Data transmission method and system and signaling security management gateway

By providing access authentication and encrypted channel transmission for the sinking access network elements through the signaling security management gateway, the risk of information leakage between the core network and the sinking access network elements in the 5G network is resolved, and the security and privacy protection of data transmission are achieved.

CN117135625BActive Publication Date: 2026-04-14CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD
Filing Date
2022-05-20
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

In 5G networks, there is a risk of information leakage during data transmission between the core network and the downstream access network elements, which is difficult to effectively solve with existing technologies.

Method used

A signaling security management gateway is introduced to provide access authentication and management, and to transmit data through an encrypted channel to ensure data security between core network elements and downstream access network elements.

Benefits of technology

It improves the security of data transmission between core network elements and downstream access network elements, reduces the risk of information leakage, and ensures the privacy and integrity of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117135625B_ABST
    Figure CN117135625B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data transmission method and system and a signaling security management gateway, and relates to the technical field of communication and network security. The signaling security management gateway receives a request of a sinking access network element accessing a core network element, authenticates the sinking access network element, establishes an encrypted channel with the sinking access network element that passes the authentication, receives a user data synchronization request sent by the sinking access network element, sends the user data synchronization request to a corresponding core network element, receives encrypted user data sent by the core network element, and sends the encrypted user data to the sinking access network element through the encrypted channel. The signaling security management gateway provides access authentication and management for the sinking access network element, and transmits data from the core network element to the sinking access network element that passes the authentication through the encrypted channel, thereby improving the security of data transmission between the core network element and the sinking access network element and reducing the risk of information leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the fields of communication and network security technology, and in particular to a data transmission method and system and a signaling security management gateway. Background Technology

[0002] In 5G networks, some core network functions are decentralized to the access network as needed. Data transmission between core network elements and decentralized access network elements poses a risk of information leakage. Summary of the Invention

[0003] This embodiment of the disclosure provides access authentication and management for the sinking access network elements through a signaling security management gateway. Data sent from the core network elements is transmitted to the authenticated sinking access network elements through an encrypted channel, thereby improving the security of data transmission between the core network elements and the sinking access elements and reducing the risk of information leakage.

[0004] This disclosure provides a data transmission method according to some embodiments, including:

[0005] The signaling security management gateway receives requests from the sinking access network element to access the core network element and authenticates the sinking access network element.

[0006] The signaling security management gateway establishes an encrypted channel with the authenticated sinking access network element;

[0007] The signaling security management gateway receives the user data synchronization request sent by the sinking access network element and sends the user data synchronization request to the corresponding core network element.

[0008] The signaling security management gateway receives encrypted user data sent by the core network element and sends the encrypted user data to the sinking access network element through the encrypted channel.

[0009] In some embodiments, the signaling security management gateway receives a request from a lower-level access network element to access a core network element, and authenticates the lower-level access element, including:

[0010] The signaling security management gateway receives a request from a sinking access network element to access a core network element, which carries the identifier of the sinking access network element, the identifier of the user card embedded in the sinking access network element, and the certificate information in the user subscription data.

[0011] If the binding relationship between the identifier of the access network element in the access request and the identifier of the user card is incorrect or does not exist, the signaling security management gateway determines that the authentication of the access network element fails; or,

[0012] If the signaling security management gateway determines that the authentication of the sinking access network element fails if the timeliness and legality of the certificate information in the user's subscription data in the access request do not meet the requirements; or...

[0013] If the binding relationship between the identifier of the sinking access network element in the access request and the identifier of the user card is correct, and the timeliness and legality of the certificate information in the user subscription data meet the requirements, the signaling security management gateway determines that the sinking access network element has been authenticated.

[0014] In some embodiments, the signaling security management gateway receives a user data synchronization request sent by the sinking access network element. The user data synchronization request includes the identifier and data network information of the sinking access network element. The gateway then sends the user data synchronization request to the corresponding core network element so that the core network element can locate the encrypted user data corresponding to the identifier and data network information of the sinking access network element.

[0015] In some embodiments, it also includes:

[0016] The signaling security management gateway receives a request from the sinking access network element to download user subscription data. The request includes the identifier of the sinking access network element and the identifier and certificate of the user card embedded in the sinking access network element.

