Contract data updating method and device, node and storage medium
Patent Information
- Application Number
- CN202311034974.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-16
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2040-10-16
AI Technical Summary
[0006]在现有技术中,通常以重用5G主认证流程(即上述5G-AKA或EAP-AKA’)的方式产生密钥KAKMA,当认证成功后,UE和AUSF由密钥KAUSF推衍产生AKMA锚定密钥KAKMA,在产生密钥KAKMA的同时也产生密钥KAKMA相关密钥标识A-KID,那么密钥KAKMA也只能通过5G主认证流程进行更新
[0036]本申请实施例提供了一种签约数据更新方法、装置、节点和存储介质,该方法包括在第一网络功能节点确定用户的AKMA签约数据更新的情况下,第一网络功能节点确定存储用户的AKMA上下文的第二网络功能节点;第一网络功能节点向第二网络功能节点发送签约数据管理通知消息;第一网络功能节点接收第二网络功能节点发送的签约数据管理通知响应消息;其中,签约数据管理通知响应消息是第二网络功能节点根据签约数据管理通知消息删除用户的AKMA上下文后发送的。通过这样的设计方式,在用户签约数据发生更新的情况下,第二网络功能节点不保留AKMA相关的上下文,从而避免被攻击者滥用的情况。
Smart Images

Figure CN117041955B_ABST
Abstract
Description
[0001] This application is a divisional application of Chinese patent application No. 202011111639.9, filed on October 16, 2020, entitled "Method, Apparatus, Node and Storage Medium for Updating Contract Data". Technical Field
[0002] This application relates to the field of wireless communication technology, and in particular to a method, apparatus, node, and storage medium for updating contracted data. Background Technology
[0003] According to the definition of the 3rd Generation Partnership Project (3GPP) standards working group, 5th generation wireless systems (5G) include the 5G Radio Access Network (5G RAN) and the 5G Core Network (5G Core, 5GC). Figure 1As shown, the architecture of a 5G system includes several Network Functions (NFs). Among them, the 5G radio access subsystem includes New Radio (NR) base stations, i.e., Radio Access Nodes (R)ANs. The 5G core network subsystem includes Unified Data Management (UDM), Access Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Security Anchor Function (SEAF), Authentication Server Function (AUSF), and Authentication Credential Repository and Processing Function (ARPF). Currently, 5G networks include Subscription Concealed Identifier (SUCI) and Subscription Permanent Identifier (SUPI). SUPI can include International Mobile Subscriber Identification Number (IMSI) or Network Access Identifier (NAI).
[0004] Figure 2This is a schematic diagram of the Architecture for Authentication and Key Management for Applications (AKMA), a service-oriented architecture. Compared to 5G network systems, it introduces a new network function—the AKMA Anchor Function (AAnF). AAnF resides in the home network and is primarily used to generate session keys between User Equipment (UE) and Application Functions (AF), as well as maintain the security context between the UE and the UE. AAnF is similar to the Bootstrapping Server function (BSF) in the General Bootstrapping Architecture (GBA), and the interface Ua* between the UE and AF is also similar to the Ua interface in GBA. Furthermore… Figure 2 Nnef, Nausf, Naanf, and Namf are the service-based interfaces of NEF, AUSF, AAnF, and AMF, respectively.
[0005] Figure 3 This is a key derivation architecture diagram for the application identity authentication and key management system. When a UE accesses the 5G network, it uses 5G-Authentication and Key Agreement (AKA), or Extensible Authentication Protocol-AKA, or EAP-AKA, to successfully authenticate. After successful authentication, AUSF and the UE generate a key K. AUSF Meanwhile, by key K AUSF Derive the AKMA anchoring key K AKMA ME and AAnF are determined by key K. AKMA Derive the application key K AF AUSF and AAnF are both in the home network.
[0006] In existing technologies, key K is typically generated by reusing the 5G master authentication process (i.e., the aforementioned 5G-AKA or EAP-AKA'). AKMA After successful authentication, the UE and AUSF are connected via key K. AUSF The AKMA anchor key K is derived. AKMA In generating key K AKMA At the same time, it also generates key K AKMA The relevant key identifier is A-KID, then the key K AKMAUpdates can only be performed through the 5G master authentication process. While existing AKMA technology provides end-to-end security protection for 5G network users, updates to user-subscribed data will affect the use of AKMA services. If AAnF continues to retain AKMA-related security contexts, there is a possibility of abuse by attackers. Summary of the Invention
[0007] The main objective of this application is to provide a method, apparatus, node, and storage medium for updating subscription data. The aim is to prevent the second network functional node from retaining AKMA-related context when user subscription data is updated, thereby avoiding misuse by attackers.
