A key deduction method and apparatus

By generating and managing unique keys through access and mobility management network elements, the problem of insufficient communication security when terminal devices connect to the same PLMN through two 3GPP access points is solved, achieving key isolation and enhanced security.

CN119729465BActive Publication Date: 2026-05-26HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2023-09-26
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

When terminal devices connect to the same public terrestrial mobile network through two 3GPP access points, the lack of an effective key deduction scheme leads to insufficient communication security.

Method used

The access and mobility management network elements generate and manage two different keys to distinguish different 3GPP accesses through indication information and access type identifiers, ensuring that each access uses a unique key and employing different bearer parameters and uplink NAS counter values ​​to achieve key isolation.

Benefits of technology

It achieves key isolation for different 3GPP accesses within the same access and mobility management network element, improving communication security and avoiding the problem of key stream reuse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119729465B_ABST
    Figure CN119729465B_ABST
Patent Text Reader

Abstract

A key derivation method and apparatus are disclosed, relating to the field of communications. In this method, an access and mobility management network element (AMI) receives a first registration request message from a terminal device. The first registration request message is used to request the terminal device to register with the network via a first 3GPP access network, generate a first key, and send the first key to the first access network device. The first key is used for communication between the terminal device and the first access network device. The AMI also receives a second registration request message from the terminal device. The second registration request message is used to request the terminal device to register with the network via a second 3GPP access network, generate a second key, and send the second key to the second access network device. The first key is different from the second key. Using this method, two different keys are generated for two 3GPP accesses, achieving key isolation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a key deduction method and apparatus. Background Technology

[0002] Currently, terminal devices can register in the same access and mobility management function (AMF) network element through the 3rd generation partnership project (3GPP) and non-3GPP access, thereby connecting to the same public land mobile network (PLMN).

[0003] Specifically, when a terminal device connects to the same PLMN via 3GPP access and non-3GPP access, the terminal device can perform only one primary authentication with the AMF network element to maintain the common security context. For 3GPP access, the terminal device registers with the AMF through the next-generation NodeB (gNB) in the 5G mobile communication system. For non-3GPP access, the terminal device also registers with the AMF through the Non-3GPP Interworking Function (N3IWF) network element. Therefore, the AMF maintains NAS connection parameters for 3GPP access and non-3GPP access separately, thereby achieving secure isolation between the two access methods.

[0004] However, when a terminal device connects to the same PLMN through two 3GPP access points, there is no corresponding key derivation scheme. Summary of the Invention

[0005] This application provides a key deduction method and apparatus to solve the problem of how to deduce the key when a terminal device is connected to the same PLMN through two 3GPP access connections.

[0006] In a first aspect, this application provides a key derivation method, which can be executed by an access and mobility management network element or a module (such as a chip) within the access and mobility management network element. The method includes: receiving a first registration request message from a terminal device, the first registration request message being used for the terminal device to request registration with a network via a first 3GPP access scheme; generating a first key, the first key being a key used for communication between the terminal device and a first access network device; the first access network device being used for the first 3GPP access; sending the first key to the first access network device; receiving a second registration request message from the terminal device, the second registration request message being used for the terminal device to request registration with a network via a second 3GPP access scheme; generating a second key, the second key being a key used for communication between the terminal device and the second access network device, the second access network device being used for the second 3GPP access; the first key being different from the second key; and sending the second key to the second access network device. Using the above method, when a terminal device registers with the same access and mobility management network element through two 3GPP accesses, the access and mobility management network element generates two different keys for the two 3GPP accesses. That is, the key used for communication between the terminal device and the first access network device is different from the key used for communication between the terminal device and the second access network device, which can achieve key isolation and ensure communication security.

[0007] In one possible design, the first registration request message and / or the second registration request message include indication information for instructing the terminal device to connect to the network via two 3GPP access points.

[0008] Using the above design, the access and mobility management network elements can determine, through indication information, that the terminal device is connected to the network via two 3GPP access points. These two 3GPP access points can also be replaced with multiple 3GPP access points.

[0009] In one possible design, when generating the first key, the first key is generated based on the first access type identifier corresponding to the first 3GPP access; when generating the second key, the second key is generated based on the second access type identifier corresponding to the second 3GPP access, wherein the first access type identifier and the second access type identifier are different.

[0010] By adopting the above design, and using different access type identifiers in the two 3GPP access processes, it is possible to ensure that the first key and the second key are different, thereby achieving key isolation.

[0011] In one possible design, the second registration request message includes the indication information; before generating the second key, the second access type identifier is determined for the second 3GPP access based on the indication information.

[0012] Using the above design, the access and mobility management network element can determine that the terminal device is connected to the network through two 3GPP accesses by indication information, and then determine a second access type identifier for the second 3GPP access that is different from the first access type identifier.

[0013] In one possible design, the first registration request message includes the indication information; before generating the first key, a first access type identifier is determined for the first 3GPP access based on the indication information, the first access type identifier being one of the dual 3GPP access type identifiers; before generating the second key, a second access type identifier is determined for the second 3GPP access, the second access type identifier being the other of the dual 3GPP access type identifiers.

[0014] With the above design, the access and mobility management network element can determine that the terminal device is connected to the network through two 3GPP access points by indication information, and then use one of the dual 3GPP access type identifiers as the first access type identifier and the other as the second access type identifier, so that the first access type identifier and the second access type identifier are different.

[0015] In one possible design, the second access type identifier is one of the unused 3GPP access type identifiers.

[0016] In one possible design, a first registration acceptance message is sent to the terminal device, the first registration acceptance message including the first access type identifier; and / or, a second registration acceptance message is sent to the terminal device, the second registration acceptance message including the second access type identifier.

[0017] Using the above design, the terminal device can obtain the first access type identifier through the first registration receiving message and the second access type identifier through the second registration receiving message.

[0018] In one possible design, the first bearer parameter includes the first access type identifier, and the second bearer parameter includes the second access type identifier; the first NAS signaling is protected by the NAS security protection key and the first bearer parameter, and the first NAS signaling corresponds to the first 3GPP access; the second NAS signaling is protected by the NAS security protection key and the second bearer parameter, and the second NAS signaling corresponds to the second 3GPP access.

[0019] By using the above method and employing different bearer parameters, the problem of key stream reuse caused by two 3GPPs using the same NAS security protection key can be avoided.

[0020] In one possible design, when generating the first key, the first key is generated based on a third access type identifier and a first 3GPP access identifier, wherein the third access type identifier indicates that the access type is 3GPP access; when generating the second key, the second key is generated based on the third access type identifier and a second 3GPP access identifier; wherein the first 3GPP access identifier is different from the second 3GPP access identifier.

[0021] By using the above method, by providing new identifiers for different 3GPP accesses in two 3GPP access processes, it is possible to ensure that the first key and the second key are different, thereby achieving key isolation.

[0022] In one possible design, the first registration request message includes the indication information; before generating the first key, the identifier of the first 3GPP access is determined for the first 3GPP access based on the indication information; before generating the second key, the identifier of the second 3GPP access is determined for the second 3GPP access.

[0023] With the above design, the access and mobility management network element can determine that the terminal device is connected to the network through two 3GPP accesses by indication information, and then determine the identifier of the first 3GPP access for the first 3GPP access and the identifier of the second 3GPP access for the second 3GPP access.

[0024] In one possible design, when determining the identifier of the first 3GPP access for the first 3GPP access according to the indication information, two 3GPP access identifiers are obtained from the data management network element according to the indication information; one of the two 3GPP identifiers is used as the identifier of the first 3GPP access; when determining the identifier of the second 3GPP access for the second 3GPP access, the other of the two 3GPP identifiers is used as the identifier of the second 3GPP access.

[0025] Using the above method, the access and mobility management network element can obtain two pre-configured 3GPP access identifiers from the data management network element according to the instruction information, and use these two 3GPP access identifiers as the identifiers for the first 3GPP access and the second 3GPP access, respectively.

[0026] In one possible design, a first registration acceptance message is sent to the terminal device, the first registration acceptance message including the identifier of the first 3GPP access; a second registration acceptance message is sent to the terminal device, the second registration acceptance message including the identifier of the second 3GPP access.

[0027] With the above design, the terminal device can obtain the identifier of the first 3GPP access through the first registration receiving message, and obtain the identifier of the second 3GPP access through the second registration receiving message.

[0028] In one possible design, the first registration request message includes the identifier of the first 3GPP access, and the second registration request message includes the identifier of the second 3GPP access.

[0029] Using the above design, the terminal device can provide the identifier of the first 3GPP access and the identifier of the second 3GPP access.

[0030] In one possible design, the first bearer parameter corresponds to the identifier of the first 3GPP access, and the second bearer parameter corresponds to the identifier of the second 3GPP access; the NAS security protection key and the first bearer parameter are used to protect the first NAS signaling, which corresponds to the first 3GPP access; the NAS security protection key and the second bearer parameter are used to protect the second NAS signaling, which corresponds to the second 3GPP access.

[0031] By adopting the above design and using different bearer parameters, the problem of key stream reuse caused by two 3GPPs using the same NAS security protection key can be avoided.

[0032] In one possible design, when generating the first key, the first key is generated based on a first value of the uplink NAS counter; when generating the second key, the second key is generated based on a second value of the uplink NAS counter; wherein the first 3GPP access and the second 3GPP access share the uplink NAS counter, and the first value is different from the second value.

[0033] By adopting the above design, and using different values ​​of the same uplink NAS counter in two 3GPP access processes, it is possible to ensure that the first key and the second key are different, thereby achieving key isolation.

[0034] Secondly, this application provides a key derivation method, which can be executed by a terminal device or a module (such as a chip) in the terminal device. The method includes: sending a first registration request message to an access and mobility management network element, the first registration request message being used to request the terminal device to register with the network via a first 3GPP access; generating a first key, the first key being a key used for communication between the terminal device and the first access network device; the first access network device being used for the first 3GPP access; sending a second registration request message to the access and mobility management network element, the second registration request message being used to request the terminal device to register with the network via a second 3GPP access; generating a second key, the second key being a key used for communication between the terminal device and the second access network device, the second access network device being used for the second 3GPP access; the first key and the second key are different.

[0035] Using the above method, when a terminal device registers with the same access and mobility management network element through two 3GPP accesses, the terminal device generates two different keys for these two 3GPP accesses. That is, the key used for communication between the terminal device and the first access network device is different from the key used for communication between the terminal device and the second access network device, which can achieve key isolation and ensure communication security.

[0036] In one possible design, the first registration request message and / or the second registration request message include indication information for instructing the terminal device to connect to the network via two 3GPP access points.

[0037] Using the above design, the terminal device can notify the access and mobility management network elements via instruction information to connect to the network through two 3GPP access points. These two 3GPP access points can also be replaced with multiple 3GPP access points.

[0038] In one possible design, when generating the first key, the first key is generated based on the first access type identifier corresponding to the first 3GPP access; when generating the second key, the second key is generated based on the second access type identifier corresponding to the second 3GPP access, wherein the first access type identifier and the second access type identifier are different.

[0039] By adopting the above design, and using different access type identifiers in the two 3GPP access processes, it is possible to ensure that the first key and the second key are different, thereby achieving key isolation.

[0040] In one possible design, before generating the first key, a first access type identifier is determined for the first 3GPP access, the first access type identifier being one of the dual 3GPP access type identifiers; before generating the second key, a second access type identifier is determined for the second 3GPP access, the second access type identifier being the other of the dual 3GPP access type identifiers.

[0041] In one possible design, the second access type identifier is one of the unused 3GPP access type identifiers.

[0042] In one possible design, a first registration acceptance message is received from the access and mobility management network element, the first registration acceptance message including the first access type identifier; and / or, a second registration acceptance message is received from the access and mobility management network element, the first registration acceptance message including the second access type identifier.

[0043] With the above design, the terminal device can obtain the first access type identifier through the first registration acceptance message and / or obtain the second access type identifier through the second registration acceptance message. That is, the terminal device obtains the first access type identifier and / or the second access type identifier from the access and mobility management network element.

[0044] In one possible design, a first AS security mode command is received from the first access network device, the first AS security mode command including the first access type identifier; and / or, a second AS security mode command is received from the second access network device, the second AS security mode command including the second access type identifier.

[0045] With the above design, the terminal device can obtain the first access type identifier through the first AS security mode command and / or obtain the second access type identifier through the second AS security mode command. That is, the terminal device obtains the first access type identifier from the first access network device and / or obtains the second access type identifier from the second access network device.

[0046] In one possible design, the first bearer parameter includes the first access type identifier, and the second bearer parameter includes the second access type identifier; the first NAS signaling is protected by the NAS security protection key and the first bearer parameter, and the first NAS signaling corresponds to the first 3GPP access; the second NAS signaling is protected by the NAS security protection key and the second bearer parameter, and the second NAS signaling corresponds to the second 3GPP access.

[0047] By using the above method and employing different bearer parameters, the problem of key stream reuse caused by two 3GPPs using the same NAS security protection key can be avoided.

[0048] In one possible design, when generating the first key, the first key is generated based on a third access type identifier and a first 3GPP access identifier, wherein the third access type identifier indicates that the access type is 3GPP access; when generating the second key, the second key is generated based on the third access type identifier and a second 3GPP access identifier; wherein the first 3GPP access identifier is different from the second 3GPP access identifier.

[0049] By using the above method, by providing new identifiers for different 3GPP accesses in two 3GPP access processes, it is possible to ensure that the first key and the second key are different, thereby achieving key isolation.

[0050] In one possible design, before generating the first key, an identifier for the first 3GPP access is determined; and before generating the second key, an identifier for the second 3GPP access is determined.