[0017] The signaling security management gateway authenticates the user card based on its identifier and certificate. After successful authentication, it queries the user subscription data loaded by the sinking access network element. If the sinking access network element has not loaded user subscription data or the loaded user subscription data has expired, it notifies the sinking access network element to download new user subscription data and establishes a binding information between the identifier of the sinking access network element and the identifier of the user card embedded in the sinking access network element.

[0018] In some embodiments, the signaling security management gateway notifies the sinking access network element to download new user subscription data, including:

[0019] The signaling security management gateway notifies the sinking access network element to download new user subscription data, so that the sinking access network element can download and enable the new user subscription data through an encrypted channel;

[0020] The signaling security management gateway receives a message from the sinking access network element indicating that the new user subscription data has been successfully enabled.

[0021] In some embodiments, the signaling security management gateway issues user cards to each sinking access network element, and each user card includes the certificate of the user card.

[0022] In some embodiments, the core network elements include UDM network elements, UPF network elements, AMF network elements, and SMF network elements.

[0023] In some embodiments, the sinking access network element includes UDM network element, UPF network element, AMF network element, and SMF network element.

[0024] In some embodiments, the user card includes an embedded UICC.

[0025] This disclosure provides some embodiments of a signaling security management gateway, including:

[0026] The authentication module is configured to receive requests from the sinking access network element to access the core network element, and to authenticate the sinking access network element.

[0027] The channel establishment module is configured to establish an encrypted channel with the authenticated sinking access network element;

[0028] The information proxy module is configured to receive user data synchronization requests sent by the sinking access network element, send the user data synchronization requests to the corresponding core network element, receive encrypted user data sent by the core network element, and send the encrypted user data to the sinking access network element through the encryption channel.

[0029] In some embodiments, the signaling security management gateway further includes: a download management module, configured to receive a request from the sinking access network element to download user subscription data, the request including the identifier of the sinking access network element and the identifier and certificate of the user card embedded in the sinking access network element; perform authentication based on the identifier and certificate of the user card; after successful authentication, query the user subscription data loaded by the sinking access network element; if the sinking access network element has not loaded user subscription data or the loaded user subscription data has expired, notify the sinking access network element to download new user subscription data, and establish binding information between the identifier of the sinking access network element and the identifier of the user card embedded in the sinking access element.

[0030] In some embodiments, the authentication module is configured to:

[0031] Receive a request from a sinking access network element to access a core network element, which carries the identifier of the sinking access network element, the identifier of the user card embedded in the sinking access network element, and the certificate information in the user subscription data;

[0032] If the binding relationship between the identifier of the sinking access network element and the identifier of the user card in the access request is incorrect or does not exist, the authentication of the sinking access network element is determined to be unsuccessful; or,

[0033] If the timeliness and legality of the certificate information in the user's subscription data in the access request do not meet the requirements, the authentication of the sinking access network element is deemed unsuccessful; or...

[0034] If the binding relationship between the identifier of the sinking access network element in the access request and the identifier of the user card is correct, and the timeliness and legality of the certificate information in the user subscription data meet the requirements, the sinking access network element is deemed to have passed authentication.

[0035] Some embodiments of this disclosure provide a signaling security management gateway, including: a memory; and a processor coupled to the memory, the processor being configured to execute data transmission methods of various embodiments based on instructions stored in the memory.

[0036] This disclosure provides a data transmission system comprising: a signaling security management gateway according to various embodiments; a core network element configured to respond to a user data synchronization request and send encrypted user data to the signaling security management gateway; and a sinking access network element configured to send a request to the signaling security management gateway to access the core network element, establish an encrypted channel with the signaling security management gateway, send a user data synchronization request to the signaling security management gateway, and receive encrypted user data sent by the signaling security management gateway through the encrypted channel.

[0037] Some embodiments of this disclosure provide a non-transitory computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the steps of the data transmission methods of various embodiments. Attached Figure Description

[0038] The accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. This disclosure can be more clearly understood from the following detailed description with reference to the accompanying drawings.

