / or
[0132] A security algorithm is obtained according to the additional security context indication.
[0133] As a possible implementation manner, the acquisition unit is further used to obtain a first security context before receiving an additional security context indication from the session management function network element, where the first security context is used to protect a first communication service, which is different from the second communication service.
[0134] As a possible implementation manner, the obtaining unit generating the security key based on the first key according to the additional security context indication includes:
[0135] Obtaining the first key based on the AS root key of the first security context according to the additional security context indication;
[0136] The security key is generated according to the first key.
[0137] As a possible implementation manner, the additional generation indication includes an indication of a first derived parameter, and the obtaining unit obtains the first key based on the AS root key of the first security context according to the additional security context indication, including:
[0138] The first key is generated according to the AS root key of the first security context and the first derivative parameter.
[0139] As a possible implementation manner, the first derived parameter is a downlink PDCP COUNT, and the indication of the first derived parameter is part of bits of the downlink PDCP COUNT.
[0140] As a possible implementation manner, the additional security context indication includes the first key, and the obtaining unit obtains the security key based on the first key according to the additional security context indication, including:
[0141] The security key is generated according to the first key.
[0142] As a possible implementation manner, the acquiring unit generating the security key according to the first key includes:
[0143] The security key is generated according to the first key and a third derived parameter.
[0144] As a possible implementation manner, the additional security context indication includes an identifier of a security algorithm, and the acquiring unit generates the security key according to the first key and the third derived parameter, including:
[0145] The security key is generated according to the first key and the identifier and type of the security algorithm.
[0146] As a possible implementation manner, the additional generation indication includes an identifier of the security algorithm.
[0147] As a possible implementation, the additional security context indication includes an identifier of the security algorithm.
[0148] As a possible implementation manner, the acquiring unit acquiring the security algorithm according to the additional security context indication includes:
[0149] According to the additional security context indication, the security algorithm is obtained based on the security capability of the terminal device and a preconfigured algorithm priority list, where the security capability of the terminal device is used to indicate all security algorithms supported by the terminal device.
[0150] As a possible implementation manner, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.
[0151] A seventh aspect discloses a security context generation device, which may be a terminal device or a module (e.g., a chip) within the terminal device. The security context generation device may include: a processor, a memory, an input interface, and an output interface. The input interface is configured to receive information from a device other than the device, and the output interface is configured to output information to the device other than the device. When the processor executes a computer program stored in the memory, the processor performs the security context generation method disclosed in the first aspect or any embodiment of the first aspect.
[0152] In an eighth aspect, a security context generation device is disclosed. The security context generation device may be a session management function network element or a module (e.g., a chip) within the session management function network element. The security context generation device may include: a processor, a memory, an input interface, and an output interface. The input interface is configured to receive information from a device other than the device, and the output interface is configured to output information to the device other than the device. When the processor executes a computer program stored in the memory, the processor executes the security context generation method disclosed in the second aspect or any embodiment of the second aspect.
[0153] A ninth aspect discloses a security context generation device, which may be a data transmission network element or a module (e.g., a chip) within a data transmission network element. The security context generation device may include: a processor, a memory, an input interface, and an output interface, the input interface being configured to receive information from a device other than the device, and the output interface being configured to output information to a device other than the device. When the processor executes the computer program stored in the memory, the processor executes the security context generation method disclosed in the third aspect or any embodiment of the third aspect.
[0154] A tenth aspect discloses a communication system, which includes the security context generation device of the seventh aspect, the security context generation device of the eighth aspect, and the security context generation device of the ninth aspect.
[0155] In an eleventh aspect, a computer-readable storage medium is disclosed, on which a computer program or computer instructions are stored. When the computer program or computer instructions are executed, the security context generation method disclosed in the above aspects is implemented.
[0156] The twelfth aspect discloses a chip, comprising a processor for executing a program stored in a memory. When the program is executed, the chip executes the above method.
[0157] As a possible implementation, the memory is located outside the chip.
[0158] A thirteenth aspect discloses a computer program product, which includes a computer program code. When the computer program code is executed, the above method is performed. BRIEF DESCRIPTION OF THE DRAWINGS
[0159] Figure 1 This is a schematic diagram of a network architecture disclosed in an embodiment of the present application;
[0160] Figure 2 This is a schematic diagram of a process for generating a security context disclosed in an embodiment of the present application;
[0161] Figure 3 This is a schematic diagram of another process for generating a security context disclosed in an embodiment of the present application;
[0162] Figure 4 This is another schematic diagram of a process for generating a security context disclosed in an embodiment of the present application;
[0163] Figure 5 This is another schematic diagram of a process for generating a security context disclosed in an embodiment of the present application;
[0164] Figure 6 This is another schematic diagram of a process for generating a security context disclosed in an embodiment of the present application;
[0165] Figure 7 This is a schematic structural diagram of a communication device disclosed in an embodiment of the present application;
[0166] Figure 8 is a schematic structural diagram of another communication device disclosed in an embodiment of the present invention;
[0167] Figure 9 is a structural diagram of another communication device disclosed in an embodiment of the present invention;
[0168] Figure 10 is a structural diagram of another communication device disclosed in an embodiment of the present invention;
[0169] Figure 11 It is a structural diagram of another communication device disclosed in an embodiment of the present invention. DETAILED DESCRIPTION
[0170] The embodiments of the present application disclose a security context generation method, apparatus, and computer-readable storage medium for improving the security of communication services. Detailed descriptions are provided below.
[0171] In order to better understand the security context generation method, device and computer-readable storage medium disclosed in the embodiments of the present invention, the network architecture used in the embodiments of the present invention is described below. Figure 1 , Figure 1 This is a schematic diagram of a network architecture disclosed in an embodiment of the present invention. Figure 1As shown, the network architecture may include user equipment (UE), (radio) access network (R)AN) equipment, user plane function (UPF) network element, data network (DN), session management function (SMF) network element, access and mobility management function (AMF) network element, unified data management (UDM) network element, authentication server function (AUSF) network element, network slice selection function (NSSF) network element, policy control function (PCF) network element, application function (AF) network element, network slice selection support information (NSSAI) network element, network data analysis function (NWDAF) network element, network exposure function (NEF) network element and network storage function (NRF) network element.
[0172] UE, which may also be called terminal equipment, mobile station (MS), mobile terminal (MT), etc., is a device that provides voice and / or data connectivity to users. The terminal device may be a handheld terminal, a laptop computer, a subscriber unit, a cellular phone, a smart phone, a wireless data card, a personal digital assistant (PDA) computer, a tablet computer, a wireless modem, a handheld device, a laptop computer, a cordless phone or a wireless local loop (WLL) station, a machine type communication (MTC) terminal, a wearable device (such as a smart watch, a smart bracelet, a pedometer, etc.), an in-vehicle device (such as a car, a bicycle, an electric car, an airplane, a ship, a train, a high-speed rail, etc.), a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a smart home device (such as a refrigerator, a television, an air conditioner, an electric meter, etc.), an intelligent robot, a workshop device, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a smart grid, etc. The invention relates to wireless terminals in a network, a wireless terminal in a transportation safety grid, a wireless terminal in a smart city, a wireless terminal in a smart home, flying equipment (for example, smart robots, hot air balloons, drones, airplanes), or other devices that can access the network. Figure 1 The terminal device is shown as UE, which is only an example and does not limit the terminal device. The UE can access the DN by establishing a session between the UE-(R)AN device-UPF-DN, that is, a protocol data unit (PDU) session.
[0173] (R)AN equipment provides wireless access for UEs and is primarily responsible for air interface-side functions such as radio resource management, quality of service (QoS) flow management, data compression, and encryption. The (R)AN can communicate directly with the UE through the AS. (R)AN equipment can include various types of base stations, such as macro base stations, micro base stations (also known as small cells), relay stations, and access points. (R)AN equipment can also include wireless fidelity (WiFi) access points (APs). (R)AN equipment can also include worldwide interoperability for microwave access (WiMax) base stations (BSs). The (R)AN can be a network-side device in a 5G network or a network beyond 5G, or a network device in a PLMN network, such as a next-generation base station (gNB), a next-generation-evolved base station (ng-eNB), or a long-term evolution base station (eNB).
[0174] The AMF network element can access the UE's non-access stratum (NAS) signaling (including mobility management (MM) signaling and session management (SM) signaling) through the N1 interface and the RAN signaling through the N2 interface to complete the forwarding of the UE's SM signaling and mobility management.
[0175] The SMF network element is primarily responsible for session management in mobile networks, such as session establishment, modification, release, and update processes. Specific functions include allocating IP addresses to users and selecting UPF network elements that provide message forwarding capabilities. Messages between the SMF and the UE can be encapsulated in the session management (SM) container of the NAS message. The AMF can extract the SM container content from the NAS message and then send it to the SMF.
[0176] The PCF network element is responsible for terminal device policy management, including mobility-related policies and PDU session-related policies, such as QoS policies and billing policies. The PCF can manage user session policies.
[0177] The AF network element mainly supports interaction with the 3rd Generation Partnership Project (3GPP) core network to provide services, affecting service flow routing, access network capability exposure, policy control, etc.
[0178] The UDM network element is responsible for user key management, user identity processing, access authorization of subscription data, UE network function entity management, session and service continuity management, short message push, lawful interception, contract management, short message management, and is used to control user data, such as contract information management.
[0179] The UPF network element is primarily responsible for user message processing, such as forwarding and billing. It can receive user messages from the DN and transmit them to the UE via RAN equipment. It can also receive user messages from the UE via RAN equipment and forward them to the DN. The transmission resources and scheduling functions that the UPF network element provides to the UE are managed and controlled by the SMF network element.
[0180] A DN can be the internet, an IP Multimedia Service (IMS) network, or a local area network (e.g., a multi-access edge computing (MEC) network). The DN is the destination for a UE's PDU session access. The DN includes or deploys an application server, which can communicate with the UE and provide services to the UE.
[0181] The AUSF network element may be responsible for authenticating and authorizing UE access.
[0182] The data transmission network element is mainly responsible for processing user messages and can be a RAN device or a UPF network element.
[0183] The above network elements in the core network can also be called functional entities, that is, they can be network elements implemented on dedicated hardware, software instances running on dedicated hardware, or instances of virtualized functions on an appropriate platform. For example, the above virtualization platform can be a cloud platform.
[0184] It should be noted that Figure 1 The system architecture shown is not limited to including only the network elements shown in the figure, but may also include other devices or network elements not shown in the figure, which will not be listed one by one in this application.
[0185] It should be noted that the embodiment of the present application does not limit the distribution form of each network element in the core network. Figure 1 The distribution form shown is only exemplary and is not limited in this application.
[0186] It should be understood that the names of all network elements in this application are only examples. In future communications, such as 6G, they may also be called other names, or in future communications, such as 6G, the network elements involved in this application may also be replaced by other entities or devices with the same functions, etc., and this application does not limit this. A unified explanation is given here and no further details will be given later.
[0187] It should be noted that Figure 1 The 5G network architecture shown does not constitute a limitation on the 5G network. Optionally, the method of the embodiment of the present application is also applicable to various future communication systems, such as 6G or other communication networks.
[0188] In addition, the above network structure may further include an authentication authorization and accounting (AAA) network element, which can complete the authentication of the access terminal device.
[0189] In order to better understand the embodiments of the present application, the application scenarios of the embodiments of the present application are described below.
