A communication method and apparatus
By generating a second mobility management network element key and retaining the first security context, the security and performance issues in dual 3GPP access scenarios are resolved, achieving both security protection and performance improvement.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2023-09-26
- Publication Date
- 2026-05-26
AI Technical Summary
In dual 3GPP access scenarios, how can we ensure the security of terminal devices in multi-registration scenarios and avoid unnecessary authentication processes to improve network performance?
The first mobility management network element generates a second mobility management network element key, which is used to deduce the security protection key, ensure the security protection of messages for non-access stratum connections, and retain the first security context when necessary to avoid the terminal device from repeating the master authentication.
It improves security in dual 3GPP scenarios, reduces unnecessary authentication processes, and enhances network performance.
Smart Images

Figure CN119729469B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication, and more particularly to a communication method and apparatus. Background Technology
[0002] In the 3rd Generation Partnership Project (3GPP), terminal devices can access two different public land mobile networks (PLMNs) based on one 3GPP access type and one non-3GPP access type, maintaining two different security contexts for the serving networks of the two PLMNs. Specifically, the security context corresponding to the 3GPP access type is established after the terminal device performs primary authentication with the home public land mobile network (HPLMN) based on the 3GPP access type's identity credential 1, while the security context corresponding to the non-3GPP access type is established after the terminal device performs primary authentication with the HPLMN based on the non-3GPP access type's identity credential 2. That is, in multi-registration scenarios involving both 3GPP and non-3GPP access types, the terminal device needs to perform two primary authentications with the HPLMN based on two different identity credentials.
[0003] Currently, 3GPP is further introducing dual 3GPP access scenarios, meaning that terminal devices can access two PLMNs respectively based on their 3GPP access type. Ensuring the security of dual 3GPP access scenarios is a pressing technical issue that needs to be addressed. Summary of the Invention
[0004] This application provides a communication method and apparatus for avoiding unnecessary authentication processes in dual 3GPP access type scenarios.
[0005] Firstly, this application provides a communication method that can be executed by a first mobility management network element. The first mobility management network element can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualization function instantiated on a platform (e.g., a cloud platform). Optionally, the first mobility management network element can be implemented by a single device, multiple devices working together, or it can be a functional module within a single device.
[0006] Communication methods include:
[0007] A first mobility management network element (MMU) receives a first message from a second mobility management network element (MMLE). The first message includes a registration request from a terminal device, which includes indication information indicating dual 3GPP access. A first non-access stratum (NASS) connection based on a 3GPP access type exists between the terminal device and the first MMU. The first MMU generates a second MMU key based on its own first MMU key. The first MMU sends a second message to the second MMU, which includes the second MMU key. The first MMU key is used to derive a first security protection key, which provides security protection for messages transmitted on the first NASS connection. The second MMU key is used to derive a second security protection key, which provides security protection for messages transmitted on a second NASS connection. The second NASS connection is a 3GPP access type-based connection between the terminal device and the second MMU. The second message may be a response to the first message.
[0008] In the above technical solution, when the first mobility management network element determines that the registration request indicates dual 3GPP access, that is, when it determines that the terminal device requests to establish a second non-access stratum connection with the second mobility management network element based on the 3GPP access type, the first mobility management network element generates a second mobility management network element key based on the first mobility management network element key, and sends the second mobility management network element key to the second mobility management network element to achieve security protection of messages transmitted on the second non-access stratum connection, thereby improving security in the dual 3GPP scenario. In other words, after receiving the second mobility management network element key, the second mobility management network element generates a second security protection key based on the second mobility management network element key, and performs security protection on messages transmitted on the second non-access stratum connection based on the second security protection key to improve security.
[0009] Furthermore, if the registration request indicates dual 3GPP access, then after receiving the registration request from the terminal device, the second mobility management element (MLE) can send the registration request to the first MLE to obtain the second MLE key, without instructing the terminal device to perform a second primary authentication with the HPLMMN based on the 3GPP access type identity credentials. Thus, the terminal device only needs to perform primary authentication with the HPLMMN based on the 3GPP access type identity credentials during its first access to the PLMN. During the second access to the second PLMN based on the 3GPP access type, it does not need to perform primary authentication with the HPLMMN based on the 3GPP access type identity credentials again. Additionally, generating the second MLE key after primary authentication helps avoid unnecessary procedures and improves network performance.
[0010] In one possible implementation, the first message also includes a message authentication code. Before the first mobility management network element sends the second message to the second mobility management network element, that is, after receiving the first message, the first mobility management network element can also successfully verify the registration request in the first message based on the first security protection key and the message authentication code in the first message.
[0011] In the above technical solution, the first mobility management network element verifies the registration request in the first message based on the first security protection key. After successful verification, the first mobility management network element considers the terminal device to be a legitimate terminal device. Thus, the terminal device does not need to perform a second primary authentication with the HPLMN based on its 3GPP access type identity credentials, which helps avoid unnecessary procedures and improves network performance.
[0012] In one possible implementation, after the first mobility management element generates a second mobility management element key based on the first mobility management element key, it still retains (i.e. does not delete) the first security context of the first non-access stratum connection, wherein the first security context includes the first mobility management element key and the first security protection key.
[0013] In the above technical solution, the first mobility management network element determines that the network supports the simultaneous existence of a first non-access stratum connection and a second non-access stratum connection based on the indication information. Therefore, after generating the second mobility management network element key, the first security context is still retained. In this way, the first mobility management network element can continue to provide security protection for messages transmitted on the first non-access stratum connection based on the first security context.
[0014] In one possible implementation, the first mobility management network element further generates a second key set identifier based on the first key set identifier. The first key set identifier identifies a first security context for the first non-access stratum connection, and the second key set identifier identifies a second security context for the second non-access stratum connection. The second security context includes a second mobility management network element key and a second security protection key. Subsequently, the first mobility management network element may also send the second key set identifier to the second mobility management network element via a second message.
[0015] In the above technical solution, the first mobility management network element generates a second key set identifier based on the first key set identifier and sends the second key set identifier to the second mobility management network element. Thus, the second mobility management network element can provide security protection for messages transmitted on the second non-access stratum connection based on the second security context associated with the second key set identifier, thereby improving security in dual 3GPP scenarios. Furthermore, when the terminal device does not need to index the first security context based on the first key set identifier from the second mobility management network element (e.g., the terminal device maintains only one security context (i.e., the first security context)), the first mobility management network element does not need to send the first key set identifier to the second mobility management network element, which helps reduce the length of transmitted messages.
[0016] In one possible implementation, the second message also includes a first key set identifier. That is, the first mobility management network element can also send the first key set identifier to the second mobility management network element via the second message. The first key set identifier can be used by the second mobility management network element to generate a second key set identifier based on the first key set identifier, and then associate the second key set identifier with the second security context.
[0017] In the above technical solution, the second mobility management network element generates a second key set identifier, which can prevent the first mobility management network element from obtaining other security information about the second non-access stratum connection besides the second mobility management network element key, thereby preventing the first mobility management network element from obtaining the second security context of the second non-access stratum connection, which helps to achieve security isolation.
[0018] In one possible implementation, the type field included in the second key set identifier has the same value as the type field included in the first key set identifier. However, the value field included in the second key set identifier has a different value than the value field included in the first key set identifier.
[0019] In one possible implementation, the first message is a context transfer request (e.g., Namf_Communication_UEContextTransfer message), and the second message is a context transfer response (e.g., Namf_Communication_UEContextTransfer response message); or, the first message is an N1 message notification (e.g., Namf_Communication_N1MessageNotify message), and the second message is a context creation response (e.g., Namf_Communication_CreateUEContext message); or, the first message is a dual 3GPP access security context transfer request (e.g., Namf_Dual3GPPaccessSecurityContextTransfer message), and the second message is a dual 3GPP access security context transfer response (e.g., Namf_Dual3GPPaccessSecurityContextTransfer response message).
[0020] In one possible implementation, when the first mobility management network element generates the second mobility management network element key based on the first mobility management network element key, specifically, the first mobility management network element generates the second mobility management network element key based on the first mobility management network element key and first information; wherein, the first information includes one or more of the following: an identifier of the key generation function; a count value of messages transmitted on the first non-access stratum connection; the direction of messages transmitted on the first non-access stratum connection; an identifier of the 3GPP access type; an identifier of the public land mobile network to which the first mobility management network element belongs; and an identifier of the public land mobile network to which the second mobility management network element belongs. In one example, the direction of messages transmitted on the first non-access stratum connection is downlink, and the count value of messages transmitted on the first non-access stratum connection is equal to the number of times the first mobility management network element sends downlink messages to the terminal device on the first non-access stratum connection based on the first security protection key. In another example, the direction of message transmission on the first non-access stratum connection is uplink, and the count value of message transmission on the first non-access stratum connection is equal to the number of times the first mobility management network element receives uplink messages from the terminal device on the first non-access stratum connection according to the first security protection key.
[0021] In the above technical solution, specific input parameters are provided when the first mobility management network element generates the second mobility management network element key based on the first mobility management network element key. These specific input parameters are the same input parameters maintained by the first mobility management network element and the terminal device, so that the first mobility management network element and the terminal device can generate the same second mobility management network element key based on these input parameters.
[0022] Secondly, this application provides a communication method that can be executed by a terminal device or a module (such as a chip) in the terminal device. For ease of description, the following description will use the terminal device as an example.
[0023] The communication method includes: a terminal device sending a registration request to a second mobility management network element (MMI). The registration request includes indication information indicating dual 3GPP access, and a first non-access stratum connection based on a 3GPP access type exists between the terminal device and the first MMI. The terminal device generates a second MMI key based on the first MMI key. The first MMI key is used to derive a first security protection key, which is used to securely protect messages transmitted on the first non-access stratum connection. The second MMI key is used to derive a second security protection key, which is used to securely protect messages transmitted on the second non-access stratum connection. The second non-access stratum connection is a 3GPP access type-based connection between the terminal device and the second MMI. Optionally, the terminal device also receives a registration response from the second MMI. The registration response is the response to the registration request, such as a registration accept message.