[0039] Obviously, the accompanying drawings described below are merely some embodiments of this disclosure. Those skilled in the art can obtain other drawings based on these drawings without any creative effort.

[0040] Figure 1 A schematic diagram of a secure data transmission system according to some embodiments of the present disclosure is shown.

[0041] Figure 2 A schematic diagram illustrating a secure data transmission method according to some embodiments of this disclosure is shown.

[0042] Figure 3 A schematic diagram illustrating a secure data transmission method according to other embodiments of this disclosure is shown.

[0043] Figure 4A schematic diagram of the structure of a signaling security management gateway according to some embodiments of this disclosure is shown.

[0044] Figure 5 A schematic diagram of the structure of a signaling security management gateway according to other embodiments of this disclosure is shown. Detailed Implementation

[0045] The technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings.

[0046] Unless otherwise stated, the terms "first," "second," etc., used in this disclosure are used to distinguish different objects and are not used to indicate size or sequence.

[0047] Figure 1 A schematic diagram of a secure data transmission system according to some embodiments of the present disclosure is shown.

[0048] like Figure 1 As shown, the secure data transmission system of this embodiment includes: a core network element 110, a signaling security management gateway 120, and a sinking access network element 130.

[0049] Core network elements 110 are various network elements deployed in the core network, including Unified Data Management (UDM) elements, User Plane Function (UPF) elements, Access and Mobility Management Function (AMF) elements, and Session Management Function (SMF) elements. The core network provides network services such as terminal access and mobility management, authentication and authorization management, session management, and policy control through these various core network elements. Taking 5G networks as an example, the 5G SA (Stand Alone) core network provides 5G terminal access and mobility management, authentication and authorization management, session management, and policy control, among other 5G network services.

[0050] The signaling security management gateway 120 includes functions such as network element authentication and authorization, remote management of embedded user cards, and information brokerage. The remote management function for embedded user cards includes, for example, interacting with embedded user cards to establish encrypted channels; managing and downloading embedded user card data; interacting with embedded user cards to download user subscription data to the embedded user cards; and remotely configuring user data to meet users' needs for secure and flexible configuration and management of embedded user cards. Utilizing the security capabilities of remote management of embedded user cards, it provides authentication management for decentralized access network elements. The user cards include, for example, embedded universal integrated circuit cards (eUICC).

[0051] User subscription data includes, but is not limited to: user authentication-related subscription data, access management subscription data, and session management subscription data. User authentication-related subscription data includes, but is not limited to: International Mobile Subscriber Identity (IMSI), mobile subscriber number, etc., where the mobile subscriber number is, for example, MSISDN (Mobile Subscriber International ISDN number). Access management subscription data includes, but is not limited to: UE (User Equipment) level uplink and downlink bandwidth, prohibited area data, service area restriction data, RFSP (RAT / Frequency Selection Priority; RAT: Radio Access Technology), authentication methods, etc. Session management subscription data includes, but is not limited to: S-NSSAI (Single Network Slice Selection Assistance Information), DNN (Data Network Name), quality of service, and whether the default DNN is used, etc.

[0052] Downlink access element 130 refers to network elements that have functions moved from the core network to the edge access network. Examples of downlink access element 130 include UDM network elements, UPF network elements, AMF network elements, and SMF network elements. For instance, a downlink UDM network element is formed by moving some functions of a core network UDM network element to the edge access network. Downlink access element 130 needs to interact with core network element 110 for data exchange, such as user authentication.

[0053] The sinking access network element 130 can be configured with an embedded user card. The embedded user card can store card files, data, and applications, and can remotely download user subscription data. User subscription data includes, but is not limited to, user identification information and service information. Embedded user cards may include, for example, embedded UICCs.

[0054] The interfaces between the core network element 110 and the signaling security management gateway 120 include, for example, N4 / N8 / N10 / N12 / N14, and the interfaces between the signaling security management gateway 120 and the sinking access network element 130 include, for example, N4 / N8 / N10 / N12 / N14.