[0051] In one possible design, a first registration acceptance message is received from the access and mobility management network element, the first registration acceptance message including the identifier of the first 3GPP access; and / or a second registration acceptance message is received from the access and mobility management network element, the second registration acceptance message including the identifier of the second 3GPP access.

[0052] With the above design, the terminal device can obtain the identifier of the first 3GPP access through the first registration acceptance message, and / or obtain the identifier of the second 3GPP access through the second registration acceptance message. That is, the terminal device can obtain the identifier of the first 3GPP access and / or the identifier of the second 3GPP access from the access and mobility management network element.

[0053] In one possible design, a first AS security mode command is received from the first access network device, the first AS security mode command including the identifier of the first 3GPP access; and / or, a second AS security mode command is received from the second access network device, the second AS security mode command including the identifier of the second 3GPP access.

[0054] With the above design, the terminal device can obtain the identifier of the first 3GPP access through the first AS security mode command, and / or obtain the identifier of the second 3GPP access through the second AS security mode command. That is, the terminal device obtains the identifier of the second 3GPP access from the first access network device, and / or obtains the identifier of the second 3GPP access from the second access network device.

[0055] In one possible design, the first registration request message includes the identifier of the first 3GPP access, and the second registration request message includes the identifier of the second 3GPP access.

[0056] Using the above design, the terminal device can provide the identifier of the first 3GPP access and the identifier of the second 3GPP access.

[0057] In one possible design, a first bearer parameter corresponds to the identifier of the first 3GPP access, and a second bearer parameter corresponds to the identifier of the second 3GPP access; a NAS security protection key and the first bearer parameter are used to securely protect the first NAS signaling, which corresponds to the first 3GPP access; the NAS security protection key and the second bearer parameter are used to securely protect the second NAS signaling, which corresponds to the second 3GPP access.

[0058] In one possible design, when generating the first key, the first key is generated based on a first value of the uplink NAS counter; when generating the second key, the second key is generated based on a second value of the uplink NAS counter; wherein the first 3GPP access and the second 3GPP access share the uplink NAS counter, and the first value is different from the second value.

[0059] By adopting the above design, and using different values ​​of the same uplink NAS counter in two 3GPP access processes, it is possible to ensure that the first key and the second key are different, thereby achieving key isolation.

[0060] Thirdly, this application provides a communication device that includes a unit for performing the method described in any one of the preceding aspects.

[0061] Fourthly, this application provides a communication device including at least one processing element and at least one storage element, wherein the at least one storage element is used to store programs and data, and the at least one processing element is used to read and execute the programs and data stored in the storage element so that the method described in any of the foregoing aspects of this application is implemented.

[0062] Fifthly, this application also provides a computer program that, when run on a computer, causes the computer to perform the method described in any of the preceding aspects.

[0063] In a sixth aspect, this application provides a communication device comprising: an interface circuit; the interface circuit being configured to provide input and / or output of a program or instructions to at least one processor; the at least one processor being configured to execute the program or instructions such that the communication device can implement the method described in any of the preceding aspects.

[0064] In one possible embodiment, the communication device includes the at least one processor.

[0065] In one possible embodiment, the communication device includes the at least one memory.

[0066] In a seventh aspect, this application provides a computer storage medium storing a software program that, when read and executed by one or more processors, can implement the method described in any one of the preceding aspects.

[0067] Eighthly, this application provides a computer program product containing instructions that, when executed on a computer, cause the computer to perform the method described in any of the preceding aspects.

[0068] A ninth aspect provides a chip system comprising at least one chip and a memory, the at least one chip being configured to read and execute a program stored in the memory to implement the method described in any of the preceding aspects.

[0069] A tenth aspect provides a communication system, including a terminal device, a first access network device, a second access network device, and an access and mobility management network element. The terminal device is configured to perform the method described in any one of the first aspects, and the access and mobility management network element is configured to perform the method described in any one of the second aspects.

[0070] Based on the implementations provided in the above aspects, this application can be further combined to provide more implementations. Attached Figure Description

[0071] Figure 1 A schematic diagram of the architecture of a mobile communication system used in the embodiments of this application;

[0072] Figure 2 This is a schematic diagram of the key deduction architecture in the 5G system of this application;

[0073] Figure 3A This is a schematic diagram illustrating the use of confidentiality keys to protect messages in this application;

[0074] Figure 3B This is a schematic diagram illustrating the use of an integrity protection key to protect messages in this application;

[0075] Figure 4 This is a schematic diagram showing the terminal equipment in this application connecting to the same PLMN through two 3GPP access points;

[0076] Figure 5 This is one of the flowcharts outlining a key deduction method in this application;

[0077] Figure 6 This is the second flowchart outlining a key deduction method in this application;

[0078] Figure 7 This is the third flowchart outlining a key deduction method in this application;

[0079] Figure 8 This is the fourth flowchart outlining a key deduction method in this application;

[0080] Figure 9 This is a schematic diagram of the structure of a communication device according to this application;

[0081] Figure 10 This is a schematic diagram of another communication device in this application. Detailed Implementation

[0082] The embodiments of this application can be applied to various communication systems, such as: Global System for Mobile Communications (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE Frequency Division Duplex (FDD) system, LTE Time Division Duplex (TDD) system, Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WIMAX) communication system, 5th Generation (5G) system, or New Radio (NR), or applied to future communication systems or other similar communication systems, etc.

[0083] like Figure 1The diagram shows the architecture of a 5G communication system as defined by the 3rd Generation Partnership Project (3GPP) standard. Figure 1 The 5G network architecture shown may include terminal devices, access network devices, and core network devices. Terminal devices access the data network (DN) through access network devices and core network devices.

[0084] Access network equipment can be radio access network (RAN) equipment. Examples include: base stations, evolved NodeBs (eNodeBs), transmission reception points (TRPs), next-generation NodeBs (gNBs) in 5G mobile communication systems, next-generation base stations in the 6th generation (6G) mobile communication systems, base stations in future mobile communication systems, or access nodes in wireless fidelity (WiFi) systems. It can also be a module or unit that performs some of the functions of a base station; for example, it can be a central unit (CU) or a distributed unit (DU). RAN equipment can be macro base stations, micro base stations, indoor stations, relay nodes, or donor nodes. The embodiments of this application do not limit the specific technologies or equipment forms used in the RAN equipment.

[0085] Terminal devices can be user equipment (UE), mobile stations, mobile terminals, etc. They can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), the Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, and smart cities. Terminal devices can include mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicles, urban air mobility vehicles (such as drones and helicopters), ships, robots, robotic arms, and smart home devices.

[0086] Access network equipment and terminal equipment can be fixed or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; and they can be deployed in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of the access network equipment and terminal equipment.

[0087] The core network equipment includes user plane function (UPF) network elements, AMF network elements, session management function (SMF) network elements, network exposure function (NEF) network elements, network function repository function (NRF) network elements, unified data management (UDM) network elements, policy control function (PCF) network elements, application function (AF) network elements, authentication server function (AUSF) network elements, and network slice selection function (NSSF) network elements. Among these, the UPF network element is a user plane network element, and the other network elements mentioned above are control plane network elements.

[0088] The interfaces between various control plane network elements can be service-oriented interfaces (such as...) Figure 1 (As shown), it can also be a point-to-point interface; this application does not limit this, but only uses... Figure 1 Let's take an example to illustrate.

[0089] The following is a brief introduction to some core network equipment:

[0090] 1. The SMF (Service Management Function) network element is primarily used for session management, IP address allocation and management of terminal devices, selection of manageable user equipment plane functions, policy control, or charging function interface endpoints, and downlink data notification. Nsmf (Network Function Interface) is a service-based interface provided by the SMF, allowing the SMF to communicate with other network functions.

[0091] 2. The AMF network element, abbreviated as AMF, is mainly used for mobility management and access management. The Namf is a service-based interface provided by the AMF, through which the AMF can communicate with other network functions.

[0092] 3. UDM network element, abbreviated as UDM, is used to handle user identification, subscription, access authentication, registration, or mobility management. Nudm is a service-based interface provided by UDM, through which UDM can communicate with other network functions.

[0093] 4. UPF network element, abbreviated as UPF, is used for packet routing and forwarding, or quality of service (QoS) processing of user plane data, etc.

[0094] 5. AUSF network element, abbreviated as AUSF, is mainly used for user authentication, etc. Nausf is a service-based interface provided by AUSF, through which AUSF can communicate with other network functions.

[0095] It is understood that core network equipment may also include other network elements, and this application does not limit this. The above network elements are examples of one implementation method, and this application does not exclude the existence of network elements or devices with the above-mentioned network element functions in 6G or later wireless communication systems with other names or other forms. The above-mentioned network elements or functions can be network components in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., cloud platform). As a possible implementation method, the above-mentioned network elements or functions can be implemented by one device, or by multiple devices, or can be a functional module within a device; this application does not specifically limit this.

[0096] like Figure 2 The diagram shows an exemplary key deduction architecture in a 5G system.

[0097] Authentication can be performed between terminal devices and service networks. Specifically, two authentication methods can be used: Extensible Authentication Protocol Authentication and Key Agreement (EAP-AKA′) and 5G AKA.

[0098] The terminal device stores a long-term key K and related functions. During two-way authentication, the terminal device can use the long-term key K and related functions to verify the authenticity of the network. The long-term key K can be stored in the terminal device's Universal Subscriber Identity Module (USIM). Correspondingly, the network side also stores the long-term key K and related functions. For example, the long-term key K and related functions can be stored in a UDM or an Authentication Repository and Processing Function (ARPF) network element (ARPF for short).

[0099] On the service network side, the UDM or ARPF derives the encryption key (CK) and integrity key (IK) based on the long-term key K. If the 5G AKA authentication method is used, the UDM or ARPF can derive the KAUSF based on CK and IK. If the EAP-AKA′ authentication method is used, the UDM or ARPF can derive CK′ and IK′ based on CK and IK, and send CK′ and IK′ to the AUSF. The AUSF then further derives the KAUSF based on CK′ and IK′.

[0100] The key derivation process for the subsequent two authentication methods is similar. AUSF derives the anchor key KSEAF based on KAUSF and sends KSEAF to the security anchor function (SEAF) network element (SEAF for short). SEAF then derives KAMF through KSEAF. SEAF can be part of AMF or an independent functional network element; this application does not limit this.

[0101] Furthermore, AMF, based on K AMF Derivation of NAS confidentiality key K NASenc NAS Integrity Protection Key K NASint AMF also based on K AMF Derivation of K gNB and K gNB And NH (next hop) is sent to gNB. gNB then sends K based on the next hop. gNB The RRC key and user plane key are derived from NH. The RRC key includes the RRC confidentiality key K. RRCenc and RRC integrity protection key K RRCint The user plane key includes the user plane confidentiality key K. UPenc User plane integrity protection key K UPint For non-3GPP access AMF, it also depends on K AMF Derivation of K N3IWF and K N3IWF Send to N3IWF to protect subsequent non-3GPP access data traffic.

[0102] On the terminal device side, the terminal device includes USIM and mobile equipment (ME). Similar to the key deduction process on the service network side, the key deduction process is completed by the ME.

[0103] The following is a brief introduction to the key deduction and key usage scenarios involved in this application:

[0104] (1) AMF according to KAMF Derivation of K gNB Required input parameters.

[0105] It is understandable that the ME in AMF and UE adopts the same approach based on K. AMF Deducing K gNB For example, according to K AMF Derivation of K gNB The specific input parameters are as follows:

[0106] FC = 0x6E;

[0107] P0 = Uplink NAS counter value (uplink NAS COUNT);

[0108] L0 = the length of the uplink NAS counter value;

[0109] P1 = Access Type Distinguisher;

[0110] L1 = Length of the access type identifier.

[0111] The values ​​of P1 can be shown in Table 1.

[0112] Table 1

[0113] Access type identifier Value 3GPP Access 0x01 Non-3GPP access 0x02

[0114] From the above, we can see that K gNB =KDF(FC, P0, L0, P1, L1), where KDF is short for Key Derivation Function. The access type identifier (i.e., P1) can be used to distinguish between 3GPP access and non-3GPP access.

[0115] (2) Use of integrity protection keys and confidentiality keys

[0116] The process of protecting messages using confidential keys, such as Figure 3A As shown. The process of protecting messages using an integrity protection key is as follows: Figure 3B As shown. By Figure 3A and Figure 3B As can be seen, the left side of the dashed line represents the sending end, and the right side of the dashed line represents the receiving end.

[0117] exist Figure 3A In message protection, besides the confidentiality key, the following input parameters are required: counter value, bearer parameter, direction parameter, and length parameter. Specifically, when the confidentiality protection key is K... NASenctWhen the bearer parameter is the NAS connection identifier, it is the same as the access type identifier. The direction parameter has a value of 0 for uplink and a value of 1 for downlink. When the direction parameter indicates uplink, the counter takes the value of the uplink NAS counter; when the direction parameter indicates downlink, the counter takes the value of the downlink NAS counter.

[0118] Similarly, in Figure 3B In message protection, besides the integrity protection key, the following input parameters are also required: counter value, message parameter, direction parameter, and bearer parameter. When the integrity protection key is K... NASint At this time, the bearer parameter is the NAS connection identifier, which is the same as the access type identifier.

[0119] A single terminal device can simultaneously access networks via 3GPP and non-3GPP networks. When using access traffic steering, switching, and splitting (ATSSS) functions, the terminal device establishes a special protocol data unit (PDU) session: a multi-access PDU session (MA PDU). This session supports multiple accesses, and data within this session can be transmitted on different access paths. The terminal device needs to support various steering functions, namely: multipath TCP (MPTCP), multipath QUIC (MPQUIC), and ATSSS-low layer (LL). TCP stands for Transmission Control Protocol. QUIC stands for Quick UDP Internet Connection. UDP stands for User Datagram Protocol. Each redirection function in the terminal device, according to the ATSSS rules provided by the network, allows traffic redirection, switching, and offloading across 3GPP access and non-3GPP access.