[0190] In a PNI-NPN scenario, three roles can exist: the terminal device (e.g., a company computer used by Volkswagen employees), the PLMN (e.g., China Mobile), and the NPN (e.g., Volkswagen). The terminal device can simultaneously access public and private network services through the PLMN. For example, a terminal device can use instant messaging applications and email simultaneously. Considering the security of 5G networks, the terminal device can provide security protection with the access network. Specifically, a set of security contexts can be used to protect communications between the UE and (R)AN devices, thereby ensuring the security of user-plane data flows between the user and the network.
[0191] In order to facilitate understanding of this application, the relevant technical knowledge involved in the embodiments of this application is first introduced here.
[0192] The security context is a context that can be used to securely protect the communication content. The security protection may include confidentiality protection and / or integrity protection. The context contains at least a security key and a security algorithm. Optionally, the context may also include a security policy, a security activation indication, a freshness parameter, etc. When the communication content is a communication service, the security key used for confidentiality protection may be Kup-enc, the security algorithm used for confidentiality protection may be the 5G encryption algorithm (encryption algorithm for 5G, NEA) or the EPS encryption algorithm (evolved packet system encryption algorithm, EEA), the security key used for integrity protection may be Kup-int, and the security algorithm used for integrity protection may be the 5G integrity algorithm (intergrity algorithm for 5G, NIA) or the EPS integrity algorithm (evolved packet system integrity algorithm, EIA). The communicating party may configure the security key and security algorithm to the PDCP layer. The sender may use the security key and security algorithm to encrypt and / or integrity protect the sent communication content. The receiver may use the same security key and security algorithm to decrypt and / or integrity check the received communication content.
[0193] Communication services are user-plane traffic between terminal devices and server-provided services over the mobile network. These services can include public and / or private network services. Public network services represent publicly accessible services provided by servers, such as applications provided by service providers. Private network services represent restricted-access services provided by servers, such as enterprise-owned operational applications. Terminal devices may need to establish different sessions with the mobile network for different services.
[0194] The encryption key kup-enc and the encryption algorithm can be used between the UE and the (R)AN device to encrypt and protect the user plane traffic, and the integrity protection key kup-int and the integrity protection algorithm can be used to protect the integrity of the user plane traffic. The security key may include an encryption key and an integrity protection key, and the security algorithm may include an encryption algorithm and an integrity protection algorithm. The security context may include a security key and / or a security algorithm. User plane traffic can be sent through different data radio bearers (DRBs), and different DRBs may have encryption protection or integrity protection enabled or disabled. When DRB protection is enabled, the keys and algorithms used by all DRBs with protection enabled are the same, that is, all terminal devices and access network devices can use the same set of security contexts for communication protection. At this time, when an attacker obtains the security key used for the public network service, he also obtains the security key of the private network service, thereby obtaining the service traffic of the private network, and vice versa. For example, an attacker can obtain the security key used by the public network service by cracking the security algorithm used by the public network service, thereby obtaining the security context of the public network service. If an attacker obtains the security context of the public network, they can also obtain the security context of the private network, and then use the private network security context to obtain the private network's service traffic. The above protection method does not achieve the secure isolation of public network service protection and private network service protection. Therefore, how to achieve the secure isolation of public network service and private network service in PNI-NPN is an urgent technical problem to be solved.
[0195] Based on the above network architecture, please refer to Figure 2 , Figure 2 This is a flow chart of a security context generation method disclosed in an embodiment of the present invention. Figure 2 As shown, the security context generating method may include the following steps.
[0196] 201. The terminal device obtains a first security context.
[0197] When a terminal device needs to protect data, the terminal device may generate a first security context so that the data can be securely protected using the first security context. The first security context may include a first security key and / or a first security algorithm. The first security key may include a first encryption key and / or a first integrity protection key. The first security algorithm may include a first encryption algorithm and / or a first integrity protection algorithm. The first security context may protect a first communication service of the terminal device. The first communication service may be a public network service or a private network service. It should be understood that the above-mentioned data may be user plane data.
[0198] After the terminal device registers with the PLMN and requests to establish a session for the first communication service, the terminal device and the access network device can obtain a first security context for protecting the first communication service and can use the first security context to protect the first communication service. The process for the terminal device to obtain the first security context can be referred to the relevant description in 3GPP TS 33.501.
[0199] 202. The terminal device sends a session request message to the session management function network element.
[0200] The terminal device may send a session request message to the session management function network element. Correspondingly, the session management function network element may receive the session request message from the terminal device. Specifically, the terminal device may first send a NAS message to the access and mobility management network element. The NAS message may include an SM message. After receiving the NAS message from the terminal device, the access and mobility management function network element may first extract the SM message from the NAS message and then send the SM message to the session management function network element. The session request message may be an SM message. The SM message may be a PDU session proposal request message or a PDU session modification request message. The session request message may be used to request establishment of a session for the second communication service. The NAS message may include a DNN and / or NSSAI. The access and mobility management network element may extract the DNN and / or NSSAI from the NAS message and send it to the session management function network element. In addition, when the data transmission network element is a user plane function network element, the session request message may include an identifier of the terminal device. The identifier of the terminal device may be used to identify the user plane function network element. It should be understood that the session request message refers to completing the session request to establish the second communication service, and the name of this message is not limited.
[0201] The session request message may include first indication information, which may indicate that the terminal device supports the generation of a second security context. That is, it can be understood that the first indication information may indicate that the terminal device supports the generation of a second security context, the first indication information may also be used to request the generation of a second security context, and the first indication information may also be used to indicate that the session requires secure isolation. The second security context may include a second security algorithm and / or a second security key. The second security algorithm may include a second encryption algorithm and / or a second integrity protection algorithm. The second security key may include a second encryption key and / or a second integrity protection key.
[0202] The first communication service and the second communication service are different communication services. The second communication service can be a public network service or a private network service. When the first communication service is a public network service, the second communication service can be a private network service; when the first communication service is a private network service, the second communication service can be a public network service.
[0203] The first and second security contexts are different security contexts. This can be understood as follows: the second security key is different from the first security key, but the second security algorithm is the same as the first security algorithm; the second security algorithm is different from the first security algorithm, but the second security key is the same as the first security key; or the second security key is different from the first security key and the second security algorithm is different from the first security algorithm. The second security context can protect a second communication service, while the first and second security contexts can protect different communication services.
[0204] 203. The session management function network element sends an additional security context indication to the data transmission network element.
[0205] After receiving the session request message from the terminal device, the session management function network element may first determine whether a second security context needs to be generated for the terminal device. If it is determined that the terminal device needs to generate a second security context, the session management function network element may send an additional security context indication to the data transmission network element. Correspondingly, the data transmission network element may receive the additional security context indication from the session management function network element. If it is determined that the terminal device does not need to generate a second security context, steps 203 to 207 may not be performed.
[0206] In one possible implementation, after receiving a session request message from a terminal device, the session management function network element may determine whether the terminal device supports the generation of a second security context based on the first indication information. In one embodiment, when the first indication information is an explicit indication, the session management function network element may determine whether the session request message includes the first indication information. When it is determined that the session request message includes the first indication information, it indicates that the terminal device supports the generation of a second security context. When it is determined that the session request message does not include the first indication information, it indicates that the terminal device does not support the generation of a second security context. In another embodiment, the first indication information is an implicit indication. For example, the session request message may include 1 bit. When this bit is a specific value, such as 0 or 1, it indicates that the terminal device supports the generation of a second security context. When this bit is not the above-mentioned specific value or does not include the above-mentioned specific value, it indicates that the terminal device of the session request message does not support the generation of a second security context.
[0207] Another possible implementation method is that after the session management function network element receives the session request message from the terminal device, it can obtain the contract information of the terminal device, and then determine whether the terminal device needs to generate a second security context based on the contract information. When the contract information includes the second indication information, it indicates that the terminal device needs to generate a second security context. Otherwise, it indicates that the terminal device does not need to generate a second security context. The second indication information may indicate that the terminal device supports the generation of a second security context, that is, indicates that the terminal device supports the generation of a second security context, or the second indication information is used to request the generation of a second security context, or the second indication information is used to indicate that the session needs to implement security isolation. The session management function network element can obtain the contract information of the terminal device from the UDM network element or the PCF network element.
[0208] In another possible implementation, the session management function network element may be pre-configured or configured by default with a local policy. Therefore, after receiving a session request message from a terminal device, it may be determined whether the terminal device needs to generate a second security context based on the relevant information of the session and the local policy. For example, if the local policy is that a different security context needs to be used for protection of a specific session, then after the session management function network element receives the DNN and / or NSSAI from the terminal device, it may be determined based on the local policy whether the service corresponding to the DNN and / or NSSAI needs to be protected using a different security context. If it is determined that a different security context is needed, the session management function network element determines that a second security context needs to be generated for the UE.
[0209] It should be understood that the session management function network element can determine whether it is necessary to generate a second security context through one or more of the above methods. That is, it can determine whether the terminal device supports the generation of the second security context through the first indication information. When it is determined through the first indication information that the terminal device supports the generation of the second security context, it is determined that the second security context needs to be generated. It can also determine whether it is necessary to generate the second security context through the contract information. It can also determine whether it is necessary to generate the second security context through the local policy. It can also determine whether it is necessary to generate the second security context through the first indication information and the contract information. When the first indication information determines that the terminal device supports the generation of the second security context, and the contract information determines that the second security context needs to be generated, it is determined that the second security context needs to be generated. It can also determine whether it is necessary to generate the second security context through the first indication information and the local policy. When the first indication information determines that the terminal device supports the generation of the second security context, and the local policy determines that the second security context needs to be generated, it is determined that the second security context needs to be generated.
[0210] The additional security context indication can be used to indicate the generation of a second security context. The additional security context indication can be indicated explicitly. For example, the additional security context indication can include 1 bit. When the value of this bit is 1, it can indicate the generation of a second security context. When the value of this bit is 0, it can indicate that the second security context is not generated. The additional security context indication can also be indicated implicitly. For example, the additional security context indication can be an information element required to generate a second security context, such as a key, algorithm, flag, indicator, index, transmission resource, etc., to send the additional security context indication to the data transmission network element. For example, when the data transmission network element receives the key, it indicates that the session management function network element instructs the data transmission network element to generate a second security context.
[0211] Optionally, after the session management function network element determines that a second security context needs to be generated for the terminal device, it may determine a security algorithm.
[0212] In one possible implementation method, the session management function network element can pre-configure the mapping relationship between the DNN and the security algorithm. When it is determined that the terminal device needs to generate a second security context, the security algorithm used by it can be directly found based on the DNN reported by the terminal device and the above mapping relationship.
[0213] In another possible implementation, the session management function network element can pre-configure a mapping relationship between the DNN and the algorithm priority list. When it is determined that the terminal device needs to generate a second security context, the algorithm priority list can be found based on the DNN reported by the terminal device and the above mapping relationship. The security algorithm to be used is then obtained based on the terminal device's security capabilities and the algorithm priority list. The algorithm priority list is a list of algorithms that reflects the priority of use and can be expressed as Priority 1: Algorithm B, Priority 2: Algorithm A, Priority 3: Algorithm C. The lower the priority number, the higher the priority. The security capabilities of the terminal device are reported by the terminal device and can indicate the algorithms that the terminal device can support. For example: Algorithm A, Algorithm B, Algorithm C. Since the terminal device supports Algorithm A, B, and C at the same time, but Algorithm B has the highest priority, Algorithm B is ultimately selected as the security algorithm.