[0055] To achieve secure data transmission, in the data transmission system, the signaling security management gateway 120 is configured to receive requests from lower-level access network elements to access core network elements, authenticate the lower-level access network elements, establish an encrypted channel with the authenticated lower-level access network elements, receive user data synchronization requests sent by the lower-level access network elements, and send the user data synchronization requests to the corresponding core network elements; receive encrypted user data sent by the core network elements, and send the encrypted user data to the lower-level access network elements through the encrypted channel; the core network element 110 is configured to respond to user data synchronization requests and send encrypted user data to the signaling security management gateway; and the lower-level access network element 130 is configured to send requests to the signaling security management gateway to access core network elements, establish an encrypted channel with the signaling security management gateway, send user data synchronization requests to the signaling security management gateway, and receive encrypted user data sent by the signaling security management gateway through the encrypted channel.

[0056] To securely download user subscription data, in the data transmission system, the signaling security management gateway 120 is configured to receive requests from the sinking access network element to download user subscription data. These requests include the identifier of the sinking access network element and the identifier and certificate of the user card embedded in the sinking access network element. Authentication is performed based on the user card identifier and certificate. Upon successful authentication, the gateway queries the user subscription data loaded by the sinking access network element. If the sinking access network element has not loaded user subscription data or the loaded user subscription data has expired, the gateway notifies the sinking access network element to download new user subscription data, and establishes a binding between the identifier of the sinking access network element and the identifier of the user card embedded in the sinking access element.

[0057] Figure 2 A schematic diagram illustrating a secure data transmission method according to some embodiments of this disclosure is shown.

[0058] like Figure 2 As shown, the secure data transmission method of this embodiment includes the following steps.

[0059] In step 200, the signaling security management gateway issues user cards to each sinking access network element, and each user card includes the certificate of the issued user card.

[0060] In step 210, the signaling security management gateway receives a request from the sinking access network element to download user subscription data. The request includes the identifier of the sinking access network element and the identifier and certificate of the user card embedded in the sinking access network element.

[0061] In step 220, the signaling security management gateway authenticates the user card based on its identifier and certificate. After successful authentication, it queries the user subscription data loaded by the sinking access network element. If the sinking access network element has not loaded user subscription data or the loaded user subscription data has expired, it notifies the sinking access network element to download new user subscription data and establishes a binding information between the identifier of the sinking access network element and the identifier of the user card embedded in the sinking access network element. If the user subscription data loaded by the sinking access network element has not expired, it notifies the sinking access network element that it does not need to download or to stop downloading user subscription data.

[0062] The authentication based on the user card's identifier and certificate includes: if the issuer of the user card's certificate is the signaling security management gateway, and the user card's certificate is valid, and the user card's certificate matches the user card's identifier, the authentication is successful; otherwise, the authentication fails.

[0063] In step 230, the signaling security management gateway notifies the sinking access network element to download new user subscription data.

[0064] In step 240, the sinking access network element downloads and activates new user subscription data through an encrypted channel, while old user subscription data can be deleted.

[0065] In step 250, the signaling security management gateway receives a message from the sinking access network element indicating that the new user subscription data has been successfully enabled.

[0066] In step 260, the signaling security management gateway receives a request from the sinking access network element to access the core network element, which carries the identifier of the sinking access network element, the identifier of the user card embedded in the sinking access network element, and the certificate information in the user subscription data.

[0067] In step 270, the signaling security management gateway authenticates the sinking access network element, for example including:

[0068] If the binding relationship between the identifier of the sinking access network element and the identifier of the user card in the access request is incorrect or does not exist, the authentication of the sinking access network element is determined to be unsuccessful; or,

[0069] If the timeliness and legality of the certificate information in the user's subscription data in the access request do not meet the requirements, the authentication of the sinking access network element is deemed unsuccessful; or...

[0070] If the binding relationship between the identifier of the sinking access network element in the access request and the identifier of the user card is correct, and the timeliness and legality of the certificate information in the user subscription data meet the requirements, the sinking access network element is deemed to have passed authentication.

[0071] Steps 290 to 2150 can only be executed after authentication is successful.

[0072] In step 280, the signaling security management gateway sends the authentication result to the sinking access network element. The authentication result may include, for example, authentication successful or authentication failed.