[0120] Currently, the multi-access scenario supports one 3GPP access and one non-3GPP access. This multi-access scenario can also be called the multi-registration scenario. After receiving a registration request message, the AMF checks whether the terminal device has passed network authentication. If a usable security context for the terminal device is found through the 5G globally unique temporary identifier (5G-GUTI), the AMF can decide not to perform a new authentication. For example, the usable security context for the terminal device is a public 5G NAS security context, also known as a public NAS security context.

[0121] For example, if a terminal device first registers with an AMF via 3GPP access, and then registers with the same AMF via non-3GPP access, the AMF can determine that a new authentication is not required if it finds the 5G NAS security context for that terminal device through 5G-GUTI. In this case, the terminal device also directly uses the 5G NAS security context to protect the registration for non-3GPP access. If the terminal device stores the NAS count for non-3GPP access in the PLMN, the stored NAS count is used to protect the registration for non-3GPP access. If the terminal device does not store the NAS count for non-3GPP access in the PLMN, the 5G NAS security context will be used for the first (partial) non-3GPP access. In this case, before using the 5G NAS security context on non-3GPP access, the terminal device needs to set the ULNAS count and DL NAS count for non-3GPP access to zero.

[0122] The AMF and end devices should establish a public NAS security context consisting of a set of NAS keys and algorithms upon initial registration. The AMF and end devices should also store parameters specific to each NAS connection within this public NAS security context. For key separation and replay protection, the parameters for each NAS connection include a pair of NAS counts for uplink and downlink and a unique NAS connection identifier. For example, for 3GPP access, the unique NAS connection identifier should be set to "0x01", and for non-3GPP access, it should be set to "0x02". Other parameters in the public NAS security context, such as the algorithm identifier, are common to multiple NAS connections.

[0123] Currently, multi-access scenarios do not support two 3GPP access paths. Therefore, how an MA PDU session can support at least two 3GPP access paths is a significant concern. These two 3GPP access paths can be in the same PLMN or in different PLMNs. The two 3GPP access paths can use the same or different standards. For example, they can include: terrestrial NR + terrestrial NR; terrestrial NR + evolved universal terrestrial radio access (E-UTRA) (e.g., using a combination of evolved packet core (EPC) and 5G core network (5GC)); terrestrial NR + non-terrestrial NR; dual non-terrestrial NR (e.g., using the same or different non-terrestrial network (NTN) orbits, such as Earth observation orbit, or medium Earth orbit, or low Earth orbit). Unless otherwise specified, this application primarily discusses multi-access scenarios where terminal devices connect to the same PLMN via two 3GPP access paths, and does not limit whether the two 3GPP access paths use the same standard. Figure 4 The diagram illustrates a terminal device connected to the same PLMN via two 3GPP access points. It should be noted that this application uses a dual 3GPP access scenario as an example, but it can also be applied to multi-3GPP access scenarios, such as scenarios with two or more 3GPP access points. In these scenarios, dual 3GPP access can be replaced with multi-3GPP access.

[0124] In multi-access scenarios, when supporting one 3GPP access and one non-3GPP access, both accesses use the same K. AMF Key derivation is performed, where K is used for 3GPP access. AMF Deducing K gNB For non-3GPP access, use K AMF Deducing K N3IWF In the derivation process of the two key types mentioned above, the input parameters include the access type identifier (i.e., P1), used to distinguish between 3GPP access and non-3GPP access. It is evident that the current access type identifier (i.e., P1) cannot distinguish between two 3GPP accesses. Therefore, when a terminal device connects to the same PLMN through two 3GPP accesses, if only one primary authentication is performed, the inability to distinguish between the two 3GPP accesses may result in both 3GPP accesses using the same key, leading to a key reuse problem.

[0125] Based on the above Figure 1The network system architecture shown and the related technologies described above are illustrated in this application embodiment, which provides several possible communication methods. The execution entities of each key deduction method are described using access and mobility management network elements and terminal devices as examples. It should be understood that access and mobility management network elements can also be replaced by communication devices with access and mobility management network element functions, or by chips, units, or modules within communication devices with access and mobility management network element functions. Terminal devices can also be replaced by communication devices with terminal functions, or by chips, units, or modules within communication devices with terminal functions.

[0126] In this embodiment, the terminal device sends a first registration request message and a second registration request message to the access and mobility management network element. The first registration request message is used to request registration with the network via a first 3GPP access. The second registration request message is used to request registration with the network via a second 3GPP access. Furthermore, the access and mobility management network element and the terminal device generate a first key for the first 3GPP access and a second key for the second 3GPP access. The first key and the second key are different; the first key is used for communication between the terminal device and the first access network device, and the second key is used for communication between the terminal device and the second access network device. The access and mobility management network element sends the first key to the first access network device and the second key to the second access network device. Using this method, two different keys are generated for the two 3GPP accesses, achieving key isolation.

[0127] In one possible implementation, communication between the terminal device and the first access network device may use a first key, or a key derived from the first key. Communication between the terminal device and the second access network device may use a second key, or a key derived from the second key.

[0128] For example, when a terminal device communicates with a first access network device, the terminal device and the first access network device can generate a first RRC key and a first user plane key based on a first key. The first RRC key includes a first RRC integrity protection key and / or a first RRC confidentiality key. The first user plane key includes a first user plane integrity protection key and / or a first user plane confidentiality key. Furthermore, the terminal device and the first access network device can securely protect first RRC signaling based on the first RRC key, and / or the terminal device and the first access network device can securely protect first data based on the first user plane key. The first RRC signaling is either RRC signaling sent by the terminal device to the first access network device or RRC signaling sent by the first access network device to the terminal device. The first data is either uplink data sent by the terminal device to the first access network device or downlink data sent by the first access network device to the terminal device.

[0129] Similarly, when the terminal device communicates with the second access network device, the terminal device and the second access network device can generate a second RRC key and a second user plane key based on the second key. The second RRC key includes a second RRC integrity protection key and / or a second RRC confidentiality key. The second user plane key includes a second user plane integrity protection key and / or a second user plane confidentiality key. Furthermore, the terminal device and the second access network device can use the second RRC key to securely protect the second RRC signaling, and / or the terminal device and the second access network device can use the second user plane key to securely protect the second data. The second RRC signaling is either RRC signaling sent by the terminal device to the second access network device, or RRC signaling sent by the second access network device to the terminal device. The second data is either uplink data sent by the terminal device to the second access network device, or downlink data sent by the second access network device to the terminal device.

[0130] like Figures 5 to 8 As shown, the above process will be explained below with specific examples. In the examples below, the terminal device is UE, the access and mobility management network element is AMF, the first access network device is RAN1, and the second access network device is RAN2.

[0131] Example 1:

[0132] S501: The UE sends a first registration request message to the AMF via RAN1. Correspondingly, the AMF receives the first registration request message.

[0133] The first registration request message is used to request the UE to register with the network through the first 3GPP access.

[0134] For example, the UE sends a first registration request message to RAN1. RAN1 selects an AMF and sends the first registration request message to the AMF. Optionally, if the UE has previously registered with another AMF (i.e., the source AMF), the AMF obtains the UE's previous context from the source AMF. If the UE has not registered with another AMF, RAN1 performs the AMF discovery and selection process.

[0135] For example, the AMF can also trigger the main authentication process, completing the authentication between the network side and the UE, and the network side deduces the key K. AMF Determine the key K AMF The corresponding key set identifier (in 5g, ngKSI). Where K... AMF The derivation process can be found in the relevant content above, and will not be repeated here. ngKSI is used to identify the key K established in the main authentication process. AMFIf UE authentication is successful, ngKSI can also be used to identify a portion of the security context created by the UE. For example, ngKSI can identify the corresponding key K. AMF Values ​​of uplink and downlink NAS counters, etc.

[0136] like Figure 2 As shown, the UE can also deduce the key K. AMF Furthermore, AMF and UE can be based on K. AMF Derivation of NAS confidentiality key K NASenc and / or NAS integrity protection key K NASint Among them, the NAS confidentiality key K NASenc and / or NAS integrity protection key K NASint It can be stored in the UE's security context. In this application, the NAS confidentiality key K NASenc and NAS integrity protection key K NASint Both can be referred to as NAS security protection keys. Both NAS security protection keys and AMF keys can be called NAS keys.

[0137] S502: AMF generates a first key based on the first access type identifier.

[0138] In one possible implementation, before generating the first key, the AMF determines a first access type identifier for the first 3GPP access. This first access type identifier can be stored in the UE's security context. For example, the AMF also creates a pair of NAS counters for the first NAS connection corresponding to the first 3GPP access and sets them to initial values. The AMF stores the parameters of the first NAS connection in the UE's security context. The parameters of the first NAS connection include the first access type identifier and the pair of NAS counters.

[0139] In one example, before generating the first key, the AMF determines the first access type identifier, and the UE also determines the first access type identifier. The AMF and the UE can agree in advance on the first allocated access type identifier through a protocol to ensure that they are assigned the same first access type identifier.

[0140] In another example, the AMF determines the first access type identifier and sends the first access type identifier to RAN1. RAN1 then notifies the UE by carrying the first access type identifier in the first access stratum (AS) security mode command.

[0141] In another example, the AMF determines a first access type identifier and notifies the UE by carrying the first access type identifier in a first registration accept message.

[0142] For example, as shown in Table 2, the first access type identifier can be 0x01 or 0x03.

[0143] Table 2

[0144] Access type identifier Value 3GPP Access 0x01 Non-3GPP access 0x02 3GPP Access 0x03

[0145] It is understood that the values ​​0x01 and 0x03 mentioned above are just examples. Other values ​​that are not currently defined can also be used by extension, such as 0x11, etc., which are not limited here.

[0146] In one possible implementation, after determining the first access type identifier, the AMF determines the AMF key (e.g., K) based on the AMF key. AMF A first key is generated using the first access type identifier and the first access type identifier. The first key can be denoted as K. gNB 1. Understandably, generating the first key requires combining other parameters, such as K. gNB 1 = KDF(FC, P0, L0, P1, L1), where P0 = the uplink NAS counter value corresponding to the first 3GPP access, L0 = the length of the uplink NAS counter value corresponding to the first 3GPP access, P1 = the first access type identifier, and L1 = the length of the first access type identifier. For details, please refer to the above related content; further explanation is not provided here.

[0147] For example, the AMF can also send a first registration acceptance message to the UE via RAN1, the first registration acceptance message including a 5G GUTI. The 5G GUTI is assigned to the UE by the AMF. Optionally, the first registration acceptance message includes a first access type identifier.

[0148] In addition, the AMF can send NAS security mode commands to the UE via RAN1. NAS security mode commands include ngKSI. The UE can also reply to the AMF with a NAS security mode complete message via RAN1.

[0149] S503: AMF sends the first key to RAN1. Correspondingly, RAN1 receives the first key from AMF.

[0150] For example, RAN1 can determine the first key received (e.g., K) gNB 1) Generate the first RRC key and the first user plane key. For example, the first RRC key includes K. RRCenc 1 and / or K RRCint 1. The first user plane key includes K UPenc 1 and / or KUPint 1.

[0151] Optionally, the AMF may also send a first access type identifier to RAN1. Furthermore, RAN1 may send a first AS security mode command to the UE, which is used to notify the UE of the RRC signaling protection cipher algorithm and / or user plane protection cipher algorithm selected by the network side. Optionally, the first AS security mode command may also include the first access type identifier. Further, after the UE generates the first key using S504, the UE may also send a first AS security mode response to RAN1. Additionally, RAN1 may use other signaling to carry the first access type identifier; this application does not limit this.

[0152] S504: The UE generates a first key based on the first access type identifier.

[0153] In one possible implementation, the UE can determine a first access type identifier for the first 3GPP access before generating the first key.

[0154] In one example, the UE determines the first access type identifier itself. The AMF and the UE can agree in advance on the first allocated access type identifier through the protocol to ensure that both are assigned the same first access type identifier.

[0155] In another example, the UE receives a first registration acceptance message from the AMF, which includes a first access type identifier.

[0156] In yet another example, the UE receives a first AS security mode command from RAN1, the first AS security mode command including a first access type identifier.

[0157] In addition, the UE creates a pair of NAS counters for the first NAS connection corresponding to the first 3GPP access and sets them to their initial values. The UE saves the parameters of the first NAS connection in the UE's security context. The parameters of the first NAS connection include the first access type identifier and a pair of NAS counters.

[0158] In one possible implementation, the UE uses an AMF key (e.g., K) AMF The first key, K, is generated using the first access type identifier and the first access type identifier. gNB 1. Furthermore, a first RRC key and a first user plane key can be generated based on the first key. The methods for generating the first key for the AMF and UE are the same, and will not be repeated here. Here, the AMF key is the same as the AMF key mentioned in S502, both being key K. AMF .

[0159] It is understood that this application does not limit the order of S502, S503 and S504.

[0160] Therefore, when RAN1 communicates with UE, RAN1 and UE can use the first RRC key to protect the first RRC signaling and / or use the first user plane key to protect the first data.

[0161] S505: The UE sends a second registration request message to the AMF. Correspondingly, the AMF receives the second registration request message.

[0162] The second registration request message is used to request the UE to register with the network through the second 3GPP access.

[0163] For example, the second registration request message includes indication information, wherein the indication information is used to instruct the UE to connect to the network through two 3GPP access points, and may also be described as instructing the UE to register to the network through two 3GPP access points.

[0164] It is understandable that the indication information can also be used to instruct the UE to connect to the network via multiple 3GPP access, or for the UE to register with the network via multiple 3GPP access. Multiple 3GPP access can be understood as two or more 3GPP access methods.