[0008] To achieve the above objectives, this application provides a method for updating contract data, which includes the following steps:
[0009] If the first network function node determines that the AKMA subscription data has been updated, the first network function node will determine the second network function node that stores the user's AKMA context.
[0010] The first network function node sends a contract data management notification message to the second network function node;
[0011] The first network function node receives the contract data management notification response message sent by the second network function node;
[0012] The Subscription Data Management Notification Response Message is sent by the second network function node after deleting the user's AKMA context based on the Subscription Data Management Notification Message.
[0013] To achieve the above objectives, this application provides a method for updating contract data, which includes the following steps:
[0014] The third network function node receives the query message sent by the first network function node;
[0015] The third network function node determines the second network function node based on the query message;
[0016] The third network function node sends a query response message to the first network function node, and the query response message carries the identifier or address of the second network function node.
[0017] To achieve the above objectives, this application provides a method for updating contract data, which includes the following steps:
[0018] The fourth network functional node determines the second network functional node;
[0019] The fourth network function node sends a message to the first network function node;
[0020] The message carries the identifier or address of the second network functional node.
[0021] To achieve the above objectives, embodiments of this application provide a contract data update apparatus, which includes:
[0022] The determination module is used to determine the second network function node that stores the user's AKMA context when the device determines that the user's AKMA subscription data has been updated;
[0023] The sending module is used to send subscription data management notification messages to the second network function node;
[0024] The receiving module is used to receive the subscription data management notification response message sent by the second network function node;
[0025] Among them, the contract data management notification response message is sent by the second network function node after deleting the user's AKMA context based on the contract data management notification message.
[0026] To achieve the above objectives, embodiments of this application provide a contract data update apparatus, which includes:
[0027] The receiving module is used to receive query messages sent by the first network function node;
[0028] The determination module is used to determine the second network function node based on the query message;
[0029] The sending module is used to send a query response message to the first network function node, and the query response message carries the identifier or address of the second network function node.
[0030] To achieve the above objectives, embodiments of this application provide a contract data update apparatus, which includes:
[0031] The determination module is used to determine the second network functional node;
[0032] The sending module is used to send messages to the first network function node;
[0033] The message carries the identifier or address of the second network function node.
[0034] To achieve the above objectives, embodiments of the present invention provide a network function node, which includes a processor, and implements the subscription data update method provided in the embodiments of this application when the program is executed by the processor.
[0035] To achieve the above objectives, embodiments of the present invention provide a readable and writable storage medium for computer storage. The storage medium stores one or more programs, which can be executed by one or more processors to implement the subscription data update method provided in the embodiments of this application.
[0036] This application provides a method, apparatus, node, and storage medium for updating subscription data. The method includes, when a first network function node determines that a user's AKMA subscription data has been updated, the first network function node determines a second network function node that stores the user's AKMA context; the first network function node sends a subscription data management notification message to the second network function node; the first network function node receives a subscription data management notification response message sent by the second network function node; wherein the subscription data management notification response message is sent by the second network function node after deleting the user's AKMA context according to the subscription data management notification message. Through this design, when the user's subscription data is updated, the second network function node does not retain the AKMA-related context, thereby preventing abuse by attackers. Attached Figure Description
[0037] Figure 1 This is a schematic diagram of the existing 5G system architecture.
[0038] Figure 2 This is a schematic diagram of the architecture of an application identity authentication and key management system in existing technologies.
[0039] Figure 3 This is a schematic diagram of the key derivation architecture of an application identity authentication and key management system in existing technologies.
[0040] Figure 4 This is a schematic diagram of the existing AKMA anchor key generation method.
[0041] Figure 5 This is a flowchart of a contract data update method provided in an embodiment of this application.
[0042] Figure 6 This is a signaling interaction diagram of a contract data update method provided in an embodiment of this application.
[0043] Figure 7 This is a signaling interaction diagram of a contract data update method provided in an embodiment of this application.
[0044] Figure 8 This is a signaling interaction diagram of a contract data update method provided in an embodiment of this application.
[0045] Figure 9 This is a signaling interaction diagram of a contract data update method provided in an embodiment of this application.