[0073] In step 290, the signaling security management gateway establishes an encrypted channel with the authenticated sinking access network element.

[0074] The establishment of an encrypted channel can refer to existing technologies. An encrypted channel may include, for example, encryption key information negotiated by the communicating parties. After the encrypted channel is established, the communicating parties can use the negotiated encryption key to transmit information. Since a third party does not know the encryption key, even if they intercept the encrypted information, they will have no way of knowing the transmitted information.

[0075] In step 2100, the signaling security management gateway receives a user data synchronization request sent by the sinking access network element. The user data synchronization request includes the identifier of the sinking access network element and data network information.

[0076] Data network information includes, but is not limited to, the data network name (DNN).

[0077] In step 2110, the signaling security management gateway sends the user data synchronization request to the corresponding core network element.

[0078] For example, the signaling security management gateway forwards user data synchronization requests from the downlink UDM network element to the core network UDM network element.

[0079] The core network element is hidden from the sinking access network element. The sinking access network element sends the request to the signaling security management gateway without sending it to the core network element. The signaling security management gateway can then send the request to the core network element.

[0080] In step 2120, the core network element searches for the user data corresponding to the identifier and data network information of the sinking access network element and encrypts it to obtain encrypted user data.

[0081] Among them, the core network element can encrypt user data according to the key pre-negotiated with the sinking access network element to obtain encrypted user data.

[0082] User data includes, for example, user cards and authentication data, such as IMSI and KI (Key Identifier).

[0083] In step 2130, the signaling security management gateway receives encrypted user data sent by the core network element.

[0084] In step 2140, the signaling security management gateway sends the encrypted user data to the sinking access network element through the encrypted channel.

[0085] In step 2150, the sinking access network element receives the encrypted user data, decrypts it to obtain the user data, and uses the user data to ensure service according to service needs, such as ensuring uninterrupted service.

[0086] Among them, the sinking access network element can decrypt the encrypted user data to obtain the user data according to the key pre-negotiated with the core network element.

[0087] The above embodiments provide access authentication and management for the sinking access network elements through the signaling security management gateway. Data sent from the core network elements is transmitted to the authenticated sinking access network elements through an encrypted channel, thereby improving the security of data transmission between the core network elements and the sinking access elements and reducing the risk of information leakage.

[0088] The following is combined Figure 3This describes a method for securely transmitting user data between core network UDM elements and downstream UDM elements through a signaling security management gateway.

[0089] Figure 3 A schematic diagram illustrating a secure data transmission method according to other embodiments of this disclosure is shown.

[0090] like Figure 3 As shown, the secure data transmission method of this embodiment includes the following steps.

[0091] In step 300, the sinking UDM network element has an embedded UICC, and the UICC is issued by the signaling security management gateway.

[0092] In step 310, the sinking UDM network element requests access to the 5G SA network on time or as needed. It actively connects to the signaling security management gateway through the embedded UICC and requests to download user subscription data (set as Profile). The request carries the EID (Electronic Identity) of the embedded UICC and the device ID of the sinking UDM network element.

[0093] In step 320, after receiving the request, the network element access management gateway performs security authentication based on the EID and certificate information in the UICC. After successful authentication, it queries whether the corresponding downstream UDM network element has loaded the Profile. If it has not loaded or the Profile has expired, it notifies the downstream UDM network element to prepare to download user subscription data and binds the EID and the device ID. If the Profile has been loaded and has not expired, it notifies the downstream UDM network element to stop downloading.

[0094] The security authentication based on EID and UICC certificate information includes: if the issuer of the UICC certificate is the signaling security management gateway, the UICC certificate is valid, and the UICC certificate matches the EID, the authentication passes; otherwise, the authentication fails.

[0095] In step 330, the signaling security management gateway sends a request to the sinking UDM network element, requesting the establishment of an encrypted channel and the download and activation of the Profile.

[0096] In step 340, an encrypted channel is established between the sinking UDM network element and the signaling security management gateway. A new profile is downloaded through the encrypted channel. If an expired profile has been loaded previously, the old profile is deleted and a new profile is enabled.

[0097] In step 350, the sinking UDM network element returns a message to the signaling security management gateway indicating that the Profile has been successfully enabled.

