Key acquisition method, apparatus, device, and chip system
By receiving the key identification information of the terminal device and determining its access network identifier related to AF, the problem of unreasonable key acquisition in multi-registration scenarios of the AKMA mechanism is solved, and the efficiency and success rate of application session establishment are improved.
Patent Information
- Application Number
- CN202380008090.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-06
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2043-01-06
AI Technical Summary
The existing AKMA mechanism cannot effectively support communication between terminal devices and application functions (AF) in multi-registration scenarios, resulting in unreasonable key acquisition methods and affecting the application session establishment effect in multi-registration scenarios.
By receiving the key identification information of the terminal device, the access network identifier associated with AF is determined, and the corresponding key is only provided to the access network, avoiding the provision of keys to unrelated networks, thereby realizing the effective support of the AKMA mechanism in multi-registration scenarios.
This enables the key to be provided only to access network devices associated with AF in multi-registration scenarios, improving the efficiency and success rate of application session connections and ensuring the effectiveness of the AKMA mechanism.
Smart Images

Figure CN118614096B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and particularly relates to a key obtaining method and device, equipment and chip system. BACKGROUND
[0002] Based on the 3rd generation partnership project (3GPP) authentication and key management for application (AKMA), the identity of an application program in a terminal device can be verified and key management can be implemented. In some scenarios, the AKMA mechanism has been used as a solution to protect the communication between the terminal device and the application function (AF).
[0003] In the related art, in order to support roaming, the network device (for example, AKMA anchor function (AAnF)) network element of the home network of the terminal device, and the AF will send a key to the visited network of the terminal device. In a multi-registration scenario, the terminal device will be connected to multiple visited networks. The key obtaining method in the related art will cause the AKMA mechanism to be unable to effectively support the multi-registration scenario. SUMMARY
[0004] The embodiments of the present disclosure provide a key obtaining method, device, equipment, chip system, storage medium, computer program and computer program product, which can be applied to the technical field of communication, and can enable the AKMA mechanism to effectively support the multi-registration scenario.
[0005] In a first aspect, the embodiments of the present disclosure provide a key obtaining method, which is executed by an application function (AF), and the method comprises: receiving a first request message sent by a terminal device, wherein the first request message comprises key identification information; determining an identifier of a visited network of the terminal device related to the AF, wherein the identifier of the visited network is used for a first network device of the visited network to obtain a key corresponding to the key identification information.
[0006] In a second aspect, the embodiments of the present disclosure provide a key obtaining method, which is executed by a second network device of the home network of the terminal device; the method comprises: determining an application key corresponding to key identification information; wherein the application key is provided to a first network device of a visited network of the terminal device related to an application function (AF) based on an identifier of the visited network.
[0007] In a third aspect, the embodiments of the present disclosure provide a key obtaining method, which is performed by a first network device of an access network of a terminal device, and the access network is related to an application function (AF); the method comprises: obtaining a key corresponding to key identification information, wherein the key is provided to the first network device based on an identifier of the access network.
[0008] In a fourth aspect, the embodiments of the present disclosure provide a key obtaining method, which is performed by a first network element; the method comprises: determining an identifier of an access network of a terminal device, wherein the access network is related to an application function (AF), and the identifier of the access network is used by a first network device of the access network to obtain a key corresponding to key identification information.
[0009] In a fifth aspect, the embodiments of the present disclosure provide a key obtaining method, which is performed by a terminal device; the method comprises: sending a first request message to an application function (AF), wherein the first request message comprises: key identification information; and an identifier of an access network of the terminal device, wherein the access network is related to the AF, and the identifier of the access network is used by a first network device of the access network to obtain a key corresponding to the key identification information.
[0010] In a sixth aspect, the embodiments of the present disclosure provide a communication apparatus, which has part or all of the functions of the application function (AF) in the method of the first aspect, for example, the communication apparatus can have part or all of the functions in the embodiments of the present disclosure, or can have the function of implementing any one of the embodiments of the present disclosure independently. The functions can be implemented by hardware, or by hardware executing corresponding software. The hardware or software comprises one or more units or modules corresponding to the above functions.
[0011] Optionally, in an embodiment of the present disclosure, the communication apparatus can comprise a transceiver module and a processing module, and the processing module is configured to support the communication apparatus to perform the corresponding functions in the above method. The transceiver module is used to support the communication between the communication apparatus and other devices. The communication apparatus can further comprise a storage module, which is used to couple with the transceiver module and the processing module, and stores the necessary computer programs and data of the communication apparatus.
[0012] For example, the processing module can be a processor, the transceiver module can be a transceiver or a communication interface, and the storage module can be a memory.
[0013] In a seventh aspect, an embodiment of the present disclosure provides a communication apparatus having part or all of functions of the second network device in the method of the second aspect, for example, the communication apparatus can have part or all of the functions in the embodiments of the present disclosure, or can have the functions of implementing any of the embodiments of the present disclosure independently. The functions can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above functions.
[0014] Optionally, in an embodiment of the present disclosure, the communication apparatus can include a transceiver module and a processing module in its structure, and the processing module is configured to support the communication apparatus to perform the corresponding functions in the above method. The transceiver module is used to support the communication between the communication apparatus and other devices. The communication apparatus can also include a storage module, which is used to be coupled with the transceiver module and the processing module, and saves the necessary computer programs and data of the communication apparatus.
[0015] For example, the processing module can be a processor, the transceiver module can be a transceiver or a communication interface, and the storage module can be a memory.
[0016] In an eighth aspect, an embodiment of the present disclosure provides a communication apparatus having part or all of functions of the first network device in the method of the third aspect, for example, the communication apparatus can have part or all of the functions in the embodiments of the present disclosure, or can have the functions of implementing any of the embodiments of the present disclosure independently. The functions can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above functions.
[0017] Optionally, in an embodiment of the present disclosure, the communication apparatus can include a transceiver module and a processing module in its structure, and the processing module is configured to support the communication apparatus to perform the corresponding functions in the above method. The transceiver module is used to support the communication between the communication apparatus and other devices. The communication apparatus can also include a storage module, which is used to be coupled with the transceiver module and the processing module, and saves the necessary computer programs and data of the communication apparatus.
[0018] For example, the processing module can be a processor, the transceiver module can be a transceiver or a communication interface, and the storage module can be a memory.
[0019] In a ninth aspect, an embodiment of the present disclosure provides a communication apparatus having part or all of the functions of the first network element in the method of the fourth aspect, for example, the communication apparatus can have part or all of the functions in the embodiments of the present disclosure, or can have the functions of any one of the embodiments of the present disclosure implemented independently. The functions can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above functions.
[0020] Optionally, in an embodiment of the present disclosure, the communication apparatus can include a transceiver module and a processing module in its structure, and the processing module is configured to support the communication apparatus to perform the corresponding functions in the above method. The transceiver module is used to support the communication between the communication apparatus and other devices. The communication apparatus can also include a storage module, which is used to be coupled with the transceiver module and the processing module, and stores the necessary computer programs and data of the communication apparatus.
[0021] For example, the processing module can be a processor, the transceiver module can be a transceiver or a communication interface, and the storage module can be a memory.
[0022] In a tenth aspect, an embodiment of the present disclosure provides a communication apparatus having part or all of the functions of the terminal device in the method of the fifth aspect, for example, the communication apparatus can have part or all of the functions in the embodiments of the present disclosure, or can have the functions of any one of the embodiments of the present disclosure implemented independently. The functions can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above functions.
[0023] Optionally, in an embodiment of the present disclosure, the communication apparatus can include a transceiver module and a processing module in its structure, and the processing module is configured to support the communication apparatus to perform the corresponding functions in the above method. The transceiver module is used to support the communication between the communication apparatus and other devices. The communication apparatus can also include a storage module, which is used to be coupled with the transceiver module and the processing module, and stores the necessary computer programs and data of the communication apparatus.
[0024] For example, the processing module can be a processor, the transceiver module can be a transceiver or a communication interface, and the storage module can be a memory.