[0024] In the above technical solution, when the terminal device establishes a second non-access stratum connection with the second mobility management network element based on a 3GPP access type request, it sends a registration request to the second mobility management network element. This registration request indicates dual 3GPP access. Correspondingly, the second mobility management network element requests a second mobility management network element key from the first mobility management network element. The terminal device also generates a second mobility management network element key based on the first mobility management network element key. This achieves secure protection for messages transmitted on the second non-access stratum connection, thereby improving security in dual 3GPP scenarios. In other words, the terminal device generates a second security protection key based on the second mobility management network element key, and uses the second security protection key to securely protect messages transmitted on the second non-access stratum connection, thus improving security.
[0025] Furthermore, if the registration request indicates dual 3GPP access, the second mobility management element (MLE) can send the registration request to the first MLE to obtain a second MLE key from the first MLE. The terminal device then generates a second MLE key based on the first MLE key. In this way, the terminal device only needs to perform primary authentication with the HPLMN using its 3GPP access type credentials the first time it accesses the PLMN, helping to avoid unnecessary procedures and improve network performance.
[0026] In one possible implementation, when the terminal device sends a registration request to the second mobility management network element, specifically, the terminal device generates a message authentication code for verifying the registration request based on the first security protection key and the registration request. The terminal device then sends the registration request and the message authentication code to the second mobility management network element.
[0027] In the above technical solution, the terminal device generates a message authentication code based on the first security protection key and the registration request, and sends the message authentication code and registration request together to the second mobility management network element. Correspondingly, the second mobility management network element can send the message authentication code and registration request together to the first mobility management network element, and the message authentication code can be used by the first mobility management network element to verify the registration request. Thus, the terminal device no longer needs to perform a second primary authentication with the HPLMN based on the identity credentials of the 3GPP access type, which helps improve network performance.
[0028] In one possible implementation, the terminal device further receives a second key set identifier from a second mobility management network element. The second key set identifier identifies a second security context for the second non-access stratum connection, and the second security context includes a second mobility management network element key and a second security protection key. For example, the second key set identifier is carried in a non-access stratum security mode command.
[0029] Alternatively, the terminal device may also receive a first key set identifier and a second key set identifier from a second mobility management network element. The first key set identifier identifies a first security context for the first non-access stratum connection, and the first security context includes a first mobility management network element key and a first security protection key. For example, the first key set identifier and the second key set identifier are carried in a non-access stratum security mode command.
[0030] In one possible implementation, the terminal device further initializes a count value for transmitting messages on the second non-access stratum connection. Thus, the terminal device can transmit messages with the second mobility management element on the second non-access stratum connection based on the initialized count value.
[0031] In one possible implementation, when the terminal device generates the second mobility management network element key based on the first mobility management network element key, specifically, the terminal device generates the second mobility management network element key based on the first mobility management network element key and first information; wherein, the first information includes one or more of the following: an identifier of the key generation function; a count value of messages transmitted on the first non-access stratum connection; the direction of messages transmitted on the first non-access stratum connection; an identifier of the 3GPP access type; an identifier of the public land mobile network to which the first mobility management network element belongs; and an identifier of the public land mobile network to which the second mobility management network element belongs. In one example, the direction of messages transmitted on the first non-access stratum connection is downlink, and the count value of messages transmitted on the first non-access stratum connection is equal to the number of times the terminal device receives downlink messages from the first mobility management network element on the first non-access stratum connection based on the first security protection key. In another example, the direction of messages transmitted on the first non-access stratum connection is uplink, and the count value of messages transmitted on the first non-access stratum connection is equal to the number of times the terminal device sends uplink messages to the first mobility management network element on the first non-access stratum connection based on the first security protection key.
[0032] In the above technical solution, specific input parameters are provided when the terminal device generates the second mobility management network element key based on the first mobility management network element key. These specific input parameters are the same input parameters maintained by both the terminal device and the first mobility management network element. In this way, the terminal device and the first mobility management network element can each generate the same second mobility management network element key based on these input parameters.
[0033] Thirdly, this application provides a communication method that can be executed by a second mobility management network element. The second mobility management network element can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the second mobility management network element can be implemented by a single device, multiple devices working together, or it can be a functional module within a single device.
[0034] The communication method includes: a second mobility management network element receiving a registration request from a terminal device, the registration request including indication information for indicating dual 3GPP access; the second mobility management network element sending a first message to a first mobility management network element, the first message including the registration request, indicating a first non-access stratum connection based on 3GPP access type between the terminal device and the first mobility management network element; the second mobility management network element receiving a second message from the first mobility management network element in response to the first message, the second message including a second mobility management network element key; the second mobility management network element generating a second security protection key based on the second mobility management network element key, the second security protection key being used to securely protect messages transmitted on the second non-access stratum connection, the second non-access stratum connection being a 3GPP access type connection between the terminal device and the second mobility management network element. Optionally, the second mobility management network element sending a registration response to the terminal device, the registration response being a response to the registration request, such as a registration acceptance message.
[0035] In the above technical solution, when the second mobility management network element determines that the registration request indicates dual 3GPP access, that is, when it determines that the terminal device requests to establish a second non-access stratum connection with the second mobility management network element based on the 3GPP access type, the second mobility management network element sends the registration request to the first mobility management network element, and then obtains the second mobility management network element key from the first mobility management network element. This achieves secure protection for messages transmitted on the second non-access stratum connection, thereby improving security in dual 3GPP scenarios. Specifically, after receiving the second mobility management network element key, the second mobility management network element generates a second security protection key based on the second mobility management network element key, and uses the second security protection key to securely protect messages transmitted on the second non-access stratum connection, thereby improving security.
[0036] Furthermore, if the registration request indicates dual 3GPP access, then after receiving the registration request from the terminal device, the second mobility management element can send the registration request to the first mobility management element to obtain the second mobility management element key, instead of instructing the terminal device to perform a second primary authentication with the HPLMN based on the 3GPP access type's identity credentials. This helps avoid unnecessary procedures and improves network performance.
[0037] In one possible implementation, the second mobility management element key is generated based on the first mobility management element key. The first mobility management element key is used to derive the first security protection key, which is used to provide security protection for messages transmitted on the first non-access stratum connection. The second mobility management element key is used to derive the second security protection key.
[0038] In one possible implementation, the second mobility management network element also receives a message authentication code from the terminal device and sends the message authentication code to the first mobility management network element via a first message. The message authentication code is used by the first mobility management network element to verify the registration request.
[0039] In one possible implementation, the second message further includes a second key set identifier, which identifies a second security context for the second non-access stratum connection. The second security context includes a second mobility management element key and a second security protection key. The second key set identifier is generated based on a first key set identifier, which identifies a first security context for the first non-access stratum connection. The first security context includes a first mobility management element key and a first security protection key. The second mobility management element also sends the second key set identifier to the terminal device. In another possible implementation, the second message further includes a first key set identifier, and the second mobility management element also sends the first key set identifier to the terminal device.
[0040] In one possible implementation, the second message further includes a first key set identifier, which identifies a first security context for the first non-access stratum connection. The second mobility management network element also generates a second key set identifier based on the first key set identifier, which identifies a second security context for the second non-access stratum connection. The second mobility management network element sends the second key set identifier to the terminal device, or sends both the first and second key set identifiers to the terminal device.
[0041] In one possible implementation, the value of the type field included in the second key set identifier is the same as the value of the type field included in the first key set identifier; the value field included in the second key set identifier is different from the value field included in the first key set identifier.
[0042] In one possible implementation, the second key set identifier is carried in the non-access stratum security mode command, or the first key set identifier and the second key set identifier are carried in the non-access stratum security mode command.
[0043] In one possible implementation, the second mobility management network element initializes a count value for transmitting messages on the second non-access stratum connection. Thus, the second mobility management network element can transmit messages with the terminal device on the second non-access stratum connection based on the initialized count value.
[0044] Fourthly, embodiments of this application provide a communication device.
[0045] The device has the function of implementing the first mobility management network element in the first aspect or any possible implementation of the first aspect. The device may be a single device, or include multiple devices, or be a functional module within a single device.
[0046] The device may also have the function of a terminal device in the second aspect or any possible implementation of the second aspect described above. The device may be a terminal device or a chip included in the terminal device.
[0047] The device may also have the function of implementing the second mobility management network element in the third aspect or any possible implementation of the third aspect. The device may be a single device, or include multiple devices, or be a functional module within a single device.
[0048] The functions of the aforementioned communication device can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules, units, or means corresponding to the aforementioned functions.
[0049] In one possible implementation, the device includes a processing module and a transceiver module.
[0050] The processing module is configured to support the device in performing the functions corresponding to the first mobility management network element in the first aspect or any implementation thereof, or to support the device in performing the functions corresponding to the terminal device in the second aspect or any implementation thereof, or to perform the functions corresponding to the second mobility management network element in the third aspect or any implementation thereof. The transceiver module supports communication between the device and other communication devices; for example, when the device is a terminal device, it can send a registration request to the second mobility management network element. The communication device may also include a storage module coupled to the processing module, which stores necessary program instructions and data for the device. As an example, the processing module may be a processor, the communication module may be a transceiver, and the storage module may be a memory. The memory may be integrated with the processor or separated from it.
[0051] In another possible implementation, the device includes a processor and may also include a memory. The processor is coupled to the memory and can be used to execute computer program instructions stored in the memory to cause the device to perform the methods of the first aspect or any possible implementation thereof, or to perform the methods of the second aspect or any possible implementation thereof, or to perform the methods of the third aspect or any possible implementation thereof. Optionally, the device further includes a communication interface, to which the processor is coupled. When the device is a network device or a terminal device, the communication interface may be a transceiver or an input / output interface; when the device is a chip included in a network device or a chip included in a terminal device, the communication interface may be an input / output interface of the chip. Optionally, the transceiver may be a transceiver circuit, and the input / output interface may be an input / output circuit.
[0052] Fifthly, embodiments of this application provide a chip system, including: a processor and a memory, the processor being coupled to the memory, the memory being used to store programs or instructions, and when the program or instructions are executed by the processor, causing the chip system to implement the methods in the first aspect or any possible implementation of the first aspect, or implement the methods in the second aspect or any possible implementation of the second aspect, or execute the methods in the third aspect or any possible implementation of the third aspect.
[0053] Optionally, the chip system also includes an interface circuit for exchanging code instructions with the processor.
[0054] Optionally, the chip system may include one or more processors, which can be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, integrated circuit, etc. When implemented in software, the processor may be a general-purpose processor that reads software code stored in memory.
[0055] Optionally, the chip system may contain one or more memories. These memories may be integrated with the processor or disposed separately. For example, the memory may be a non-transitory processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or disposed on separate chips.