[0098] In step 360, the sinking UDM network element initiates a request to access the core network UDM network element in the 5G SA network to the signaling security management gateway, carrying the embedded UICC's EID, device ID, and certificate information in the Profile.

[0099] In step 370, the signaling security management gateway checks whether the binding relationship between EID and device ID is correct based on the request information of the UDM network element. If it is incorrect or does not exist, the UDM network element is not allowed to access. If it is correct, the validity and legality of the certificate in the Profile are verified. After successful verification, the UDM network element is allowed to access.

[0100] In step 380, after successful authentication, the signaling security management gateway sends an authentication success notification to the submerged UDM network element.

[0101] In step 390, the sinking UDM network element uses embedded UICC-related security information, such as EID, to establish an encrypted channel with the signaling security management gateway.

[0102] In step 3100, the sinking UDM network element sends a user data synchronization request to the signaling security management gateway, carrying information such as DNN and device ID.

[0103] In step 3110, the signaling security management gateway hides the core network UDM topology information and forwards the user data synchronization request to the corresponding core network UDM element to request the synchronization of user data.

[0104] In step 3120, after receiving the user data synchronization request, the core network UDM element finds the relevant user card data and authentication data, such as IMSI, KI, etc., based on the device ID and DNN information, and encrypts the user data. The encryption key is negotiated or set in advance by the core network UDM element and the sinking UDM element.

[0105] In step 3130, the core network UDM element transmits the encrypted user data to the signaling security management gateway.

[0106] In step 3140, the signaling security management gateway transmits encrypted user data to the sinking UDM network element through an encrypted channel.

[0107] In step 3150, the UDM network element decrypts the encrypted user data to obtain the user data. Based on the needs of 5G application scenarios (such as emergency communication, emergency communication, etc.), the user card data and authentication data are used as needed to ensure that 5G services are not interrupted.

[0108] The above embodiments do not change the existing 5G architecture and service implementation process. By utilizing embedded UICC remote configuration technology and security encryption technology, they perform security authentication and management on untrusted access network element devices such as 5G UDMs accessing the 5G core network. This effectively reduces the security interaction risks between the 5G core network elements and the 5G core network. At the same time, sensitive data (such as user card data and authentication data) in the requested 5G core network UDM are encrypted and transmitted through encrypted channels, effectively reducing the security risk of information leakage, thereby improving the network security and data security of 5G.

[0109] Figure 4 A schematic diagram of the structure of a signaling security management gateway according to some embodiments of this disclosure is shown.

[0110] like Figure 4 As shown, the signaling security management gateway 120 in this embodiment includes:

[0111] The authentication module 410 is configured to receive requests from the sinking access network element to access the core network element, and to authenticate the sinking access network element.

[0112] The channel establishment module 420 is configured to establish an encrypted channel with the authenticated sinking access network element;

[0113] The information proxy module 430 is configured to receive user data synchronization requests sent by the sinking access network element, send the user data synchronization requests to the corresponding core network element, receive encrypted user data sent by the core network element, and send the encrypted user data to the sinking access network element through the encryption channel.

[0114] In some embodiments, the signaling security management gateway 120 further includes: a download management module 440, configured to receive a request from the sinking access network element to download user subscription data, the request including the identifier of the sinking access network element and the identifier and certificate of the user card embedded in the sinking access network element; perform authentication based on the identifier and certificate of the user card; after successful authentication, query the user subscription data loaded by the sinking access network element; if the sinking access network element has not loaded user subscription data or the loaded user subscription data has expired, notify the sinking access network element to download new user subscription data, and establish binding information between the identifier of the sinking access network element and the identifier of the user card embedded in the sinking access element.

[0115] In some embodiments, the authentication module 410 is configured to:

[0116] Receive a request from a sinking access network element to access a core network element, which carries the identifier of the sinking access network element, the identifier of the user card embedded in the sinking access network element, and the certificate information in the user subscription data;

[0117] If the binding relationship between the identifier of the sinking access network element and the identifier of the user card in the access request is incorrect or does not exist, the authentication of the sinking access network element is determined to be unsuccessful; or,

[0118] If the timeliness and legality of the certificate information in the user's subscription data in the access request do not meet the requirements, the authentication of the sinking access network element is deemed unsuccessful; or...