[0025] In an eleventh aspect, an embodiment of the present disclosure provides a communication apparatus including a processor, which executes the key acquisition method described above when the processor invokes a computer program in a memory.
[0026] In a twelfth aspect, the embodiments of the present disclosure provide a communication device, which comprises a processor and a memory, the memory storing a computer program; the processor executes the computer program stored in the memory, so that the communication device executes the key acquisition method described above.
[0027] In a thirteenth aspect, the embodiments of the present disclosure provide a communication device, which comprises a processor and an interface circuit, the interface circuit being configured to receive code instructions and transmit the code instructions to the processor, and the processor being configured to execute the code instructions so that the device executes the key acquisition method described above.
[0028] In a fourteenth aspect, the embodiments of the present disclosure provide a communication system, which comprises the communication device described above.
[0029] In a fifteenth aspect, the embodiments of the present disclosure provide a computer readable storage medium, which is configured to store instructions for the application function AF, and when the instructions are executed, the application function AF executes the key acquisition method of the first aspect described above.
[0030] In a sixteenth aspect, the embodiments of the present disclosure provide a computer readable storage medium, which is configured to store instructions for the second network device, and when the instructions are executed, the second network device executes the key acquisition method of the second aspect described above.
[0031] In a seventeenth aspect, the embodiments of the present disclosure provide a computer readable storage medium, which is configured to store instructions for the first network device, and when the instructions are executed, the first network device executes the key acquisition method of the third aspect described above.
[0032] In an eighteenth aspect, the embodiments of the present disclosure provide a computer readable storage medium, which is configured to store instructions for the first network element, and when the instructions are executed, the first network element executes the key acquisition method of the fourth aspect described above.
[0033] In a nineteenth aspect, the embodiments of the present disclosure provide a computer readable storage medium, which is configured to store instructions for the terminal device, and when the instructions are executed, the terminal device executes the key acquisition method of the fifth aspect described above.
[0034] In a twentieth aspect, the embodiments of the present disclosure further provide a computer program product comprising a computer program, which, when executed on a computer, causes the computer to execute the key acquisition method described above.
[0035] In a twenty-first aspect, the embodiments of the present disclosure provide a chip system, which comprises at least one processor and an interface, and is configured to support the network device to implement the functions described above, for example, to determine or process at least one of the data and information involved in the methods described above.
[0036] In a possible design, the chip system further includes a memory configured to store computer programs and data necessary for the network device.
[0037] In a twenty-second aspect, the present disclosure provides a chip system, which includes at least one processor and an interface configured to support a terminal device to implement the functions described above, for example, to determine or process at least one of the data and information involved in the methods described above.
[0038] In a possible design, the chip system further includes a memory configured to store computer programs and data necessary for the terminal device. The chip system can be composed of a chip, or include the chip and other discrete devices.
[0039] In a twenty-third aspect, the present disclosure provides a computer program, which, when running on a computer, causes the computer to perform the key acquisition method described above.
[0040] To sum up, the key acquisition method, device, equipment, chip system, storage medium, computer program and computer program product provided by the embodiments of the present disclosure can achieve the following technical effects:
[0041] The AF receives a first request message sent by a terminal device, wherein the first request message includes key identification information, and determines an identity of an AF-related access network of the terminal device, wherein the identity of the access network is used by a first network device of the access network to acquire a key corresponding to the key identification information, thereby realizing the provision of the key corresponding to the key identification information only to the first network device of the AF-related access network without triggering the provision of the key corresponding to the key identification information to network devices of other access networks not related to the AF, so as to enable the AKMA mechanism to effectively support a multi-registration scenario. BRIEF DESCRIPTION OF DRAWINGS
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the background art, the drawings needed to be used in the embodiments of the present disclosure or the background art will be described below.
[0043] Figure 1 is an architecture schematic diagram of a communication system provided by the embodiments of the present disclosure;
[0044] Figure 2 is a flowchart of a key acquisition method provided by the embodiments of the present disclosure;
[0045] Figure 3 is a flowchart of a key acquisition method provided by the embodiments of the present disclosure;
[0046] Figure 4is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0047] Figure 5a is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0048] Figure 5b is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0049] Figure 6 is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0050] Figure 7a is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0051] Figure 7b is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0052] Figure 7c is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0053] Figure 8 is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0054] Figure 9 is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0055] Figure 10 is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0056] Figure 11 is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0057] Figure 12 is a flowchart of another key acquisition method provided by an embodiment of the present disclosure;
[0058] Figure 13 is a structural schematic diagram of a communication apparatus provided by an embodiment of the present disclosure;
[0059] Figure 14 is a structural schematic diagram of another communication apparatus provided by an embodiment of the present disclosure;
[0060] Figure 15 is a structural schematic diagram of a chip of an embodiment of the present disclosure. DETAILED DESCRIPTION
[0061] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The following description is made with reference to the accompanying drawings in which like reference numerals represent like elements or similar elements, unless the context of the description dictates otherwise. The following description of exemplary embodiments is not representative of all embodiments consistent with the present disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the present disclosure as detailed in the appended claims.
[0062] The terminology used in the present disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. As used in the present disclosure and the appended claims, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0063] It is to be understood that, although the terms first, second, third, etc. can be used herein to describe various information, these terms are not intended to denote a particular order or hierarchy. These terms are used merely for the purpose of distinguishing between two or more information. For example, without departing from the scope of the present disclosure, a first information can be termed a second information, and similarly, a second information can be termed a first information. The word "if" as used herein means "when" or "upon" or "in response to the determination" depending on the context.
[0064] For the purpose of facilitating understanding, the terms related to the present disclosure are introduced first.
[0065] 1. Access and mobility management function (AMF).
[0066] AMF is a logical node function network element on the core network side, which is the core network control plane access point of terminal and wireless, receives all connection and session related information from user equipment, and performs registration, connection, reachability, mobility management. In addition, the AMF provides a session management message transmission channel for terminal equipment and session management function (SMF) equipment, and provides authentication and authorization functions when the user accesses.
[0067] 2. Application function (AF), similar to an application server, which can interact with other core network control plane network functions (NF) and provide service services. AF can exist for different application services, and can be owned by operators or trusted third parties.
[0068] 3. Network exposure function (NEF), located between the core network and external third-party application functions (possibly also part of internal AFs), responsible for managing the opening of network data to the outside, all external applications. NEF provides corresponding security protection to ensure the security of external applications to the 3GPP network, provides quality of service (QoS) customization capability opening for external applications, mobility state event subscription, AF request distribution, and other functions.
[0069] 4. User plane function (UPF), including user data packet routing and forwarding, data interaction with external data networks, user plane quality of service (QoS) processing, flow control rule implementation (such as gating, redirection, traffic steering), etc.
[0070] 5. Authentication server function (AUSF), AUSF is used to receive the request of AMF to authenticate the terminal device (user equipment, UE), and request a key from the unified data management function (UDM), and then forward the key issued by the UDM to the AMF for authentication processing.
[0071] 6. Unified data management function (UDM).
[0072] The UDM is responsible for the management of terminal device identification, subscription data, authentication data, and the registration and management of service network elements for terminal devices (such as the current AMF providing services for the terminal device, etc., such as when the terminal device switches the accessed AMF, the UDM will also initiate a de-registration message to the old AMF, requiring the old AMF to delete user-related information).
[0073] 7. AKMA anchor function (AAnF), in AKMA, AAnF is a newly introduced network element. AAnF can perform two-way authentication with UE through an authentication and key agreement (AKA) protocol, and generate a shared key after successful authentication. AAnF will pass the shared key and related key parameters, user data, etc. to the network AF. The shared key will be used for secure transmission of information between UE and AF.
[0074] 8. A policy control function (PCF) that supports a unified policy framework to govern network behavior, provides policy rules to network entities to enforce, and accesses subscription information in a unified data repository.