[0214] After the session management function network element determines the security algorithm, the additional security context indication may include the identifier of the security algorithm.
[0215] Optionally, after the session management function network element determines that a second security context needs to be generated for the terminal device, the first key may be determined.
[0216] The first key may also be obtained according to a secondary authentication key, wherein the session management function network element receives the secondary authentication key from the authentication, authorization and accounting network element.
[0217] The session management function network element can generate a first key based on the secondary authentication key and the second derived parameter. The session management function network element can trigger secondary authentication of the terminal device. For example, when the session management function network element confirms that a second security context needs to be generated, the session management function network element can trigger secondary authentication between the terminal device and the authentication, authorization, and billing network element based on the contract information of the DNN and the terminal device. After the secondary authentication of the terminal device is successful, the authentication, authorization, and billing network element can send the secondary authentication key to the session management function network element. The session management function network element can receive the secondary authentication key from the authentication, authorization, and billing network element. The second derived parameter can be a freshness parameter, and the second derived parameter can include one or more of the uplink or downlink NAS COUNT, NSSAI, DNN, and PDU session ID. The NAS COUNT can be stored in the non-access stratum context of the terminal device and updated each time the key is derived, which can prevent the first key generated twice in a row from being the same. For example, assuming the value of the NAS COUNT is a, after using the NAS COUNT for one derivation, the NAS COUNT can be updated to a+b. Therefore, the updated NAS COUNT value can be used for the second derivation. b can be 1, 2, or other values, which are not limited here. The value of b can be the same each time it is updated, that is, the value of NAS COUNT is incremented or decremented in steps of b, or it can be different. The session management function network element can obtain NSSAI, DNN, and PDU session ID from the terminal device through a session request message. Since different terminal devices or session management network elements access different slices (NSSAI identifier), data networks (DNN identifier), and PDU sessions (PDU session ID identifier), the generated first keys can be different.
[0218] After the session management function network element determines the first key, the additional security context indication may include the first key.
[0219] It should be understood that different methods for generating the second security context require different information for generating the second security context. Therefore, the additional security context indication may include different information depending on the method for generating the second security context. For example, the additional security context indication may be an explicit indication, an identifier of the security algorithm, or a first key. The additional security context indication may also include an explicit indication and an identifier of the security algorithm, or may include the first key and an identifier of the security algorithm.
[0220] The session management function network element may send an additional security context indication to the data transmission network element through different messages, signaling, etc. For example, when the data transmission network element is an access network device, the session management function network element may encapsulate the additional security context indication in an N2SM information container and send it to the data transmission network element; when the data transmission network element is a user plane function network element, the session management function network element may encapsulate the additional security context indication in an N4 session establishment request message and send it to the data transmission network element.
[0221] 204. The data transmission network element obtains a second security context according to the additional security context indication.
[0222] After receiving the additional security context indication from the session management function network element, the data transmission network element may obtain the second security context according to the additional security context indication.
[0223] The data transmission network element can obtain the security algorithm according to the additional security context indication.
[0224] In one possible implementation, an algorithm priority list may be pre-configured in the data transmission network element. The algorithm priority list may include the security capabilities of the terminal device and the priority information of the security algorithm. The data transmission network element may determine the security algorithm based on the algorithm priority list. The data transmission network element may obtain the security capabilities of the terminal device from the stored context of the terminal device. When the data transmission network element has a first security context, since the data transmission network element needs to generate a first security algorithm and a second security algorithm for the same terminal device, in order to ensure that the first security algorithm and the second security algorithm are different, the algorithm priority lists corresponding to the first security algorithm and the second security algorithm need to be different. For the same terminal device, the data transmission network element uses the same algorithm priority list, which may very likely result in the final determined first security algorithm and the second security algorithm being the same, thereby failing to achieve the purpose of security isolation. It should be understood that the security algorithm obtained according to the additional security context indication is the second security algorithm.
[0225] In another possible implementation manner, when the additional security context indication includes an identifier of a security algorithm, the data transmission network element may determine the security algorithm corresponding to the identifier as the security algorithm.
[0226] In another possible implementation manner, when the data transmission network element has the first security context, the data transmission network element may obtain the security algorithm from the first security algorithm of the first security context according to the additional security context indication.
[0227] The data transmission network element may obtain the security key based on the first key according to the additional security context indication. It can be understood that the additional security context indication may trigger the data transmission network element to obtain the security key based on the first key. It can also be understood that the data transmission network element may obtain the security key based on the first key in response to the additional security context indication.
[0228] In one case, the data transmission network element may first determine the first key, and then obtain the security key based on the first key.
[0229] When the data transmission network element has the first security context, the data transmission device can obtain the first key based on the AS root key of the first security context according to the additional security context indication, that is, determine (or generate) the first key based on the AS root key of the first security context. The AS root key can be the key K gNB , or K eNB , can also be the next hop (nexthop, NH).
[0230] In one embodiment, the data transmission network element may use the AS root key of the first security context as the first key.
[0231] In another manner, the data transmission network element may generate a first key based on the AS root key of the first security context and the first derived parameter. The first derived parameter may be a PDCP COUNT, which may be stored in the access layer context of the terminal device. Each time the data transmission network element uses the PDCP COUNT, the value of the PDCP COUNT needs to be updated, that is, the value of the PDCP COUNT is updated each time a key is derived, so as to prevent the same key from being generated twice in a row. For example, assuming that the value of the PDCP COUNT is a, after using the PDCP COUNT for derivation once, the value of the PDCP COUNT may be updated to a+b, so that the updated value of the PDCP COUNT may be used for the next derivation. b may be 1, 2, or other values, which are not limited here. The value of b may be the same each time it is updated, that is, the value of the PDCP COUNT may be increased or decreased in steps of b, or it may be different. It should be understood that the first derived parameter may be a freshness parameter. By updating the value of the PDCP COUNT, the security key generated each time may be different, thereby improving the security of the key and achieving a secure isolation effect.
[0232] When the data transmission network element is configured with a correspondence between the terminal device's identifier and the Kn root key, and the additional security context indication can carry the terminal device's identifier, the data transmission network element can obtain the first key based on the terminal device's identifier, that is, determine (or generate) the first key based on Kn. The Kn root key should be different for each terminal device and can be pre-configured on the data transmission network element. The data transmission network element can determine the Kn root key based on the terminal device's identifier and the correspondence between the terminal device and the Kn root key.
[0233] In one approach, the data transmission network element may use the Kn root key as the first key.
[0234] In another embodiment, after the data transmission network element determines the Kn root key, it can generate the first key based on the Kn root key and the first derived parameter. For a detailed description of generating the first key, refer to the above description of the data transmission network element generating the first key based on the AS root key and the first derived parameter, and will not be repeated here.
[0235] In another case, the additional security context indication may include the first key. The data transmission network element may first extract the first key from the additional security context indication, and then generate a security key based on the first key.
[0236] After the data transmission network element determines the first key, a security key may be further generated based on the first key.
[0237] Optionally, the data transmission network element may generate a security key according to the first key and the third derived parameter.
[0238] The third derived parameter may include the identifier and type of the security algorithm. In this case, the data transmission network element may determine the identifier and type of the security algorithm based on the obtained security algorithm.
[0239] Optionally, the data transmission network element may obtain a security algorithm according to the additional security context indication, and determine the identifier and type of the security algorithm according to the obtained security algorithm.
[0240] Optionally, when the data transmission network element has the first security context, the data transmission network element may obtain a security algorithm according to the first security algorithm of the first security context, and determine the identifier and type of the security algorithm according to the obtained security algorithm.
[0241] The security algorithm identifier can be used to identify the obtained security algorithm. For example, the encryption algorithm can be EEA1, NEA1, etc., and the integrity algorithm can be EIA1, NIA1, etc.
[0242] The security algorithm type can be set to different values depending on the scenario in which the current algorithm is used. For example, when the security algorithm is used for user plane confidentiality protection, the security algorithm type can be set to the value 0x05 corresponding to N-UP-ENC-ALG. When the security algorithm is used for user plane integrity protection, the security algorithm type can be set to the value 0x06 corresponding to N-UP-INT-ALG. Therefore, the security algorithm type can be either 0x05 or 0x06. Furthermore, the security algorithm type can also be a value different from the existing values 0x01-0x06 to indicate that the security algorithm is used for user plane confidentiality protection or user plane integrity protection of the second communication service. For example, when the current algorithm is used for user plane confidentiality protection of the second communication service, the security algorithm type can be 0x07. When the current algorithm is used for user plane integrity protection of the second communication service, the security algorithm type can be 0x08. The data transmission network element can generate a security key based on the first key and the identifier and type of the security algorithm. The specific method for generating the first key can be detailed in the above-mentioned related description and is not further elaborated here.
[0243] Optionally, the data transmission network element may also generate a security key based on the first key and a special character string. The special character string may be a pre-configured specific character string, such as "NPN", "Secondary", etc.
[0244] The introduction of a special string distinguishes the security algorithm type from the existing 0x01-0x06 and serves as a key derivation parameter to generate a second encryption key and a second integrity protection key. This ensures that even if the obtained security algorithm is the same as the first security algorithm and the obtained first key is the same as the AS root key of the first security context, the obtained security key is still different from the first security key. This can be understood as the first encryption key being different from the second encryption key, the first integrity protection key being different from the second integrity protection key, and the first integrity protection key being different from the second integrity protection key. This prevents the first security context from being the same as the second security context, ensures the effectiveness of security isolation, and thus, the security of communication services.
[0245] It should be understood that the method for determining the security algorithm and the method for generating the security key may be related to each other or may be independent.
[0246] 205. The data transmission network element sends an additional generation indication to the terminal device.
[0247] The additional generation indication can be used to indicate the generation of a second security context. The additional generation indication can be indicated explicitly. For example, the additional generation indication may include 1 bit. When the value of this bit is 1, it can indicate the generation of a second security context. When the value of this bit is 0, it can indicate that the second security context is not generated. The additional generation indication can also be indicated implicitly. For example, the additional generation indication can be an information element required to generate the second security context, such as an algorithm, a flag bit, an indicator, an index, a transmission resource, etc., to send the additional generation indication to the terminal device. For example, when the terminal device receives the indicator, it indicates that the data transmission network element instructs the terminal device to generate a second security context.
[0248] After the data transmission network element determines the security key, the additional generation indication can also be used to instruct the terminal device to obtain the security key. In this case, the additional generation indication can include an indication of the first derived parameter. The indication of the first derived parameter can be the first derived parameter itself, or it can be used to indicate the value of the first derived parameter. For example, if the second derived parameter includes PDCP COUNT, then the indication of the first derived parameter can include some bits of PDCP COUNT.
[0249] After the data transmission network element determines the security algorithm, the additional generation instruction can also be used to instruct the terminal device to obtain the security algorithm. In this case, the additional generation instruction may include the identifier of the security algorithm.
[0250] It should be understood that the method for determining the second security context is not unique. Different determination methods may result in different additional security context indications received and additional generation indications sent by the data transmission network element. Therefore, the additional generation indication may include different information depending on the second security context generation method. For example, the additional generation indication may be an explicit indication, an indication of the first derived parameter, or an identifier of the security algorithm. The additional security context indication may also include an explicit indication and an identifier of the security algorithm, an indication of the first derived parameter and an identifier of the security algorithm, or an explicit indication, an indication of the first derived parameter, and an identifier of the security algorithm. It should be understood that only when the data transmission network element uses the first derived parameter and / or the third derived parameter to generate the second security context, the additional generation indication will correspond to the packet or the indication of the first derived parameter and / or the identifier of the security algorithm.