[0119] If the binding relationship between the identifier of the sinking access network element in the access request and the identifier of the user card is correct, and the timeliness and legality of the certificate information in the user subscription data meet the requirements, the sinking access network element is deemed to have passed authentication.

[0120] Figure 5 A schematic diagram of the structure of a signaling security management gateway according to other embodiments of this disclosure is shown.

[0121] like Figure 5 As shown, the signaling security management gateway 120 of this embodiment includes a memory 510 and a processor 520 coupled to the memory 510. The processor 520 is configured to execute the secure data transmission method of any of the foregoing embodiments based on instructions stored in the memory 510.

[0122] The memory 510 may include, for example, system memory, fixed non-volatile storage media, etc. The system memory may store, for example, the operating system, application programs, boot loader, and other programs.

[0123] The processor 520 can be implemented using a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gates, or transistors, or other discrete hardware components.

[0124] The signaling security management gateway 120 may also include input / output interfaces 530, network interfaces 540, and storage interfaces 550. These interfaces 530, 540, and 550, as well as the memory 510 and processor 520, can be connected via, for example, a bus 560. The input / output interface 530 provides a connection interface for input / output devices such as displays, mice, keyboards, and touchscreens. The network interface 540 provides a connection interface for various networked devices. The storage interface 550 provides a connection interface for external storage devices such as SD cards and USB flash drives. The bus 560 can use any bus architecture from various bus structures. For example, bus architectures include, but are not limited to, Industry Standard Architecture (ISA) buses, MicroChannel Architecture (MCA) buses, and Peripheral Component Interconnect (PCI) buses.

[0125] Those skilled in the art will understand that embodiments of this disclosure can be provided as methods, systems, or computer program products. Therefore, this disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this disclosure can take the form of a computer program product embodied on one or more non-transitory computer-readable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer program code.

[0126] This disclosure is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0127] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0128] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0129] The above description is only a preferred embodiment of this disclosure and is not intended to limit this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the protection scope of this disclosure.

Claims

1. A data transmission method, characterized in that, include: The signaling security management gateway receives a request from the sinking access network element to download user subscription data. The request includes the identifier of the sinking access network element and the identifier and certificate of the user card embedded in the sinking access network element. The signaling security management gateway authenticates the user card based on its identifier and certificate. After successful authentication, it queries the user subscription data loaded by the sinking access network element. If the sinking access network element has not loaded user subscription data or the loaded user subscription data has expired, it notifies the sinking access network element to download new user subscription data and establishes a binding information between the identifier of the sinking access network element and the identifier of the user card embedded in the sinking access network element. The signaling security management gateway receives a request from a sinking access network element to access a core network element, and authenticates the sinking access network element based on the user subscription data and the binding information. The signaling security management gateway establishes an encrypted channel with the authenticated sinking access network element; The signaling security management gateway receives the user data synchronization request sent by the sinking access network element and sends the user data synchronization request to the corresponding core network element. The signaling security management gateway receives encrypted user data sent by the core network element and sends the encrypted user data to the sinking access network element through the encrypted channel.

2. The method according to claim 1, characterized in that, The signaling security management gateway receives requests from sinking access network elements to access core network elements, and performs authentication on the sinking access network elements, including: The signaling security management gateway receives a request from a sinking access network element to access a core network element, which carries the identifier of the sinking access network element, the identifier of the user card embedded in the sinking access network element, and the certificate information in the user subscription data. If the binding relationship between the identifier of the access network element in the access request and the identifier of the user card is incorrect or does not exist, the signaling security management gateway determines that the authentication of the access network element fails; or, If the signaling security management gateway determines that the authentication of the sinking access network element fails if the timeliness and legality of the certificate information in the user's subscription data in the access request do not meet the requirements; or... If the binding relationship between the identifier of the sinking access network element in the access request and the identifier of the user card is correct, and the timeliness and legality of the certificate information in the user subscription data meet the requirements, the signaling security management gateway determines that the sinking access network element has passed authentication.