[0075] See Figure 1 , Figure 1 An architecture of a communication system is provided in the embodiments of the present disclosure. The communication system can include, but is not limited to, one network device, one terminal device, and an application function (AF), as shown in the figure. Figure 1 The number and form of devices shown in the figure are only for example and do not constitute a limitation on the embodiments of the present disclosure. In actual applications, two or more network devices and two or more terminal devices can be included. Figure 1 The communication system shown in the figure takes two network devices 101, one terminal device 102, and an application function (AF) 103 as an example.
[0076] It should be noted that the technical solutions of the embodiments of the present disclosure can be applied to various communication systems. For example: long term evolution (LTE) system, 5th generation (5G) mobile communication system, 5G new radio (NR) system, or other future new mobile communication systems, etc.
[0077] The network device 101 in the embodiments of the present disclosure is an entity for transmitting or receiving signals on the network side. For example, the network device 101 can be an evolved NodeB (eNB), a transmission reception point (TRP), a next generation NodeB (gNB) in the NR system, a base station in other future mobile communication systems, or an access node in a wireless fidelity (WiFi) system, etc. The embodiments of the present disclosure do not limit the specific technology and specific device form adopted by the network device.
[0078] The network device provided in the embodiments of the present disclosure can be composed of a central unit (CU) and a distributed unit (DU), wherein the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layer of the network device, such as a base station, and place part of the protocol layer functions in the CU for centralized control, and the remaining part or all of the protocol layer functions are distributed in the DU and controlled by the CU.
[0079] The terminal device 102 in the embodiments of the present disclosure is an entity for receiving or transmitting signals on the user side, such as a mobile phone. The terminal device can also be referred to as a terminal, a user equipment (UE), a mobile station (MS), a mobile terminal (MT), and the like. The terminal device can be a car, a smart car, a mobile phone, a wearable device, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, and the like.
[0080] The embodiments of the present disclosure do not limit the specific technology and specific device form adopted by the terminal device.
[0081] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. It can be known by those skilled in the art that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.
[0082] Among them, one network device 101 can be a network device of a home network of the terminal device, and the other network device can be a network device of a visited network of the terminal device. In the following description, the network device of the visited network of the terminal device can be referred to as the first network device, and the network device of the home network of the terminal device can be referred to as the second network device, which is not limited.
[0083] The key acquisition method and the device thereof provided by the present disclosure will be described in detail below in combination with the drawings. Figure 2 FIG. 1 is a flowchart of a key acquisition method provided by the embodiments of the present disclosure, which is executed by an application function (AF). The key acquisition method in the embodiments of the present disclosure can be applied in the application function (AF), which is not limited.
[0084] AsFigure 2 As shown, the method can include, but is not limited to, the following steps:
[0085] S201: receiving a first request message sent by a terminal device, wherein the first request message includes key identification information.
[0086] Wherein, the terminal device can support AKMA service, and the AKMA authentication of the terminal device can be performed after the terminal device is successfully registered and the main authentication is completed. The terminal device and the authentication service function AUSF generate an application identity authentication and a key management root key (kakma) and key identification information (AKMA key identifier, A-KID) respectively. The terminal device requests a session service from an application function AF, and the AF requests kakma from the AUSF using the key identification information sent by the terminal device. The AUSF determines the key management root key (kakma) according to the key identification information, and sends the key management root key (kakma) to the AAnF. The key management root key (kakma) can be used to determine the application key, and then the AF can obtain the application key and the validity period of the application key from the AAnF.
[0087] In the embodiments of the present disclosure, the first request message can be an application session establishment request message in related technologies of multiplexing, or it can also be a new application session establishment request message, and the present disclosure does not limit this.
[0088] Wherein, the first request message is used to request to establish an application session between the AF and the UE, and the first request message can include key identification information (A-KID). The key identification information can be used to uniquely identify the key required for establishing the application session between the AF and the UE.
[0089] In the embodiments of the present disclosure, the key can be, for example, a key derived based on a key management root key (kakma) of application authentication and key management AKMA. The key can include an application key and an encryption key.
[0090] S202: determining an identity of an access network related to the AF of the terminal device, wherein the identity of the access network is used by a first network device of the access network to obtain a key corresponding to the key identification information.
[0091] In the related art, in order to support roaming, the network device (for example, AKMA anchor function (AAnF) network element) of the home network of the terminal device, and the AF will send a key to the network device of the access network of the terminal device, and in the multi-registration scenario, the terminal device will be connected to multiple access networks at the same time, and since the terminal device only uses a specific access network to establish a connection with the AF. Therefore, if the key is sent to the network devices of multiple access networks, the AKMA mechanism cannot effectively support the multi-registration scenario.
[0092] In the embodiments of the present disclosure, after receiving the first request message sent by the terminal device, the AF can determine the identity of the access network related to the AF of the terminal device, and then, based on the identity of the access network, the first network device of the access network obtains the key corresponding to the key identification information.
[0093] The identity of the access network can be used to identify the access network related to the AF. For example, a network identifier. The identity of the access network related to the AF of the terminal device can specifically refer to the identity of the access network participating in establishing the connection between the terminal device and the AF, and / or the session, and / or the service, and / or the AF session. It can also refer to the identity of the access network participating in establishing the protocol data unit (PDU) session between the terminal device, the UPF connected to the AF, and / or the PCF. This is not limited.
[0094] The access network related to the AF can refer to the access network participating in establishing the connection between the terminal device and the AF, and / or the session, and / or the service, and / or the AF session. It can also refer to the access network participating in establishing the protocol data unit (PDU) session between the terminal device, the UPF connected to the AF, and / or the PCF.
[0095] That is to say, in the multi-registration scenario of the terminal device, the terminal device is connected to multiple access networks at the same time. In the embodiments of the present disclosure, the identity of the access network related to the AF is identified from the multiple access networks, so as to provide the key corresponding to the key identification information only to the first network device of the access network related to the AF, without triggering the network device of the other access network unrelated to the AF to provide the key corresponding to the key identification information, thereby enabling the AKMA mechanism to effectively support the multi-registration scenario.
[0096] The key obtaining method provided in the embodiments of the present disclosure is not limited to being applied in the first network device, and can be applied in any one or more of the UPF network element, the second AAnF network element, and the AMF network element.
[0097] The second AAnF network element refers to an AAnF network element of an AF-related access network of the terminal device, and correspondingly, the first AAnF network element below refers to an AAnF network element of a home network of the terminal device.
[0098] In the embodiments, the first request message sent by the terminal device is received by the AF, wherein the first request message includes key identification information, and the identity of the AF-related access network of the terminal device is determined, wherein the identity of the access network is used by the first network device of the access network to obtain the key corresponding to the key identification information, so as to realize providing the key corresponding to the key identification information only to the first network device of the AF-related access network, without triggering the key corresponding to the key identification information to be provided to the network device of the other access network not related to the AF, thereby enabling the AKMA mechanism to effectively support the multi-registration scenario.
[0099] Figure 3 FIG. 1 is a flowchart of a key obtaining method provided by the embodiments of the present disclosure, which is performed by an application function (AF). The key obtaining method in the embodiments can be applied in the AF, and the present disclosure is not limited thereto.
[0100] As shown in FIG. 1, the method can include but is not limited to the following steps: Figure 3
[0101] S301: receiving a first request message sent by a terminal device, wherein the first request message includes key identification information.
[0102] S302: sending a second request message to a first network element, wherein the second request message is used to request to obtain the identity of an AF-related access network of the terminal device, and the identity of the access network is used by the first network device of the access network to obtain the key corresponding to the key identification information.
[0103] The key obtaining method provided in the embodiments of the present disclosure is not limited to being applied in the first network device, and can be applied in any one or more of the UPF network element, the second AAnF network element, and the AMF network element.
[0104] The first network element can be a UPF network element connected with the AF, or a PCF network element connected with the AF, or a UPF network element and a PCF network element connected with the AF, and the present disclosure is not limited thereto.
[0105] The second request message is used to request to obtain the identifier of the access network related to the AF of the terminal device. The AF can send the second request message to a user plane function (UPF) network element and / or a policy control function (PCF) network element, to request to obtain the identifier of the access network from the UPF network element and / or the PCF network element.
[0106] S303: receiving the identifier of the access network sent by the first network element.