[0251] The data transmission network element may directly send the additional generation indication to the terminal device, and may send it via an RRC message. Optionally, the RRC message may be an RRC reconfiguration message.
[0252] The data transmission network element can indirectly send an additional generation indication to the terminal device through the session management function network element. At this time, the additional generation indication can be encapsulated in the N4Session Establishment Response message and sent to the session management function network element, and the session management function network element encapsulates the additional generation indication in the session acceptance message and sends it to the terminal device.
[0253] It should be understood that step 205 is an optional step.
[0254] 206. The session management function network element sends a session acceptance message to the terminal device.
[0255] After receiving the session request message from the terminal device, the session management function network element may establish a session for transmitting the second communication service based on the session request message. After establishing the session, the session management function network element may send a session accept message to the terminal device. Correspondingly, the terminal device may receive the session accept message from the session management function network element. The session accept message may indicate the completion of establishing the session for the second communication service. The session accept message may be a PDU session proposal request message or a PDU session modification request message.
[0256] Optionally, the session accept message may include an additional generation indication, where the additional generation indication is used to instruct the terminal device to generate a second security context.
[0257] After the session management function network element determines the security algorithm, the additional generation instruction can also be used to instruct the terminal device to obtain the security algorithm. In this case, the additional generation instruction can include the security algorithm identifier. It should be understood that the security algorithm identifier can be included in either the session accept message or the additional generation instruction sent by the data transmission network element to the terminal device, or can be included in neither. This does not limit the specific information in which the security algorithm identifier is included.
[0258] After the session management function network element determines the first key, the additional generation indication can also be used to instruct the terminal device to obtain the first key. At this time, the additional generation indication can include an indication of a second derived parameter. The indication of the second derived parameter can be the second derived parameter itself, or it can be a value used to indicate the second derived parameter. For example, if the second derived parameter includes NAS COUNT, then the indication of the second derived parameter can include some bits of NAS COUNT, if the second derived parameter includes NSSAI, DNN and PDU session ID, then the indication of the second derived parameter can include NSSAI, DNN and PDUsession ID itself, or because the terminal device already knows NSSAI, DNN and PDU session ID, then the indication of the second derived parameter can include a specific value, when the value is 1, it is used to instruct the terminal device to obtain NSSAI, DNN and PDUsession ID.
[0259] When the session management function network element receives the additional generation instruction from the data transmission network element, it can forward the additional generation instruction to the terminal device. The session management function network element can encapsulate the additional generation instruction in a session accept message and send it to the terminal device.
[0260] It should be understood that step 205 and step 206 can be executed serially or in parallel, and the execution order is not limited.
[0261] 207. The terminal device obtains an additional generation indication.
[0262] The terminal device can obtain additional generation indications, which can be understood as the terminal device can receive additional generation indications from the data transmission network element and / or the session management network element.
[0263] The terminal device may receive additional generation indications from the data transmission network element.
[0264] In one case, the terminal device can directly receive the additional generation indication from the data transmission network element, that is, the terminal device can receive the additional generation indication from the data transmission device.
[0265] In another case, the terminal device may indirectly receive the additional generation indication from the data transmission network element. That is, the data transmission network element may forward the additional generation indication to the terminal device via the session management function network element. A detailed description can be found in the description of the additional security indication sent by the data transmission network element to the terminal device via the session management network element in step 205, and is not repeated here.
[0266] The terminal device can receive an additional generation indication from the session management function network element, that is, the terminal device can receive an additional generation indication from the session management function.
[0267] The additional generation indication may include one or more of the following: an indication of a first derived parameter, an indication of a second derived parameter, and an identification of a security algorithm.
[0268] It should be understood that since the additional generation indication can include multiple indications, it can be divided into two parts according to the source of reception, one part is obtained from the data transmission network element, and the other part is obtained from the session management network element. Therefore, the terminal device can obtain a part of the additional generation indication from the data transmission network element, and then obtain another part of the additional generation indication from the session management network element. For example, the terminal device can obtain an indication of the first derived parameter and an identifier of the security algorithm from the data transmission network element, and can also obtain an indication of the second derived parameter from the session management function network element. The terminal device can obtain an indication of the first derived parameter from the data transmission network element, and can also obtain an indication of the second derived parameter and an identifier of the security algorithm from the session management function network element. The terminal device can obtain an identifier of the security algorithm from the data transmission network element, and can also obtain an indication of the second derived parameter from the session management function network element.
[0269] 208. The terminal device obtains a second security context according to the additional generation indication.
[0270] After the terminal device obtains the additional generation instruction, it can generate a second security context according to the additional generation instruction. It should be understood that the terminal device generates the second security context in the same way as the data transmission network element generates the second security context. For detailed description, please refer to the relevant description of step 204.
[0271] The terminal device can obtain the security algorithm according to the additional generation indication.
[0272] It should be noted that when the additional generation instruction includes the identifier of the security algorithm, the terminal device can determine the security algorithm based on the identifier. When the additional generation instruction does not include the identifier of the security algorithm, the terminal device can obtain the security algorithm based on the first security algorithm in the first security context.
[0273] The terminal device can obtain the first key according to the additional generation indication.
[0274] When the terminal device has the first security context, the first key can be obtained based on the AS root key of the first security context according to the additional generation indication, that is, the first key is determined based on the AS root key of the first security context.
[0275] In one approach, the terminal device may use the AS root key of the first security context as the first key.
[0276] In another embodiment, the additional generation indication includes an indication of the first derived parameter, and the terminal device may generate the first key based on the AS root key of the first security context and the first derived parameter. For a detailed description, reference may be made to the step 204 in which the data transmission network element generates the first key based on the AS root key of the first security context and the first derived parameter, and no further details are given here.
[0277] The terminal device can be pre-configured with a Kn root key, and the terminal device can generate a first key based on the Kn root key according to an additional generation instruction.
[0278] In one way, the terminal device can use the Kn root key as the first key
[0279] In another embodiment, the additional generation indication includes an indication of the first derived parameter, and the terminal device can generate the first key based on the Kn root key and the first derived parameter. For a detailed description, refer to the description of the data transmission network element generating the first key based on the Kn root key and the first derived parameter in step 204, which is not repeated here.
[0280] After the session management function network element triggers secondary authentication, the terminal device may perform secondary authentication. During the secondary authentication process, the terminal device may generate a secondary authentication key. The terminal device may receive an additional generation instruction, which may include an instruction for a second derived parameter. The terminal device may generate a first key based on the secondary authentication key and the second derived parameter. A detailed description of the generation method can be found in the description of the session management function network element generating the first key based on the secondary authentication key and the second derived parameter in step 203, and is not further elaborated here.
[0281] After the terminal device generates the first key, it can further obtain a security key based on the first key according to the additional generation instruction. The second security context is generated based on the first key. The specific generation method can be the same as the generation method of the data transmission network element in step 204.
[0282] The additional generation indication includes an identifier of the security algorithm, and the terminal device can generate a security key based on the first key and the third derived parameter. For detailed description, please refer to the description of the data transmission network element generating the security key based on the first key and the third derived parameter in step 204, which is not repeated here.
[0283] It should be understood that the second security context can be generated by the terminal device and the data transmission network element. The data transmission network element can be an access network device, a user plane function network element, or other network elements with the same function. That is, it can be understood that a set of security contexts can be generated by two devices, wherein, when the data transmission network element has the first security context, the first security context and the second security context can both be generated by the terminal device and the data transmission network element. When the data transmission network element does not have the first security context, the second security context can be obtained by the terminal device and the data transmission network element. At this time, the two sets of security contexts are in different devices. Since the two sets of security contexts have different algorithms and / or keys and are in different network elements, security isolation can be further achieved.
[0284] After receiving the session acceptance message from the session management function network element, the terminal device can determine that the second communication service has been established based on the session acceptance message. It can then transmit the service corresponding to the second communication service with the data network, and the transmitted second communication service can be protected using the second security context. As can be seen, when the public network service is attacked, the impact on the private network service can be avoided, and vice versa. Therefore, the public network service and the private network service can be securely isolated, thereby improving the security of the public network service and the private network service.
[0285] Based on the above network architecture, please refer to Figure 3 , Figure 3 This is a flow chart of another security context generation method disclosed in an embodiment of the present invention. Figure 3 As shown, the security context generating method may include the following steps.
[0286] 301. The terminal device obtains a first security context.
[0287] The detailed description of step 301 can refer to the description of step 201 and will not be repeated here.
[0288] 302. The access network device obtains a first security context.
[0289] The detailed description of step 302 can refer to the description of step 201 and will not be repeated here.
[0290] 303. The terminal device sends a session request message to the session management function network element.
[0291] The detailed description of step 303 can refer to the description of step 202 and will not be repeated here.
[0292] 304. The session management function network element sends an additional security context indication to the access network device.
[0293] The detailed description of step 304 can refer to the description of step 203 and will not be repeated here.
[0294] It should be understood that when the session management function network element has determined the security algorithm, the additional security context indication may also include an identifier of the security algorithm.
[0295] 305. The access network device obtains a second security context according to the additional security context indication.
[0296] After receiving the additional security context indication from the session management function network element, the access network device can generate a second security context according to the additional security context indication. For a detailed description of generating the second security context, please refer to the description of step 204.
[0297] The access network device can obtain the security algorithm according to the additional security context indication.
[0298] In one possible implementation, when the additional security context indicates support for generating a second security context, the access network device may obtain a security algorithm according to the algorithm priority list. Detailed descriptions may refer to the relevant descriptions in step 204 and are omitted here.
[0299] In another possible implementation, the additional security context indication may include a security algorithm identifier, and the access network device may determine the security algorithm based on this identifier. The security algorithm may have already been determined in the session management function network element. For detailed descriptions, refer to the corresponding descriptions of the session management function network element determining the security algorithm in step 203 and determining the security algorithm based on the additional security context indication in step 204, and are not repeated here.
[0300] In another possible implementation manner, the access network device may obtain the security algorithm from the first security algorithm of the first security context according to the additional security context indication.
[0301] The access network device may generate the first key according to the additional security context indication.
[0302] In one possible implementation, the access network device may obtain the AS root key of the first security context and use the AS root key as the first key. For a detailed description, please refer to the relevant description in step 204 and will not be repeated here.
[0303] In another possible implementation, the access network device may generate the first key based on the AS root key of the first security context and the first derived parameter. Detailed descriptions may refer to the relevant descriptions in step 204 and are not repeated here.
[0304] Furthermore, the access network device may generate a security key based on the first key according to the additional security context indication.
[0305] The access network device can generate a security key based on the first key and the third derived parameter. For a detailed description of generating the security key, please refer to the description of generating the security key based on the first key and the third derived parameter in step 204, which will not be repeated here.
[0306] 306. The session management function network element sends a session acceptance message to the terminal device.
[0307] The detailed description of step 306 can refer to the description of step 206 and will not be repeated here.
[0308] It should be understood that when the session management function network element has determined the security algorithm, the session accept message may include an additional generation indication, and the additional generation indication may include an identifier of the security algorithm.
[0309] 307. The access network device sends an additional generation indication to the terminal device.