[0056] In a sixth aspect, this application provides a computer-readable storage medium storing a computer program or instructions that, when executed by a communication device, cause the communication device to perform the method of the first aspect or any possible implementation thereof, or cause the communication device to perform the method of the second aspect or any possible implementation thereof, or cause the communication device to perform the method of the third aspect or any possible implementation thereof.
[0057] In a seventh aspect, this application provides a computer program product comprising a computer program or instructions that, when executed by a communication device, implement the method in the first aspect or any possible implementation of the first aspect, or implement the method in the second aspect or any possible implementation of the second aspect, or implement the method in the third aspect or any possible implementation of the third aspect.
[0058] Eighthly, this application provides a communication method, comprising: a second mobility management network element receiving a registration request from a terminal device, and sending a first message to a first mobility management network element, the first message including a registration request, the registration request including indication information, the indication information being used to indicate dual 3GPP access, and a first non-access stratum connection based on a 3GPP access type existing between the terminal device and the first mobility management network element; the first mobility management network element generating a second mobility management network element key according to a first mobility management network element key, and sending a second message to the second mobility management network element, the first mobility management network element key being used to deduce a first security protection key, the first security protection key being used to provide security protection for messages transmitted on the first non-access stratum connection; the second mobility management network element generating a second security protection key according to the second mobility management network element key included in the second message, the second security protection key being used to provide security protection for messages transmitted on a second non-access stratum connection, the second non-access stratum connection being a connection based on a 3GPP access type between the terminal device and the second mobility management network element.
[0059] In one possible implementation, before the second mobility management network element receives the registration request from the terminal device, the method further includes: the terminal device sending a registration request to the second mobility management network element;
[0060] After the second mobility management network element generates the second security protection key based on the second mobility management network element key included in the second message, the process further includes: the terminal device generating the second mobility management network element key based on the first mobility management network element key.
[0061] Ninthly, this application provides a communication system including a first mobility management network element and a second mobility management network element. The first mobility management network element is used to implement the method of the first aspect or any possible implementation thereof; the second mobility management network element is used to implement the method of the third aspect or any possible implementation thereof. In one possible implementation, the communication system further includes a terminal device, which is used to implement the method of the second aspect or any possible implementation thereof.
[0062] The specific implementations of the above aspects can be referenced from each other, and the technical effects that can be achieved by the above aspects can also be referenced from each other. They will not be repeated here. Attached Figure Description
[0063] Figure 1 A schematic diagram of a 5G network architecture provided in this application;
[0064] Figure 2 A schematic diagram illustrating a terminal device accessing the core network via 3GPP access type and non-3GPP access type, provided in this application;
[0065] Figure 3 A schematic diagram of a 5G key deduction architecture provided for this application;
[0066] Figure 4 A schematic diagram illustrating a terminal device accessing the core network via dual 3GPP access types, as provided in this application;
[0067] Figure 5 A flowchart illustrating the first communication method provided in this application;
[0068] Figure 6 A flowchart illustrating the second communication method provided in this application;
[0069] Figure 7 A flowchart illustrating the third communication method provided in this application;
[0070] Figure 8 A schematic diagram of the structure of a communication device provided in this application;
[0071] Figure 9 A schematic diagram of another communication device provided in this application. Detailed Implementation
[0072] The relevant technical features involved in the embodiments of this application will be explained below. It should be noted that these explanations are for the purpose of making the embodiments of this application easier to understand, and should not be regarded as a limitation on the scope of protection claimed by this application.
[0073] I. 5G Network Architecture
[0074] Figure 1 This is a schematic diagram of a 5G network architecture. Figure 1 The 5G network architecture shown can be divided into three parts: terminal equipment, data network (DN), and operator network. The functions of some of these network elements are briefly described below.
[0075] The operator network may include one or more of the following network elements: authentication server function (AUSF), network exposure function (NEF), policy control function (PCF), unified data management (UDM), unified data repository (UDR), network repository function (NRF), access and mobility management function (AMF), session management function (SMF), access network, and user plane function (UPF). The portion of the operator network excluding the radio access network can be referred to as the core network. In one possible implementation, the operator network may also include application functions (AF). Alternatively, the AF may not belong to the operator network but to a third party.
[0076] A terminal device, also known as user equipment (UE), is a device with wireless transceiver capabilities. It can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; on water (such as on ships); and in the air (such as on airplanes, balloons, and satellites). Terminal devices can include mobile phones, tablets, computers with wireless transceiver capabilities, virtual reality (VR) terminals, augmented reality (AR) terminals, wireless terminals in industrial control, wireless terminals in self-driving vehicles, wireless terminals in remote medical care, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, and wireless terminals in smart homes, among others.
[0077] The aforementioned terminal devices can establish connections with the operator's network through interfaces provided by the operator's network (such as N1), and use data and / or voice services provided by the operator's network. The terminal devices can also access the DN (Network Provider) through the operator's network, and use operator services deployed on the DN, and / or services provided by third parties. These third parties can be service providers outside of the operator's network and terminal devices, and can provide data and / or voice services to the terminal devices. The specific form of these third parties can be determined based on the actual application scenario and is not limited here.
[0078] The core network includes user plane functions and control plane functions.
[0079] User plane functions include UPF. As the interface with the data network, UPF performs functions such as forwarding user plane data (e.g., packet data), quality of service (QoS) control, session / flow-based billing statistics, and bandwidth limiting.
[0080] The control plane functions primarily handle user registration and authentication, mobility management, and the distribution of packet forwarding policies and QoS control policies to the user plane functions. The control plane functions can be further refined to include other network elements besides the UPF, such as the AMF and SMF.
[0081] The AMF (Access Frame Controller) primarily handles the user registration process upon access, as well as location management and access authentication / authorization during user movement. It is also responsible for transmitting user policies between the terminal device and the PCF (Programmable Frame Controller). The connection between the terminal device and the AMF is called a non-access stratum (NAS) connection, and the messages transmitted between them are NAS messages.
[0082] SMF is mainly responsible for establishing corresponding session connections when users initiate services and providing specific services to users, such as sending data packet forwarding policies and QoS policies to UPF based on the NG4 interface between SMF and UPF.
[0083] AUSF is primarily responsible for authenticating users and verifying the legitimacy of terminal devices in order to determine whether or not to allow them to access the network.
[0084] UDM is primarily responsible for storing terminal device subscription data and user access authorization functions.
[0085] UDR is primarily responsible for storing and retrieving data of various types, such as contract data, strategy data, and application data.
[0086] PCF is primarily responsible for issuing business-related strategies to AMF or SMF.
[0087] NEF is primarily used to support the opening of capabilities and events.
[0088] The Application Provider (AF) primarily relays the application-side requirements to the Network Provider Function (PCF), enabling the PCF to generate corresponding policies. The AF can be a third-party functional entity or an application service deployed by the operator, such as the Internet Protocol (IP) Multimedia Subsystem (IMS) voice call service.
[0089] NRF (Network Element Detection) can be used to provide network element discovery functionality, providing network element information corresponding to the network element type based on requests from other network elements. NRF also provides network element management services, such as network element registration, updating, deregistration, and network element status subscription and push.
[0090] A Domain Provider (DN) is a network located outside of the carrier's network. A carrier's network can connect to multiple DNs, and various services can be deployed on a DN, providing data and / or voice services to terminal devices. For example, a DN might be the private network of a smart factory. Sensors installed in the workshop can act as terminal devices, and a control server for these sensors is deployed within the DN. The control server provides services to the sensors. Sensors can communicate with the control server, receive instructions from it, and transmit the collected sensor data back to the control server accordingly. Another example is a DN serving as an internal office network for a company. Employees' mobile phones or computers can act as terminal devices, accessing information and data resources on the company's internal office network.
[0091] Figure 1 Nnssf, Nausf, Nnef, Nnrf, Npcf, Nudm, Naf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface sequence numbers. The meanings of these interface sequence numbers can be found in the definitions in the 3GPP protocol, and are not limited here.
[0092] It is understood that the aforementioned network element or function can be a network component in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the aforementioned network element or function can be implemented by one device, multiple devices working together, or a functional module within a single device; this application embodiment does not specifically limit this.
[0093] In this application embodiment, the access and mobility management function (also referred to as the mobility management function), the authentication server function, and the unified data management function can respectively be Figure 1 The AMF, AUSF, and UDM mentioned above can also be network elements with the functions of the AMF, AUSF, and UDM in future communications such as 6th generation (6G) networks. This application does not limit this.
[0094] The access network is a sub-network of the operator's network, serving as the implementation system between service nodes and terminal equipment within the operator's network. For a terminal device to access the operator's network, it first passes through the access network, and then connects to the operator's network's service nodes via the access network.
[0095] Access networks can include 3GPP access networks and / or non-3GPP access networks, meaning that terminal devices can access the core network through 3GPP access networks and / or non-3GPP access networks. Non-3GPP access networks refer to access networks outside of 3GPP, such as wireless local area networks (WLANs), wireless fidelity (Wi-Fi) networks, worldwide interoperability for microwave access (WiMAX), and fixed networks. The access type of a terminal device in a 3GPP access network is called 3GPP access, and the access type of a terminal device in a non-3GPP access network is called non-3GPP access.
[0096] Access equipment in a 3GPP access network can be devices that provide wireless communication functions for terminal devices. 3GPP access network access equipment can also be referred to as access network equipment, base stations, etc. Access equipment in a 3GPP access network includes, but is not limited to: next-generation base stations (g node B, gNB) in 5G, evolved node B (eNB), radio network controller (RNC), node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (e.g., home evolved node B, or home node B, HNB), baseband unit (BBU), transmitting and receiving point (TRP), transmitting point (TP), mobile switching center, etc. Messages transmitted between terminal devices and 3GPP access network access equipment can be radio resource control (RRC) messages, user plane (UP) messages, etc. For ease of description, the following explanation uses a gNB as an example of 3GPP access network access equipment.
[0097] Access equipment in non-3GPP access networks can be called non-3GPP interworking function (N3IWF) devices or next-generation packet data gateways (ngPDGs). N3IWFs are similar to evolved packet data gateways (ePDGs) in Long Term Evolution (LTE), and in 5G, they are used to establish Internet Protocol Security (IPsec) tunnels with terminal devices when the terminal device accesses the core network through a non-3GPP access network. The name N3IWF may change in future 5G definitions; this application only uses a non-3GPP network access gateway as an example for illustration. For example, N3IWF devices may include routers, etc.