[0165] For example, the indication information can indicate that the registration type is dual 3GPP registration, or the indication information can indicate that the access type is dual 3GPP access.

[0166] For example, the indication information may indicate that the registration type is multiple 3GPP registration, or the indication information may indicate that the access type is multiple 3GPP access.

[0167] In addition, the second registration request message may also include 5G-GUTI, and optionally, it may also include ngKSI. The UE may also use the NAS integrity protection key K. NASint Integrity protection is applied to the second registration request message. It is understood that, based on the above S501, the NAS integrity protection key K... NASint According to K AMF The NAS integrity protection key K is obtained through deduction. NASint It is stored in the UE's security context.

[0168] For example, the UE sends a second registration request message to RAN2. RAN2 obtains the AMF's identifier based on the 5G-GUTI and forwards the second registration request message to the AMF. For instance, the AMF's identifier is a globally unique AMF identifier (GUAMI), where <5G-GUTI> = <guami>+<5G-TMSI>, the identifier of the PLMN registered by the UE is also provided in the GUAMI of 5G-GUTI. For example, the mobile country code (MCC) and mobile network code (MNC) are also included in the GUAMI.

[0169] After receiving the second registration request message, the AMF can retrieve the security context of the UE from the AMF based on the 5G-GUTI (and ngKSI) in the second registration request message, and use the NAS integrity protection key K in the UE's security context. NASint The integrity of the second registration request message is verified, thereby completing the authentication of the UE.

[0170] S506: The AMF generates a second key based on the second access type identifier.

[0171] In one possible implementation, after the AMF successfully authenticates the UE but before generating the second key, the AMF determines the second access type identifier for the second 3GPP access based on the indication information.

[0172] For example, the AMF determines a second access type identifier, different from the first access type identifier, for the second 3GPP access based on the indication information and the first access type identifier. Using this method, the AMF can determine from the indication information that the UE is connected to the network through two 3GPP access points, and then obtain the first access type identifier based on the UE's security context. The AMF then determines a second access type identifier for the second 3GPP access, and this second access type identifier is an unused access type identifier. The first access type identifier and the second access type identifier are different.

[0173] For example, as shown in Table 2, if the first access type identifier is 0x01, then the second access type identifier is 0x03. If the first access type identifier is 0x03, then the second access type identifier is 0x01.

[0174] In addition, the AMF creates a pair of NAS counters for the second NAS connection corresponding to the second 3GPP access and sets them to their initial values. The AMF stores the parameters of the second NAS connection in the UE's security context. The parameters of the second NAS connection include the second access type identifier and a pair of NAS counters.

[0175] Understandably, the AMF maintains a set of security contexts for the first 3GPP access and the second 3GPP access. The security context of the UE includes two sets of NAS connection parameters. The parameters of the first NAS connection include a first access type identifier and a pair of NAS counters, and the parameters of the second NAS connection include a second access type identifier and a pair of NAS counters.

[0176] In one possible implementation, after determining the second access type identifier, the AMF determines the AMF key (e.g., K) based on the AMF key. AMF The second key is generated from the second access type identifier and the second access type identifier. The second key can be denoted as K. gNB 2. The AMF key here is the same as the AMF key mentioned in S502 and S504 above, which is key K. AMF It is understandable that generating the second key requires combining other parameters, such as K. gNB 2 = KDF(FC, P0, L0, P1, L1), where P0 = the uplink NAS counter value corresponding to the second 3GPP access, L0 = the length of the uplink NAS counter value corresponding to the second 3GPP access, P1 = the second access type identifier, and L1 = the length of the second access type identifier.

[0177] In addition, the AMF can also send a second registration acceptance message to the UE. Optionally, the second registration acceptance message may include a second access type identifier.

[0178] S507: AMF sends the second key to RAN2. Correspondingly, RAN2 receives the second key from AMF.

[0179] For example, RAN2 can use the received second key (e.g., K) gNB 2) Generate a second RRC key and a second user plane key. For example, the second RRC key includes K. RRCenc 2 and K RRCint 2. The second user plane key includes K UPenc 2 and K UPint 2.

[0180] Optionally, the AMF can also send a second access type identifier to RAN2. Furthermore, RAN2 can send a second AS security mode command to the UE, which is used to notify the UE of the RRC signaling protection cryptographic algorithm and / or user plane protection cryptographic algorithm selected by the network side. Optionally, the second AS security mode command can also include the second access type identifier. Further, after the UE generates the second key using S508, the UE can also send a second AS security mode response to RAN2. Additionally, RAN2 can use other signaling to carry the second access type identifier; this application does not limit this.

[0181] S508: The UE generates a second key based on the second access type identifier.

[0182] In one possible implementation, the UE determines a second access type identifier for the second 3GPP access before generating the second key.

[0183] In one example, the UE determines the second access type identifier for the second 3GPP access based on the first access type identifier in the UE's security context. For instance, the UE determines that the first 3GPP access has already used the first access type identifier and allocates an unused second access type identifier for the second 3GPP access. Since the AMF and the UE have pre-agreed on the first allocated access type identifier through a protocol, and as shown in Table 2, there are two access type identifiers used to identify 3GPP access, it can be guaranteed that the second allocated second access type identifier will also be the same.

[0184] In another example, the AMF sends a second registration acceptance message to the UE, which includes a second access type identifier. Therefore, the UE can determine the second access type identifier based on the second registration acceptance message.

[0185] In another example, the AMF sends a second access type identifier to RAN2, and RAN2 sends a second AS security mode command to the UE. The second AS security mode command includes the second access type identifier. Therefore, the UE can determine the second access type identifier based on the second AS security mode command.

[0186] In addition, the UE creates a pair of NAS counters for the second NAS connection corresponding to the second 3GPP access and sets them to the initial value. The UE saves the parameters of the second NAS connection, which include the second access type identifier and a pair of NAS counters.

[0187] It is understandable that the UE maintains a set of security contexts for the first 3GPP access and the second 3GPP access. The UE's security context includes two sets of NAS connection parameters. The parameters of the first NAS connection include a first access type identifier and a pair of NAS counters, and the parameters of the second NAS connection include a second access type identifier and a pair of NAS counters.

[0188] In one possible implementation, the UE uses an AMF key (e.g., K) AMF The second key, K, is generated from the second access type identifier. gNB 2. Furthermore, a second RRC key and a second user plane key can be generated based on the second key. The methods for generating the second key are the same for both the AMF and the UE. The AMF key here is the same as the AMF key mentioned in S502, S504, and S506 above, which is key K. AMF .

[0189] It is understood that this application does not specify the order of S506, S507 and S508.

[0190] Therefore, when RAN2 communicates with UE, RAN2 and UE can use the second RRC key to protect the second RRC signaling and the second user plane key to protect the second data.

[0191] By using the above method, different access type identifiers can be used in the two 3GPP access processes to ensure that the first key and the second key are different, thus achieving key isolation.

[0192] Example 2:

[0193] S601: The UE sends a first registration request message to the AMF via RAN1. Correspondingly, the AMF receives the first registration request message.

[0194] For details of S601, please refer to S501 above.

[0195] The difference from S501 above is that the first registration request message includes instruction information. This instruction information can be referenced from the relevant content in S505 above.

[0196] S602: AMF generates a first key based on the first access type identifier.

[0197] In one possible implementation, before generating the first key, the AMF determines a first access type identifier for the first 3GPP access based on indication information. This first access type identifier is one of two 3GPP access type identifiers. The first access type identifier can be stored in the UE's security context. For example, if the AMF determines that the UE is connected to the network via two 3GPP accesses based on indication information, it determines one of the two 3GPP access type identifiers for the first 3GPP access as the first access type identifier and creates a pair of NAS counters, setting them to their initial values. The AMF stores the parameters of the first NAS connection corresponding to the first 3GPP access in the UE's security context. The parameters of the first NAS connection include the first access type identifier and the pair of NAS counters.

[0198] The Dual 3GPP Access Type Identifier is a newly defined access type identifier. Its value differs from the previous access type identifier used to identify 3GPP access. The Dual 3GPP Access Type Identifier is used in scenarios involving multiple or dual 3GPP access. It can also be called a Multiple 3GPP Access Type Identifier, and generally, it can include two or more identifiers.

[0199] Table 3 illustrates one possible implementation of dual 3GPP access type identifiers. As shown in Table 3, the first access type identifier can be 0x03 or 0x04.

[0200] Table 3

[0201] Access type identifier Value 3GPP Access 0x01 Non-3GPP access 0x02 Dual 3GPP access 0x03 Dual 3GPP access 0x04

[0202] It is understood that the values ​​0x03 and 0x04 mentioned above are just examples, and other values ​​that are not currently defined can also be used by extension, which is not limited here.

[0203] In one example, before generating the first key, the AMF determines the first access type identifier, and the UE also determines the first access type identifier. At this time, the AMF and the UE can agree in advance on the first assigned identifier among the two 3GPP access type identifiers to ensure that they are assigned the same identifier.

[0204] In another example, the AMF determines the first access type identifier and notifies the UE of the first access type identifier by carrying the first access type identifier in the first registration accept message.

[0205] In another example, the AMF determines the first access type identifier and sends the first access type identifier to RAN1. RAN1 then uses the first AS security mode command to carry the first access type identifier to notify the UE.

[0206] Furthermore, in one possible implementation, a new field can be added to the UE's security context. For example, this field may be designated as the first field. Exemplarily, the first field may include 1 bit. A value of 1 indicates that the UE connects to the network via two 3GPP access points, or that the UE's access type (or registration type) is dual 3GPP access or multiple 3GPP access. A value of 0 indicates that the UE does not connect to the network via two 3GPP access points, or that the UE's access type (or registration type) is neither dual 3GPP access nor multiple 3GPP access. The AMF can determine the value of the first field based on the indication information.

[0207] In one possible implementation, after determining the first access type identifier, the AMF determines the AMF key (e.g., K) based on the AMF key. AMF A first key is generated using the first access type identifier and the first access type identifier. The first key can be denoted as K. gNB 1, for example, K gNB 1 = KDF(FC, P0, L0, P1, L1, P2, L2), P0 = the uplink NAS counter value corresponding to the first 3GPP access, L0 = the length of the uplink NAS counter value corresponding to the first 3GPP access, P1 = the first access type identifier, L1 = the length of the first access type identifier.

[0208] In addition, the AMF can also send a first registration acceptance message to the UE via RAN1. Optionally, the first registration acceptance message includes a first access type identifier.

[0209] S603: AMF sends the first key to RAN1. Correspondingly, RAN1 receives the first key from AMF.

[0210] For example, RAN1 can determine the first key received (e.g., K) gNB 1) Generate the first RRC key and the first user plane key. For example, the first RRC key includes K. RRCenc 1 and / or K RRCint 1. The first user plane key includes K UPenc 1 and / or K UPint 1.

[0211] Optionally, the AMF can also send a first access type identifier to RAN1. Furthermore, RAN1 can send a first AS security mode command to the UE, which informs the UE of the RRC signaling protection cipher algorithm and / or user plane protection cipher algorithm selected by the network side. Optionally, the first AS security mode command can also include the first access type identifier. Further, after the UE executes S504 to generate the first key, the UE can also send a first AS security mode response to RAN1.

[0212] S604: The UE generates a first key based on the first access type identifier.

[0213] In one possible implementation, the UE can determine a first access type identifier for the first 3GPP access before generating the first key.

[0214] In one example, the UE knows that it is connected to the network through two 3GPP access points, and the first 3GPP access point is the first 3GPP access point. Before generating the first key, the UE determines a first access type identifier for the first 3GPP access point. The first access type identifier is one of the two 3GPP access type identifiers.

[0215] In another example, the UE receives a first registration acceptance message from the AMF, which includes a first access type identifier.

[0216] In yet another example, the UE receives a first AS security mode command from RAN1, the first AS security mode command including a first access type identifier.

[0217] In addition, the UE creates a pair of NAS counters for the first NAS connection corresponding to the first 3GPP access and sets them to their initial values. The UE saves the parameters of the first NAS connection in the UE's security context. The parameters of the first NAS connection include the first access type identifier and a pair of NAS counters.

[0218] Furthermore, in one possible implementation, the UE uses the AMF key (e.g., K) AMF The first key, K, is generated using the first access type identifier and the first access type identifier. gNB 1. Furthermore, a first RRC key and a first user plane key can be generated based on the first key. The methods for generating the first key for the AMF and UE are the same, and will not be repeated here. The AMF key here is the same as the AMF key mentioned in S602, both being key K. AMF .

[0219] It is understood that this application does not limit the order of S602, S603 and S604.

[0220] Therefore, when RAN1 communicates with UE, RAN1 and UE can use the first RRC key to protect the first RRC signaling and use the first user plane key to protect the first data.

[0221] S605: The UE sends a second registration request message to the AMF. Correspondingly, the AMF receives the second registration request message.

[0222] The second registration request message is used to request the UE to register with the network through a second 3GPP access method. Optionally, the second registration request message may also include indication information.

[0223] In addition, further details regarding the second registration request message can be found in S505.

[0224] S606: AMF generates a second key based on the second access type identifier.

[0225] In one possible implementation, after successful authentication of the UE and before generating the second key, the AMF determines a second access type identifier for the second 3GPP access.

[0226] For example, the AMF can obtain the first access type identifier based on the UE's security context. Since the first access type identifier is one of the dual 3GPP access type identifiers, the AMF determines that the UE is connected to the network through two 3GPP access points. Alternatively, if the UE's security context includes a first field, the AMF determines that the UE is connected to the network through two 3GPP access points based on the first field in the UE's security context. Or, if the second registration request message includes indication information, the AMF determines that the UE is connected to the network through two 3GPP access points based on the indication information.