3. The method according to claim 1, characterized in that, The signaling security management gateway receives a user data synchronization request sent by the sinking access network element. The user data synchronization request includes the identifier and data network information of the sinking access network element. The gateway then sends the user data synchronization request to the corresponding core network element so that the core network element can locate the encrypted user data corresponding to the identifier and data network information of the sinking access network element.

4. The method according to claim 1, characterized in that, The signaling security management gateway notifies the sinking access network element to download new user subscription data, including: The signaling security management gateway notifies the sinking access network element to download new user subscription data, so that the sinking access network element can download and enable the new user subscription data through an encrypted channel; The signaling security management gateway receives a message from the sinking access network element indicating that the new user subscription data has been successfully enabled.

5. The method according to claim 1, characterized in that, The signaling security management gateway issues user cards to each sinking access network element, and each user card includes the certificate of the user card.

6. The method according to any one of claims 1-5, characterized in that, The core network elements include UDM network elements, UPF network elements, AMF network elements, and SMF network elements; The sinking access network elements include UDM network elements, UPF network elements, AMF network elements, and SMF network elements; The user card includes an embedded UICC.

7. A signaling security management gateway, characterized in that, include: The download management module is configured to receive a request from the sinking access network element to download user subscription data. The request includes the identifier of the sinking access network element and the identifier and certificate of the user card embedded in the sinking access network element. Authentication is performed based on the user card's identifier and certificate. After successful authentication, the user subscription data loaded by the sinking access network element is queried. If the sinking access network element has not loaded user subscription data or the loaded user subscription data has expired, the sinking access network element is notified to download new user subscription data, and the binding information between the identifier of the sinking access network element and the identifier of the user card embedded in the sinking access network element is established. The authentication module is configured to receive requests from the sinking access network element to access the core network element, and to authenticate the sinking access network element based on the user subscription data and the binding information. The channel establishment module is configured to establish an encrypted channel with the authenticated sinking access network element; The information proxy module is configured to receive user data synchronization requests sent by the sinking access network element, send the user data synchronization requests to the corresponding core network element, receive encrypted user data sent by the core network element, and send the encrypted user data to the sinking access network element through the encrypted channel.

8. The signaling security management gateway according to claim 7, characterized in that, The authentication module is configured as follows: Receive a request from a sinking access network element to access a core network element, which carries the identifier of the sinking access network element, the identifier of the user card embedded in the sinking access network element, and the certificate information in the user subscription data; If the binding relationship between the identifier of the sinking access network element and the identifier of the user card in the access request is incorrect or does not exist, the authentication of the sinking access network element is determined to be unsuccessful; or, If the timeliness and legality of the certificate information in the user's subscription data in the access request do not meet the requirements, the authentication of the sinking access network element is deemed unsuccessful; or... If the binding relationship between the identifier of the sinking access network element in the access request and the identifier of the user card is correct, and the timeliness and legality of the certificate information in the user subscription data meet the requirements, the sinking access network element is deemed to have passed authentication.

9. A signaling security management gateway, comprising: Memory; as well as A processor coupled to the memory, the processor being configured to execute the data transfer method of any one of claims 1-6 based on instructions stored in the memory.

10. A data transmission system, comprising: The signaling security management gateway according to any one of claims 7-9, The core network element is configured to send encrypted user data to the signaling security management gateway in response to user data synchronization requests. as well as The sinking access network element is configured to send a request to the signaling security management gateway to access the core network element, establish an encrypted channel with the signaling security management gateway, send a user data synchronization request to the signaling security management gateway, and receive encrypted user data sent by the signaling security management gateway through the encrypted channel.

11. The data transmission system according to claim 10, characterized in that, The core network elements include UDM network elements, UPF network elements, AMF network elements, and SMF network elements; The sinking access network elements include UDM network elements, UPF network elements, AMF network elements, and SMF network elements.

12. A non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the data transmission method according to any one of claims 1-6.

Citation Information

Patent Citations

  • System and method for controlling for hierarchical network

    KR1020160091625A

  • Terminal access method, access management method, network equipment and communication system

    WO2009155812A1