[0098] like Figure 2 This diagram illustrates how a terminal device accesses the core network via both 3GPP and non-3GPP access methods. For explanations of each network element, please refer to [link to relevant documentation]. Figure 1 The description in the relevant embodiments.
[0099] II. 5G Key Deduction Architecture
[0100] The key hierarchy includes the following keys: K, CK, IK, and the AUSF key (K). AUSF SEAF key (K) SEAF ), AMF key (K AMF ), NAS integrity key (K NASint ), NAS encryption key (K NASenc ), N3IWF key (K N3IWF ), gNB key (K gNB ), RRC Integrity Key (K RRCint ), RRC encryption key (K RRCenc ), UP Integrity Key (K UPint ), UP encryption key (K UPenc ).
[0101] Combination Figure 3 Explanation of a schematic diagram of a 5G key deduction architecture:
[0102] Taking the network side as an example:
[0103] In HPLMN, after primary authentication, UDM derives the AUSF key from CK,IK and provides the AUSF key to the AUSF. AUSF derives the SEAF key from the AUSF key and provides the SEAF key to the SEAF in the service network.
[0104] In the service network, SEAF derives the AMF key from the SEAF key and provides the AMF key to the AMF.
[0105] The AMF derives the NAS integrity key and NAS encryption key from the AMF key. These keys can be used to protect NAS messages transmitted over the NAS connection between the AMF and the terminal equipment. Furthermore, the AMF can derive the N3IWF key and gNB key from the AMF key. The N3IWF key is provided to the N3IWF to protect subsequent non-3GPP access data traffic. The gNB key and next hop (NH) parameters are also provided to the gNB.
[0106] The gNB generates an RRC integrity key, an RRC encryption key, a UP integrity key, and a UP encryption key based on the gNB key and NH parameters. The RRC integrity key and RRC encryption key are used to protect RRC messages transmitted between the gNB and the terminal device; the UP integrity key and UP encryption key are used to protect user plane data transmitted between the gNB and the terminal device.
[0107] Furthermore, the NAS integrity key, RRC integrity key, and UP integrity key are all used for message integrity protection. The NAS encryption key, RRC encryption key, and UP encryption key are all used for message encryption protection.
[0108] Taking NAS integrity key and NAS encryption key as examples:
[0109] When the AMF sends downlink NAS messages to the terminal device, the AMF and the terminal device can perform integrity protection on the downlink NAS messages based on the NAS integrity key. Specifically, the AMF can generate a message authentication code (MAC) for integrity protection of the NAS messages based on the NAS messages and the NAS integrity key, and then send the NAS messages and MAC together to the terminal device. Correspondingly, the terminal device receives the MAC and NAS messages from the AMF and verifies the integrity of the NAS messages based on the MAC and the locally stored NAS integrity key. In addition, the AMF and the terminal device can also encrypt the downlink NAS messages based on the NAS encryption key. Specifically, the AMF can encrypt the NAS messages based on the NAS encryption key to obtain encrypted NAS messages, and then send the encrypted NAS messages to the terminal device. Correspondingly, the terminal device receives the encrypted NAS messages from the AMF and decrypts the encrypted NAS messages based on the locally stored NAS encryption key.
[0110] Similarly, when a terminal device sends an uplink NAS message to the AMF, the terminal device and the AMF can perform integrity protection on the uplink NAS message based on the NAS integrity key, and encrypt the uplink NAS message based on the NAS encryption key. See the description above regarding the AMF sending downlink NAS messages to the terminal device for details.
[0111] It is understandable that when AMF transmits NAS messages to the terminal device, it can perform both integrity protection and encryption protection, or one of these protections. In this application, integrity protection and encryption protection can be collectively referred to as security protection.
[0112] III. Key Set Identifier (NAS key set identifier, ngKSI) for Next Generation Radio Access Network
[0113] ngKSI is used to identify the security context of a NAS connection. ngKSI can be assigned by the AMF during master authentication and key negotiation, or during inter-system changes. ngKSI consists of a value and a security context parameter type, where the security context parameter type indicates whether the security context is a local security context or a mapped security context. When the security context is a native security context, the value of ngKSI is KSI. AMF When the security context is a type mapping, the value of ngKSI is KSI. ASME .
[0114] For example, ngKSI occupies 8 bits. The lower three bits represent the NAS key set identifier, i.e., the value, which can take 7 values: from 000 to 110, where 111 represents no key available. The fourth bit represents the type, with a value of 0 representing the local security context and 1 representing the mapped security context. The higher four bits indicate that ngKSI belongs to the NAS key set identifier and is a type 1 information element.
[0115] IV. Access traffic steering, switching, splitting, ATSSS
[0116] ATSSS technology supports multipath transmission control protocol (MPTCP), multipath quick UDP internet connections (MPQUIC), and ATSSS low layer (ATSSS-LL).
[0117] Among them, MPTCP is for multiplexing Transmission Control Protocol (TCP) traffic, MPQUIC is for multiplexing User Datagram Protocol (UDP) traffic, and ATSSS-LL is for multiplexing Internet Protocol (IP) packets. ATSSS-LL can be used by terminal devices or UPFs to select transmission paths for data packets based on traffic splitting mode and link status, and can support multiplexing of TCP and UDP services.
[0118] ATSSS technology supports the following steering modes: active-standby, smallest delay, load balancing, priority-based, redundancy, or future possible steering modes.
[0119] In the primary / standby traffic splitting mode, only one data channel is used for data transmission at a time. Specifically, in this mode, one transmission path (3GPP access or non-3GPP access) can be designated as active, while the other transmission path is in standby mode. When the active transmission path is available, all data in the service flow is transmitted to the peer through the active transmission path. When the active path is unavailable, all data in the service flow is switched to the standby transmission path for transmission.
[0120] In the minimum latency offloading mode, the shortest latency transmission path can be selected to transmit service stream data. In this mode, the terminal device or UPF can monitor the transmission latency of the path in real time. For example, path monitoring can be implemented by the transport layer protocol (such as the MPTCP layer which has the function of detecting round trip time (RTT)), or by the performance measurement function (PMF) module in the UPF.
[0121] In load balancing, service data can be distributed proportionally to different transmission paths. The distribution ratio can be determined based on the current load of the two transmission paths in the network. For example, a heavier-loaded path will receive a smaller distribution ratio, while a lighter-loaded path will receive a larger distribution ratio.
[0122] In priority-based traffic splitting mode, one transmission path can be designated as a high-priority path, and the other as a low-priority path. When the high-priority path is uncongested, all data in the service flow is transmitted through it. When the high-priority path becomes congested, some data in the service flow will be transmitted through the low-priority path. When the high-priority path is unavailable, all data in the service flow will be transmitted through the low-priority path.
[0123] Possible future traffic offloading modes may include user-preference-based offloading modes, offloading modes selected autonomously by terminal devices or UPFs, and offloading modes based on QoS requirements, etc. This application does not specifically limit these modes.
[0124] Based on the above explanation of the technologies and terms involved in this application, the embodiments of this application are explained below.
[0125] In 3GPP, a terminal device can access two different PLMNs using one 3GPP access type and one non-3GPP access type. This means the terminal device can establish NAS connections with two different AMFs within two different PLMNs and maintain separate security contexts for each NAS connection. Specifically, after performing primary authentication with the HPLMN using identity credential 1 (3GPP access type), the terminal device establishes NAS connection 1 with AMF1 and maintains the security context of NAS connection 1. Similarly, after performing primary authentication with the HPLMN using identity credential 2 (non-3GPP access type), the terminal device establishes NAS connection 2 with AMF2 and maintains the security context of NAS connection 2. Because the terminal device uses different identity credentials when accessing the two PLMNs using 3GPP and non-3GPP access types, it needs to perform two primary authentications with the HPLMN using these two different identity credentials.
[0126] Based on ATSSS technology, 3GPP has further introduced dual 3GPP access type scenarios.
[0127] For example, a terminal device can access two PLMNs respectively based on the 3GPP access type; that is, a terminal device can access two PLMNs respectively based on two 3GPP access types. Figure 4 This application provides a schematic diagram of a terminal device accessing two PLMNs. Specifically, when the terminal device accesses an HPLMN based on the 3GPP access type, it establishes a NAS connection with AMF1 in the HPLMN; when the terminal device accesses a VPLMN based on the 3GPP access type, it establishes a NAS connection with AMF2 in the VPLMN. Further, UPF1 in the HPLMN can be referred to as the anchor UPF, and UPF2 in the VPLMN is connected to the anchor UPF to enable the terminal device to access the DN through the user plane connection with UPF2. For further explanation of each network element, please refer to... Figure 1 The description in the relevant embodiments.
[0128] Furthermore, terminal devices can also access the same PLMN via two 3GPP access points, including AMF1 and AMF2. The terminal device can establish a NAS connection with AMF1 based on the 3GPP access type, and establish a NAS connection with AMF2 based on the 3GPP access type. Figure 4 In this scenario, HPLMN and VPLMN are considered to be the same PLMN, which can be either HPLMN or VPLMN. This application's embodiments can also be applied to other scenarios, which will not be listed here again.
[0129] Improving the security of dual 3GPP access scenarios is a pressing technical problem that needs to be solved.
[0130] Furthermore, if the dual 3GPP access type scenario employs the method described above, where the terminal device accesses two different PLMNs using one 3GPP access type and one non-3GPP access type respectively, then when the terminal device accesses the first PLMN using the 3GPP access type, it needs to perform primary authentication with the HPLMN using the 3GPP access type's identity credential 1; similarly, when the terminal device accesses the second PLMN using the 3GPP access type, it also needs to perform primary authentication with the HPLMN using the same identity credential 1. As such, the terminal device uses the same identity credential to perform the same primary authentication twice with the HPLMN, making the process quite redundant.
[0131] To address this, this application provides a possible communication method. In a dual 3GPP access type scenario, a first NAS connection based on the 3GPP access type exists between the terminal device and the first AMF. Furthermore, when the terminal device needs to establish a second NAS connection with the second AMF based on the 3GPP access type, it can send a registration request to the second AMF. The registration request indicates dual 3GPP access. Correspondingly, the second AMF requests a second AMF key from the first AMF, generates a second security protection key based on the second AMF key, and then uses the second security protection key to securely protect messages transmitted on the second NAS connection, thereby improving security in the dual 3GPP scenario.