[0227] Furthermore, after the AMF determines that the UE is connected to the network through two 3GPP access points, the AMF assigns a second access type identifier to the second 3GPP access point. This second access type identifier is the other identifier in the dual 3GPP access type identifier set, and it is an unused identifier within the dual 3GPP access type identifier set. The first access type identifier is different from the second access type identifier.

[0228] In addition, the AMF creates a pair of NAS counters for the second NAS connection corresponding to the second 3GPP access and sets them to their initial values. The AMF stores the parameters of the second NAS connection in the UE's security context. The parameters of the second NAS connection include the second access type identifier and a pair of NAS counters.

[0229] Understandably, the AMF maintains a set of security contexts for the first 3GPP access and the second 3GPP access. The security context of the UE includes two sets of NAS connection parameters. The parameters of the first NAS connection include a first access type identifier and a pair of NAS counters, and the parameters of the second NAS connection include a second access type identifier and a pair of NAS counters.

[0230] Furthermore, in one possible implementation, after determining the second access type identifier, the AMF determines the AMF key (e.g., K) based on the AMF key. AMF The second key is generated from the second access type identifier and the second access type identifier. The second key can be denoted as K. gNB 2. Understandably, generating the second key requires combining other parameters, such as K. gNB 2 = KDF(FC, P0, L0, P1, L1), where P0 = the uplink NAS counter value corresponding to the second 3GPP access, L0 = the length of the uplink NAS counter value corresponding to the second 3GPP access, P1 = the second access type identifier, and L1 = the length of the second access type identifier. The AMF key here is the same as the AMF key mentioned in S602 and S604 above, which is key K. AMF .

[0231] In addition, the AMF can also send a second registration acceptance message to the UE. Optionally, the second registration acceptance message may include a second access type identifier.

[0232] S607: AMF sends the second key to RAN2. Correspondingly, RAN2 receives the second key from AMF.

[0233] For example, RAN2 can use the received second key (e.g., K) gNB 2) Generate a second RRC key and a second user plane key. For example, the second RRC key includes K. RRCenc 2 and K RRCint 2. The second user plane key includes K UPenc 2 and K UPint 2.

[0234] Optionally, the AMF can also send a second access type identifier to RAN2. Furthermore, RAN2 can send a second AS security mode command to the UE, which informs the UE of the RRC signaling protection cipher algorithm and / or user plane protection cipher algorithm selected by the network side. Optionally, the second AS security mode command can also include the second access type identifier. Further, after the UE generates the second key using S508, the UE can also send a second AS security mode response to RAN2.

[0235] S608: The UE generates a second key based on the second access type identifier.

[0236] In one possible implementation, the UE determines a second access type identifier for the second 3GPP access before generating the second key.

[0237] In one example, the UE determines and allocates a second access type identifier for the second 3GPP access based on the first access type identifier in the UE's security context. The UE identifies the first access type identifier as one of the dual 3GPP access type identifiers and allocates the other identifier from the dual 3GPP access type identifiers to the second 3GPP access as the second access type identifier. This second access type identifier is an unused identifier in the dual 3GPP access type identifiers. The first access type identifier and the second access type identifier are different. Since the AMF and the UE have pre-agreed on the first allocated identifier in the dual 3GPP access type identifiers through the protocol, and as shown in Table 3, there are two identifiers used to identify dual 3GPP access types, it can be further guaranteed that the second access type identifier allocated by both parties is also the same.

[0238] In another example, the AMF sends a second registration acceptance message to the UE, which includes a second access type identifier. Therefore, the UE can determine the second access type identifier based on the second registration acceptance message.

[0239] In another example, the AMF sends a second access type identifier to RAN2, and RAN2 sends a second AS security mode command to the UE. The second AS security mode command includes the second access type identifier. Therefore, the UE can determine the second access type identifier based on the second AS security mode command.

[0240] In addition, the UE creates a pair of NAS counters for the second NAS connection corresponding to the second 3GPP access and sets them to the initial value. The UE saves the parameters of the second NAS connection, which include the second access type identifier and a pair of NAS counters.

[0241] It is understandable that the UE maintains a set of security contexts for the first 3GPP access and the second 3GPP access. The UE's security context includes two sets of NAS connection parameters. The parameters of the first NAS connection include a first access type identifier and a pair of NAS counters, and the parameters of the second NAS connection include a second access type identifier and a pair of NAS counters.

[0242] In one possible implementation, the UE generates a second key, namely K, based on the AMF key and the second access type identifier. gNB 2. Furthermore, a second RRC key and a second user plane key can be generated based on the second key. The methods for generating the second key for the AMF and UE are the same and will not be repeated here. The AMF key here is the same as the AMF key mentioned in S602, S604, and S606 above, which is key K. AMF .

[0243] It is understood that this application does not specify the order of S606, S607 and S608.

[0244] Therefore, when RAN2 communicates with UE, RAN2 and UE can use the second RRC key to protect the second RRC signaling and the second user plane key to protect the second data.

[0245] By using the above method, different access type identifiers can be used in the two 3GPP access processes to ensure that the first key and the second key are different, thus achieving key isolation.

[0246] Furthermore, regarding Examples 1 and 2 above, in another possible implementation, the AMF uses a NAS security protection key and a first bearer parameter to securely protect the first NAS signaling, which corresponds to a first 3GPP access. It also uses a NAS security protection key and a second bearer parameter to securely protect the second NAS signaling, which corresponds to a second 3GPP access. The first bearer parameter is a first access type identifier, and the second bearer parameter is also a first access type identifier.

[0247] As can be seen from S501 above, the NAS security protection key includes the NAS confidentiality key K. NASenc and / or NAS integrity protection key K NASint The first NAS signaling is the NAS signaling transmitted between the AMF and the UE via the first 3GPP access. The second NAS signaling is the NAS signaling transmitted between the AMF and the UE via the second 3GPP access.

[0248] For example, AMF according to K AMF Derivation of NAS confidentiality key K NASenc NAS Integrity Protection Key K NASint According to NAS confidentiality key K NASenc The first NAS signaling is confidentialized using the first access type identifier and the NAS integrity protection key K. NASint Integrity protection is provided for the first NAS signaling using the first access type identifier and the NAS confidentiality key K. NASenc The second access type identifier provides confidentiality protection for the second NAS signaling, based on the NAS integrity protection key K. NASint The second access type identifier and the second NAS signaling are used to protect the integrity of the signaling.

[0249] For example, combining Figure 3A As shown, for the first 3GPP access, based on the NAS confidentiality key K NASenc The first NAS signaling is protected for confidentiality by corresponding input parameters. These input parameters include at least one of the following: the value of a first counter, a first bearer parameter, a first direction parameter, and a first length parameter. The first bearer parameter includes a first access type identifier. If the AMF protects the first NAS signaling for confidentiality, the first counter is the downlink NAS counter corresponding to the first 3GPP access, and the first direction parameter indicates downlink. If the UE protects the first NAS signaling for confidentiality, the first counter is the uplink NAS counter corresponding to the first 3GPP access, and the first direction parameter indicates uplink.

[0250] For the second 3GPP access, based on the NAS confidentiality key K NASenc The second NAS signaling is protected for confidentiality by corresponding input parameters. These input parameters include at least one of the following: the value of the second counter, a second bearer parameter, a second direction parameter, and a second length parameter. The second bearer parameter includes a second access type identifier. If the AMF protects the second NAS signaling for confidentiality, the second counter is the downlink NAS counter corresponding to the second 3GPP access, and the second direction parameter indicates downlink. If the UE protects the second NAS signaling for confidentiality, the second counter is the uplink NAS counter corresponding to the second 3GPP access, and the second direction parameter indicates uplink.

[0251] For example, combining Figure 3B As shown, for the first 3GPP access, the AMF or UE uses the NAS integrity protection key K. NASint The second NAS signaling is protected for integrity using corresponding input parameters. These input parameters include at least one of the following: the value of a first counter, a first bearer parameter, a first direction parameter, and a first message parameter. The first bearer parameter includes a first access type identifier. For the second 3GPP access, the AMF or UE uses the NAS integrity protection key K... NASint The second NAS signaling is protected for integrity by corresponding input parameters, wherein the input parameters include at least one of the following: the value of the second counter, the second bearer parameter, the second direction parameter, and the second message parameter. The second bearer parameter includes the second access type identifier.

[0252] By using the above method and employing different bearer parameters, the problem of key stream reuse caused by two 3GPPs using the same NAS key can be avoided.

[0253] Example 3:

[0254] S701: The UE sends a first registration request message to the AMF via RAN1. Correspondingly, the AMF receives the first registration request message.

[0255] For details of S701, please refer to the above-mentioned S501.

[0256] The difference from S501 above is that the first registration request message includes instruction information. This instruction information can be referenced from the relevant content in S505 above.

[0257] S702: The AMF generates a first key based on the third access type identifier and the first 3GPP access identifier.

[0258] In one possible implementation, before generating the first key, the AMF determines the identifier of the first 3GPP access based on the indication information.

[0259] For example, the identifier of the first 3GPP access is the path identifier of the first 3GPP access, or other identifiers used to identify the first 3GPP access, wherein the identifier of the first 3GPP access is different from the access type identifier. For example, the path identifier of the first 3GPP access is the identifier of the data transmission path between the UE and the UPF. For instance, taking downlink data as an example, downlink data from the DN arrives at UPF1, is forwarded to RAN1 via UPF2, and then RAN1 sends the downlink data to the UE. The downlink data transmission path is UPF1→UPF2→RAN1→UE. Similarly, the uplink data transmission path is UE→RAN1→UPF2→UPF1. Therefore, the path identifier of the first 3GPP access is the identifier used to identify the uplink data transmission path and / or the downlink data transmission path. For example, the AMF may determine the identifier of the first 3GPP access based on the indication information in the following ways, including but not limited to:

[0260] Method a: The AMF can allocate a first 3GPP access identifier for the first 3GPP access based on the indication information. In this case, the AMF also needs to send the first 3GPP access identifier to the UE. For example, the AMF sends a first registration acceptance message to the UE, which includes the first 3GPP access identifier. Alternatively, the AMF sends the first 3GPP access identifier to RAN1, and RAN1 notifies the UE by carrying the first 3GPP access identifier in a first AS security mode command.

[0261] Method b: The AMF can obtain the identifier of the first 3GPP access from other core network elements. In addition, the AMF also needs to send the identifier of the first 3GPP access to the UE. For example, the AMF sends a first registration acceptance message to the UE, which includes the identifier of the first 3GPP access. Alternatively, the AMF sends the identifier of the first 3GPP access to RAN1, and RAN1 notifies the UE by carrying the identifier of the first 3GPP access in a first AS security mode command.

[0262] For example, the AMF can obtain two 3GPP access identifiers from the UDM. For instance, the UDM may configure two different 3GPP access identifiers in its subscription information when the UE connects to the network via two different 3GPP access methods. The AMF sends a Nudm_UECM_Registration request message to the UDM, which includes indication information. The UDM can then obtain the two 3GPP access identifiers from the subscription information based on this indication information and send them to the AMF. The AMF selects one of the two 3GPP access identifiers as the identifier for the first 3GPP access method.

[0263] In one example, the UDM can also indicate the allocation order of the two 3GPP access identifiers, and then the AMF determines the identifier of the first 3GPP access from the two 3GPP access identifiers according to the allocation order.

[0264] In another example, if the UDM replies with two 3GPP access identifiers without indicating the allocation order, the AMF can determine the identifier for the first 3GPP access from the two 3GPP access identifiers. For example, the AMF can randomly select one of the two 3GPP access identifiers as the identifier for the first 3GPP access.

[0265] Furthermore, after the AMF determines the identifier of the first 3GPP access, the AMF can store the identifier of the first 3GPP access in the UE's security context. In addition, the AMF can also store the identifier of another 3GPP access that has not yet been assigned in the UE's security context.

[0266] Method c: The first registration request message includes the identifier of the first 3GPP access, that is, the UE determines the identifier of the first 3GPP access.

[0267] For example, after determining the identifier of the first 3GPP access, the AMF can store the identifier of the first 3GPP access in the UE's security context. Furthermore, the AMF creates a pair of NAS counters for the first NAS connection corresponding to the first 3GPP access and sets them to their initial values.

[0268] In one possible implementation, the AMF is based on an AMF key (e.g., K). AMF The first key is generated from the third access type identifier and the identifier of the first 3GPP access. The third access type identifier is the access type identifier used to identify 3GPP access as shown in Table 1. Referring to Table 1, the access type identifier here can be 0x01, and the first key can be denoted as K. gNB1 .

[0269] In one example, the identifier of the first 3GPP access is used as the basis for generating K. gNB1 The new input parameters, then K gNB 1 = KDF(FC, P0, L0, P1, L1, P2, L2), P0 = the uplink NAS counter value corresponding to the first 3GPP access, L0 = the length of the uplink NAS counter value corresponding to the first 3GPP access, P1 = the third access type identifier, L1 = the length of the third access type identifier, P2 is the identifier of the first 3GPP access, and L2 is the length of the identifier of the first 3GPP access.

[0270] In another example, the definition of P1 is updated by determining P1 based on the identifier of the first 3GPP access and the identifier of the third access type. For example, P1 is obtained by concatenating the identifier of the first 3GPP access with the identifier of the third access type. gNB 1 = KDF(FC, P0, L0, P1, L1), P0 = the uplink NAS counter value corresponding to the first 3GPP access, L0 = the length of the uplink NAS counter value corresponding to the first 3GPP access, P1 = the third access type identifier || the identifier of the first 3GPP access, L1 = the length of the third access type identifier || the identifier of the first 3GPP access.