[0310] The access network device may send an additional generation instruction to the terminal device, and correspondingly, the terminal device may receive the additional generation instruction from the access network device. For detailed descriptions, please refer to the descriptions of steps 205 to 207, which will not be repeated here.
[0311] It should be noted that the additional generation indication may include one or more of the following: an explicit indication, an indication of the first derived parameter, and an identifier of the security algorithm.
[0312] It should be understood that in step 306 and step 307, one of the messages includes the identifier of the security algorithm.
[0313] 308. The terminal device obtains a second security context according to the additional generation indication.
[0314] For a detailed description of step 308 , reference may be made to the descriptions of steps 305 and 208 .
[0315] The terminal device can obtain the security algorithm according to the additional generation indication.
[0316] The additional generation instruction may include an identifier of the security algorithm. The terminal device may determine the security algorithm based on this identifier. The terminal device may also obtain the security algorithm based on the first security algorithm of the first security context. For a detailed description, please refer to the relevant description of step 208 and will not be repeated here.
[0317] The terminal device may generate the first key according to the additional generation instruction.
[0318] In one possible implementation, the terminal device may obtain the AS root key of the first security context and use the AS root key as the first key. For detailed description, please refer to the relevant descriptions in step 208 and step 305, which will not be repeated here.
[0319] In another possible implementation, when the additional generation instruction includes an instruction for the first derived parameter, the terminal device may generate the first key based on the AS root key of the first security context and the first derived parameter. For a detailed description, reference may be made to the description of generating the first key based on the AS root key and the first derived parameter in steps 204, 208, and 305, which will not be repeated here.
[0320] Furthermore, the terminal device may generate a security key based on the first key according to the additional generation indication.
[0321] When the additional generation instruction includes the identifier of the security algorithm, the terminal device may generate the security key based on the first key and the third derived parameter. The third derived parameter may be the identifier of the security algorithm. For a detailed description of generating the security key, refer to the description of generating the security key based on the first key and the third derived parameter in steps 204, 208, and 305, and are not repeated here.
[0322] At this point, the terminal device can protect user plane data using the first security context and the second security context. The first security context and the second security context can be used to protect private network services (public network data) and public network services (private network data), respectively. If an attacker obtains one set of security contexts, the other set of security contexts will not be exposed because the two security contexts are different. This achieves the goal of protecting both public network services and private network services separately, improving the security of communication services.
[0323] It should be understood that the data transmission network element in this embodiment is an access network device.
[0324] Based on the above network architecture, please refer to Figure 4 , Figure 4 This is a flow chart of another security context generation method disclosed in an embodiment of the present invention. Figure 4 As shown, the security context generating method may include the following steps.
[0325] 401. The terminal device obtains a first security context.
[0326] The detailed description of step 401 can refer to the description of step 201 and will not be repeated here.
[0327] 402. The access network device obtains a first security context.
[0328] The detailed description of step 402 can refer to the description of step 201 and will not be repeated here.
[0329] 403. The terminal device sends a session request message to the session management function network element.
[0330] The detailed description of step 403 can refer to the description of step 202 and will not be repeated here.
[0331] 404. The terminal device performs secondary authentication.
[0332] The session management function network element can trigger secondary authentication between the terminal device and the authentication, authorization, and billing network element based on the DNN and / or terminal device subscription information carried in the session request message. The terminal device subscription information can be obtained by requesting the UDM. For example, when the DNN is a specific DNN, or when the terminal device subscription information indicates that secondary authentication needs to be triggered, the session management function network element can trigger secondary authentication.
[0333] A terminal device can obtain a secondary authentication key through secondary authentication. Secondary authentication can be implemented based on the Extensible Authentication Protocol (EAP). The terminal device and the authentication, authorization, and billing network element can generate a secondary authentication key. The secondary authentication key can be a master session key (MSK) or an extended master session key (EMSK).
[0334] The secondary authentication process can be found in 3GPP TS 33.501 and RFC 3748.
[0335] After the authentication authorization accounting network element completes the secondary authentication, the authentication authorization accounting network element may send a secondary authentication key to the session management function network element. Correspondingly, the session management function network element may receive the secondary authentication key from the authentication authorization accounting network element.
[0336] 405. The session management function network element generates a first key based on the secondary authentication key.
[0337] The session management function network element may first determine whether a second security context needs to be generated. Detailed descriptions may refer to the description of the session management function network element determining whether the terminal device needs to generate a second security context in step 203, which will not be repeated here.
[0338] When the session management function network element determines that a second security context needs to be generated, the session management function network element may determine a security algorithm. Detailed description of the process of the session management function network element determining the security algorithm generation process can be found in the relevant description of step 203 and will not be repeated here.
[0339] When the session management function network element determines that a second security context needs to be generated, the session management function network element may generate a first key based on the received secondary authentication key. The session management function network element may generate the first key based on the second derived parameter and the secondary authentication key. A detailed description of the generation process can be found in the relevant description of step 203 and is not repeated here.
[0340] 406. The session management function network element sends an additional security context indication to the access network device.
[0341] The detailed description of step 406 can refer to the description of step 203 and will not be repeated here.
[0342] It should be noted that the additional security context indication includes at least the first key.
[0343] It should be understood that when the session management function network element has determined the security algorithm, the additional security context indication may also include an identifier of the security algorithm.
[0344] 407. The access network device obtains a second security context according to the additional security context indication.
[0345] After receiving the additional security context indication from the session management function network element, the access network device can obtain the second security context according to the additional security context indication. For a detailed description of generating the second security context, please refer to the description of step 204.
[0346] The access network device can obtain the security algorithm according to the additional security context indication.
[0347] In one possible implementation, when the additional security context indicates support for generating a second security context, the access network device may obtain a security algorithm according to the algorithm priority list. Detailed descriptions may refer to the relevant descriptions in step 204 and are omitted here.
[0348] In another possible implementation, the additional security context indication may include a security algorithm identifier, and the access network device may determine the security algorithm based on this identifier. The security algorithm may be determined by the session management function network element. For detailed descriptions, please refer to the corresponding descriptions of steps 203 and 204 and are not repeated here.
[0349] In another possible implementation manner, the access network device may obtain the security algorithm from the first security algorithm of the first security context according to the additional security context indication.
[0350] The access network device may generate the first key according to the additional security context indication.
[0351] The additional security context indication may include the first key, and the access network device may directly obtain the first key. For detailed description, please refer to the relevant description in step 204, which will not be repeated here.
[0352] Furthermore, the access network device may generate a security key based on the first key according to the additional security context indication.
[0353] The access network device can generate a security key based on the first key and the third derived parameter. For a detailed description of generating the security key, please refer to the relevant description in step 204, which will not be repeated here.
[0354] 408. The session management function network element sends a session acceptance message to the terminal device.
[0355] The detailed description of step 408 can refer to the description of step 206 and will not be repeated here.
[0356] The session accept message may include an additional generation indication, which may include an indication of a second derivative parameter and / or an identification of a security algorithm.
[0357] 409. The access network device sends an additional generation indication to the terminal device.
[0358] Correspondingly, the terminal device receives the additional generation instruction from the session management function network element. For a detailed description of step 409 , reference can be made to the description of steps 205 and 207 .
[0359] It should be noted that the additional generation indication may include one or more of the following: an explicit indication and an identifier of a security algorithm.
[0360] It should be understood that in step 408 and step 409, one of the messages includes the identifier of the security algorithm.
[0361] 410. The terminal device obtains a second security context according to the additional generation indication.
[0362] For a detailed description of step 410 , reference may be made to the descriptions of steps 407 and 208 .
[0363] The additional generation instruction may include an identifier for the security algorithm, and the terminal device may determine the security algorithm based on this identifier. If the additional generation instruction does not include an identifier for the security algorithm, the terminal device may also obtain the security algorithm based on the first security algorithm of the first security context. For detailed descriptions, please refer to the relevant descriptions in steps 407 and 208 and are not repeated here.
[0364] The terminal device may generate the first key according to the additional generation instruction.
[0365] The additional generation instruction may include an indication of a second derived parameter, which may instruct the terminal device to obtain the first key based on the second derived parameter. The terminal device may generate the first key based on the secondary authentication key and the second derived parameter. For detailed descriptions, please refer to the relevant descriptions in steps 203, 208, and 407, and are not repeated here.
[0366] Furthermore, the terminal device may generate a security key based on the first key according to the additional generation indication.
[0367] When the additional generation instruction includes an identifier of the security algorithm, the terminal device may generate a security key based on the first key and the third derived parameter. For a detailed description of generating the security key, reference may be made to the description of generating the security key based on the first key and the third derived parameter in steps 204, 208, and 407, which will not be repeated here.
[0368] At this point, the terminal device can protect the user plane data through the second security context and the first security context. The terminal device can obtain two sets of security contexts, the second security context and the first security context. When the terminal device sends data corresponding to the PDU session (for example, private network data), the terminal device can use the second security context for user plane security protection. When the terminal device sends data corresponding to the PDU session (for example, public network data), the terminal device can use the first security context for user plane security protection, thereby achieving secure isolation between public network services and public network services.
[0369] It should be understood that the data transmission network element in this embodiment is an access network device.
[0370] Based on the above network architecture, please refer to Figure 5 , Figure 5 This is a flow chart of another security context generation method disclosed in an embodiment of the present invention. Figure 5 As shown, the security context generating method may include the following steps.
[0371] 501. The terminal device obtains a first security context.
[0372] 502. The access network device obtains a first security context.
[0373] 503. The terminal device sends a session request message to the session management function network element.
[0374] 504. The terminal device performs secondary authentication.
[0375] 505. The session management function network element generates a first key based on the secondary authentication key.
[0376] The detailed description of steps 501-505 can refer to the description of steps 401-405, which will not be repeated here.
[0377] 506. The session management function network element sends an additional security context indication to the user plane function network element.
[0378] For a detailed description of step 506 , reference may be made to the relevant description of step 203 , which will not be repeated here.
[0379] It should be noted that the additional security context indication includes at least the first key.
[0380] It should be understood that when the session management function network element has determined the security algorithm, the additional security context indication may also include an identifier of the security algorithm.
[0381] 507. The user plane functional network element obtains the second security context according to the additional security context indication.
[0382] After receiving the additional security context indication from the session management function network element, the user plane function network element may generate a second security context according to the additional security context indication. For a detailed description of generating the second security context, please refer to the description of step 204.
[0383] The user plane functional network element can obtain the security algorithm according to the additional security context indication.
[0384] In one possible implementation, when the additional security context indicates support for generating a second security context, the user plane function network element may obtain a security algorithm according to the algorithm priority list. Detailed descriptions may refer to the relevant descriptions in step 204 and are omitted here.
[0385] In another possible implementation, the additional security context indication may include a security algorithm identifier, and the user plane function network element may determine the security algorithm based on this identifier. The security algorithm may be determined by the session management function network element or the user plane function network element. For detailed descriptions, please refer to the corresponding descriptions of steps 203 and 204 and are not repeated here.
[0386] The user plane function network element may generate the first key according to the additional security context indication.
[0387] The additional security context indication may include the first key, and the user plane function network element may directly obtain the first key. For detailed description, please refer to the relevant description in step 204, which will not be repeated here.
[0388] Furthermore, the user plane function network element may generate a security key based on the first key according to the additional security context indication.
[0389] The user plane function network element can generate a security key based on the first key and the third derived parameter. For a detailed description of generating the security key, please refer to the relevant description in step 204, which will not be repeated here.