[0046] Figure 10 This is a flowchart of a contract data update method provided in an embodiment of this application.
[0047] Figure 11 This is a flowchart of a contract data update method provided in an embodiment of this application.
[0048] Figure 12 This is a schematic diagram of a contract data update device provided in an embodiment of this application.
[0049] Figure 13 This is a schematic diagram of a contract data update device provided in an embodiment of this application.
[0050] Figure 14 This is a schematic diagram of a contract data update device provided in an embodiment of this application.
[0051] Figure 15 This is a schematic diagram of the structure of a network functional node provided in an embodiment of this application. Detailed Implementation
[0052] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in detail below with reference to the accompanying drawings. It should be noted that, unless otherwise specified, the embodiments and features described in these embodiments can be arbitrarily combined with each other.
[0053] Furthermore, in the embodiments of this application, terms such as "optionally" or "exemplarily" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "optionally" or "exemplarily" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of terms such as "optionally" or "exemplarily" is intended to present the relevant concepts in a specific manner.
[0054] To facilitate understanding of the methods provided in the embodiments of this application, the related concepts such as network function node functions involved in the embodiments of this application and the accompanying drawings are further explained as follows:
[0055] UDM is used to permanently store user subscription data and resides in the user's home network. ARPF stores long-term security credentials used for authentication and uses these credentials as input to perform key operations. Both UDM and ARPF reside in the secure environment of the operator or a third-party system and are not exposed to unauthorized physical access. Furthermore, ARPF and ARPF can interact with each other.
[0056] The Access Controller (AM) manages user access to the network, handling functions such as Non-Access Stratum (NAS) layer signaling management and user mobility management. The Authentication and Management Function (AMF) has a Security Assistance Frame (SEAF) that interacts with the Access Default Server (AUSF) and the User Equipment (UE), receiving intermediate keys established for the UE authentication process. For authentication methods based on the Universal Subscriber Identity Module (USIM), the AMF obtains security-related data from the AAUSF.
[0057] AUSF has authentication capabilities that interact with ARPF and can terminate requests from SEAF. AUSF resides in a secure environment of the carrier or third-party systems and is not exposed to unauthorized physical access.
[0058] SMF is used to manage user Packet Data Unit (PDU) sessions, Quality of Service (QoS) flows, and to define packet inspection and forwarding rules for UPF.
[0059] UPF is responsible for routing and forwarding Internet Protocol (IP) data and non-IP data, as well as usage reporting.
[0060] PCF is responsible for providing policy rules at various levels for AMF and SMF.
[0061] Data Network (DN) includes networks such as carrier services, network access, and third-party services.
[0062] AF is used to manage AF sessions.
[0063] SUCI consists of six parts, as follows:
[0064] (1) SUPI Type, with a value of 0-7, where 0 is the International Mobile Subscriber Identification Number (IMSI), 1 is the Network Access Identifier (NAI), and the others are reserved.
[0065] (2) Home Network Identifier, which identifies home network users. When SUPI is IMSI, it consists of Mobile Country Code (MCC) and Mobile Network Code (MNC); when SUPI is NAI, NAI is defined in Section 2.2 of standard IETF RFC 7542.
[0066] (3) Routing Indicator (RID), which is allocated by the home network operator and configured in the Universal Subscriber Identity Module (USIM), and together with the home network identifier indicates the AUSF and UDM of the network signaling to the serving user.
[0067] (4) Protection Scheme Identifier, which represents one of two types: null-scheme or non-null-scheme.
[0068] (5) Home Network Public Key Identifier, which indicates an identifier of the public key provided by the home network for protecting SUPI, and the value is 0 when there is no protection.
[0069] (6) Scheme Output, when there is no protection, it is the Mobile Subscriber Identification Number (MSIN) part of IMSI or NAI; when there is protection, it is the value of MSIN and NAI encrypted by elliptic curve cryptography.
[0070] For example, when IMSI is 234150999999999, i.e., MCC=234, MNC=15 and MSISN=0999999999, routing indicator is 678, home network public key identifier is 27, the unprotected SUCI is 0, 234, 15, 678, 0, 0 and 0999999999, and the protected SUCI is 0, 234, 15, 678, 1, 27, <EEC ephemeral public key value>, <encrypted 0999999999> and <MAC tag value>.