[0271] In another example, the definition of P1 is updated by determining P1 based on the identifier of the first 3GPP access. For example, if the identifier of the first 3GPP access is used as P1, then K gNB 1 = KDF(FC, P0, L0, P1, L1), P0 = the uplink NAS counter value corresponding to the first 3GPP access, L0 = the length of the uplink NAS counter value corresponding to the first 3GPP access, P1 = the identifier of the first 3GPP access, L1 = the length of the identifier of the first 3GPP access.

[0272] It is understood that the above examples are merely illustrative and not intended to limit this application. K can be generated using one or more parameters from the following: the value of the uplink NAS counter corresponding to the first 3GPP access, the length of the uplink NAS counter value corresponding to the first 3GPP access, the identifier of the first 3GPP access, the length of the identifier of the first 3GPP access, the third access type identifier, and the length of the third access type identifier. gNB 1.

[0273] In one possible implementation, a new field can be added to the UE's security context. For example, this field may be designated as the first field. Exemplarily, the first field may include 1 bit. A value of 1 indicates that the UE connects to the network via two 3GPP access points, or that the UE's access type (or registration type) is dual 3GPP access or multiple 3GPP access. A value of 0 indicates that the UE does not connect to the network via two 3GPP access points, or that the UE's access type (or registration type) is neither dual 3GPP access nor multiple 3GPP access. The AMF can determine the value of the first field based on the indication information.

[0274] In addition, the AMF can also send a first registration acceptance message to the UE through RAN1. Optionally, the first registration acceptance message includes the identifier corresponding to the first 3GPP access.

[0275] S703: AMF sends the first key to RAN1. Correspondingly, RAN1 receives the first key from AMF.

[0276] For example, RAN1 can determine the first key received (e.g., K) gNB 1) Generate the first RRC key and the first user plane key. For example, the first RRC key includes K. RRCenc 1 and K RRCint 1. The first user plane key includes K UPenc 1 and K UPint 1.

[0277] Optionally, the AMF can also send a first access type identifier to RAN1. Furthermore, RAN1 can send a first AS security mode command to the UE, which informs the UE of the RRC signaling protection cipher algorithm and / or user plane protection cipher algorithm selected by the network side. Optionally, the first AS security mode command can also include the first access type identifier. Further, after the UE executes S504 to generate the first key, the UE can also send a first AS security mode response to RAN1.

[0278] S704: The UE generates a first key based on the third access type identifier and the first 3GPP access identifier.

[0279] In one possible design, the UE determines the identifier of the first 3GPP access before generating the first key.

[0280] In one example, if the UE knows that it is connected to the network through two 3GPP access points, and the first 3GPP access point is its first 3GPP access, then before generating the first key, the UE determines the identifier of the first 3GPP access point. Exemplarily, the UE can determine the identifier of the first 3GPP access point itself. In this case, the first registration request message may include the identifier of the first 3GPP access point.

[0281] In another example, the UE receives a first registration acceptance message from the AMF, which includes the identifier of the first 3GPP access.

[0282] In yet another example, the UE receives a first AS security mode command from RAN1, which includes the identifier of a first 3GPP access.

[0283] In addition, the UE creates a pair of NAS counters for the first NAS connection corresponding to the first 3GPP access and sets them to the initial value.

[0284] Furthermore, in one possible design, the UE generates a first key, namely K, based on the AMF key, the third access type identifier, and the first 3GPP access identifier. gNB 1. Furthermore, a first RRC key and a first user plane key can be generated based on the first key. The methods for generating the first key are the same for AMF and UE, and will not be elaborated here.

[0285] It is understood that this application does not limit the order of S702, S703 and S704.

[0286] Therefore, when RAN1 communicates with UE, RAN1 and UE can use the first RRC key to protect the first RRC signaling and use the first user plane key to protect the first data.

[0287] S705: The UE sends a second registration request message to the AMF. Correspondingly, the AMF receives the second registration request message.

[0288] The second registration request message is used to request the UE to register with the network through the second 3GPP access protocol. Optionally, the second registration request message may also include indication information. Furthermore, other details regarding the second registration request message can be found in S505.

[0289] S706: The AMF generates a second key based on the third access type identifier and the second 3GPP access identifier.

[0290] In one possible implementation, after successful authentication of the UE but before generating the second key, the AMF determines the second 3GPP identifier for the second 3GPP access. Specifically, this can include, but is not limited to, the following methods:

[0291] Method a: If the UE's security context includes a first field, the AMF determines that the UE is connected to the network through two 3GPP access points based on the first field in the UE's security context. Alternatively, if the second registration request message includes indication information, the AMF determines that the UE is connected to the network through two 3GPP access points based on the indication information. Furthermore, the AMF can assign an identifier for the second 3GPP access point. In this case, the AMF also needs to send the identifier of the second 3GPP access point to the UE. For example, the AMF sends a second registration acceptance message to the UE, which includes the identifier of the second 3GPP access point. Or, the AMF sends the identifier of the second 3GPP access point to RAN2, and RAN2 uses a second AS security mode command to carry the identifier of the second 3GPP access point to notify the UE.

[0292] Method b: If the AMF obtains the identifier of an unassigned 3GPP access based on the UE's security context, and thus determines that the UE is connected to the network through two 3GPP accesses, the AMF further uses the identifier of the unassigned 3GPP access as the identifier of the second 3GPP access. In this case, the AMF also needs to send the identifier of the second 3GPP access to the UE. For example, the AMF sends a second registration acceptance message to the UE, which includes the identifier of the second 3GPP access. Alternatively, the AMF sends the identifier of the second 3GPP access to RAN2, and RAN2 uses a second AS security mode command to carry the identifier of the second 3GPP access to notify the UE.

[0293] Method c: The second registration request message includes the identifier of the second 3GPP access, that is, the identifier of the second 3GPP access assigned to the UE. In this case, the AMF determines, based on the identifier of the second 3GPP access in the second registration request message, whether the UE is connected to the network through two 3GPP accesses, and also determines the identifier of the second 3GPP access.

[0294] In addition, the AMF saves the identifier of the second 3GPP access to the UE's context. The AMF also creates a pair of NAS counters for the first NAS connection corresponding to the second 3GPP access and sets them to their initial values.

[0295] Understandably, the AMF maintains a set of security contexts for the first 3GPP access and the second 3GPP access. The security context of the UE includes two sets of NAS connection parameters. The parameters of the first NAS connection include the identifier of the first 3GPP access, the identifier of the third access type, and a pair of NAS counters. The parameters of the second NAS connection include the identifier of the second 3GPP access, the identifier of the third access type, and a pair of NAS counters.

[0296] For example, the AMF is based on the AMF key (e.g., K). AMF The second key is generated from the third access type identifier and the second 3GPP access identifier. The third access type identifier is the access type identifier used to identify 3GPP access as shown in Table 1. Referring to Table 1, this access type identifier can be 0x01. The second key can be denoted as K. gNB 2.

[0297] In one example, the identifier of the second 3GPP access is used to generate K. gNB 2. The new input parameters, then K gNB2 =KDF(FC, P0, L0, P1, L1, P2, L2), P0 = the uplink NAS counter value corresponding to the second 3GPP access, L0 = the length of the uplink NAS counter value corresponding to the second 3GPP access, P1 = the third access type identifier, L1 = the length of the third access type identifier, P2 is the identifier of the second 3GPP access, and L2 is the length of the identifier of the second 3GPP access.

[0298] In another example, the definition of P1 is updated by determining P1 based on the identifier of the second 3GPP access and the identifier of the third access type. For example, P1 is obtained by concatenating the identifier of the second 3GPP access with the identifier of the third access type. gNB 2 = KDF(FC, P0, L0, P1, L1), P0 = the uplink NAS counter value corresponding to the second 3GPP access, L0 = the length of the uplink NAS counter value corresponding to the second 3GPP access, P1 = the third access type identifier || the identifier of the second 3GPP access, L1 = the length of the third access type identifier || the identifier of the second 3GPP access.

[0299] In another example, the definition of P1 is updated by determining P1 based on the identifier of the second 3GPP access. For example, if the identifier of the second 3GPP access is used as P1, then K gNB 2 = KDF(FC, P0, L0, P1, L1), P0 = the uplink NAS counter value corresponding to the second 3GPP access, L0 = the length of the uplink NAS counter value corresponding to the second 3GPP access, P1 = the identifier of the second 3GPP access, L1 = the length of the identifier of the second 3GPP access.

[0300] It is understood that the above examples are merely illustrative and not intended to limit this application. K can be generated using one or more parameters from the following: the value of the uplink NAS counter corresponding to the second 3GPP access, the length of the uplink NAS counter value corresponding to the second 3GPP access, the identifier of the second 3GPP access, the length of the identifier of the second 3GPP access, the third access type identifier, and the length of the third access type identifier. gNB 2.

[0301] S707: AMF sends the second key to RAN2. Correspondingly, RAN2 receives the second key from AMF.

[0302] For example, RAN2 can use the received second key (e.g., K) gNB 2) Generate a second RRC key and a second user plane key. For example, the second RRC key includes K. RRCenc 2 and K RRCint 2. The second user plane key includes K UPenc 2 and K UPint 2.

[0303] Optionally, the AMF can also send a second access type identifier to RAN2. Furthermore, RAN2 can send a second AS security mode command to the UE, which informs the UE of the RRC signaling protection cipher algorithm and / or user plane protection cipher algorithm selected by the network side. Optionally, the second AS security mode command can also include the second access type identifier. Further, after the UE generates the second key using S508, the UE can also send a second AS security mode response to RAN2.

[0304] S708: The UE generates a second key based on the third access type identifier and the second 3GPP access identifier.

[0305] In one possible implementation, the UE determines the identifier of the second 3GPP access before generating the second key.

[0306] In one example, if the UE knows that it is connected to the network through two 3GPP access points, and that the second 3GPP access point is a second 3GPP access point, then before generating the second key, the UE determines the second 3GPP identifier for the second 3GPP access point. For example, the UE can assign the second 3GPP access point itself.

[0307] In another example, the UE receives a second registration acceptance message from the AMF, which includes the identifier of a second 3GPP access.

[0308] In yet another example, the UE receives a second AS security mode command from RAN2, which includes the identifier of a second 3GPP access.

[0309] The UE also creates a pair of NAS counters for the second NAS connection corresponding to the second 3GPP access and sets them to the initial value.

[0310] It is understandable that the UE maintains a set of security contexts for the first 3GPP access and the second 3GPP access. The UE's security context includes two sets of NAS connection parameters. The parameters of the first NAS connection include the identifier of the first 3GPP access, the identifier of the third access type, and a pair of NAS counters. The parameters of the second NAS connection include the identifier of the second 3GPP access, the identifier of the third access type, and a pair of NAS counters.

[0311] Furthermore, the UE generates a second key, namely K, based on the AMF key, the third access type identifier, and the second 3GPP access identifier. gNB 2. Furthermore, a second RRC key and a second user plane key can be generated based on the second key. The methods for generating the second key are the same for AMF and UE, and will not be elaborated here.

[0312] It is understood that this application does not limit the order of S706, S707 and S708.

[0313] Therefore, when RAN2 communicates with UE, RAN2 and UE can use the second RRC key to protect the second RRC signaling and the second user plane key to protect the second data.

[0314] By using the above method, by assigning new identifiers to different 3GPP access processes in two 3GPP access processes, it is possible to ensure that the first key and the second key are different, thereby achieving key isolation.

[0315] Furthermore, in one possible implementation, the AMF uses a NAS security protection key and a first bearer parameter to securely protect the first NAS signaling, which corresponds to a first 3GPP access. It also uses a secure NAS protection key and a second bearer parameter to securely protect the second NAS signaling, which corresponds to a second 3GPP access. The first bearer parameter corresponds to the identifier of the first 3GPP access, meaning it is determined based on that identifier. For example, the first bearer parameter may be the identifier of the first 3GPP access or determined based on the identifier of the first 3GPP access and a third access type identifier. Similarly, the second bearer parameter corresponds to the identifier of the second 3GPP access, meaning it is determined based on the identifier of the second 3GPP access. For example, the second bearer parameter may be the identifier of the second 3GPP access or determined based on the identifier of the second 3GPP access and a third access type identifier.

[0316] For example, AMF according to K AMF Derivation of NAS confidentiality key K NASenc NAS Integrity Protection Key K NASint According to NAS confidentiality key K NASenc The first NAS signaling is confidentialized using the first bearer parameters and the NAS integrity protection key K. NASint Integrity protection is provided for the first NAS signaling using the first bearer parameters and the NAS confidentiality key K. NASenc The second bearer parameters provide confidentiality protection for the second NAS signaling, based on the NAS integrity protection key K. NASint The second bearer parameters provide integrity protection for the second NAS signaling.

[0317] Therefore, by using different bearer parameters, the problem of key stream reuse caused by two 3GPPs using the same NAS key can be avoided.

[0318] Example 4:

[0319] S801: The UE sends a first registration request message to the AMF via RAN1. Correspondingly, the AMF receives the first registration request message.

[0320] For details of S801, please refer to S501 above.

[0321] Optionally, the first registration request message includes instruction information. This instruction information may refer to the relevant content in S505 above.

[0322] S802: AMF generates the first key based on the first value of the uplink NAS counter.

[0323] For example, the AMF assigns a third access type identifier to the first NAS connection corresponding to the first 3GPP access and creates a pair of NAS counters, setting them to their initial values. The pair of NAS counters includes an uplink NAS counter and a downlink NAS counter. The AMF stores the parameters of the first NAS connection in the UE's security context. The parameters of the first NAS connection include the third access type identifier and the pair of NAS counters. The third access type identifier is the access type identifier used to identify 3GPP access as shown in Table 1. Referring to Table 1, the access type identifier here can be 0x01.