[0107] In this embodiment, the first request message sent by the terminal device is received, wherein the first request message includes key identification information, and the second request message is sent to the first network element, wherein the second request message is used to request to obtain the identifier of the access network related to the AF of the terminal device, the identifier of the access network is used for the first network device of the access network to obtain the key corresponding to the key identification information, and the identifier of the access network sent by the first network element is received, so that the identifier of the access network related to the AF of the terminal device is obtained in time, and the AKMA mechanism effectively supports the multi-registration scenario.
[0108] The key obtaining method provided in the embodiment of the present disclosure can also obtain the identifier of the access network related to the AF from the local policy of the AF when the step of determining the identifier of the access network related to the AF of the terminal device is performed, wherein the local policy of the AF is a local policy related to the first network element to which the terminal device establishes a service, so that the identifier of the access network related to the AF of the terminal device is flexibly obtained, and the AKMA mechanism effectively supports the multi-registration scenario.
[0109] The first network element can be a UPF network element connected with the AF, or a PCF network element connected with the AF, or a UPF network element and a PCF network element connected with the AF, and the present disclosure does not make any limitation in this regard.
[0110] Figure 4 is a flowchart of another key obtaining method provided by the embodiment of the present disclosure, and the method is performed by an application function (AF). The key obtaining method in this embodiment can be applied in the application function (AF), and the present disclosure does not make any limitation in this regard.
[0111] As shown in Figure 4 , the method can include but is not limited to the following steps:
[0112] S401: receiving a first request message sent by a terminal device, wherein the first request message includes key identification information.
[0113] S402: sending a third request message to a second network device of a home network of the terminal device, wherein the third request message is used to request to obtain an application key.
[0114] The network device of the home network of the terminal device can be referred to as a second network device.
[0115] In the embodiments of the present disclosure, after the AF receives the first request message sent by the terminal device and determines the key identification information according to the first request message, the AF can perform request interaction with the second network device of the home network of the terminal device to request the application key corresponding to the key identification information from the second network device. For example, the AF can send a third request message to the second network device of the home network of the terminal device. The second network device of the home network of the terminal device determines the application key corresponding to the key identification information according to the third request message, and then sends a response message of the third request message to the AF. The response message can include the requested application key corresponding to the key identification information.
[0116] S403: receiving the application key sent by the second network device.
[0117] The AF can receive the application key sent by the second network device, and then trigger the establishment of the connection between the AF and the UE based on the application key corresponding to the key identification information, and determine the identity of the access network related to the AF of the terminal device, so that the first network device of the access network related to the AF can obtain the application key corresponding to the key identification information.
[0118] In the key obtaining method provided in the embodiments of the present disclosure, the second network device includes a first AAnF network element. In the case that the AF is deployed in the home network, the third request message is sent to the first AAnF network element, and the application key sent by the first AAnF network element is received.
[0119] The AF deployed in the home network can be an internal AF (internal HPLMN AF) of the home network. HPLMN refers to a home public land mobile network (Home Public Land Mobile Network).
[0120] In the key obtaining method provided in the embodiments of the present disclosure, the second network device includes a network exposure function (NEF) network element and a first AAnF network element. In the case that the AF is an external AF in the data network, the third request message is sent to the NEF network element, wherein the third request message is used to request the NEF network element to obtain the application key from the first AAnF network element, and the application key sent by the NEF network element is received.
[0121] The AF as an external AF in the data network refers to an external AF (external AF in the Data Network) in the data network.
[0122] That is to say, the embodiments of the present disclosure provide two methods of obtaining application keys, which can determine the way of obtaining application keys according to the deployment of AF. If the AF is deployed in the home network, the application key is obtained from the first AAnF network element in the home network. If the AF is an external AF in the data network, the application key is obtained from the first AAnF network element through the NEF network element in the home network, thereby improving the flexibility of obtaining the application key and the probability of obtaining the application key successfully.
[0123] In the embodiments of the present disclosure, the key identification information (A-KID) contains information of the home network of the terminal device UE, so that the AF can determine the deployment of the AF according to the information of the home network of the terminal device UE, and select the way of obtaining the application key according to the deployment of the AF to obtain the application key.
[0124] S404: Determine the identity of the access network related to the AF of the terminal device, wherein the identity of the access network is used by the first network device of the access network to obtain the key corresponding to the key identification information.
[0125] It should be noted that the steps of the key obtaining method in the present embodiment can be executed simultaneously or in any order, and the embodiments of the present disclosure do not limit this.
[0126] In the present embodiment, the first request message sent by the terminal device is received, wherein the first request message includes key identification information, and a third request message is sent to the second network device of the home network of the terminal device, wherein the third request message is used to request to obtain the application key, the application key sent by the second network device is received, and the identity of the access network related to the AF of the terminal device is determined, wherein the identity of the access network is used by the first network device of the access network to obtain the key corresponding to the key identification information. Not only can the AKMA mechanism effectively support the multi-registration scenario, but also can timely establish the application session connection between the AF and the UE, and can effectively improve the application session establishment effect in the multi-registration scenario.
[0127] Figure 5a is a flowchart of another key obtaining method provided by the embodiments of the present disclosure, which is executed by an application function AF. The key obtaining method in the present embodiment can be applied in the application function AF, and the present disclosure does not limit this.
[0128] As Figure 5a shown, the method can include but is not limited to the following steps:
[0129] S501a: Receive the first request message sent by the terminal device, wherein the first request message includes key identification information.
[0130] S502a: Determine the identity of the AF-related access network of the terminal device.
[0131] S503a: Obtain the application key corresponding to the key identification information.
[0132] S504a: If the AF is deployed in the home network of the terminal device, derive the encryption key according to the application key.
[0133] S505a: According to the identity of the access network, send the encryption key to the first network device of the access network.
[0134] S506a: If the AF is an external AF in the data network, send the identity of the access network to the first AAnF network element of the home network of the terminal device, wherein the first AAnF network element sends the application key corresponding to the key identification information to the first network device of the AF-related access network based on the identity of the access network.
[0135] That is, if the AF is deployed in the home network of the terminal device, the AF sends the encryption key corresponding to the key identification information to the first network device, if the AF is an external AF in the data network, the AF sends the identity of the access network to the first AAnF network element of the home network of the terminal device, and the first AAnF network element sends the application key corresponding to the key identification information to the first network device, then the encryption key corresponding to the key identification information and the application key corresponding to the key identification information both belong to the key corresponding to the key identification information.
[0136] The timing diagram for this embodiment can be as shown in Figure 5b , Figure 5b is a flowchart of another key acquisition method provided by the embodiments of the present disclosure, Figure 5b shows an interaction diagram between the AF, the terminal device, the first network device, the second network device, the first AAnF network element, and the first network element. The home network of the terminal device can be represented as home network, the access network of the terminal device can be represented as visited network, the first AAnF network element in the second network device can be represented as hAAnF, the second AAnF network element in the first network device can be represented as vAAnF. If the AF successfully acquires the application key, an application session establishment response can be generated, if the AF fails to acquire the application key, the application session establishment can also be rejected, and the failure reason can be attached. Then, the UE can trigger a new application session establishment request to the AF of AKMA with the latest A-KID.
[0137] It should be noted that the steps of the key acquisition method in this embodiment can be executed simultaneously or in any order, and the embodiments of the present disclosure do not limit this.
[0138] That is, in this embodiment, the way of sending the key to the first network device of the access network related to the AF is determined according to the deployment of the AF, if the AF is deployed in the home network of the terminal device, the AF sends the encryption key to the first network device of the access network related to the AF, the encryption key is derived from the application key, if the AF is an external AF in the data network, the AF provides the identity of the access network to the first AAnF network element of the home network of the terminal device, and the first AAnF network element sends the application key to the first network device of the access network related to the AF, thereby improving the flexibility of key (encryption key and / or application key) sending, so that the first network device of the access network related to the AF can effectively obtain the key corresponding to the key identification information.