[0071] As Figure 4 shown, the 5G primary authentication process is as follows:
[0072] S401, AUSF, and UDM interact to obtain authentication information. For example, authentication credentials (AKA authentication vector (AV)) are obtained using the Nudm_UEAuthentication_Get Request service.
[0073] S402. In the response message, the UDM can indicate to the AUSF whether an AKMA key needs to be generated for the UE.
[0074] S403. If the AUSF receives the AKMA instruction from the UDM, then the AUSF stores the K... AUSF And after successful master authentication, based on K AUSF Generate AKMA anchor key K AKMA And A-KID. Before the UE initiates communication with the AKMA application server, the UE is based on K... AUSF Generate AKMA anchor key K AKMA And A-KID.
[0075] After generating the AKMA key material using S404 and AUSF, the Naanf_AKMA_KeyRegistration Request service operation is used to transfer the user's SUPI, the generated A-KID, and the key. AKMA Send to AAnF. AAnF stores the latest key material sent by AUSF.
[0076] S405 and AAnF use the Naanf_AKMA_KeyRegistration Response service to send the response to AUSF.
[0077] Based on the above concepts, this application provides a method for updating contract data, the flowchart of which is shown below. Figure 5 As shown, the specific steps include, but are not limited to, the following:
[0078] S501, if the first network function node determines that the user's AKMA subscription data has been updated, the first network function node determines the second network function node that stores the user's AKMA context.
[0079] In this embodiment of the application, the first network functional node in this step can be understood as UDM, and the second network functional node can be understood as AAnF.
[0080] The user's AKMA subscription data updates in this step may include, but are not limited to, the following situations: 1. The user cancels the service and the user's subscription message is deleted in UDM; 2. The user no longer uses the AKMA service and the AKMA subscription information is deleted; 3. The user is unable to use the service due to arrears or other reasons.
[0081] In other words, this step can be understood as the UDM needing to confirm the AAnF storing the user's AKMA context when the user's AKMA subscription data is updated.
[0082] S502, The first network function node sends a contract data management notification message to the second network function node.
[0083] After the first network function node determines the second network function node, when sending a subscription data management notification message to the second network function node, it may include the user identifier SUPI in the message. Optionally, it may also include the user's AKMA subscription instruction in the message.
[0084] S503, the first network function node receives the contract data management notification response message sent by the second network function node.
[0085] After receiving the subscription data management notification message from the first network functional node, the second network functional node can delete the AKMA context of the user it stores based on the user identifier SUPI carried in the message. For example, SUPI, A-KID, and K AKMA Then, it sends a contract data management notification response message to the first network function node.
[0086] This application provides a method for updating subscription data. The method includes, when a first network function node determines that a user's AKMA subscription data has been updated, the first network function node determines a second network function node that stores the user's AKMA context; the first network function node sends a subscription data management notification message to the second network function node; the first network function node receives a subscription data management notification response message sent by the second network function node; wherein the subscription data management notification response message is sent by the second network function node after deleting the user's AKMA context according to the subscription data management notification message. Through this design, when the user's subscription data is updated, the second network function node does not retain the AKMA-related context, thereby preventing abuse by attackers.
[0087] In one embodiment, the implementation of step S501 may include, but is not limited to, the following situations:
[0088] In the first scenario, the first network function node determines the second network function node based on its local configuration.
[0089] In the second scenario, the first network function node determines the second network function node through the third network function node.
[0090] In the third scenario, the first network function node determines the second network function node through the fourth network function node.
[0091] Furthermore, such as Figure 6 As shown, the implementation of the first case mentioned above may include the first network function node determining the second network function node based on some fields of the user identifier.
[0092] For example, some of the fields mentioned above may include MCC or MNC, etc.
[0093] like Figure 7 As shown, the implementation of the second scenario can include the following process: the first network function node sends a query message to the third network function node; the first network function node receives a query response message sent by the third network function node based on the query message, the query response message carrying the identifier or address of the second network function node; the first network function node determines the second network function node based on the query response message.
[0094] For example, the query message may carry a network function name (e.g., AAnF) and / or a network type (e.g., AAnF type), as well as the user identifier SUPI and / or the location information of the first network function node. The third network function node may be an NRF, that is, the NRF queries the AAnF storing the user's AKMA context based on the SUPI and / or UDM location information in the query message, as well as the AAnF network function name and / or AAnF network type, and then sends a query response message to the UDM.