[0390] 508. The user plane function network element sends an additional generation indication to the session management function network element.
[0391] The user plane function network element may send an additional creation instruction to the session management function network element, and correspondingly, the session management function network element may receive the additional creation instruction from the user plane function network element. The additional creation instruction may include the identifier of the security algorithm. The additional creation instruction may be encapsulated in the N4Session Establishment Response message.
[0392] The detailed description of step 508 may refer to the relevant descriptions in steps 205 and 207 and will not be repeated here.
[0393] It should be understood that step 508 is an optional step.
[0394] 509. The session management function network element sends a session acceptance message to the terminal device.
[0395] After the session management function network element receives the additional generation indication from the user plane function network element, it can encapsulate the received additional generation indication in a session acceptance message, and then send the session acceptance message to the terminal device. Correspondingly, the terminal device can receive the session acceptance message from the session management function network element.
[0396] It should be noted that the session accept message may include an additional generation indication, which may include one or more of the following: an indication of a second derived parameter and an identifier of a security algorithm. The indication of the second derived parameter may come from a session management function network element; and the identifier of the security algorithm may come from either a user plane function network element or a session management function network element.
[0397] The detailed description of 509 can refer to the relevant descriptions in steps 205-207, which will not be repeated here.
[0398] 510. The terminal device obtains a second security context according to the additional generation indication.
[0399] The terminal device may obtain the second security context according to the additional generation indication. For a detailed description of step 510 , reference may be made to the descriptions in steps 507 and 208 .
[0400] The terminal device may obtain the security algorithm based on the additional generation indication. The additional generation indication may include an identifier of the security algorithm, and the terminal device may determine the security algorithm based on the identifier of the security algorithm. If the additional generation indication does not include an identifier of the security algorithm, the terminal device may also obtain the security algorithm based on the first security algorithm of the first security context. For detailed descriptions, please refer to the relevant descriptions in step 508 and step 208 and are not repeated here.
[0401] The terminal device may generate the first key according to the additional generation instruction.
[0402] The additional generation instruction may include an indication of a second derived parameter, which may instruct the terminal device to obtain the first key based on the second derived parameter. The terminal device may generate the first key based on the secondary authentication key and the second derived parameter. For detailed descriptions, please refer to the relevant descriptions in steps 203, 208, and 507, and will not be repeated here.
[0403] Furthermore, the terminal device may generate a security key based on the first key according to the additional generation indication.
[0404] When the additional generation instruction includes an identifier of the security algorithm, the terminal device may generate a security key based on the first key and the third derived parameter. A detailed description of generating the security key can be found in the description of generating the security key based on the first key and the third derived parameter in steps 204, 208, and 507, and is not repeated here.
[0405] At this point, the terminal device can protect the user plane data through the second security context and the first security context. The terminal device can obtain two sets of security contexts, the second security context and the first security context. When sending data corresponding to the PDU session (for example, private network data), the terminal device can use the first security context for user plane security protection, and the access network device will deprotect it. When sending data corresponding to the PDU session (for example, public network data), the terminal device can use the second security context for user plane security protection, and the user plane functional network element will deprotect it. As a result, one set of security contexts is on the access network device, and the other set of security contexts is on the user plane functional network element. The two sets of security contexts have different algorithms and keys and are in different entities, so security isolation can be achieved. In addition, the second security context can be generated by the key generated after the terminal device and the authentication, authorization and billing network element perform secondary authentication. The first security context can be generated by the key generated after the terminal device and the unified data management network element (located in the public network) perform the first authentication. In this way, even if an attacker obtains the key of the unified data management network element, the attacker cannot obtain the first key of the second security context because they do not have the key of the authentication, authorization, and accounting network element, thereby further achieving isolation. Furthermore, assuming that the user plane function network element, session management function network element, and authentication, authorization, and accounting network element are all maintained by the private network, while the access network equipment and access and mobility management function network elements are maintained by the public network, the public network cannot obtain the first security context either, thus resolving the problem of mutual trust between the private and public networks.
[0406] It should be understood that the data transmission network element in this embodiment is a user plane function network element.
[0407] Based on the above network architecture, please refer to Figure 6 , Figure 6 This is a flow chart of another security context generation method disclosed in an embodiment of the present invention. Figure 6 As shown, the security context generating method may include the following steps.
[0408] 601. The terminal device obtains a first security context.
[0409] The detailed description of step 601 can refer to the description of step 201 and will not be repeated here.
[0410] 602. The user plane functional network element pre-configures the correspondence between the terminal device identifier and the Kn root key.
[0411] The user plane functional network element can pre-configure the correspondence between the identifier of the terminal device and the Kn root key. The identifier of the terminal device can be a generic public subscription identifier (GPSI) or an Internet Protocol (IP) address. That is, the identifier of the terminal device itself is known, and the user plane functional network element can determine the first key based on the correspondence between the identifier of the terminal device and the Kn root key. For example, the user plane functional network element can pre-configure a mapping relationship table between the identifier of the terminal device and the Kn root key, where one identifier can correspond to one Kn root key. It should be understood that the above example is an example of how the user plane functional network element can pre-configure the correspondence between the identifier of the terminal device and the Kn root key, and does not constitute a limitation.
[0412] After the user plane functional network element pre-configures the correspondence between the terminal device's identifier and the Kn root key, it can issue the Kn root key to the corresponding terminal device.
[0413] The detailed description of step 602 can refer to the description of step 205 and is not repeated here.
[0414] 603. The terminal device pre-configures the Kn root key.
[0415] 604. The terminal device sends a session request message to the session management function network element.
[0416] The detailed description of step 604 can refer to the description of step 202 and will not be repeated here.
[0417] It should be noted that the session request message may include the identifier of the terminal device.
[0418] 605. The session management function network element determines the corresponding user plane function network element.
[0419] The session management function network element may first determine whether a second security context needs to be generated. For a detailed description, please refer to the description of step 203 and will not be repeated here.
[0420] The session management function network element may determine the user plane function network element. Optionally, the user plane function network element has a corresponding relationship between the identifier of the terminal device and the Kn root key.
[0421] In one possible implementation, there is only one user plane functional network element corresponding to the DNN of the session request message, that is, this user plane functional network element can be determined as the network element for generating the corresponding second security context.
[0422] Another possible implementation method is that there are multiple user plane function network elements corresponding to the DNN in the session request message. The session management function network element can determine the user plane function network element by pre-configuring the correspondence between the identifier of the terminal device and the user plane function network element. Optionally, the session management function network element can also obtain the context of the corresponding terminal device based on the session request message, and then determine the identifier of the terminal device based on the context of the terminal device, and then determine the user plane function network element based on the correspondence between the identifier of the pre-configured terminal device and the user plane function network element. It should be understood that the identifier of the terminal device can be carried in the SM message or stored in the context of the session management function network element.
[0423] 606. The session management function network element sends an additional security context indication to the user plane function network element.
[0424] The detailed description of step 606 can refer to the description of step 203 and will not be repeated here.
[0425] It should be noted that the additional security context indication may include the identifier of the terminal device.
[0426] 607. The user plane function network element obtains the second security context according to the additional security context indication.
[0427] After receiving the additional security context indication from the session management function network element, the user plane function network element may generate a second security context according to the additional security context indication. For detailed description, please refer to the description of step 204.
[0428] The user plane function network element can obtain the security algorithm according to the additional security context indication. For detailed description, please refer to the description in step 204, which will not be repeated here.
[0429] The user plane function network element may generate the first key according to the additional security context indication.
[0430] In one possible implementation, the user plane function network element may first determine the Kn root key based on the received terminal device identifier and the correspondence between the terminal device and the Kn root key. The user plane function network element may use the Kn root key as the first key.
[0431] Another possible implementation method is that after the user plane functional network element determines the root Kn key, it can generate a first key based on the Kn root key and the first derivative parameter. The description of the specific generation method can refer to the relevant description in step 204 and will not be repeated here.
[0432] Furthermore, the user plane function network element may generate a security key based on the first key according to the additional security context indication.
[0433] The user plane function network element can generate a security key based on the first key and the third derived parameter. For a detailed description of generating the security key, please refer to the description of generating the security key based on the first key and the third derived parameter in step 204, which will not be repeated here.
[0434] 608. The user plane function network element sends an additional generation indication to the session management function network element.
[0435] The user plane function network element may send an additional generation indication to the session management function network element, and correspondingly, the session management function network element may receive the additional generation indication from the user plane function network element.
[0436] The detailed description of step 608 can refer to the description of step 205 and step 207, which will not be repeated here.
[0437] 609. The session management function network element sends a session acceptance message to the terminal device.
[0438] After the session management function network element receives the additional generation indication from the user plane function network element, it can encapsulate the received additional generation indication in a session acceptance message, and then send the session acceptance message to the terminal device. Correspondingly, the terminal device can receive the session acceptance message from the session management function network element.
[0439] It should be noted that the session accept message may include an additional generation indication, which may include one or more of the following: an indication of a first derived parameter, an indication of a second derived parameter, and an identifier of a security algorithm. The indication of the first derived parameter may come from a user plane function network element; the indication of the second derived parameter may come from a session management function network element; and the identifier of the security algorithm may come from either a user plane function network element or a session management function network element.
[0440] The detailed description of step 609 can refer to the description of steps 205-207, which will not be repeated here.
[0441] 610. The terminal device generates a second security context according to the additional generation indication.
[0442] The terminal device may obtain the second security context according to the additional generation indication. For a detailed description of step 610 , reference may be made to the descriptions of steps 607 and 208 .
[0443] The terminal device can obtain the security algorithm based on the additional generation instruction. The additional generation instruction can include the identifier of the security algorithm, and the terminal device can determine the security algorithm based on the identifier of the security algorithm. For detailed description, please refer to the relevant descriptions in step 607 and step 208, which are not repeated here.
[0444] The terminal device may generate the first key according to the additional generation instruction. For detailed description, please refer to the relevant descriptions in step 607 and step 208, which will not be repeated here.
[0445] The terminal device may use the pre-configured Kn root key as the first key. For detailed description, please refer to the relevant descriptions in step 607 and step 208, which will not be repeated here.
[0446] The additional generation indication may include an indication of a first derivative parameter, and the terminal device may generate the first key based on the Kn root key and the first derivative parameter.
[0447] Furthermore, the terminal device may generate a security key based on the first key according to the additional generation indication.
[0448] When the additional generation instruction includes an identifier of the security algorithm, the terminal device may generate a security key based on the first key and the third derived parameter. A detailed description of generating the security key can be found in the description of generating the security key based on the first key and the third derived parameter in steps 204, 208, and 607, and is not repeated here.
[0449] It should be noted that, when the terminal device can generate the first key when generating the second security context, the first key can be determined according to the Kn root key and the first derivative parameter configured on the terminal device.
[0450] At this point, the terminal device can protect the user plane data through the second security context and the first security context. The second security context is generated by the Kn root key pre-configured on the terminal device and the user plane function network element, and Figure 5 In the corresponding method embodiment, the first security context is generated by the key generated after the terminal device and the unified data management network element (located in the public network) perform the first authentication. In this way, even if the key of the unified data management network element is obtained by an attacker, since the attacker does not obtain the key of the user plane function network element, the attacker cannot obtain the key of the second security context, thereby further achieving security isolation. In addition, compared to Figure 5 Corresponding to the method embodiment, this embodiment can not only achieve the above functions, but also further reduce the cost of private network equipment.