[0132] For example, the first AMF could be Figure 4 In AMF1, the second AMF can be Figure 4 AMF2 in; or, the first AMF can be Figure 4 In AMF2, the second AMF can be Figure 4 AMF1 in the context of terminal devices. Terminal devices can be, for example, AMF1. Figure 4 Terminal devices in the process.
[0133] The first AMF can also be referred to as the first Access and Mobility Management Element (Function), the first Mobility Management Element (Function), etc., and the second AMF can also be referred to as the second Access and Mobility Management Element (Function), the second Mobility Management Element (Function), etc. The PLMN to which the first AMF belongs is called the first PLMN, which can be an HPLMN or a Visit Public Land Mobile Network (VPLMN). The PLMN to which the second AMF belongs is called the second PLMN, which can be an HPLMN or a VPLMN. The first PLMN and the second PLMN may be the same or different.
[0134] The first NAS connection is a NAS connection based on the 3GPP access type between the terminal device and the first AMF. The first NAS connection can also be referred to as the first non-access stratum connection. The uplink NAS message sent by the terminal device to the first AMF on the first NAS connection can be referred to as the first uplink message, and the downlink NAS message sent by the first AMF to the terminal device on the first NAS connection can be referred to as the first downlink message.
[0135] The second NAS connection is a NAS connection based on the 3GPP access type between the terminal device and the second AMF. The second NAS connection can also be referred to as the second non-access stratum connection. Uplink NAS messages sent by the terminal device to the second AMF over the second NAS connection are referred to as second uplink messages, and downlink NAS messages sent by the second AMF to the terminal device over the second NAS connection are referred to as second downlink messages.
[0136] The first NAS connection is established before the second NAS connection, and the network supports the simultaneous existence of both NAS connections.
[0137] The first key set identifier can also be called the first ngKSI, and the second key set identifier can also be called the second ngKSI.
[0138] The following is a preliminary description of possible applicable scenarios for the embodiments of this application:
[0139] The terminal device has already accessed the first PLMN via the 3GPP access type. That is, the terminal device has performed primary authentication with the HPLMN based on its 3GPP access type identity credentials. After primary authentication, it establishes a first NAS connection with the first AMF in the first PLMN. The terminal device and the first AMF each maintain a first security context for the first NAS connection.
[0140] 3GPP access type identity credentials include, for example, the credentials included in the Universal Subscriber Identity Module (USIM) card of the terminal device.
[0141] The first security context may include at least one or more of the following parameters (1) to (7):
[0142] (1) The first ngKSI is used to identify the first security context, or to identify the key set in the first security context (such as the first AMF key, the first security protection key, etc.).
[0143] (2) The first AMF key is derived from the SEAF key after the master authentication.
[0144] (3) The first security protection key is derived from the first AMF key. For example, the first security protection key may be the first NAS integrity key, or the first security protection key may be the first NAS encryption key, or the first security protection key may include the first NAS integrity key and the first NAS encryption key. The first security protection key may also be referred to as the first NAS key.
[0145] (4) First NAS count value, which is the count value of messages transmitted on the first NAS connection. The first NAS count value includes the first uplink NAS count value and / or the first downlink NAS count value.
[0146] For the terminal device, the first uplink NAS count value is the number of times the terminal device uses the first security protection key to protect the first uplink message on the first NAS connection; the first downlink NAS count value is the number of times the terminal device uses the first security protection key to protect the first downlink message on the first NAS connection.
[0147] For the first AMF, the first uplink NAS count value is the number of times the first AMF uses the first security protection key to protect the first uplink message on the first NAS connection; the first downlink NAS count value is the number of times the first AMF uses the first security protection key to protect the first downlink message on the first NAS connection.
[0148] (5) First NAS connection identifier, used to identify the first NAS connection.
[0149] (6) The identifier of the terminal device, wherein the identifier of the terminal device may include at least one or more of the following: globally unique temporary identity (GUTI), temporary mobile subscriber identity (TMSI), and subscription permanent identifier (SUPI).
[0150] (7) Security capabilities of terminal devices: integrity protection algorithms and encryption algorithms supported by terminal devices.
[0151] Subsequently, when the terminal device needs to establish a second NAS connection (i.e., the second NAS connection) through the 3GPP access type, it sends a registration request to the second AMF in the second PLMN. At this time, the second NAS connection has not yet been established between the terminal device and the second AMF, nor has a second security context with the second NAS connection been maintained.
[0152] like Figure 5 This is a flowchart illustrating a first communication method provided by example in this application. The communication method describes how a second AMF obtains a second AMF key from a first AMF after receiving a registration request from a terminal device.
[0153] Step 501: The second AMF sends the first message to the first AMF.
[0154] Correspondingly, the first AMF receives the first message from the second AMF.
[0155] The first message includes a registration request from the terminal device. The registration request indicates dual 3GPP access.
[0156] As an optional approach, the registration request includes indication information used to indicate dual 3GPP access; or, to understand, the registration request includes a registration type used to indicate dual 3GPP access, i.e., the registration type is the indication information. Optionally, the indication information has one or more of the following functions: indicating that two NAS connections established based on the 3GPP access type can exist in the network; indicating that the registration request is used to request a second NAS connection established based on the 3GPP access type; instructing the second AMF to forward the registration request to the first AMF. For example, the indication information is a dual 3GPP access indication.
[0157] In one possible approach, after receiving the registration request from the terminal device, the second AMF determines that the terminal device is requesting a second NAS connection based on the 3GPP access type, and then sends a first message to the first AMF, which includes the registration request. Specifically, the second AMF can determine whether the terminal device is requesting a second NAS connection based on the registration request; for example, the second AMF obtains indication information from the registration request and makes the above determination based on the indication information.
[0158] Optionally, the registration request may also include the identifier of the terminal device. This identifier can be used by the second AMF to determine the first AMF before sending the first message to the first AMF. In one possible approach, the identifier of the terminal device is specifically a GUTI. The GUTI may include a globally unique AMF identifier (GUAMI) and a TMSI. After receiving the registration request from the terminal device, the second AMF can determine the GUAMI based on the GUTI in the registration request, and then determine the PLMN to which the terminal device is registered based on information such as the mobile country code (MCC) and mobile network code (MNC) in the GUAMI. Finally, it can determine the first AMF from the PLMN to which the terminal device is registered based on the AMF identifier in the GUAMI.
[0159] Optionally, the identifier of the terminal device may also be used in the first AMF index of the first security context. Alternatively, the registration request may also include a first ngKSI, where the identifier of the terminal device and the first ngKSI can be used in the first AMF index of the first security context, or the first ngKSI can be used in the first AMF index of the first security context. See step 502 below for details.
[0160] In one possible approach, the first security protection key is a first NAS integrity key. The terminal device can generate a first MAC for verifying the registration request based on the first NAS integrity key maintained by the terminal device and the registration request, and then send the first MAC to the second AMF. For example, the first MAC and the registration request can be sent by the terminal device to the second AMF in a single message.
[0161] Accordingly, the second AMF sends a first message to the first AMF, which includes a first MAC and a registration request. The first AMF obtains the first MAC and the registration request from the first message, performs an integrity check on the registration request based on the first NAS integrity key and the first MAC maintained by the first AMF, and performs the following step 502 after determining that the received registration request has passed the integrity check.
[0162] Furthermore, the terminal device can generate the first MAC not only based on the first NAS integrity key and the registration request, but also by combining one or more of the following parameters: the first NAS count value, the transmission direction (specifically uplink), and the first NAS connection identifier. For example, the terminal device inputs the first NAS integrity key, the registration request, the first NAS count value, the transmission direction (specifically uplink), and the first NAS connection identifier into the integrity protection algorithm, which then generates the first MAC. Similarly, the first AMF can input these parameters used by the terminal device to generate the first MAC, along with the received registration request and the first MAC, into the integrity protection algorithm to verify the integrity of the registration request.
[0163] It should be added that a local policy can be pre-set in the second AMF, which can be used to indicate whether the second AMF can use AMF keys generated by other AMFs. For example, after receiving a registration request from the terminal device, if the second AMF determines according to the local policy that the second AMF can use AMF keys generated by other AMFs, it sends a first message to the first AMF, which includes the registration request; if the local policy determines that the second AMF cannot use AMF keys generated by other AMFs, it instructs the terminal device to perform primary authentication with the HPLMN based on identity credentials.
[0164] Step 502: The first AMF generates a second AMF key based on the first AMF key. The second AMF key is used to deduce a second security protection key, which is used to securely protect messages transmitted on the second NAS connection.
[0165] The first AMF can obtain a first security context, obtain a first AMF key from the first security context, and then generate a second AMF key based on the first AMF key.
[0166] The process of the first AMF acquiring the first security context may include the following examples:
[0167] Example (1): The first AMF obtains the registration request from the first message, and determines the first security context corresponding to the terminal device identifier from multiple security contexts maintained by the first AMF based on the terminal device identifier in the registration request.
[0168] Example (2): The first AMF obtains the registration request from the first message, determines the multiple security contexts corresponding to the terminal device identifier from the multiple security contexts maintained by the first AMF based on the terminal device identifier in the registration request, and then determines the first security context corresponding to the first ngKSI from the multiple security contexts corresponding to the terminal device identifier based on the first ngKSI in the registration request.
[0169] Example (3): The first AMF obtains the registration request from the first message, and determines the first security context corresponding to the first ngKSI from the multiple security contexts maintained by the first AMF based on the first ngKSI in the registration request.
[0170] In the process of the first AMF generating the second AMF key based on the first AMF key, specifically, the first AMF generates the second AMF key based on the first AMF key and the first information.
[0171] For example, the first AMF inputs the first AMF key and the first information into the AMF keyderivation function (KDF), and the AMF keyderivation function outputs the second AMF key.
[0172] The AMF key derivation function can also be called a key generation function. The AMF key derivation function is a key derivation function that is already defined in the 3GPP protocol to laterally derive another AMF key from one AMF key (denoted as AMF key derivation function 1), or, as redefined in this application, a key derivation function that is laterally derives another AMF key (i.e., the second AMF key) from one AMF key (i.e., the first AMF key) in a dual 3GPP access scenario (denoted as AMF key derivation function 2).