[0095] like Figure 8 As shown, in one embodiment, the implementation of the third case described above may include the following process: the first network function node sends a subscription change request message to the fourth network function node; the first network function node receives a subscription change request response message sent by the fourth network function node, the subscription change request response message carrying the identifier or address of the second network function node; the first network function node determines the second network function node based on the subscription change request response message.
[0096] For example, the aforementioned fourth network function node can be an AUSF. The aforementioned subscription change request may carry a network function name (e.g., AAnF) and / or network type (e.g., AAnF type), as well as the user identifier SUPI and / or the location information of the first network function node. That is, the AUSF queries the AAnF storing the user's AKMA context based on the SUPI and / or UDM location information, and the AAnF network function name and / or AAnF network type, and sends the query result to the UDM in the form of a subscription change request response message.
[0097] like Figure 9 As shown, in one embodiment, the implementation of the third case described above may further include the following process: the first network function node receives a contract data management contract message sent by the fourth network function node, the contract data management contract message carrying the identifier or address of the second network function node; the first network function node stores the identifier or address of the second network function node according to the contract data management contract message; the first network function node determines the second network function node according to the stored identifier or address of the second network function node.
[0098] Optionally, after receiving the signing data management signing message sent by the fourth network functional node, the first network functional node may also send a signing data management signing response message to the fourth network functional node.
[0099] It should be noted that before the first network functional node receives the subscription data management subscription message sent by the fourth network functional node, the first network functional node can also perform the main authentication process through the fourth network functional node. This main authentication process is the one described in this application. Figure 4 The provided implementation method. Combined with... Figure 4 As can be seen, after AUSF generates the AKMA key material, it sends this content to AAnF for storage. Thus, when a user's AKMA subscription data is updated, UDM can send a subscription management notification message to AAnF based on the stored AAnF identifier or address.
[0100] Figure 10 This is a flowchart of a contract data update method provided in an embodiment of this application, such as... Figure 10 As shown, the method may include, but is not limited to, the following steps:
[0101] S1001, the third network function node receives the query message sent by the first network function node.
[0102] In this embodiment, the third network function node can be an NRF, the first network function node can be a UDM, and the query message sent by the first network function node can carry the network function name and / or network type, as well as the user identifier and / or the location information of the first network function node.
[0103] S1002, the third network function node determines the second network function node based on the query message.
[0104] The third network function node queries the second network function node based on the network function name and / or network type in the query message, as well as the user identifier and / or the location information of the first network function node.
[0105] The second network function node can be AAnF, which is used to store the user's AKMA context.
[0106] S1003, the third network function node sends a query response message to the first network function node.
[0107] The query response message from the third network function node carries the identifier or address of the second network function node.
[0108] This application provides a method for updating subscription data. The method includes: a third network function node receiving a query message from a first network function node; the third network function node determining a second network function node based on the query message; and the third network function node sending a query response message to the first network function node, the query response message carrying the identifier or address of the second network function node. This scheme effectively identifies the second network function node, enabling the first network function node to send a subscription data management notification message to the second network function node when user subscription data is updated. This prevents the second network function node from retaining AKMA-related context, thus avoiding misuse by attackers.
[0109] Figure 11 This is a flowchart of a contract data update method provided in an embodiment of this application, such as... Figure 11 As shown, the method may include, but is not limited to, the following steps:
[0110] S1101, The fourth network function node determines the second network function node.
[0111] In this embodiment, the fourth network function node can be AUSF, and the second network function node can be AAnF, which is used to store the user's AKMA context.
[0112] For example, this step may be implemented as follows: the fourth network function node receives a subscription change request message sent by the first network function node, the subscription change request message carrying a user identifier; the fourth network function node queries the second network function node based on the user identifier.
[0113] The first network function node mentioned above can be a UDM. That is, after the AUSF receives the subscription change request message sent by the UDM, the AUSF queries the AAnF of the stored user's AKMA context based on the user identifier in the message.
[0114] S1102, The fourth network function node sends a message to the first network function node.
[0115] The message sent by the fourth network function node may carry the identifier or address of the second network function node.
[0116] This application provides a method for updating subscription data. The method includes a fourth network function node determining a second network function node, and the fourth network function node sending a message to a first network function node, the message carrying the identifier or address of the second network function node. This scheme enables the first network function node to determine the second network function node, and then, when user subscription data is updated, the first network function node sends a subscription data management notification message to the second network function node. This prevents the second network function node from retaining AKMA-related context, thus avoiding misuse by attackers.