[0451] It should be understood that the data transmission network element in this embodiment is a user plane function network element.
[0452] It should be understood that the functions performed by the terminal device in the above-mentioned security context generation method can also be performed by a module (for example, a chip) in the terminal device, the functions performed by the session management function network element can also be performed by a module (for example, a chip) in the session management function network element, the functions performed by the data transmission network element can also be performed by a module (for example, a chip) in the data transmission network element, the functions performed by the user plane function network element can also be performed by a module (for example, a chip) in the user plane function network element, and the functions performed by the access network device can also be performed by a module (for example, a chip) in the access network device.
[0453] Based on the above network architecture, please refer to Figure 7 , Figure 7 This is a schematic diagram of the structure of a security context generation device disclosed in an embodiment of the present application. Figure 7 As shown, the apparatus may include an acquiring unit 701, a sending unit 702, and a receiving unit 703, wherein:
[0454] An acquiring unit 701 is configured to acquire a first security context, where the first security context is used to protect a first communication service of the terminal device;
[0455] A sending unit 702 is configured to send a session request message to a session management function network element, where the session request message is used to request establishment of a session for a second communication service, where the second communication service is different from the first communication service;
[0456] A receiving unit 703 is configured to receive a session accept message from the session management function network element, where the session accept message is used to complete establishing a session for the second communication service;
[0457] The acquisition unit 701 is further configured to acquire an additional generation indication;
[0458] The acquiring unit 701 is further configured to acquire a second security context according to the additional generation indication, where the second security context is used to protect the second communication service.
[0459] As a possible implementation manner, the session request message includes first indication information, where the first indication information is used to indicate that the terminal device supports generating the second security context.
[0460] As a possible implementation manner, the acquiring unit 701 acquires a second security context according to the additional generation indication, where the second security context is used to protect the second communication service, including:
[0461] Obtaining a security key based on the first key according to the additional generation instruction; and / or
[0462] A security algorithm is obtained according to the additional generation instruction.
[0463] As a possible implementation manner, the acquiring unit 701 acquiring the security key based on the first key according to the additional generation indication includes:
[0464] acquiring the first key based on the AS root key of the first security context according to the additional generation indication;
[0465] The security key is generated according to the first key.
[0466] As a possible implementation manner, the additional generation indication includes an indication of the first derived parameter, and the obtaining unit 701 obtains the first key based on the AS root key of the first security context according to the additional generation indication, including:
[0467] The first key is generated according to the AS root key of the first security context and the first derivative parameter.
[0468] As a possible implementation manner, the first derived parameter is a downlink PDCP COUNT, and the indication of the first derived parameter is part of bits of the downlink PDCP COUNT.
[0469] As a possible implementation manner, the device may further include:
[0470] An execution unit 704 is configured to perform secondary authentication;
[0471] A generating unit 705 is configured to generate a secondary authentication key during the secondary authentication process;
[0472] The acquiring unit 701 acquiring the security key based on the first key according to the additional generation instruction includes:
[0473] acquiring the first key based on the secondary authentication key according to the additional generation instruction;
[0474] A security key is generated according to the first key.
[0475] As a possible implementation manner, the additional generation indication includes an indication of a second derived parameter, and the obtaining unit 701 obtains the first key based on the secondary authentication key according to the additional generation indication, including:
[0476] According to an instruction of the second derived parameter, the first key is generated based on the secondary authentication key and the second derived parameter.
[0477] As a possible implementation manner, the second derived parameter is one or more of the following parameters: downlink NASCOUNT, PDU session ID, NSSAI and DNN.
[0478] As a possible implementation manner, the acquiring unit 701 generating a security key according to the first key includes:
[0479] The security key is generated according to the first key and a third derived parameter.
[0480] As a possible implementation manner, the additional generation indication includes an identifier of the security algorithm, and the obtaining unit 701 generates the security key according to the first key and the third derived parameter, including:
[0481] The security key is generated according to the first key and the identifier and type of the security algorithm.
[0482] As a possible implementation manner, the additional generation indication includes an identifier of the security algorithm.
[0483] As a possible implementation manner, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.
[0484] For a more detailed description of the acquisition unit 701, the sending unit 702, the receiving unit 703, the execution unit 704 and the generation unit 705, please refer to the above Figure 2-Figure 6 The relevant description of the terminal device in the method embodiment shown is directly obtained and will not be repeated here.
[0485] Based on the above network architecture, please refer to Figure 8 , Figure 8 This is a schematic diagram of the structure of another security context generation device disclosed in the embodiment of this application. Figure 8 As shown, the device may include:
[0486] A receiving unit 801 is configured to receive a session request message from a terminal device, wherein the session request message is used to request establishment of a session for a second communication service;
[0487] A sending unit 802 is configured to send an additional security context indication to a data transmission network element, where the additional security context indication is used to instruct generation of a second security context, where the second security context is used to protect the second communication service;
[0488] The sending unit 802 is further configured to send a session acceptance message to the terminal device, where the session acceptance message is used to complete the establishment of the session for the second communication service.
[0489] As a possible implementation manner, the session request message includes first indication information, where the first indication information is used to indicate that the terminal device supports generating a second security context, and the sending unit 802 sends an additional security context indication to the data transmission network element, including:
[0490] When the first indication information indicates that the terminal device supports generating the second security context, the additional security context indication is sent to the data transmission network element.
[0491] As a possible implementation manner, the sending unit 802 sending the additional security context indication to the data transmission network element includes:
[0492] Acquiring the contract information of the terminal device according to the session request message;
[0493] When the subscription information of the terminal device indicates that the second security context needs to be generated, the additional security context indication is sent to the data transmission network element.
[0494] As a possible implementation manner, the sending unit 802 sending the additional security context indication to the data transmission network element includes:
[0495] When the local policy configured by the session management function network element indicates that the second security context needs to be generated, the additional security context indication is sent to the data transmission network element.
[0496] As a possible implementation manner, the additional security context indication includes an identifier of a security algorithm, and the apparatus may further include an acquiring unit 803, wherein:
[0497] The acquiring unit 803 is configured to acquire the security algorithm.
[0498] As a possible implementation manner, the additional security context indication includes a first key, and the apparatus may further include:
[0499] A triggering unit 804 is used to trigger secondary authentication;
[0500] The receiving unit 801 is further configured to receive a secondary authentication key from the authentication, authorization and accounting network element after the secondary authentication is successful;
[0501] The acquiring unit 803 is further configured to acquire the first key according to the secondary authentication key.
[0502] As a possible implementation manner, the acquiring unit 803 acquiring the first key according to the secondary authentication key includes:
[0503] The first key is obtained according to the secondary authentication key and a second derived parameter.
[0504] As a possible implementation manner, the second derived parameter is one or more of the following parameters: downlink NASCOUNT, PDU session ID, NSSAI and DNN.
[0505] As a possible implementation, the session accept message includes an indication of a second derived parameter, where the indication of the second derived parameter is used to instruct to obtain a security key according to the secondary authentication key.
[0506] For a more detailed description of the receiving unit 801, the sending unit 802, the acquiring unit 803 and the triggering unit 804, please refer to the above Figure 2-Figure 6 The relevant description of the session management function network element in the method embodiment shown is directly obtained and is not repeated here.
[0507] Based on the above network architecture, please refer to Figure 9 , Figure 9 This is a structural diagram of another security context generation device disclosed in the embodiment of this application. Figure 9 As shown, the device may include:
[0508] The receiving unit 901 is configured to receive an additional security context indication from a session management function network element;
[0509] An acquiring unit 902 is configured to acquire a second security context according to the additional security context indication, where the second security context is used to protect a second communication service;
[0510] The sending unit 903 is configured to send an additional generation indication to the terminal device, where the additional generation indication is used to instruct generation of the second security context.
[0511] As a possible implementation, the acquiring unit 902 is specifically configured to:
[0512] Obtaining a security key based on the first key according to the additional security context indication; and / or
[0513] A security algorithm is obtained according to the additional security context indication.
[0514] As a possible implementation, the acquisition unit 902 is further used to obtain a first security context before receiving an additional security context indication from the session management function network element, where the first security context is used to protect a first communication service, which is different from the second communication service.
[0515] As a possible implementation manner, the obtaining unit 902 generates the security key based on the first key according to the additional security context indication, including:
[0516] Obtaining the first key based on the AS root key of the first security context according to the additional security context indication;
[0517] The security key is generated according to the first key.
[0518] As a possible implementation manner, the additional generation indication includes an indication of a first derived parameter, and the obtaining unit 902 obtains the first key based on the AS root key of the first security context according to the additional security context indication, including:
[0519] The first key is generated according to the AS root key of the first security context and the first derivative parameter.
[0520] As a possible implementation manner, the first derived parameter is a downlink PDCP COUNT, and the indication of the first derived parameter is part of bits of the downlink PDCP COUNT.
[0521] As a possible implementation manner, the additional security context indication includes the first key, and the obtaining unit 902 obtains the security key based on the first key according to the additional security context indication, including:
[0522] The security key is generated according to the first key.
[0523] As a possible implementation manner, the acquiring unit 902 generating the security key according to the first key includes:
[0524] The security key is generated according to the first key and a third derived parameter.
[0525] As a possible implementation manner, the additional security context indication includes an identifier of a security algorithm, and the acquiring unit 902 generates the security key according to the first key and the third derived parameter, including:
[0526] The security key is generated according to the first key and the identifier and type of the security algorithm.
[0527] As a possible implementation manner, the additional generation indication includes an identifier of the security algorithm.
[0528] As a possible implementation, the additional security context indication includes an identifier of the security algorithm.
[0529] As a possible implementation manner, the acquiring unit 902 acquiring the security algorithm according to the additional security context indication includes:
[0530] According to the additional security context indication, the security algorithm is obtained based on the security capability of the terminal device and a preconfigured algorithm priority list, where the security capability of the terminal device is used to indicate all security algorithms supported by the terminal device.
[0531] As a possible implementation manner, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.
[0532] For a more detailed description of the receiving unit 901, the acquiring unit 902 and the sending unit 903, please refer to the above Figure 2-Figure 6 The relevant description of the data transmission network element in the method embodiment shown is directly obtained and will not be repeated here.
[0533] Based on the above network architecture, please refer to Figure 10 , Figure 10 This is a structural diagram of another security context generation device disclosed in the embodiment of this application. Figure 10 As shown, the security context generation device may include a processor 1001, a memory 1002, an input interface 1003, an output interface 1004, and a bus 1005. The memory 1002 may be independent or connected to the processor 1001 via the bus 1005. The memory 1002 may also be integrated with the processor 1001. The bus 1005 is used to connect these components.
[0534] In one embodiment, the security context generating device can be a terminal device or a module (e.g., a chip) within the terminal device. When the computer program instructions stored in the memory 1002 are executed, the processor 1001 is used to control the sending unit 702 and the receiving unit 703 to perform the operations performed in the above embodiments. The processor 1001 is also used to perform the operations performed by the acquiring unit 701, the executing unit 704, and the generating unit 705 in the above embodiments. The input interface 1003 is used to perform the operations performed by the receiving unit 703 in the above embodiments, and the output interface 1004 is used to perform the operations performed by the sending unit 702 in the above embodiments. The above terminal device or the module within the terminal device can also be used to perform the above Figure 2-Figure 6 The various methods executed by the terminal device in the method embodiment are not described in detail.