[0139] It should be noted that the explanation of the same or corresponding terms and method steps in the following embodiments can be referred to the above embodiments, and will not be repeated here.
[0140] Figure 6 is a flowchart of another key acquisition method provided by the embodiments of the present disclosure, which is executed by the second network device of the home network of the terminal device.
[0141] Among them, the second network device can be, for example, the first AAnF network element hAAnF of the home network of the terminal device, and can also be the NEF network element of the home network of the terminal device, which is not limited.
[0142] As shown in Figure 6 , the method can include but is not limited to the following steps:
[0143] S601: Determine the application key corresponding to the key identification information, wherein the application key is provided to the first network device of the access network based on the identity of the access network related to the application function AF of the terminal device.
[0144] Among them, the second network device of the home network of the terminal device can generate the application key corresponding to the key identification information based on the request of the AF (which can contain the key identification information), or can also receive the application key corresponding to the key identification information sent by the AUSF, such as when the terminal device requests a session service from the application function AF, the AF uses the key identification information sent by the terminal device to request kakma from the AUSF. The AUSF determines the key management root key (kakma) according to the key identification information, and sends the key management root key (kakma) to the first AAnF network element, and the first AAnF network element can determine the application key according to the key management root key (kakma), which is not limited.
[0145] The key obtaining method provided in the embodiments of the present disclosure is not limited to the first network device including one or more of a UPF network element, a second AAnF network element, and an access and mobility management function AMF network element.
[0146] In the embodiments, the application key corresponding to the key identification information is determined by the second network device of the home network of the terminal device, wherein the application key is provided to the first network device of the access network based on the identification of the access network related to the application function AF of the terminal device, and the AKMA mechanism can effectively support the multi-registration scenario.
[0147] Figure 7a FIG. 1 is a flowchart of another key obtaining method provided in the embodiments of the present disclosure, which is executed by a second network device of a home network of a terminal device. The second network device may, for example, be a first AAnF network element hAAnF of the home network of the terminal device, and may, for example, be a NEF network element of the home network of the terminal device, and the present disclosure is not limited thereto.
[0148] As shown in FIG. 2, the method can include but is not limited to the following steps: Figure 7a
[0149] S701a: determining an application key corresponding to key identification information, wherein the application key is provided to a first network device of an access network based on an identification of the access network related to an application function AF of the terminal device.
[0150] S702a: receiving a third request message sent by the AF, wherein the third request message is used to request to obtain the application key.
[0151] After determining the application key corresponding to the key identification information, the application key can also be sent to the AF based on the third request message sent by the AF.
[0152] S703a: sending the application key to the AF.
[0153] In the embodiments, by determining the application key corresponding to the key identification information, wherein the application key is provided to the first network device of the access network based on the identification of the access network related to the application function AF of the terminal device, and receiving the third request message sent by the AF, wherein the third request message is used to request to obtain the application key, and sending the application key to the AF, not only can the AKMA mechanism effectively support the multi-registration scenario, but also can timely establish the application session connection between the AF and the UE, and can effectively improve the application session establishment effect in the multi-registration scenario.
[0154] The timing diagram for the embodiments can be as shown in FIG. 3 and FIG. 4. Figure 7b Figure 7c Figure 7b is a flowchart of another key acquisition method provided by the embodiments of the present disclosure, Figure 7b An interaction schematic diagram between the AF, the terminal device, and the first AAnF network element in the second network device is shown. Figure 7c is a flowchart of another key acquisition method provided by the embodiments of the present disclosure, Figure 7c An interaction schematic diagram between the AF, the terminal device, the first AAnF network element in the second network device, and the NEF network element is shown.
[0155] In Figure 7b , the second network device comprises a first AKMA anchor function AAnF network element; wherein receiving the third request message sent by the AF comprises: the first AAnF network element receiving the third request message sent by the AF, wherein the AF is deployed in a home network; wherein sending the application key to the AF comprises: the first AAnF network element sending the application key to the AF, wherein the AF is deployed in the home network.
[0156] In Figure 7c , the second network device comprises a network exposure function NEF network element and a first AAnF network element; wherein receiving the third request message sent by the AF comprises: the NEF network element receiving the third request message sent by the AF, wherein the AF is an external AF in a data network, and the third request message is used to request the NEF network element to acquire the application key from the first AAnF network element; wherein sending the application key to the AF comprises: the NEF network element sending the application key to the AF, wherein the AF is an external AF in the data network.
[0157] That is, the embodiments of the present disclosure provide two methods of acquiring an application key, which can determine the way of acquiring the application key according to the deployment of the AF. If the AF is deployed in a home network, the application key is acquired from the first AAnF network element in the home network. If the AF is an external AF in a data network, the NEF network element in the home network is used to acquire the application key from the first AAnF network element, thereby improving the flexibility of acquiring the application key and the probability of successfully acquiring the application key.
[0158] Figure 8 is a flowchart of another key acquisition method provided by the embodiments of the present disclosure, which is executed by a second network device of a home network of a terminal device. The second network device may, for example, be a first AAnF network element hAAnF of a home network of a terminal device, and may also be a NEF network element of a home network of a terminal device, and no limitation is made in this regard.
[0159] As Figure 8 shown, the method can include but is not limited to the following steps:
[0160] S801: Determine the application key corresponding to the key identification information, wherein the application key is provided to the first network device of the access network based on the identification of the access network related to the application function AF of the terminal device.
[0161] S802: Receive the identification of the access network sent by the AF, wherein the AF is an external AF in the data network.
[0162] S803: Send the application key to the first network device according to the identification of the access network.
[0163] That is, in this embodiment, the way of sending the application key to the first network device of the access network related to the AF is determined according to the deployment of the AF, if the AF is an external AF in the data network, the AF provides the identification of the access network to the first AAnF network element of the home network of the terminal device, and the first AAnF network element sends the application key to the first network device of the access network related to the AF, thereby improving the flexibility of the application key sending mode, and enabling the first network device of the access network related to the AF to effectively obtain the application key.
[0164] Figure 9 is a flowchart of another key acquisition method provided by the present disclosure, which is executed by the first network device of the access network of the terminal device, and the access network is related to the application function AF.
[0165] As shown in Figure 9 , the method can include but is not limited to the following steps:
[0166] S901: Acquire the key corresponding to the key identification information, wherein the key is provided to the first network device based on the identification of the access network.
[0167] The key acquisition method provided in the present disclosure does not limit the first network device to include one or more of the UPF network element, the second AAnF network element, and the access and mobility management function AMF network element.
[0168] In the present disclosure, the first network device in the access network related to the application function AF of the terminal device can directly receive the encryption key sent by the AF, wherein the AF is deployed in the home network of the terminal device, and the encryption key is derived from the application key by the AF, or the first network device can also receive the application key sent by the second network device of the home network of the terminal device, wherein the second network device can be, for example, the first AAnF network element hAAnF of the home network of the terminal device, and can also be the NEF network element of the home network of the terminal device, thereby improving the flexibility of key acquisition and the probability of successful key acquisition.
[0169] In this embodiment, the first network device in the access network related to the application function AF of the terminal device can obtain the key corresponding to the key identifier information, wherein the key is provided to the first network device based on the identifier of the access network, so that the AKMA mechanism can effectively support the multi-registration scenario.
[0170] Figure 10 is a flowchart of another key obtaining method provided by the embodiments of the present disclosure, executed by a first network element, and related to an application function AF of an access network, wherein the first network element can refer to a functional network element in a core network, and the first network element can be a user plane function UPF network element and / or a policy control function PCF network element, without limitation.
[0171] As shown in Figure 10 , the method can include but is not limited to the following steps:
[0172] S1001: Determine the identifier of the access network related to the application function AF of the terminal device, wherein the identifier of the access network is used by the first network device of the access network to obtain the key corresponding to the key identifier information.
[0173] The key obtaining method provided in the embodiments of the present disclosure, the first network device includes one or more of the UPF network element, the second AAnF network element, and the access and mobility management function AMF network element, without limitation.