[0117] Figure 12 This application provides a contract data update device, such as... Figure 12 As shown, the device may include: a determining module 1201, a transmitting module 1202, and a receiving module 1203;
[0118] The determining module 1202 is used to determine the second network function node storing the user's AKMA context when the device determines that the user's AKMA subscription data has been updated.
[0119] The sending module is used to send subscription data management notification messages to the second network function node;
[0120] The receiving module is used to receive the subscription data management notification response message sent by the second network function node;
[0121] Among them, the contract data management notification response message is sent by the second network function node after deleting the user's AKMA context based on the contract data management notification message.
[0122] In one example, the aforementioned determining module is used to determine the second network function node based on the local configuration;
[0123] Alternatively, the second network function node can be determined through the third network function node;
[0124] Alternatively, the second network function node can be determined through the fourth network function node.
[0125] In one example, the module can be identified by determining the second network function node based on certain fields of the user identifier;
[0126] In one example, the determining module may include a communication unit and a determining unit;
[0127] The communication unit is used to send a query message to the third network function node and to receive a query response message sent by the third network function node based on the query message, wherein the query response message carries the identifier or address of the second network function node.
[0128] The determining unit is used to determine the second network function node based on the query response message.
[0129] In one example, the determining module may include a communication unit and a determining unit;
[0130] The communication unit is used to send a subscription change request message to the fourth network function node and to receive a subscription change request response message sent by the fourth network function node, the subscription change request response message carrying the identifier or address of the second network function node.
[0131] The determining unit is used to determine the second network function node based on the contract change request response message.
[0132] Furthermore, the query message may carry the network function name and / or network type, as well as the user identifier and / or the location information of the first network function node;
[0133] The aforementioned contract change request message may carry the network function name and / or network type, as well as the user identifier and / or the location information of the first network function node.
[0134] In one example, the aforementioned determining module may include a communication unit, a storage unit, and a determining unit;
[0135] The communication unit is used to receive the subscription data management subscription message sent by the fourth network function node. The subscription data management subscription message carries the identifier or address of the second network function node.
[0136] Storage unit, used to manage the storage of the identifier or address of the second network function node according to the contract data;
[0137] The determining unit is used to determine the second network function node based on the stored identifier or address of the second network function node.
[0138] In one example, the above-described apparatus may further include an authentication module for performing the main authentication process via a fourth network function node.
[0139] The contract data update device provided in this embodiment is used to implement... Figure 5 , Figure 6 , Figure 7 , Figure 8 , Figure 9 The contract data update method in the illustrated embodiment has a similar implementation principle and technical effect, and will not be described in detail here.
[0140] Figure 13 This application provides a contract data update device, such as... Figure 13As shown, the device may include: a receiving module 1301, a determining module 1302, and a sending module 1303;
[0141] The receiving module is used to receive query messages sent by the first network function node.
[0142] The determination module is used to determine the second network function node based on the query message;
[0143] The sending module is used to send a query response message to the first network function node, and the query response message carries the identifier or address of the second network function node.
[0144] The query message contains the network function name and / or network type, as well as the user identifier and / or the location information of the first network function node.
[0145] The contract data update device provided in this embodiment is used to implement... Figure 10 The contract data update method in the illustrated embodiment has a similar implementation principle and technical effect, and will not be described in detail here.
[0146] Figure 14 This application provides a contract data update device, such as... Figure 14 As shown, the device may include: a determining module 1401 and a sending module 1402;
[0147] The determining module is used to determine the second network functional node;
[0148] The sending module is used to send a message to the first network function node, which carries the identifier or address of the second network function node.
[0149] Optionally, the aforementioned determining module may include a communication unit and a query unit;
[0150] The communication unit is used to receive a subscription change request message sent by the first network function node, the subscription change request message carrying a user identifier.
[0151] The query unit is used to query the second network function node based on the user identifier.
[0152] The contract data update device provided in this embodiment is used to implement... Figure 11 The contract data update method in the illustrated embodiment has a similar implementation principle and technical effect, and will not be described in detail here.
[0153] Figure 15 This application provides a schematic diagram of the structure of a network node, as shown in the embodiment. Figure 15 As shown, the network node includes a processor 1501 and a memory 1502; the number of processors 1501 in the network node can be one or more. Figure 15 Taking a processor 1501 as an example; the processor 1501 and memory 1502 in a network node can be connected via a bus or other means. Figure 15 Taking the example of a connection between China and Israel via a bus.