[0173] The first information includes at least one or more of the following parameters (a) to (f):
[0174] (a) Identifier of the AMF key derivation function. For example, the identifier of AMF key derivation function 1, which is already defined in the 3GPP protocol, is 0x72. The identifier of AMF key derivation function 2, which is redefined in this application, is 0x85.
[0175] (b) The count value of messages transmitted on the first NAS connection (equivalent to the first NAS count value in (4) above).
[0176] (c) The direction of message transmission on the first NAS connection, or simply the transmission direction.
[0177] For example, in the AMF handover scenario, the NAS connection transmission message input to the AMF key deduction function is in the downlink direction; in the idle mobility registration update scenario, the NAS connection transmission message input to the AMF key deduction function is in the uplink direction; and in the dual 3GPP access scenario, the NAS connection transmission message input to the AMF key deduction function is in the uplink direction.
[0178] For example, in the AMF handover scenario, the NAS connection transmission message input to the AMF key deduction function is in the downlink direction; in the idle mobility registration update scenario, the NAS connection transmission message input to the AMF key deduction function is in the uplink direction; and in the dual 3GPP access scenario, the NAS connection transmission message input to the AMF key deduction function is in the downlink direction.
[0179] For example, the value for the uplink is 0x00, and the value for the downlink is 0x11.
[0180] (d) 3GPP access type identifier. The value is, for example, 0x01.
[0181] (e) Identification of the first PLMN to which the first AMF belongs.
[0182] (f) Identification of the second PLMN to which the second AMF belongs.
[0183] In one possible approach, the first information includes the transmission direction and a first NAS count value. For example, the transmission direction is downlink, and the first NAS count value is specifically a first downlink NAS count value. As another example, the transmission direction is uplink, and the first NAS count value is specifically a first uplink NAS count value.
[0184] In one possible approach, the first information may include not only the value of the parameter, but also the length of each parameter. For example, the length of the identifier of the AMF key derivation function, the length of the first NAS count value, the length of the transmission direction, the length of the identifier of the 3GPP access type, the length of the identifier of the first PLMN to which the first AMF belongs, and the length of the identifier of the second PLMN to which the second AMF belongs.
[0185] Combining the parameters in the first information, the following are examples of ways to generate a second AMF key from multiple first AMFs:
[0186] Example 1: The first information includes: the identifier "0x72" of AMF key derivation function 1, the uplink "0x00", and the first uplink NAS count value "100". The first AMF inputs the parameters "0x72", "0x00", "100", and the first AMF key into AMF key derivation function 1 to obtain the output of AMF key derivation function 1, which is the second AMF key.
[0187] Example 2: The first information includes: the identifier "0x72" of AMF key derivation function 1, the downlink "0x11", and the first downlink NAS count value "100". The first AMF inputs the parameters "0x72", "0x11", "100", and the first AMF key into AMF key derivation function 1 to obtain the output of AMF key derivation function 1, which is the second AMF key.
[0188] Example 3: The first information includes: the identifier "0x85" of AMF key derivation function 2, the first downlink NAS count value "100", and the length of the first downlink NAS count value "L1". The first AMF inputs the parameters "0x85", "100", "L1", and the first AMF key into AMF key derivation function 2 to obtain the output of AMF key derivation function 2, which is the second AMF key.
[0189] Example 4: The first information includes: the identifier "0x85" of AMF key derivation function 2, the identifier "0x11" of the 3GPP access type, the identifier "PLMN1" of the first PLMN to which the first AMF belongs, the length "L2" of the identifier of the first PLMN to which the first AMF belongs, the first downlink NAS count value "100", and the length "L1" of the first downlink NAS count value. The first AMF inputs the parameters "0x85", "0x11", "PLMN1", "L2", "100", "L1", and the first AMF key into AMF key derivation function 2 to obtain the output of AMF key derivation function 2, which is the second AMF key.
[0190] Example 5: The first information includes: the identifier "0x85" of AMF key derivation function 2, the identifier "0x11" of the 3GPP access type, the length of the 3GPP access type identifier "L0", the first downlink NAS count value "100", and the length of the first downlink NAS count value "L1". The first AMF inputs the parameters "0x85", "0x11", "L0", "100", "L1", and the first AMF key into AMF key derivation function 2 to obtain the output of AMF key derivation function 2, which is the second AMF key.
[0191] It is understood that the above are merely a few specific examples used to explain the embodiments of this application and do not constitute a limitation on this application. The first AMF in this application may also use other methods to generate the second AMF key.
[0192] It should be added that the first AMF can also generate a second ngKSI based on the first ngKSI. The second ngKSI is used to identify the second security context, or to identify the key set within the second security context (such as the second AMF key, the second security protection key, etc.). For an explanation of the second security context, please refer to the following... Figure 6 The description in the relevant embodiments.
[0193] Specifically, when the first AMF generates the second ngKSI based on the first ngKSI, it may determine that the value of the type field in the second ngKSI is the same as the value of the type field in the first ngKSI, and that the value field in the second ngKSI is different from the value field in the first ngKSI. The value of the type field in the first ngKSI (or the second ngKSI) may be 0, indicating that the security context identified by the first ngKSI (or the second ngKSI) is a local security context.
[0194] When the first AMF determines the value of the value field in the second ngKSI:
[0195] In one possible example, when the first AMF determines that the value in the first ngKSI value field is less than 110, if it determines that the value after adding 1 to the value in the first ngKSI value field has not been used, then it uses the value after adding 1 as the value in the second ngKSI value field; if it determines that the value after adding 1 to the value in the first ngKSI value field has been used, it will continue to add 1 and determine whether the value after adding 1 is used, until an unused value is determined as the value in the second ngKSI value field.
[0196] When the first AMF determines that the value in the value field of the first ngKSI is equal to 110, that is, when it determines that the value in the value field of the ngKSI is the maximum value (where 111 represents no key available), the first AMF further determines whether the minimum value 000 has been used. If it is determined that the minimum value 000 has not been used, then the minimum value 000 is used as the value in the value field of the second ngKSI. If it is determined that the minimum value 000 has been used, then the value after the minimum value 000 plus 1 has not been used, then the value after the increment is used as the value in the value field of the second ngKSI. If it is determined that the value after the minimum value 000 plus 1 has been used, then the increment is continued by 1, and it is determined whether the value after the increment is used, until an unused value is determined as the value in the value field of the second ngKSI.
[0197] In another possible example, the first AMF randomly selects an unused value as the value in the value field of the second ngKSI.
[0198] Specifically, the first AMF determines whether the value is used. This can be done by determining whether the value is used by the terminal device, or by determining whether the value already corresponds to the identifier of the terminal device (such as GUTI).
[0199] Optionally, the first AMF can also determine the SUPI of the terminal device based on the GUTI of the terminal device.
[0200] Step 503: The first AMF sends a second message to the second AMF.
[0201] Correspondingly, the second AMF receives the second message from the first AMF.
[0202] The second message includes the second AMF key. Specifically, the second message may be a response to the first message.
[0203] Optionally, when the first AMF also generates a second ngKSI based on the first ngKSI, the second message may also include the second ngKSI. Alternatively, the first AMF may choose not to generate the second ngKSI based on the first ngKSI, but instead send the first ngKSI to the second AMF via the second message.
[0204] Optionally, the second message may also include one or more of the following: a key derivation instruction, a SUPI of the terminal device, the security capabilities of the terminal device, and an identifier of the AMF key derivation function. The key derivation instruction informs the second AMF that the second AMF key was derived from the first AMF. Accordingly, the second AMF can retain the second AMF key based on the key derivation instruction and use it as the AMF key corresponding to the second NAS connection. For example, the key derivation instruction is a horizontal key derivation instruction, such as keyAmfHDerivationInd.
[0205] In specific implementations, the first message can be a context transfer request, and the corresponding second message can be a context transfer response. For example, the context transfer request is a `Namf_Communication_UEContextTransfer` message, and the context transfer response is a `Namf_Communication_UEContextTransfer response` message. Alternatively, the first message can be an N1 message notification, and the corresponding second message can be a context creation response. For example, the N1 message notification is a `Namf_Communication_N1MessageNotify` message, and the context creation response is a `Namf_Communication_CreateUEContext` message. Or, the first message can be a dual 3GPP access security context transfer request, and the corresponding second message can be a dual 3GPP access security context transfer response. For example, the dual 3GPP access security context transfer request is a `Namf_Dual3GPPaccessSecurityContextTransfer` message, and the dual 3GPP access security context transfer response is a `Namf_Dual3GPPaccessSecurityContextTransfer response` message.
[0206] It is worth noting that since the first NAS connection still exists in the network, the first AMF still needs to maintain the first security context. For example, after sending the second message to the second AMF, the first AMF determines, based on the indication information (i.e., the registration type of dual 3GPP access), to continue maintaining the first security context, that is, to retain / not delete the first security context.
[0207] like Figure 6 This is a flowchart illustrating a second communication method exemplarily provided in this application. The method further describes the process of establishing a second NAS connection between a terminal device and a second AMF. Details not described herein can be found at [link to relevant documentation]. Figure 5 The description in the relevant embodiments.
[0208] In step 601, the terminal device sends a registration request to the second AMF. Correspondingly, the second AMF receives the registration request from the terminal device. A description of the registration request can be found in step 501.
[0209] In step 602, the second AMF sends a first message to the first AMF. Correspondingly, the first AMF receives the first message from the second AMF. The first message includes a registration request from the terminal device. A description of the first message can be found in step 501.
[0210] Step 603: The first AMF generates a second AMF key based on the first AMF key. For details, please refer to the description in step 502.
[0211] Step 604: The first AMF sends a second message to the second AMF. Correspondingly, the second AMF receives the second message from the first AMF. The second message includes the second AMF key. For a detailed implementation, please refer to the description in step 503.
[0212] Step 605: The second AMF generates a second security protection key based on the second AMF key.
[0213] Specifically, the second AMF obtains the second AMF key from the second message, and generates a second security protection key based on the NAS key derivation function and the second AMF key. For example, the second security protection key may be a second NAS integrity key, or it may be a second NAS encryption key, or it may include both the second NAS integrity key and the second NAS encryption key. The second security protection key can also be referred to as the second NAS key.