[0174] That is, the identifier of the access network related to the application function AF of the terminal device can be determined by the user plane function UPF network element and / or the policy control function PCF network element, to support the second network device in the home network of the AF and / or the terminal device to learn the identifier of the access network related to the application function AF in time, so that the AKMA mechanism can effectively support the multi-registration scenario.
[0175] Figure 11 is a flowchart of another key obtaining method provided by the embodiments of the present disclosure, executed by a first network element, and related to an application function AF of an access network, wherein the first network element can refer to a functional network element in a core network, and the first network element can be a user plane function UPF network element and / or a policy control function PCF network element, without limitation.
[0176] As shown in Figure 11 , the method can include but is not limited to the following steps:
[0177] S1101: Receive the second request message sent by the AF, wherein the second request message is used to request to obtain the identifier of the access network, wherein the identifier of the access network is used by the first network device of the access network to obtain the key corresponding to the key identifier information.
[0178] S1102: Determine the identity of the access network related to the application function AF of the terminal device.
[0179] S1103: Send the identity of the access network to the AF.
[0180] The key acquisition method provided in the embodiments of the present disclosure does not limit the AF to subscribe to the identity of the access network of the terminal device UE based on the AF session related to the terminal device UE as a parameter if the first network element is a PCF network element.
[0181] In the embodiments, the user plane function UPF network element and / or the policy control function PCF network element can receive the second request message sent by the AF, determine the identity of the access network related to the application function AF of the terminal device based on the second request message, and send the identity of the access network to the AF, so as to support the second network device in the home network of the AF and / or the terminal device to learn the identity of the access network related to the application function AF in time.
[0182] Figure 12 is a flowchart of another key acquisition method provided by the embodiments of the present disclosure, executed by a terminal device.
[0183] As Figure 12 shown, the method can include but is not limited to the following steps:
[0184] S1201: Send a first request message to an application function AF, wherein the first request message includes: key identification information; and the identity of the access network related to the AF of the terminal device, for the first network device of the access network to acquire the key corresponding to the key identification information.
[0185] The key acquisition method provided in the embodiments of the present disclosure does not limit the first network device to include one or more of the UPF network element, the second AAnF network element, and the access and mobility management function AMF network element.
[0186] In the embodiments, the terminal device sends a first request message to an application function AF, wherein the first request message includes: key identification information; and the identity of the access network related to the AF of the terminal device, for the first network device of the access network to acquire the key corresponding to the key identification information, so as to enable the AKMA mechanism to effectively support the multi-registration scenario.
[0187] It should be noted that the steps of the key acquisition method in the above embodiments of the present disclosure can be executed simultaneously or in any order, and the embodiments of the present disclosure do not limit this.
[0188] Figure 13A structural schematic diagram of a communication apparatus provided by an embodiment of the present disclosure is shown. Figure 13 The communication apparatus 130 shown can include a transceiver module 1301 and a processing module 1302. The transceiver module 1301 can include a sending module and / or a receiving module, the sending module being used to implement a sending function, and the receiving module being used to implement a receiving function. The transceiver module 1301 can implement the sending function and / or the receiving function.
[0189] The communication apparatus 130 can be a network device (such as the application function AF, the first network device, the second network device, and the first network element in the foregoing method embodiments), can also be an apparatus in a network device, and can also be an apparatus capable of being used in matching with a network device. Alternatively, the communication apparatus 130 can be a terminal device (such as the terminal device in the foregoing method embodiments), can also be an apparatus in a terminal device, and can also be an apparatus capable of being used in matching with a terminal device.
[0190] The communication apparatus 130, on the network device side, includes:
[0191] The transceiver module 1301 is configured to receive a first request message sent by a terminal device, where the first request message includes key identification information. Alternatively, the transceiver module 1301 is configured to obtain an application key corresponding to the key identification information, where the application key is provided to a first network device of an access network based on an identifier of the access network.
[0192] The processing module 1302 is configured to determine an identifier of an access network related to the AF of the terminal device, where the identifier of the access network is used by the first network device of the access network to obtain the key corresponding to the key identification information. Alternatively, the processing module 1302 is configured to determine a key corresponding to the key identification information, where the key is provided to the first network device of the access network based on an identifier of an access network related to the application function AF of the terminal device. Alternatively, the processing module 1302 is configured to determine an identifier of an access network related to the application function AF of the terminal device, where the identifier of the access network is used by the first network device of the access network to obtain the key corresponding to the key identification information.
[0193] By implementing the method of the present disclosure, a first request message sent by a terminal device is received by the AF, where the first request message includes key identification information, and an identifier of an access network related to the AF of the terminal device is determined, where the identifier of the access network is used by the first network device of the access network to obtain the key corresponding to the key identification information. This implementation can achieve the provision of the key corresponding to the key identification information only to the first network device of the access network related to the AF, without triggering the provision of the key corresponding to the key identification information to network devices of other access networks not related to the AF, thereby enabling the AKMA mechanism to effectively support a multi-registration scenario.
[0194] The communication apparatus 130, on the terminal device side, comprises a transceiver module 1301 configured to send a first request message to an application function (AF), wherein the first request message comprises key identification information.
[0195] An identifier of an access network related to the AF of the terminal device, wherein a first network device of the access network obtains a key corresponding to the key identification information.
[0196] By implementing the method of the present disclosure, the terminal device sends a first request message to an application function (AF), wherein the first request message comprises key identification information; an identifier of an access network related to the AF of the terminal device, wherein a first network device of the access network obtains a key corresponding to the key identification information, thereby enabling the AKMA mechanism to effectively support the multi-registration scenario.
[0197] Figure 14 FIG. 2 is a structural schematic diagram of another communication apparatus provided by an embodiment of the present disclosure. The communication apparatus 140 can be a terminal device (such as the terminal device in the foregoing method embodiments), a network device (such as the application function (AF), the first network device, the second network device, and the first network element in the foregoing method embodiments), a chip, a chip system, or a processor supporting the terminal device to implement the method described above, or a chip, a chip system, or a processor supporting the network device to implement the method described above. The apparatus can be used to implement the method described in the foregoing method embodiments, and details can be referred to the descriptions in the foregoing method embodiments.
[0198] The communication apparatus 140 can comprise one or more processors 1401. The processor 1401 can be a general-purpose processor or a special-purpose processor, etc. For example, it can be a baseband processor or a central processing unit. The baseband processor can be configured to process communication protocols and communication data, and the central processing unit can be configured to control the communication apparatus (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU, or a CU, etc.), execute a computer program, and process data of the computer program.
[0199] Optionally, the communication apparatus 140 can further comprise one or more memories 1402, which can store a computer program 1404, and the processor 1401 can store a computer program 1403. The processor 1401 executes the computer program 1404 and / or the computer program 1403, so that the communication apparatus 140 performs the method described in the foregoing method embodiments.
[0200] Optionally, the memory 1402 can further store data. The communication apparatus 140 and the memory 1402 can be separately arranged or integrated together.
[0201] Optionally, the communication apparatus 140 can further include a transceiver 1405, an antenna 1406. The transceiver 1405 can be referred to as a transceiving unit, a transceiver, or a transceiving circuit, etc., for implementing the transceiving function. The transceiver 1405 can include a receiver and a transmitter. The receiver can be referred to as a receiver, a receiving circuit, etc., for implementing the receiving function; the transmitter can be referred to as a transmitter, a transmitting circuit, etc., for implementing the transmitting function.
[0202] Optionally, the communication apparatus 140 can further include one or more interface circuits 1407. The interface circuit 1407 is used to receive code instructions and transmit to the processor 1401. The processor 1401 runs the code instructions to make the communication apparatus 140 perform the methods described in the above method embodiments.
[0203] In an implementation manner, the processor 1401 can include a transceiver for implementing the receiving and transmitting functions. For example, the transceiver can be a transceiving circuit, or an interface, or an interface circuit. The transceiving circuit, the interface, or the interface circuit for implementing the receiving and transmitting functions can be separate or integrated together. The above transceiving circuit, interface, or interface circuit can be used for reading and writing of code / data, or the above transceiving circuit, interface, or interface circuit can be used for transmission or transfer of signals.