[0154] Memory 1502, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, as described in this application. Figures 5-11 The program instructions / modules corresponding to the method in any embodiment. Processor 1501 implements the above by running the software programs, instructions, and modules stored in memory 1502. Figures 5-11 The method described in the embodiments.
[0155] The memory 1502 may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a function; the data storage area may store data created based on the use of the set-top box, etc. In addition, the memory 1502 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device.
[0156] In one example, where possible, the processor in the aforementioned node can also implement the above-mentioned contract data update method through its internal logic circuits, gate circuits, and other hardware circuits.
[0157] This application also provides a read / write storage medium for computer storage. The storage medium stores one or more programs, and when these programs can be executed by one or more processors, they can achieve the following: Figures 5-11 The method provided in any embodiment.
[0158] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the device, can be implemented as software, firmware, hardware, and suitable combinations thereof.
[0159] In hardware implementations, the division between functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, as is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
[0160] The above description, with reference to the accompanying drawings, is merely an illustration of an exemplary embodiment of this application and is not intended to limit the scope of this application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of this application shall be within the scope of this application.
Claims
1. A wireless communication method, comprising: If the first network function node determines that the user's application authentication and key management architecture AKMA subscription data has been updated, the first network function node will determine the second network function node that stores the user's AKMA context. The first network function node sends a subscription data management notification message to the determined second network function node; The first network function node receives the subscription data management notification response message sent by the second network function node. The subscription data management notification response message is sent by the second network function node after the second network function node deletes the user's AKMA context according to the subscription data management notification message; Wherein, the first network function node determines the second network function node storing the user's AKMA context, including: The first network function node determines the second network function node based on its local configuration; or... The first network function node determines the second network function node through the third network function node. The process of the first network function node determining the second network function node based on its local configuration includes: the first network function node determining the second network function node based on certain fields of the user identifier.
2. The method according to claim 1, wherein, The first network function node determines the second network function node that stores the user's AKMA context, including: The first network function node sends a query message to the third network function node; The first network function node receives a query response message sent by the third network function node based on the query message, wherein the query response message carries the identifier or address of the second network function node; The first network function node determines the second network function node that stores the user's AKMA context based on the query response message.
3. The method according to claim 1, wherein, The first network function node determines the second network function node that stores the user's AKMA context, including: The first network function node sends a subscription change request message to the third network function node; The first network function node receives a subscription change request response message sent by the third network function node, the subscription change request response message carrying the identifier or address of the second network function node; The first network function node determines the second network function node that stores the user's AKMA context based on the subscription change request response message.
4. The method according to claim 2, wherein, The query message carries the network function name and / or network type, as well as the user identifier and / or the location information of the first network function node.
5. The method according to claim 3, wherein, The subscription change request message carries the network function name and / or network type, as well as the user identifier and / or the location information of the first network function node.
6. The method according to claim 1, wherein, The first network function node determines the second network function node that stores the user's AKMA context, including: The first network function node receives a contract data management contract message sent by the third network function node, the contract data management contract message carrying the identifier or address of the second network function node; The first network function node manages the signing message storage based on the signing data and stores the identifier or address of the second network function node; The first network function node determines the second network function node storing the user's AKMA context based on the identifier or address of the second network function node stored in the first network function node.
7. The method according to claim 6, wherein, Before the first network function node receives the subscription data management subscription message sent by the third network function node, the method further includes: The first network function node performs the main authentication process through the third network function node.
8. A first network functional node, comprising a memory for storing computer instructions and a processor communicating with the memory, wherein, When the processor executes the computer instructions, the processor is configured to cause the first network function node to: In the case of determining that the user's application authentication and key management architecture AKMA subscription data has been updated, the second network function node storing the user's AKMA context is identified; Send a contract data management notification message to the identified second network function node; Receive the subscription data management notification response message sent by the second network function node. The subscription data management notification response message is sent by the second network function node after the second network function node deletes the user's AKMA context according to the subscription data management notification message; Wherein, when the processor is configured to cause the first network function node to determine the second network function node storing the user's AKMA context, the processor is configured to cause the first network function node to perform one of the following operations: The second network function node is determined based on the local configuration; or The second network function node is determined by the third network function node. The step of determining the second network function node based on local configuration includes: determining the second network function node based on a portion of the user identifier field.