[0324] In one possible implementation, the AMF is based on an AMF key (e.g., K). AMF The first key is generated by combining the first value of the uplink NAS counter with the first value of the uplink NAS counter. The first key can be denoted as K. gNB 1. Understandably, generating the first key requires combining other parameters, such as K. gNB 1 = KDF(FC, P0, L0, P1, L1), where P0 = the first value of the uplink NAS counter, L0 = the length of the first value of the uplink NAS counter, P1 = the third access type identifier, and L1 = the length of the third access type identifier. For details, please refer to the above related content; further explanation is not provided here.

[0325] In addition, the AMF can also send the first registration acceptance message to the UE via RAN1.

[0326] S803: AMF sends the first key to RAN1. Correspondingly, RAN1 receives the first key from AMF.

[0327] For example, RAN1 can determine the first key received (e.g., K) gNB 1) Generate the first RRC key and the first user plane key. For example, the first RRC key includes K. RRCenc 1 and K RRCint 1. The first user plane key includes K UPenc 1 and K UPint 1.

[0328] In addition, RAN1 can also send an AS security mode command to the UE, which is used to inform the UE of the RRC signaling protection key algorithm and / or user plane protection cryptographic algorithm selected by the network side. Furthermore, after the UE generates the first key by executing S804, the UE can also send an AS security mode response to RAN1.

[0329] S804: The UE generates the first key based on the first value of the uplink NAS counter.

[0330] For example, the UE also creates a pair of NAS counters for the first NAS connection corresponding to the first 3GPP access and sets them to initial values. The UE saves the parameters of the first NAS connection, which include a third access type identifier and a pair of NAS counters. The pair of NAS counters includes an uplink NAS counter and a downlink NAS counter.

[0331] Furthermore, in one possible implementation, the UE generates a first key, namely K, based on the AMF key and the first value of the uplink NAS counter. gNB 1. Furthermore, a first RRC key and a first user plane key can be generated based on the first key. The method for generating the first key is the same for both the AMF and the UE, and will not be repeated here.

[0332] It is understood that this application does not limit the order of S802, S803 and S804.

[0333] Therefore, when RAN1 communicates with UE, RAN1 and UE can use the first RRC key to protect the second RRC signaling and use the first user plane key to protect the second data.

[0334] S805: The UE sends a second registration request message to the AMF. Correspondingly, the AMF receives the second registration request message.

[0335] The second registration request message is used to request the UE to register with the network through the second 3GPP access.

[0336] Optionally, the second registration request message includes instruction information. Further details regarding the second registration request message can be found in S505.

[0337] S806: AMF generates a second key based on the second value of the uplink NAS counter.

[0338] For example, the AMF does not create a new pair of NAS counters for the second NAS connection corresponding to the second 3GPP access, but instead uses the existing NAS counters. The AMF uses the AMF key (e.g., K) to... AMF The second key is generated by combining the second value of the uplink NAS counter with the second value of the uplink NAS counter. This second key can be denoted as K. gNB 2. Understandably, generating the second key requires combining other parameters, such as K. gNB 2 = KDF(FC, P0, L0, P1, L1), where P0 = the second value of the uplink NAS counter, L0 = the length of the second value of the uplink NAS counter, P1 = the third access type identifier, and L1 = the length of the third access type identifier.

[0339] In addition, the AMF can also send a second registration acceptance message to the UE via RAN2.

[0340] S807: AMF sends the second key to RAN2. Correspondingly, RAN2 receives the second key from AMF.

[0341] For example, RAN2 can use the received second key (e.g., K) gNB 2) Generate a second RRC key and a second user plane key. For example, the second RRC key includes K. RRCenc 2 and K RRCint 2. The second user plane key includes K UPenc 2 and K UPint 2.

[0342] In addition, RAN2 can also send an AS security mode command to the UE, which is used to inform the UE of the RRC signaling protection cryptographic algorithm and / or user plane protection cryptographic algorithm selected by the network side. Furthermore, after the UE performs S808 to generate the second key, the UE can also send an AS security mode response to RAN2.

[0343] S808: The UE generates a second key based on the second value of the uplink NAS counter.

[0344] For example, the UE does not create a new pair of NAS counters for the second NAS connection corresponding to the second 3GPP access, but instead uses the existing NAS counters. The UE uses the AMF key (e.g., K...) AMF The second key, K, is generated by the second value of the uplink NAS counter. gNB 2. Furthermore, a second RRC key and a second user plane key can be generated based on the second key. The methods for generating the second key are the same for both the AMF and the UE.

[0345] It is understood that this application does not limit the order of S806, S807 and S808.

[0346] Therefore, when RAN2 communicates with UE, RAN2 and UE can use the second RRC key to protect the second RRC signaling and the second user plane key to protect the second data.

[0347] By using the above method, and by using different values ​​of the same uplink NAS counter in two 3GPP access processes, it is possible to ensure that the first key and the second key are different, thereby achieving key isolation.

[0348] Furthermore, after generating the second key, the AMF and UE can also create a new pair of NAS counters for the second NAS connection corresponding to the second 3GPP access and set them to their initial values. Using two sets of NAS counters allows the AMF to better distinguish between packets from RAN1 and RAN2, and to better confirm the order of packets from RAN1 and from RAN2.

[0349] It is understood that, in order to implement the functions in the above embodiments, the terminal device or access and mobility management network element includes the corresponding hardware structure and / or software module for performing each function. Those skilled in the art should readily recognize that, based on the units and method steps of the various examples described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.

[0350] Figure 9 and Figure 10 The diagram illustrates the possible communication devices provided in the embodiments of this application. These communication devices can be used to implement the functions of terminal devices or access and mobility management network elements in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments.

[0351] like Figure 9 As shown, the communication device 900 includes a processing unit 910 and a transceiver unit 920. The communication device 900 is used to implement the above-mentioned... Figure 5 , 6 The methods shown in 7 and 8 illustrate the functions of terminal devices or access and mobility management network elements.

[0352] When the communication device 900 is used to achieve Figure 5 , 6 When performing the functions of access and mobility management network elements in the method embodiments shown in 7 and 8:

[0353] The transceiver unit 920 is configured to receive a first registration request message from a terminal device, the first registration request message being used for the terminal device to request registration with the network through a first 3GPP access scheme; the processing unit 910 is configured to generate a first key, the first key being a key used for communication between the terminal device and a first access network device; the first access network device is used for the first 3GPP access; the transceiver unit 920 is configured to send the first key to the first access network device; receive a second registration request message from the terminal device, the second registration request message being used for the terminal device to request registration with the network through a second 3GPP access scheme; the processing unit 910 is configured to generate a second key, the second key being a key used for communication between the terminal device and a second access network device, the second access network device being used for the second 3GPP access scheme; the first key and the second key are different; the transceiver unit 920 is configured to send the second key to the second access network device.

[0354] In one possible design, the first registration request message and / or the second registration request message include indication information for instructing the terminal device to connect to the network via two 3GPP access points.

[0355] In one possible design, the processing unit 910 is configured to generate the first key based on the first access type identifier corresponding to the first 3GPP access when generating the first key; and to generate the second key based on the second access type identifier corresponding to the second 3GPP access when generating the second key, wherein the first access type identifier and the second access type identifier are different.

[0356] In one possible design, the second registration request message includes the indication information; the processing unit 910 is configured to determine the second access type identifier for the second 3GPP access based on the indication information before generating the second key.

[0357] In one possible design, the first registration request message includes the indication information; the processing unit 910 is configured to determine a first access type identifier for the first 3GPP access based on the indication information before generating a first key, wherein the first access type identifier is one of the dual 3GPP access type identifiers; and to determine a second access type identifier for the second 3GPP access before generating a second key, wherein the second access type identifier is the other of the dual 3GPP access type identifiers.

[0358] In one possible design, the second access type identifier is one of the unused 3GPP access type identifiers.

[0359] In one possible design, the transceiver unit 920 is configured to send a first registration acceptance message to the terminal device, the first registration acceptance message including the first access type identifier; and / or send a second registration acceptance message to the terminal device, the first registration acceptance message including the second access type identifier.

[0360] In one possible design, the first bearer parameter includes the first access type identifier, and the second bearer parameter includes the second access type identifier; the processing unit 910 is used to perform security protection on the first NAS signaling using the NAS security protection key and the first bearer parameter, the first NAS signaling corresponding to the first 3GPP access; and to perform security protection on the second NAS signaling using the NAS security protection key and the second bearer parameter, the second NAS signaling corresponding to the second 3GPP access.

[0361] In one possible design, the processing unit 910 is configured to generate the first key based on a third access type identifier and a first 3GPP access identifier when generating the first key, wherein the third access type identifier indicates that the access type is 3GPP access; and to generate the second key based on the third access type identifier and a second 3GPP access identifier when generating the second key, wherein the first 3GPP access identifier is different from the second 3GPP access identifier.

[0362] In one possible design, the first registration request message includes the indication information; the processing unit 910 is configured to determine the identifier of the first 3GPP access for the first 3GPP access based on the indication information before generating the first key; and to determine the identifier of the second 3GPP access for the second 3GPP access before generating the second key.

[0363] In one possible design, the transceiver unit 920 is configured to, when determining the identifier of the first 3GPP access for the first 3GPP access according to the indication information, obtain two 3GPP access identifiers from the data management network element according to the indication information; use one of the two 3GPP access identifiers as the identifier of the first 3GPP access; and when determining the identifier of the second 3GPP access for the second 3GPP access, use the other of the two 3GPP access identifiers as the identifier of the second 3GPP access.

[0364] In one possible design, the transceiver unit 920 is configured to send a first registration acceptance message to the terminal device, the first registration acceptance message including the identifier of the first 3GPP access; and to send a second registration acceptance message to the terminal device, the second registration acceptance message including the identifier of the second 3GPP access.

[0365] In one possible design, the first registration request message includes the identifier of the first 3GPP access, and the second registration request message includes the identifier of the second 3GPP access.

[0366] In one possible design, the first bearer parameter corresponds to the identifier of the first 3GPP access, and the second bearer parameter corresponds to the identifier of the second 3GPP access; the processing unit 910 is used to perform security protection on the first NAS signaling using the NAS security protection key and the first bearer parameter, the first NAS signaling corresponding to the first 3GPP access; and to perform security protection on the second NAS signaling using the NAS security protection key and the second bearer parameter, the second NAS signaling corresponding to the second 3GPP access.

[0367] In one possible design, the processing unit 910 is configured to generate the first key based on a first value of the uplink NAS counter when generating the first key; and to generate the second key based on a second value of the uplink NAS counter when generating the second key; wherein the first 3GPP access and the second 3GPP access share the uplink NAS counter, and the first value is different from the second value.

[0368] When the communication device 900 is used to achieve Figure 5 , 6 The terminal device functions as shown in the method embodiments 7 and 8:

[0369] The transceiver unit 920 is configured to send a first registration request message to the access and mobility management network element, the first registration request message being used for the terminal device to request registration with the network through a first 3GPP access; the processing unit 910 is configured to generate a first key, the first key being a key used for communication between the terminal device and the first access network device; the first access network device is used for the first 3GPP access; the transceiver unit 920 is configured to send a second registration request message to the access and mobility management network element, the second registration request message being used for the terminal device to request registration with the network through a second 3GPP access; the processing unit 910 is configured to generate a second key, the second key being a key used for communication between the terminal device and the second access network device, the second access network device being used for the second 3GPP access; the first key and the second key are different.

[0370] In one possible design, the first registration request message and / or the second registration request message include indication information, which is used to instruct the terminal device to connect to the network through two 3GPP access points;

[0371] In one possible design, the processing unit 910 is configured to generate the first key based on the first access type identifier corresponding to the first 3GPP access when generating the first key; and to generate the second key based on the second access type identifier corresponding to the second 3GPP access when generating the second key, wherein the first access type identifier and the second access type identifier are different.

[0372] In one possible design, the processing unit 910 is configured to determine a first access type identifier for the first 3GPP access before generating a first key, wherein the first access type identifier is one of the dual 3GPP access type identifiers; and to determine a second access type identifier for the second 3GPP access before generating a second key, wherein the second access type identifier is the other of the dual 3GPP access type identifiers.

[0373] In one possible design, the second access type identifier is one of the unused 3GPP access type identifiers.

[0374] In one possible design, the transceiver unit 920 is configured to receive a first registration acceptance message from the access and mobility management network element, the first registration acceptance message including the first access type identifier; and / or, to receive a second registration acceptance message from the access and mobility management network element, the first registration acceptance message including the second access type identifier.

[0375] In one possible design, the transceiver unit 920 is configured to receive a first AS security mode command from the first access network device, the first AS security mode command including the first access type identifier; and / or, receive a second AS security mode command from the second access network device, the second AS security mode command including the second access type identifier.

[0376] In one possible design, the first bearer parameter includes the first access type identifier, and the second bearer parameter includes the second access type identifier; the processing unit 910 is used to perform security protection on the first NAS signaling using the NAS security protection key and the first bearer parameter, the first NAS signaling corresponding to the first 3GPP access; and to perform security protection on the second NAS signaling using the NAS security protection key and the second bearer parameter, the second NAS signaling corresponding to the second 3GPP access.

[0377] In one possible design, the processing unit 910 is configured to generate the first key based on a third access type identifier and a first 3GPP access identifier when generating the first key, wherein the third access type identifier indicates that the access type is 3GPP access; and to generate the second key based on the third access type identifier and a second 3GPP access identifier when generating the second key, wherein the first 3GPP access identifier is different from the second 3GPP access identifier.

[0378] In one possible design, the processing unit 910 is configured to determine the identifier of the first 3GPP access for the first 3GPP access before generating the first key; and to determine the identifier of the second 3GPP access for the second 3GPP access before generating the second key.