[0204] In an implementation manner, the processor 1401 can store a computer program 1403. The computer program 1403 runs on the processor 1401, and can make the communication apparatus 140 perform the methods described in the above method embodiments. The computer program 1403 can be fixed in the processor 1401. In this case, the processor 1401 can be implemented by hardware.
[0205] In an implementation, the communication apparatus 140 can include circuitry that can implement the functions of transmitting or receiving or communicating in the foregoing method embodiments. The processor and transceiver described in the present disclosure can be implemented on an integrated circuit (IC), an analog IC, a radio frequency integrated circuit (RFIC), a mixed-signal IC, an application specific integrated circuit (ASIC), a printed circuit board (PCB), an electronic device, etc. The processor and transceiver can also be manufactured using various IC process technologies, such as complementary metal oxide semiconductor (CMOS), N-type metal oxide semiconductor (NMOS), positive channel metal oxide semiconductor (PMOS), bipolar junction transistor (BJT), bipolar CMOS (BiCMOS), silicon germanium (SiGe), gallium arsenide (GaAs), etc.
[0206] The communication apparatus described in the foregoing embodiments can be a terminal device (such as the terminal device in the foregoing method embodiments) or a network device (such as the application function (AF), the first network device, the second network device, the first network element in the foregoing method embodiments), but the scope of the communication apparatus described in the present disclosure is not limited thereto, and the structure of the communication apparatus can not be limited by Figure 14 The communication apparatus can be a standalone device or can be part of a larger device. For example, the communication apparatus can be:
[0207] (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem;
[0208] (2) a set of one or more ICs, optionally including storage for storing data, computer programs, etc.
[0209] (3) an ASIC, such as a modem;
[0210] (4) a module that can be embedded within other devices;
[0211] (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a car device, a network device, a cloud device, an artificial intelligence device, etc.
[0212] (6) Others, and the like.
[0213] For the case that the communication apparatus can be a chip or a chip system, refer to Figure 15 , Figure 15 is a structural schematic diagram of a chip of the embodiment of the disclosure, Figure 15 The chip shown in the figure includes a processor 1501 and an interface 1502. Among them, the number of processors 1501 can be one or more, and the number of interfaces 1502 can be multiple.
[0214] For the case that the chip is used to implement the functions of the network device in the embodiment of the disclosure:
[0215] The processor 1501 is configured to implement the method steps and the like in the above Figures 2-11 embodiments.
[0216] For the case that the chip is used to implement the functions of the terminal device in the embodiment of the disclosure:
[0217] The processor 1501 is configured to implement the method steps and the like in the above Figure 12 embodiments.
[0218] Optionally, the chip further includes a memory 1503, and the memory 1503 is configured to store necessary computer programs and data.
[0219] Those skilled in the art can also understand that the various illustrative logical blocks and steps listed in the embodiments of the disclosure can be implemented by electronic hardware, computer software, or a combination of the two. Whether the function is implemented by hardware or software depends on the specific application and design requirements of the whole system. Those skilled in the art can use various methods to implement the functions for each specific application, but such implementation should not be understood as beyond the scope of protection of the embodiments of the disclosure.
[0220] The embodiments of the disclosure also provide a communication system, which includes the communication apparatus as the network device (such as the application function AF in the above method embodiments, the first network device, the second network device, and the first network element) and the communication apparatus as the terminal device in the above Figure 13 embodiments, or the system includes the communication apparatus as the network device (such as the application function AF in the above method embodiments, the first network device, the second network device, and the first network element) and the communication apparatus as the terminal device in the above Figure 14 embodiments.
[0221] The disclosure also provides a readable storage medium having instructions stored thereon, which are executed by a computer to implement the functions of any of the above method embodiments.
[0222] The present disclosure also provides a computer program product which, when executed by a computer, implements the functions of any of the method embodiments described above.
[0223] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs. When the computer programs are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer programs can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer programs can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be magnetic media (such as floppy disk, hard disk, magnetic tape), optical media (such as high-density digital video disc (digital video disc, DVD)), or semiconductor media (such as solid state disk (solid state disk, SSD)) and the like.
[0224] Those of ordinary skill in the art can understand that the first, second, and the like various numerical designations involved in the present disclosure are only for the convenience of description and do not limit the scope of the embodiments of the present disclosure, nor represent the order of precedence.
[0225] At least one of the present disclosure can also be described as one or more, and the plurality can be two, three, four or more, and the present disclosure does not limit. In the embodiments of the present disclosure, for a technical feature, the technical features in the technical feature are distinguished by "first", "second", "third", "A", "B", "C" and "D", and there is no order or size order between the technical features described by "first", "second", "third", "A", "B", "C" and "D".
[0226] The correspondence relationship shown in each table in the present disclosure can be configured or predefined. The values of the information in each table are merely examples, and other values can be configured, and the present disclosure is not limited thereto. When configuring the correspondence relationship between the information and each parameter, it is not necessarily required to configure all the correspondence relationships shown in each table. For example, the correspondence relationship shown in some rows in the table in the present disclosure can also not be configured. For another example, the above tables can be appropriately deformed, for example, split, merged, and the like. The names of the parameters shown in the titles of the above tables can also use other names understandable by the communication device, and the values or representations of the parameters can also use other values or representations understandable by the communication device. The above tables can also use other data structures when implemented, for example, arrays, queues, containers, stacks, linear tables, pointers, linked lists, trees, graphs, structures, classes, heaps, hash tables, or the like.
[0227] The predefinition in the present disclosure can be understood as definition, predefinition, storage, prestorage, prenegotiation, preconfiguration, solidification, or pre-burning.
[0228] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present disclosure.
[0229] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here.
[0230] The above is merely a specific implementation of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present disclosure, which should be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.
Claims
1. A key acquisition method, characterized in that, The method, executed by the applied function AF, includes: The terminal device receives a first request message, wherein the first request message includes: key identification information; The identifier of the access network associated with the AF of the terminal device is determined, wherein the identifier of the access network is used by the first network device of the access network to obtain the key corresponding to the key identifier information; If the AF is deployed in the home network of the terminal device, then the encryption key is derived based on the application key; and the encryption key is sent to the first network device of the accessed network based on the identifier of the accessed network; or, If the AF is an external AF in the data network, then the identifier of the access network is sent to the second network device of the home network of the terminal device, wherein the identifier of the access network is used by the second network device to send the application key to the first network device.
2. The method as described in claim 1, characterized in that, The step of determining the identifier of the access network associated with the AF for the terminal device includes: Send a second request message to the first network element, wherein the second request message is used to request the identification of the accessed network; Receive the network access identifier sent by the first network element.
3. The method as described in claim 1, characterized in that, The step of determining the identifier of the access network associated with the AF for the terminal device includes: From the local policy of the AF, obtain the identifier of the access network associated with the AF, wherein the local policy of the AF is the local policy associated with the first network element to which the terminal device establishes service connection.
4. The method as described in claim 1, characterized in that, The method further includes: A third request message is sent to a second network device in the home network of the terminal device, wherein the third request message is used to request the acquisition of an application key; Receive the application key sent by the second network device.
5. The method as described in claim 4, characterized in that, The second network device includes: a first AKMA anchor function (AAnF) network element; wherein, sending a third request message to the second network device of the home network of the terminal device includes: If the AF is deployed in the home network, then the third request message is sent to the first AAnF network element; The step of receiving the application key sent by the second network device includes: Receive the application key sent by the first AAnF network element.
6. The method as described in claim 4, characterized in that, The second network device includes: a Network Open Function (NEF) network element and a first AnF network element; wherein, sending a third request message to the second network device of the home network of the terminal device includes: If the AF is an external AF in the data network, then the third request message is sent to the NEF network element, wherein the third request message is used to request the NEF network element to obtain the application key from the first AAnF network element; The step of receiving the application key sent by the second network device includes: Receive the application key sent by the NEF network element.
7. The method according to any one of claims 1-6, characterized in that, The second network device of the home network of the terminal device includes: the first AAnF network element.