9. The first network functional node according to claim 8, wherein, When the processor is configured to cause the first network function node to determine the second network function node storing the user's AKMA context, the processor is configured to cause the first network function node to: Send a query message to the third network function node; Receive a query response message sent by the third network function node based on the query message, wherein the query response message carries the identifier or address of the second network function node; The second network function node storing the user's AKMA context is determined based on the query response message.
10. The first network functional node according to claim 8, wherein, When the processor is configured to cause the first network function node to determine the second network function node storing the user's AKMA context, the processor is configured to cause the first network function node to: Send a subscription change request message to the third network function node; Receive a subscription change request response message sent by the third network function node, wherein the subscription change request response message carries the identifier or address of the second network function node; The second network function node that stores the user's AKMA context is determined based on the subscription change request response message.
11. The first network functional node according to claim 9, wherein, The query message carries the network function name and / or network type, as well as the user identifier and / or the location information of the first network function node.
12. The first network functional node according to claim 10, wherein, The subscription change request message carries the network function name and / or network type, as well as the user identifier and / or the location information of the first network function node.
13. The first network functional node according to claim 8, wherein, When the processor is configured to cause the first network function node to determine the second network function node storing the user's AKMA context, the processor is configured to cause the first network function node to: Receive a subscription data management subscription message sent by a third network function node, wherein the subscription data management subscription message carries the identifier or address of the second network function node; According to the signed data, the management of signed messages stores the identifier or address of the second network function node; The second network function node storing the user's AKMA context is determined based on the identifier or address of the second network function node stored in the first network function node.
14. The first network functional node according to claim 13, wherein, Before the processor is configured to cause the first network function node to receive the subscription data management subscription message sent by the third network function node, the processor is further configured to cause the first network function node to: The main authentication process is performed through the third network function node.
15. A storage medium storing computer-readable instructions that, when executed by a processor in a first network functional node, cause the processor to: In the case of determining that the user's application authentication and key management architecture AKMA subscription data has been updated, the second network function node storing the user's AKMA context is identified; Send a contract data management notification message to the identified second network function node; Receive the subscription data management notification response message sent by the second network function node. The subscription data management notification response message is sent by the second network function node after the second network function node deletes the user's AKMA context according to the subscription data management notification message; Wherein, when the computer-readable instructions cause the processor to determine a second network function node storing the user's AKMA context, the computer-readable instructions cause the processor to perform one of the following operations: The second network function node is determined based on the local configuration; or The second network function node is determined by the third network function node. The step of determining the second network function node based on local configuration includes: determining the second network function node based on a portion of the user identifier field.
16. The storage medium according to claim 15, wherein, When the computer-readable instructions cause the processor to determine the second network function node storing the user's AKMA context, the computer-readable instructions cause the processor to: Send a query message to the third network function node; Receive a query response message sent by the third network function node based on the query message, wherein the query response message carries the identifier or address of the second network function node; The second network function node storing the user's AKMA context is determined based on the query response message.
17. The storage medium according to claim 16, wherein, The query message carries the network function name and / or network type, as well as the user identifier and / or the location information of the first network function node.
18. The storage medium according to claim 15, wherein, When the computer-readable instructions cause the processor to determine the second network function node storing the user's AKMA context, the computer-readable instructions cause the processor to: Send a subscription change request message to the third network function node; Receive a subscription change request response message sent by the third network function node, wherein the subscription change request response message carries the identifier or address of the second network function node; The second network function node that stores the user's AKMA context is determined based on the subscription change request response message.
19. The storage medium according to claim 18, wherein, The subscription change request message carries the network function name and / or network type, as well as the user identifier and / or the location information of the first network function node.
20. The storage medium according to claim 15, wherein, When the computer-readable instructions cause the processor to determine the second network function node storing the user's AKMA context, the computer-readable instructions cause the processor to: Receive a subscription data management subscription message sent by a third network function node, wherein the subscription data management subscription message carries the identifier or address of the second network function node; According to the signed data, the management of signed messages stores the identifier or address of the second network function node; The second network function node storing the user's AKMA context is determined based on the identifier or address of the second network function node stored in the first network function node.
21. The storage medium according to claim 20, wherein, Before the computer-readable instructions cause the processor to receive the subscription data management subscription message sent by the third network function node, the computer-readable instructions also cause the processor to: The main authentication process is performed through the third network function node.