[0379] In one possible design, the transceiver unit 920 is configured to receive a first registration acceptance message from the access and mobility management network element, the first registration acceptance message including the identifier of the first 3GPP access; and to receive and transmit a second registration acceptance message from the access and mobility management network element, the second registration acceptance message including the identifier of the second 3GPP access.

[0380] In one possible design, the transceiver unit 920 is configured to receive a first AS security mode command from the first access network device, the first AS security mode command including the identifier of the first 3GPP access; and / or, to receive a second AS security mode command from the second access network device, the second AS security mode command including the identifier of the second 3GPP access.

[0381] In one possible design, the first registration request message includes the identifier of the first 3GPP access, and the second registration request message includes the identifier of the second 3GPP access.

[0382] In one possible design, the first bearer parameter corresponds to the identifier of the first 3GPP access, and the second bearer parameter corresponds to the identifier of the second 3GPP access; the processing unit 910 is used to perform security protection on the first NAS signaling using the NAS security protection key and the first bearer parameter, the first NAS signaling corresponding to the first 3GPP access; and to perform security protection on the second NAS signaling using the NAS security protection key and the second bearer parameter, the second NAS signaling corresponding to the second 3GPP access.

[0383] In one possible design, the processing unit 910 is configured to generate the first key based on a first value of the uplink NAS counter when generating the first key; and to generate the second key based on a second value of the uplink NAS counter when generating the second key; wherein the first 3GPP access and the second 3GPP access share the uplink NAS counter, and the first value is different from the second value.

[0384] For a more detailed description of the processing unit 910 and the transceiver unit 920, please refer to [link / reference needed]. Figure 5 , 6 The relevant descriptions in the method embodiments shown in 7 and 8 are directly obtained and will not be repeated here.

[0385] like Figure 10 As shown, the communication device 1000 includes a processor 1010 and an interface circuit 1020. The processor 1010 and the interface circuit 1020 are coupled to each other. It is understood that the interface circuit 1020 can be a transceiver or an input / output interface. Optionally, the communication device 1000 may also include a memory 1030 for storing instructions executed by the processor 1010, or storing input data required by the processor 1010 to execute instructions, or storing data generated after the processor 1010 executes instructions.

[0386] When the communication device 1000 is used to implement Figure 5 , 6 When using the methods shown in 7 and 8, the processor 1010 is used to implement the functions of the processing unit 910, and the interface circuit 1020 is used to implement the functions of the transceiver unit 920.

[0387] It is understood that the processor in the embodiments of this application may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0388] This application provides another example of a device, the notification device including at least one processor and at least one memory, the at least one processor and the at least one memory coupled together, the at least one memory for storing instructions, which, when executed by the at least one processor, cause the communication device to perform the method described above. Taking a communication device including a processor and a memory as an example, such as... Figure 10 As shown, the communication device 1000 includes a processor 1010 and a memory 1030. The processor 1010 and the memory 1030 are coupled. The memory 1030 stores instructions. When the instructions stored in the memory 1030 are executed by the processor 1010, the communication device 1000 executes the method executed by the terminal device or access and mobility management network element in the above embodiment.

[0389] The method steps in the embodiments of this application can be implemented in hardware or in software instructions executable by a processor. The software instructions can consist of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. The storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in a terminal device or an access and mobility management network element. The processor and storage medium can also exist as discrete components in the terminal device or access and mobility management network element.

[0390] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are performed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video optical disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both types of storage media.

[0391] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0392] In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. In the textual description of this application, the character " / " generally indicates an "or" relationship between the preceding and following related objects; in the formulas of this application, the character " / " indicates a "division" relationship between the preceding and following related objects. "Including at least one of A, B, and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B, and C.

[0393] It is understood that the various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. The order of the process numbers described above does not imply the order of execution; the execution order of each process should be determined by its function and internal logic.< / guami>

Claims

1. A key deduction method, characterized in that, This method is applied to an access and mobility management network element or a chip within an access and mobility management network element, and the method includes: Receive a first registration request message from a terminal device, the first registration request message being used to request the terminal device to register with the network through the first 3GPP access program; A first key is generated, which is the key used for communication between the terminal device and the first access network device; the first access network device is used for the first 3GPP access. Send the first key to the first access network device; Receive a second registration request message from the terminal device, the second registration request message being used to request the terminal device to register with the network through a second 3GPP access; A second key is generated, which is the key used for communication between the terminal device and the second access network device, which is used for the second 3GPP access; the first key is different from the second key. Send the second key to the second access network device.

2. The method as described in claim 1, characterized in that, The first registration request message and / or the second registration request message include indication information, which is used to instruct the terminal device to connect to the network through two 3GPP access points.

3. The method as described in claim 2, characterized in that, Generate the first key, including: The first key is generated based on the first access type identifier corresponding to the first 3GPP access; Generate a second key, including: The second key is generated based on the second access type identifier corresponding to the second 3GPP access, wherein the first access type identifier and the second access type identifier are different.

4. The method as described in claim 3, characterized in that, The second registration request message includes the indication information; Before generating the second key, the following steps are also included: The second access type identifier is determined for the second 3GPP access based on the indicated information.

5. The method as described in claim 3, characterized in that, The first registration request message includes the indication information; Before generating the first key, the following is also included: Based on the indication information, the first access type identifier is determined for the first 3GPP access, and the first access type identifier is one of the dual 3GPP access type identifiers; Before generating the second key, the following steps are also included: The second access type identifier is determined for the second 3GPP access, and the second access type identifier is the other one of the dual 3GPP access type identifiers.

6. The method as described in claim 5, characterized in that, The second access type identifier is one of the unused 3GPP access type identifiers.

7. The method according to any one of claims 3-6, characterized in that, Also includes: Send a first registration acceptance message to the terminal device, wherein the first registration acceptance message includes the first access type identifier; And / or, send a second registration acceptance message to the terminal device, the second registration acceptance message including the second access type identifier.

8. The method according to any one of claims 3-6, characterized in that, The first bearer parameter includes the first access type identifier, and the second bearer parameter includes the second access type identifier; The method further includes: The first NAS signaling is protected by using the non-access stratum NAS security protection key and the first bearer parameter, and the first NAS signaling corresponds to the first 3GPP access. The second NAS signaling is protected by the NAS security protection key and the second bearer parameter, and the second NAS signaling corresponds to the second 3GPP access.

9. The method as described in claim 2, characterized in that, Generate the first key, including: The first key is generated based on the third access type identifier and the identifier of the first 3GPP access, wherein the third access type identifier indicates that the access type is 3GPP access; Generate a second key, including: The second key is generated based on the third access type identifier and the second 3GPP access identifier; the first 3GPP access identifier is different from the second 3GPP access identifier.

10. The method as described in claim 9, characterized in that, The first registration request message includes the indication information; Before generating the first key, the following is also included: The identifier of the first 3GPP access is determined based on the indicated information; Before generating the second key, the following steps are also included: The identifier of the second 3GPP access is determined for the second 3GPP access.

11. The method as described in claim 10, characterized in that, Determining the identifier of the first 3GPP access based on the indicated information includes: According to the instruction information, two 3GPP access identifiers are obtained from the data management network element; Use one of the two 3GPP access identifiers as the identifier of the first 3GPP access; Determining the identifier of the second 3GPP access for the second 3GPP access includes: Use the other of the two 3GPP access identifiers as the identifier for the second 3GPP access.

12. The method according to any one of claims 9-11, characterized in that, Also includes: Send a first registration acceptance message to the terminal device, wherein the first registration acceptance message includes the identifier of the first 3GPP access; A second registration acceptance message is sent to the terminal device, the second registration acceptance message including the identifier of the second 3GPP access.

13. The method as described in claim 9, characterized in that, The first registration request message includes the identifier of the first 3GPP access, and the second registration request message includes the identifier of the second 3GPP access.

14. The method according to any one of claims 9-11, 13, characterized in that, The first bearer parameter corresponds to the identifier of the first 3GPP access, and the second bearer parameter corresponds to the identifier of the second 3GPP access. The method further includes: The first NAS signaling is protected by using the NAS security protection key and the first bearer parameter, and the first NAS signaling corresponds to the first 3GPP access. The second NAS signaling is protected by the NAS security protection key and the second bearer parameter, and the second NAS signaling corresponds to the second 3GPP access.

15. The method as described in claim 1 or 2, characterized in that, Generate the first key, including: The first key is generated based on the first value of the uplink NAS counter; Generate a second key, including: The second key is generated based on the second value of the uplink NAS counter; wherein the first 3GPP access and the second 3GPP access share the uplink NAS counter, and the first value is different from the second value.

16. A key deduction method, characterized in that, This method is applied to a terminal device or a chip in a terminal device, and the method includes: Send a first registration request message to the access and mobility management network element, the first registration request message being used to request the terminal device to register with the network through the first 3GPP access; A first key is generated, which is the key used for communication between the terminal device and the first access network device; the first access network device is used for the first 3GPP access. A second registration request message is sent to the access and mobility management network element, the second registration request message being used to request the terminal device to register with the network through a second 3GPP access; A second key is generated, which is the key used for communication between the terminal device and the second access network device, which is used for the second 3GPP access; the first key is different from the second key.

17. The method as described in claim 16, characterized in that, The first registration request message and / or the second registration request message include indication information, which is used to instruct the terminal device to connect to the network through two 3GPP access points.

18. The method as described in claim 17, characterized in that, Generate the first key, including: The first key is generated based on the first access type identifier corresponding to the first 3GPP access; Generate a second key, including: The second key is generated based on the second access type identifier corresponding to the second 3GPP access, wherein the first access type identifier and the second access type identifier are different.

19. The method as described in claim 18, characterized in that, Before generating the first key, the following is also included: The first access type identifier is determined for the first 3GPP access, and the first access type identifier is one of the dual 3GPP access type identifiers; Before generating the second key, the following steps are also included: The second access type identifier is determined for the second 3GPP access, and the second access type identifier is the other one of the dual 3GPP access type identifiers.

20. The method as described in claim 19, characterized in that, The second access type identifier is one of the unused 3GPP access type identifiers.

21. The method according to any one of claims 18-20, characterized in that, Also includes: The first registration acceptance message is received from the access and mobility management network element, the first registration acceptance message including the first access type identifier; And / or, receive a second registration acceptance message from the access and mobility management network element, wherein the first registration acceptance message includes the second access type identifier; Alternatively, a first access layer AS security mode command may be received from the first access network device, the first AS security mode command including the first access type identifier; and / or, a second AS security mode command may be received from the second access network device, the second AS security mode command including the second access type identifier.

22. The method according to any one of claims 18-20, characterized in that, The first bearer parameter includes the first access type identifier, and the second bearer parameter includes the second access type identifier; The method further includes: The first NAS signaling is protected by using the NAS security protection key and the first bearer parameter, and the first NAS signaling corresponds to the first 3GPP access. The second NAS signaling is protected by the NAS security protection key and the second bearer parameter, and the second NAS signaling corresponds to the second 3GPP access.

23. The method as described in claim 17, characterized in that, Generate the first key, including: The first key is generated based on the third access type identifier and the identifier of the first 3GPP access, wherein the third access type identifier indicates that the access type is 3GPP access; Generate a second key, including: The second key is generated based on the third access type identifier and the second 3GPP access identifier; the first 3GPP access identifier is different from the second 3GPP access identifier.

24. The method as described in claim 23, characterized in that, Before generating the first key, the following is also included: The identifier of the first 3GPP access is determined for the first 3GPP access; Before generating the second key, the following steps are also included: The identifier of the second 3GPP access is determined for the second 3GPP access.

25. The method as described in claim 23 or 24, characterized in that, Also includes: The first registration acceptance message is received from the access and mobility management network element, the first registration acceptance message including the identifier of the first 3GPP access; And / or, receive a second registration acceptance message from the access and mobility management network element, the second registration acceptance message including the identifier of the second 3GPP access; Alternatively, a first AS security mode command may be received from the first access network device, wherein the first AS security mode command includes the identifier of the first 3GPP access. And / or, receive a second AS security mode command from the second access network device, the second AS security mode command including the identifier of the second 3GPP access.

26. The method as described in claim 23 or 24, characterized in that, The first registration request message includes the identifier of the first 3GPP access, and the second registration request message includes the identifier of the second 3GPP access.

27. The method as described in claim 23 or 24, characterized in that, The first bearer parameter corresponds to the identifier of the first 3GPP access, and the second bearer parameter corresponds to the identifier of the second 3GPP access. The method further includes: The first NAS signaling is protected by using the NAS security protection key and the first bearer parameter, and the first NAS signaling corresponds to the first 3GPP access. The second NAS signaling is protected by the NAS security protection key and the second bearer parameter, and the second NAS signaling corresponds to the second 3GPP access.

28. The method as described in claim 16 or 17, characterized in that, Generate the first key, including: The first key is generated based on the first value of the uplink NAS counter; Generate a second key, including: The second key is generated based on the second value of the uplink NAS counter; wherein the first 3GPP access and the second 3GPP access share the uplink NAS counter, and the first value is different from the second value.

29. A communication device, characterized in that, It includes units or modules for performing the method as described in any one of claims 1-15, or includes units or modules for performing the method as described in any one of claims 16-28.

30. A communication device, characterized in that, include: One or more processors and one or more memories; wherein the one or more memories store one or more programs that, when executed by the one or more processors, cause the apparatus to perform the method as claimed in any one of claims 1-15, or to perform the method as claimed in any one of claims 16-28.

31. A chip system, characterized in that, The chip system includes at least one chip and a memory, wherein the at least one chip is used to read and execute a program stored in the memory to implement the method as described in any one of claims 1-15, or to implement the method as described in any one of claims 16-28.

32. A readable storage medium, characterized in that, The readable storage medium includes a program that, when run on the device, causes the device to perform the method as claimed in any one of claims 1-15, or to perform the method as claimed in any one of claims 16-28.