[0214] The second AMF can also initialize the count value of messages transmitted on the second NAS connection (i.e., the second NAS count value). For example, the second AMF determines the second NAS count value to be 0. Specifically, the second NAS count value includes the second NAS uplink count value and the second NAS downlink count value, and the second AMF determines that both the second NAS uplink count value and the second NAS downlink count value are 0. After the second AMF establishes a second NAS connection with the terminal device based on the 3GPP access type, each time the second AMF receives a second uplink message according to the second security protection key (i.e., each time the second AMF performs security protection on the second uplink message according to the second security protection key), the second AMF increments the second NAS uplink count value by 1; each time the second AMF sends a second downlink message according to the second security protection key (i.e., each time the second AMF performs security protection on the second downlink message according to the second security protection key), the second AMF increments the second NAS downlink count value by 1.
[0215] Optionally, the second AMF also obtains the first ngKSI from the second message and generates the second ngKSI based on the first ngKSI, wherein the second AMF generates the second ngKSI in a similar way to the first AMF.
[0216] Alternatively, it can be understood that after receiving the second message, the second AMF generates a second security context for the second NAS connection. The second security context includes one or more of the following parameters: the second AMF key, the second security protection key, the second ngKSI, the count value of messages transmitted on the second NAS connection, the SUPI of the terminal device, the security capabilities of the terminal device, and the identifier of the NAS key derivation function.
[0217] Step 606: The second AMF sends a third message to the terminal device.
[0218] Correspondingly, the terminal device receives a third message from the second AMF.
[0219] The third message is, for example, a non-access stratum security mode command (NAS SMC).
[0220] The third message includes a second ngKSI. The second ngKSI is used to associate the terminal device with multiple keys generated by the terminal device (such as a second AMF key, a second security protection key, etc.), or the second ngKSI is used to identify a second security context generated by the terminal device, which is the same as the second security context generated by the second AMF.
[0221] The third message may also include one or more of the following: a key update instruction, a first ngKSI, an identifier for the NAS key derivation function, and an identifier for the AMF key derivation function. The key update instruction informs the terminal device that it needs to generate a new AMF key; for example, the key update instruction is K_AMF_change_flag = 1. The first ngKSI is used by the terminal device to index a first security context from multiple locally maintained security contexts, and then obtain the first AMF key from the first security context. The identifier for the AMF key derivation function is used by the terminal device to determine the AMF key derivation function used to generate the second AMF key. The identifier for the NAS key derivation function is used by the terminal device to determine the NAS key derivation function used to generate the second security protection key.
[0222] Step 607: The terminal device generates a second AMF key based on the first AMF key.
[0223] The terminal device can obtain a first security context, obtain a first AMF key from the first security context, and then generate a second AMF key based on the first AMF key.
[0224] In one specific implementation of the terminal device obtaining the first security context, the terminal device obtains the first ngKSI from the third message, and then determines the first security context corresponding to the first ngKSI from multiple security contexts maintained by the terminal device based on the first ngKSI.
[0225] When the terminal device generates the second AMF key based on the first AMF key and the AMF key derivation function, it can specifically involve inputting the first AMF key and first information into the AMF key derivation function, which then outputs the second AMF key. The specific details of the first information and the derivation method can be found in step 502 regarding the key derivation of the first AMF. If the first information includes a first NAS count value, i.e., the first NAS count value is used as an input parameter to the AMF key derivation function, to ensure that the first NAS count value input by the first AMF and the terminal device is the same, the terminal device can also include the first NAS count value recorded when sending the registration request in the registration request. Correspondingly, the first AMF can obtain the first NAS count value from the registration request and input it into the AMF key derivation function to obtain the second AMF key. Similarly, the terminal device can also input the first NAS count value carried in the registration request into the AMF key derivation function to obtain the second AMF key.
[0226] In one specific implementation, the terminal device obtains a key update instruction, a first ngKSI, and the identifier of the AMF key derivation function from the third message. Further, based on the key update instruction, the terminal device determines that a new AMF key needs to be generated. Therefore, it determines a first security context based on the first ngKSI and obtains the first AMF key from the first security context. Based on the identifier of the AMF key derivation function, it determines the AMF key derivation function, and then generates a second AMF key based on the first AMF key and the AMF key derivation function.
[0227] Step 608: The terminal device generates a second security protection key based on the second AMF key.
[0228] In one specific implementation, the terminal device obtains the identifier of the NAS key derivation function from the third message, determines the NAS key derivation function based on the identifier of the NAS key derivation function, and then generates a second security protection key based on the second AMF key and the NAS key derivation function.
[0229] The terminal device can also initialize the count value for messages transmitted on the second NAS connection (i.e., the second NAS count value). For example, the terminal device determines the second NAS count value to be 0. Specifically, the second NAS count value includes a second NAS uplink count value and a second NAS downlink count value, and the terminal device determines that both the second NAS uplink count value and the second NAS downlink count value are 0. After the terminal device establishes a second NAS connection with the second AMF based on the 3GPP access type, each time the terminal device sends a second uplink message according to the second security protection key (i.e., each time the terminal device performs security protection on the second uplink message according to the second security protection key), the terminal device determines that the second NAS uplink count value is incremented by 1; each time the terminal device receives a second downlink message according to the second security protection key (i.e., each time the terminal device performs security protection on the second downlink message according to the second security protection key), the terminal device determines that the second NAS downlink count value is incremented by 1.
[0230] It should be added that the AMF key derivation function can be pre-agreed or pre-configured by the first AMF and the terminal device, without the first AMF sending the AMF key derivation function identifier to the second AMF, or the second AMF sending the AMF key derivation function identifier to the terminal device. Similarly, the NAS key derivation function can be pre-agreed or pre-configured by the second AMF and the terminal device, without the second AMF sending the NAS key derivation function identifier to the terminal device.
[0231] When a terminal device sends a registration request to the second AMF, it can record the key set identifier (i.e., the first ngKSI) corresponding to the first security protection key used for security protection of the registration request. Correspondingly, after receiving the third message, the terminal device can determine the first security context based on its recorded first ngKSI and obtain the first AMF key from the first security context. Alternatively, the terminal device may maintain only one security context (i.e., the first security context). In this case, after receiving the third message, the terminal device can directly obtain the first AMF key from this first security context. Subsequently, the terminal device can generate the second AMF key based on the first AMF key. That is, in this scenario, the third message does not need to carry the first ngKSI.
[0232] Optionally, to ensure the integrity of the third message transmitted between the second AMF and the terminal device, the second AMF also generates a second MAC for verifying the third message based on the second NAS integrity key maintained by the second AMF and the third message, and sends the second MAC and the third message to the terminal device. Correspondingly, the terminal device obtains the first ngKSI from the third message, generates a second AMF key based on the first AMF key indicated by the first ngKSI, generates a second NAS integrity key based on the second AMF key, and then performs integrity verification on the third message based on the second NAS integrity key and the second MAC. The method by which the second AMF and the terminal device protect the integrity of the third message based on the second NAS integrity key is detailed in the above description of the method by which the first AMF and the terminal device protect the integrity of the registration message based on the first NAS integrity key, and will not be repeated here.
[0233] Optionally, after the second AMF sends the second MAC and the third message to the terminal device, it enables the second NAS encryption key. Correspondingly, the terminal device receives the second MAC and the third message, and after determining that the third message passes integrity verification based on the second NAS integrity key and the second MAC, it enables the second NAS encryption key. In this way, the terminal device and the second AMF can further encrypt and protect NAS messages on the second NAS connection based on the second NAS encryption key.
[0234] The terminal device uses the second ngKSI, the second AMF key, the second security protection key, and the count value of messages transmitted on the second NAS connection (i.e., the second NAS count value) to form the second security context of the second NAS connection. Optionally, the second security context may also include the terminal device's SUPI, the terminal device's security capabilities, the identifier of the AMF key derivation function, and the identifier of the NAS key derivation function.
[0235] Furthermore, the terminal device includes a USIM card and non-volatile memory. When the terminal device determines that the USIM card supports the storage of security contexts, it stores a second security context on the USIM card. When the terminal device determines that the USIM card does not support the storage of security contexts, it stores the second security context on the non-volatile memory.
[0236] Step 609: The terminal device sends a fourth message to the second AMF.
[0237] Correspondingly, the second AMF receives the fourth message from the terminal device.
[0238] The fourth message is a response from the terminal device to the third message. For example, when the third message is NAS SMC, the fourth message can be NAS SMC completion.
[0239] For example, when the terminal device sends a fourth message to the second AMF:
[0240] The terminal device can not only protect the integrity of the fourth message using the second NAS integrity key, but also encrypt the fourth message using the second NAS encryption key. Specifically, the terminal device encrypts the fourth message using the second NAS encryption key to obtain the encrypted fourth message, and then sends the encrypted fourth message to the second AMF. Correspondingly, the second AMF receives the encrypted fourth message and decrypts it using the second NAS encryption key maintained by the second AMF to obtain the fourth message.
[0241] Furthermore, the terminal device can encrypt the fourth message not only based on the second NAS encryption key, but also by combining one or more of the following parameters: the second NAS count value, the transmission direction (specifically uplink), the second NAS connection identifier, and the length of the key stream generated by the encryption algorithm. For example, the terminal device inputs the second NAS encryption key, the fourth message, the second NAS count value, the transmission direction (specifically uplink), the second NAS connection identifier, and the length of the key stream generated by the encryption algorithm into the encryption protection algorithm. The encryption protection algorithm then outputs key stream parameters, and encrypts the fourth message based on these key stream parameters to obtain the encrypted fourth message. Similarly, the second AMF can input these parameters used by the terminal device to encrypt the fourth message, along with the received encrypted fourth message, into the encryption protection algorithm. The encryption protection algorithm outputs the decrypted fourth message (i.e., the original fourth message).
[0242] Understandably, the terminal device can first generate a second MAC based on the second NAS integrity key and the fourth message maintained by the terminal device, and then encrypt the fourth message based on the second NAS encryption key maintained by the terminal device to obtain the encrypted fourth message. Correspondingly, the second AMF decrypts the encrypted fourth message based on the second NAS encryption key maintained by the second AMF to obtain the fourth message, and then performs integrity verification on the fourth message based on the second NAS integrity key and the second MAC maintained by the second AMF.
[0243] Of course, here it is also possible that the terminal device first encrypts the fourth message according to the second NAS encryption key maintained by the terminal device, and then generates the second MAC according to the second NAS integrity key maintained by the terminal device and the encrypted fourth message. Correspondingly, the second AMF can first perform integrity verification on the encrypted fourth message according to the second NAS integrity key and the second MAC maintained by the second AMF. After determining that the encrypted fourth message passes the integrity verification, the encrypted fourth message is then decrypted according to the second NAS encryption key maintained by the second AMF.