8. The method as described in claim 2 or 3, characterized in that, The first network element includes at least one of the following: User plane function UPF network element; Policy control function PCF network element.
9. The method according to any one of claims 1-6, characterized in that, The first network device includes at least one of the following: UPF network elements; Second AAnF network element; Access and mobility management functions (AMF) network elements.
10. A key acquisition method, characterized in that, The method is executed by a second network device within the home network of the terminal device; the method includes: Determine the application key corresponding to the key identification information, wherein the application key is provided to the first network device of the access network based on the identifier of the access network related to the application function AF of the terminal device; The terminal device receives the identifier of the access network associated with the AF sent by the AF, wherein the AF is an external AF in the data network, and sends an application key to the first network device according to the identifier of the access network.
11. The method as described in claim 10, characterized in that, The method further includes: Receive a third request message sent by the AF, wherein the third request message is used to request to obtain the application key; Send the application key to the AF.
12. The method as described in claim 11, characterized in that, The second network device includes: a first AKMA anchor function (AAnF) network element; wherein, receiving the third request message sent by the AF includes: The first AAnF network element receives a third request message sent by the AF, wherein the AF is deployed in the home network; Sending the application key to the AF includes: The first AAnF network element sends the application key to the AF, wherein the AF is deployed in the home network.
13. The method as described in claim 11, characterized in that, The second network device includes: a Network Open Function (NEF) network element and a first AnF network element; wherein, receiving the third request message sent by the AF includes: The NEF network element receives a third request message sent by the AF, wherein the AF is an external AF in the data network, and the third request message is used to request the NEF network element to obtain the application key from the first AAnF network element; Sending the application key to the AF includes: The NEF network element sends the application key to the AF, wherein the AF is an external AF in the data network.
14. The method according to any one of claims 10-13, characterized in that, The first network device includes at least one of the following: User plane function UPF network element; Second AAnF network element; Access and mobility management functions (AMF) network elements.
15. A key acquisition method, characterized in that, The method is executed by a first network device accessing a network associated with an application function (AF); the method includes: Obtaining a key corresponding to the key identification information, wherein the key is provided to the first network device based on the identifier of the access network, the step of obtaining the key corresponding to the key identification information includes: The device receives an encryption key sent by the AF, wherein the AF is deployed in the home network of the terminal device, and the encryption key is derived from the application key; or... The terminal device receives an application key sent by a second network device from its home network, wherein the AF is an external AF in the data network, and the application key is sent by the second network device based on the identifier of the accessed network.
16. The method as described in claim 15, characterized in that, The second network device includes at least one of the following: First AKMA anchor point function AAnF network element; Network Open Functions (NEF) network elements.
17. The method according to any one of claims 15-16, characterized in that, The first network device includes at least one of the following: User plane function UPF network element; Second AAnF network element; Access and mobility management functions (AMF) network elements.
18. A key acquisition method, characterized in that, The method, executed by the first network element, includes: The identifier of the access network associated with the application function (AF) of the terminal device is determined. The identifier of the access network is used by a first network device of the access network to obtain a key corresponding to key identification information. The first network device obtaining the key corresponding to the key identification information includes: receiving an encryption key sent by the AF, the encryption key being derived from the application key, and the AF being deployed in the home network of the terminal device; or receiving an application key sent by a second network device of the home network of the terminal device, wherein the AF is an external AF in a data network, and the application key is sent by the second network device based on the identifier of the access network.
19. The method as described in claim 18, characterized in that, The method further includes: Receive a second request message sent by the AF, wherein the second request message is used to request to obtain the identifier of the access network; Send the identifier of the access network to the AF.
20. The method according to any one of claims 18-19, characterized in that, The first network element includes at least one of the following: User plane function UPF network element; Policy control function PCF network element.
21. The method according to any one of claims 18-19, characterized in that, The first network device includes at least one of the following: Second AKMA anchor point function AAnF network element; Access and mobility management functions (AMF) network elements; UPF network element.
22. A key acquisition method, characterized in that, The method, executed by a terminal device, includes: Sending a first request message to the Application Function (AF), wherein the first request message includes: key identification information; and an identifier of the access network associated with the AF of the terminal device, for the first network device of the access network to obtain a key corresponding to the key identification information. The first network device of the access network obtaining the key corresponding to the key identification information includes: receiving an encryption key sent by the AF, wherein the encryption key is derived based on the application key, and the AF is deployed in the home network of the terminal device; or, receiving an application key sent by a second network device of the home network of the terminal device, wherein the AF is an external AF in the data network, and the application key is sent by the second network device based on the identifier of the access network.
23. The method as described in claim 22, characterized in that, The first network device includes at least one of the following: Second AKMA anchor point function AAnF network element; Access and mobility management functions (AMF) network elements; User plane function UPF network element.
24. A communication device, characterized in that, The device includes: The transceiver module is used to receive a first request message sent by a terminal device, wherein the first request message includes: key identification information; The processing module is used to determine the identifier of the access network associated with the application function (AF) of the terminal device, wherein the identifier of the access network is used by the first network device of the access network to obtain the key corresponding to the key identifier information; if the AF is deployed in the home network of the terminal device, the encryption key is derived based on the application key. The transceiver module is configured to send the encryption key to a first network device of the accessed network based on the identifier of the accessed network; or, if the AF is an external AF in a data network, send the identifier of the accessed network to a second network device of the home network of the terminal device, wherein the identifier of the accessed network is used by the second network device to send an application key to the first network device.
25. A communication device, characterized in that, The device includes: A processing module is used to determine an application key corresponding to key identification information, wherein the application key is provided to a first network device of the access network based on the identifier of the access network associated with the application function AF of the terminal device; The terminal device receives the identifier of the access network associated with the AF sent by the AF, wherein the AF is an external AF in the data network, and sends an application key to the first network device according to the identifier of the access network.
26. A communication device, characterized in that, The device includes: The transceiver module is used to obtain a key corresponding to the key identification information, wherein the key is provided to a first network device of the access network based on the identifier of the access network related to the application function (AF) of the terminal device, and obtaining the key corresponding to the key identification information includes: The device may receive an encryption key sent by the AF, wherein the AF is deployed in the home network of the terminal device, and the encryption key is derived from an application key; or, the device may receive an application key sent by a second network device in the home network of the terminal device, wherein the AF is an external AF in the data network, and the application key is sent by the second network device based on the identifier of the access network.
27. A communication device, characterized in that, The device includes: The processing module is used to determine the identifier of the access network associated with the application function (AF) of the terminal device. The identifier of the access network is used by a first network device of the access network to obtain a key corresponding to the key identifier information. The first network device obtaining the key corresponding to the key identifier information includes: receiving an encryption key sent by the AF, the encryption key being derived from the application key, and the AF being deployed in the home network of the terminal device; or receiving an application key sent by a second network device of the home network of the terminal device, wherein the AF is an external AF in a data network, and the application key is sent by the second network device based on the identifier of the access network.
28. A communication device, characterized in that, The device includes: The transceiver module is used to send a first request message to an application function (AF), wherein the first request message includes: key identification information; and an identifier of the access network associated with the AF of the terminal device, for a first network device of the access network to obtain a key corresponding to the key identification information. The first network device of the access network obtaining the key corresponding to the key identification information includes: receiving an encryption key sent by the AF, the encryption key being derived from an application key, and the AF being deployed in the home network of the terminal device; or receiving an application key sent by a second network device of the home network of the terminal device, wherein the AF is an external AF in a data network, and the application key is sent by the second network device based on the identifier of the access network.
29. A communication system, characterized in that, The communication system includes network devices and terminal devices, wherein the network devices perform the method as described in any one of claims 1-21, and the terminal devices perform the method as described in any one of claims 22-23.
30. A computer-readable storage medium for storing instructions that, when executed, cause the method of any one of claims 1-23 to be implemented.
Citation Information
Patent Citations
Method and apparatus for multiple registrations
CN111670587A
Key acquisition method and device
CN113543126A
Method and system of enabling AKMA service in roaming scenario
US20220210636A1