[0535] In one embodiment, the security context generating device may be a session management function network element or a module (e.g., a chip) within the session management function network element. When the computer program instructions stored in the memory 1002 are executed, the processor 1001 is used to control the receiving unit 801 and the sending unit 803 to perform the operations performed in the above embodiment. The processor 1001 is also used to execute the operations performed by the acquisition unit 803 and the triggering unit 804 in the above embodiment. The input interface 1003 is used to execute the operations performed by the receiving unit 801 in the above embodiment, and the output interface 1004 is used to execute the operations performed by the sending unit 802 in the above embodiment. The above session management function network element or the module within the session management function network element may also be used to execute the above Figure 2-Figure 6 The various methods executed by the session management function network element in the method embodiment are not described in detail.
[0536] In one embodiment, the security context generating device can be a data transmission network element or a module (e.g., a chip) within the data transmission network element. When the computer program instructions stored in the memory 1002 are executed, the processor 1001 is used to control the receiving unit 901 and the sending unit 903 to perform the operations performed in the above embodiment. The processor 1001 is also used to execute the operations performed by the acquisition unit 902 in the above embodiment. The input interface 1003 is used to execute the operations performed by the receiving unit 901 in the above embodiment, and the output interface 1004 is used to execute the operations performed by the sending unit 903 in the above embodiment. The above data transmission network element or the module within the data transmission network element can also be used to perform the above Figure 2-Figure 6 The various methods executed by the data transmission network element in the method embodiment are not described in detail.
[0537] Based on the above network architecture, please refer to Figure 11 , Figure 11 This is a structural diagram of another security context generation device disclosed in the embodiment of this application. Figure 11As shown, the security context generation device may include an input interface 1101, a logic circuit 1102, and an output interface 1103. The input interface 1101 and the output interface 1103 are connected via the logic circuit 1102. The input interface 1101 is used to receive information from other devices, and the output interface 1103 is used to output, schedule, or send information to other devices. The logic circuit 1102 is used to perform operations other than those of the input interface 1101 and the output interface 1103, such as implementing the functions implemented by the processor 1001 in the above-mentioned embodiment. The security context generation device may be a terminal device or a module of a terminal device, a session management function network element or a module of a session management function network element, or a data transmission network element or a module of a data transmission network element. A more detailed description of the input interface 1101, the logic circuit 1102, and the output interface 1103 can be directly obtained by referring to the relevant descriptions of the terminal device, the session management function network element, and the data transmission network element in the above-mentioned method embodiment, and is not repeated here.
[0538] An embodiment of the present application further discloses a computer-readable storage medium having instructions stored thereon, which, when executed, execute the method in the above method embodiment.
[0539] The embodiments of the present application further disclose a computer program product comprising instructions, which, when executed, perform the method in the above method embodiments.
[0540] The present application also discloses a communication system, which includes a terminal device, a session management function network element and a data transmission network element. For a detailed description, please refer to Figure 2-Figure 6 The security context generation method shown.
[0541] The specific implementation methods described above further illustrate the purpose, technical solutions and beneficial effects of this application. It should be understood that the above description is only the specific implementation methods of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of this application should be included in the scope of protection of this application.
Claims
1. A security context generation method, characterized in that: Applicable to a security context generation device, including: Obtaining a first security context, where the first security context is used to protect a first communication service of a terminal device; Sending a session request message to a session management function network element, where the session request message is used to request establishment of a session for a second communication service, where the second communication service and the first communication service are different services in a public network service and a private network service, and the public network service and the private network service are services in a non-public network integrated with a public network; receiving a session accept message from the session management function network element, where the session accept message is used to complete establishing a session for the second communication service; Get additional generation instructions; A second security context is obtained according to the additional generation indication, where the second security context is used to protect the second communication service; the second security context is different from the first security context.
2. The method according to claim 1, characterized in that The session request message includes first indication information, where the first indication information is used to indicate that the security context generating device supports generating the second security context.
3. The method according to claim 1, characterized in that The obtaining of the second security context according to the additional generation indication includes: Obtaining a security key based on the first key according to the additional generation instruction; and / or A security algorithm is obtained according to the additional generation instruction.
4. The method according to claim 3, characterized in that The obtaining of the security key based on the first key according to the additional generation instruction includes: acquiring, according to the additional generation indication, the first key based on an access stratum AS root key of the first security context; The security key is generated according to the first key.
5. The method according to claim 4, characterized in that The additional generation instruction includes an instruction of a first derived parameter, and obtaining the first key based on the AS root key of the first security context according to the additional generation instruction includes: The first key is generated according to the AS root key of the first security context and the first derivative parameter.
6. The method according to claim 5, characterized in that The first derived parameter is a downlink packet data convergence protocol PDCP COUNT, and the indication of the first derived parameter is a portion of bits of the downlink PDCP COUNT.
7. The method according to claim 3, characterized in that After the security context generating device sends the session request message to the session management function network element and before the security context generating device receives the additional generation instruction, the method further includes: Perform secondary authentication; generating a secondary authentication key during the secondary authentication process; The obtaining of the security key based on the first key according to the additional generation instruction includes: acquiring the first key based on the secondary authentication key according to the additional generation instruction; A security key is generated according to the first key.
8. The method according to claim 7, characterized in that The additional generation instruction includes an instruction of a second derived parameter, and obtaining the first key based on the secondary authentication key according to the additional generation instruction includes: According to an instruction of the second derived parameter, the first key is generated based on the secondary authentication key and the second derived parameter.
9. The method according to claim 8, characterized in that The second derived parameter is one or more of the following parameters: downlink non-access layer NAS COUNT, protocol data unit session identity PDU session ID, network slice selection support information NSSAI and data network name DNN.
10. The method according to any one of claims 4 to 9, characterized in that: The generating the security key according to the first key includes: The security key is generated according to the first key and a third derived parameter.
11. The method according to claim 10, characterized in that The third derived parameter includes an identifier and a type of the security algorithm, and generating the security key according to the first key and the third derived parameter includes: The security key is generated according to the first key and the identifier and type of the security algorithm.
12. The method according to claim 3, characterized in that The additional generation indication includes an identification of the security algorithm.
13. The method according to any one of claims 1 to 9, characterized in that The first communication service is a public network service, and the second communication service is a private network service; or, the first communication service is a private network service, and the second communication service is a public network service.
14. The method according to any one of claims 1 to 9, characterized in that The security context generating device is the terminal device or a chip in the terminal device.
15. A security context generating device, characterized in that: The device comprises: An acquiring unit, configured to acquire a first security context, where the first security context is used to protect a first communication service of a terminal device; a sending unit, configured to send a session request message to a session management function network element, wherein the session request message is used to request establishment of a session for a second communication service, where the second communication service and the first communication service are different services in a public network service and a private network service, and the public network service and the private network service are services in a non-public network integrated with a public network; a receiving unit, configured to receive a session accept message from the session management function network element, wherein the session accept message is used to complete the establishment of the session for the second communication service; The acquisition unit is further configured to acquire an additional generation indication; The acquiring unit is further configured to acquire a second security context according to the additional generation indication, where the second security context is used to protect the second communication service; the second security context is different from the first security context.
16. The device according to claim 15, characterized in that The session request message includes first indication information, where the first indication information is used to indicate that the security context generating device supports generating the second security context.
17. The device according to claim 15, characterized in that The acquiring unit acquires a second security context according to the additional generation indication, where the second security context is used to protect the second communication service, including: Obtaining a security key based on the first key according to the additional generation instruction; and / or A security algorithm is obtained according to the additional generation instruction.
18. The device according to claim 17, characterized in that The acquiring unit acquiring the security key based on the first key according to the additional generation instruction includes: acquiring the first key based on the AS root key of the first security context according to the additional generation indication; The security key is generated according to the first key.
19. The device according to claim 18, characterized in that The additional generation indication includes an indication of the first derived parameter, and the obtaining unit obtains the first key based on the AS root key of the first security context according to the additional generation indication, including: The first key is generated according to the AS root key of the first security context and the first derivative parameter.
20. The device according to claim 19, characterized in that The first derived parameter is a downlink packet data convergence protocol PDCP COUNT, and the indication of the first derived parameter is a portion of bits of the downlink PDCP COUNT.
21. The device according to claim 17, characterized in that The device further comprises: An execution unit, configured to execute secondary authentication; A generating unit, configured to generate a secondary authentication key during the secondary authentication process; The acquiring unit acquiring the security key based on the first key according to the additional generation instruction includes: acquiring the first key based on the secondary authentication key according to the additional generation instruction; A security key is generated according to the first key.
22. The device according to claim 21, characterized in that The additional generation instruction includes an instruction of a second derived parameter, and the obtaining unit obtains the first key based on the secondary authentication key according to the additional generation instruction, including: According to an instruction of the second derived parameter, the first key is generated based on the secondary authentication key and the second derived parameter.
23. The device according to claim 22, characterized in that The second derived parameter is one or more of the following parameters: downlink non-access layer NAS COUNT, protocol data unit session identity PDU session ID, network slice selection support information NSSAI and data network name DNN.
24. The device according to any one of claims 18 to 23, characterized in that The acquiring unit generating a security key according to the first key includes: The security key is generated according to the first key and a third derived parameter.
25. The device according to claim 24, characterized in that The third derived parameter includes the identifier and type of the security algorithm, and the generating unit generates the security key according to the first key and the third derived parameter, including: The security key is generated according to the first key and the identifier and type of the security algorithm.
26. The device according to claim 17, characterized in that The additional generation indication includes an identification of the security algorithm.
27. The device according to any one of claims 15 to 23, characterized in that The first communication service is a public network service, and the second communication service is a private network service; or, the first communication service is a private network service, and the second communication service is a public network service.
28. The device according to any one of claims 15 to 23, characterized in that The security context generating device is the terminal device or a chip in the terminal device.
29. A security context generating device, characterized in that: It includes a processor, a memory, an input interface and an output interface, the input interface is used to receive information from other security context generation devices outside the security context generation device, the output interface is used to output information to other security context generation devices outside the security context generation device, and the processor calls the computer program stored in the memory to implement the method described in any one of claims 1-14.
30. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program or computer instructions, and when the computer program or computer instructions are executed, the method according to any one of claims 1 to 14 is implemented.
31. A chip, characterized in that: The chip comprises a processor configured to execute a program stored in a memory, wherein when the program is executed, the chip executes the method according to any one of claims 1 to 14.
32. A security context generation method, characterized in that: include: The terminal device obtains a first security context, where the first security context is used to protect a first communication service of the terminal device; The terminal device sends a session request message to the session management function network element, where the session request message is used to request establishment of a session for a second communication service, where the second communication service and the first communication service are different services in a public network service and a private network service, and the public network service and the private network service are services in a non-public network integrated with a public network; The session management function network element receives the session request message and sends a session acceptance message to the terminal device, where the session acceptance message is used to complete the establishment of the session for the second communication service; The terminal device receives the session acceptance message; The terminal device obtains an additional generation indication; The terminal device obtains a second security context according to the additional generation indication, where the second security context is used to protect the second communication service; The second security context is different from the first security context.
33. A system, characterized in that include: The security context generation device according to any one of claims 15 to 28, and a session management function network element: configured to receive a session request message and send a session accept message to the security context generation device.
Citation Information
Patent Citations
Security context isolation method, device and system
CN111328112A