[0244] Step 610: The second AMF sends a registration response to the terminal device.
[0245] Correspondingly, the terminal device receives a registration response from the second AMF.
[0246] A registration response is the response to a registration request. Specifically, this response can be a registration accept message.
[0247] Once the second AMF successfully sends a registration response to the terminal device, it can be considered that a second NAS connection based on the 3GPP access type has been successfully established between the second AMF and the terminal device. After that, the second AMF and the terminal device can transmit messages through the second NAS connection, and the second security protection key is used to protect the messages transmitted on the second NAS connection to improve the security in the dual 3GPP scenario.
[0248] Combining the first and second communication methods mentioned above, such as Figure 7 The flowchart of the third communication method provided as an example for the application is a relatively complete and detailed process from the terminal device initiating a registration request to the terminal device establishing a second NAS connection with the second AMF.
[0249] In the third communication method described below, the context transfer request is an example of the first message, the context transfer response is an example of the second message, the NAS SMC is an example of the third message, the NAS SMC completion is an example of the fourth message, the registration accept message is an example of the registration response, and the dual 3GPP access indication is an example of the indication message.
[0250] Step 701: The terminal device generates a first MAC based on the registration request and the first NAS integrity key in the terminal device. The first MAC is used to verify the integrity of the registration request.
[0251] Understandably, prior to step 701, the terminal device has already registered with the first AMF, and both the terminal device and the first AMF maintain a first security context for the first NAS connection. Furthermore, the terminal device has completed the main authentication process with the HPLMN.
[0252] Step 702: The terminal device sends a registration request and a first MAC address to the second AMF. Correspondingly, the first AMF receives the registration request and the first MAC address from the terminal device.
[0253] The registration request includes the terminal device's GUTI, dual 3GPP access indication (as a value for the registration type), and the first ngKSI.
[0254] Step 703: The second AMF sends a context transfer request to the first AMF, and correspondingly, the first AMF receives the context transfer request from the second AMF. The context transfer request includes a registration request and a first MAC address.
[0255] Step 704: The first AMF determines the first security context based on the GUTI and the first ngKSI. The first security context includes the first AMF key, the first NAS integrity key, the first ngKSI, and the security capabilities of the terminal device.
[0256] Step 705: The first AMF successfully verifies the registration request based on the first NAS integrity key and the first MAC.
[0257] Step 706: The first AMF generates a second AMF key based on the first AMF key, and generates a second ngKSI based on the first ngKSI.
[0258] Step 707: The first AMF retains the first security context (i.e., does not delete the first security context).
[0259] Step 708: The first AMF sends a context transfer response to the second AMF, and correspondingly, the second AMF receives the context transfer response from the first AMF. The context transfer response includes a horizontal key derivation indicator, the second AMF key, the first ngKSI, the second ngKSI, and the SUPI of the terminal device. The horizontal key derivation indicator is used to indicate that the second AMF key was derived from the first AMF.
[0260] Step 709: The second AMF generates a second NAS integrity key based on the second AMF key and the NAS key derivation algorithm. The message count value transmitted on the second NAS connection is initialized, thereby generating a second security context.
[0261] Step 710: The second AMF generates a second MAC based on the second NAS integrity key in the NAS SMC and the second AMF. The second MAC is used to verify the integrity of the NAS SMC.
[0262] Step 711: The second AMF sends the NAS SMC and the second MAC to the terminal device. Correspondingly, the terminal device receives the NAS SMC and the second MAC from the second AMF. The NAS SMC includes the first ngKSI, the second ngKSI, the identifier of the NAS key derivation algorithm, and a key update indication. The key update indication is used to instruct the terminal device to regenerate the AMF key.
[0263] Step 712: The terminal device indexes the first security context using the first ngKSI, then obtains the first AMF key from the first security context, and generates a second AMF key based on the first AMF key. Finally, it generates a second NAS integrity key based on the second AMF key.
[0264] Step 713: The terminal device successfully verifies the NAS SMC based on the second NAS integrity key and the second MAC.
[0265] In step 714, the terminal device sends a NAS SMC end message to the second AMF. Correspondingly, the second AMF receives the NAS SMC end message from the terminal device.
[0266] Optionally, the terminal device performs integrity protection on the NAS SMC end message based on the second NAS integrity key stored in the terminal device. Optionally, the terminal device also performs encryption protection on the NAS SMC end message based on the second NAS encryption key stored in the terminal device.
[0267] Step 715: The second AMF sends a registration acceptance message to the terminal device. Correspondingly, the terminal device receives the registration acceptance message from the second AMF. Optionally, the second AMF performs integrity protection on the registration acceptance message using the second NAS integrity key within the second AMF. Optionally, the second AMF performs encryption protection on the registration acceptance message using the second NAS encryption key within the second AMF.
[0268] Step 716: The terminal device stores the second security context in the USIM or non-volatile memory.
[0269] Understandable Figure 7 For any details not described in the relevant embodiments, please refer to [link / reference]. Figure 5 and Figure 6The descriptions in the relevant embodiments are as follows. Specifically, steps 701 to 703 can be found in the descriptions of steps 501, 601, and 602. Steps 704 to 707 can be found in the descriptions of steps 502 and 603. Step 708 can be found in the descriptions of steps 503 and 604. Step 709 can be found in the description of step 605. Steps 710 and 711 can be found in the description of step 606. Steps 712 and 716 can be found in the descriptions of steps 607 and 608. Steps 713 and 714 can be found in the description of step 609. Step 715 can be found in the description of step 610.
[0270] In the above technical solution, when a terminal device requests to establish a second NAS connection with a second AMF based on a 3GPP access type, it can send a registration request to the second AMF. This registration request indicates dual 3GPP access. Correspondingly, the second AMF can forward the registration request to the first AMF, allowing the first AMF to generate a second AMF key corresponding to the second NAS connection based on the first AMF key corresponding to the established first NAS connection, and send the second AMF key to the second AMF. Subsequently, the second AMF can generate a second security protection key based on the second AMF key, and use the second security protection key to securely protect messages transmitted on the second NAS connection, thereby improving security in dual 3GPP scenarios. Furthermore, compared to methods that access two different PLMNs based on one 3GPP access type and one non-3GPP access type respectively, in this registration request indicating dual 3GPP access, the second AMF, upon receiving the registration request, no longer instructs the terminal device to perform a second primary authentication with the HPLMN based on the identity credentials of the 3GPP access type. In this way, the terminal device only needs to perform primary authentication with the HPLMN based on the identity credentials of the 3GPP access type when it first accesses the PLMN based on the 3GPP access type. When it accesses the second PLMN based on the 3GPP access type for the second time, it does not need to perform primary authentication with the HPLMN based on the identity credentials of the 3GPP access type. In addition, a second AMF key is generated after the primary authentication, which helps to avoid unnecessary procedures and improve network performance.
[0271] This application also needs to be supplemented with the following three points:
[0272] Supplement 1, Figure 5 Related embodiments to Figure 7The step numbers in the flowcharts described in the related embodiments are merely examples of the execution flow and do not constitute a restriction on the order of step execution. There is no strict execution order between steps in this application embodiment that have no temporal dependency. Not all steps shown in the flowcharts are mandatory; some steps can be deleted or added as needed. Each of the three embodiments focuses on describing the differences from other embodiments; aside from the differences, the two embodiments can be referred to each other. Furthermore, different implementations or examples within the same embodiment can also be referred to.
[0273] Supplement 2: Dual 3GPP access can not only mean that the terminal device accesses two PLMNs respectively through two 3GPP access types, but also that the terminal device accesses two standalone non-public networks (SNPNs) respectively through two 3GPP access types, or that the terminal device accesses one PLMN through one 3GPP access type and accesses the SNPN through another 3GPP access type.
[0274] When the first AMF belongs to the PLMN and the second AMF belongs to the SNPN, this application can also enable the terminal device to perform primary authentication in the HPLMN using the identity credentials of the 3GPP access type only when it first accesses the PLMN based on the 3GPP access type, that is, when establishing the first NAS connection with the first AMF, to generate the security context corresponding to the first NAS connection. Then, when accessing the SNPN again based on the 3GPP access type, that is, when establishing the second NAS connection with the second AMF, the security context corresponding to the first NAS connection is used to protect and authenticate the access process, and the security key corresponding to the second NAS connection is deduced.
[0275] When the first AMF belongs to the SNPN and the second AMF belongs to the PLMN, this application can also enable the terminal device to perform primary authentication in the HPLMN using the identity credentials of the 3GPP access type only when it first accesses the SNPN based on the 3GPP access type, that is, when establishing the first NAS connection with the first AMF, to generate the security context corresponding to the first NAS connection. Then, when accessing the PLMN again based on the 3GPP access type, that is, when establishing the second NAS connection with the second AMF, the security context corresponding to the first NAS connection is used to protect and authenticate the access process, and the security key corresponding to the second NAS connection is deduced.
[0276] When the first AMF belongs to the first SNPN and the second AMF belongs to the second SNPN, this application can further enable the terminal device to perform primary authentication with the HPLMN using the identity credentials of the 3GPP access type only when it first accesses the first SNPN based on the 3GPP access type, that is, when establishing the first NAS connection with the first AMF, generating the security context corresponding to the first NAS connection. Then, when accessing the second SNPN again based on the 3GPP access type, that is, when establishing the second NAS connection with the second AMF, the security context corresponding to the first NAS connection is used to protect and authenticate the access process, and the security key corresponding to the second NAS connection is deduced. Furthermore, the first SNPN and the second SNPN can be the same SNPN or different SNPNs.
[0277] Furthermore, the two 3GPP access types may use the same or different standards. For example, both 3GPP access types may use terrestrial new radio (NR); or, the two 3GPP access types may use terrestrial NR and terrestrial UMTS terrestrial radio access network (E-UTRAN) respectively, where UMTS specifically stands for Universal Mobile Telecommunications System, for example, using a combination of evolved packet core (EPC) and 5G core network (5GC / 5GCN); or, the two 3GPP access types may use terrestrial NR and non-terrestrial NR respectively; or, both 3GPP access types may use non-terrestrial NR, for example, using the same or different non-terrestrial networks (NTN) orbits, such as Earth observation / Medium Earth / Low Earth orbits.
[0278] Supplement 3: The embodiments of this application are applicable not only to dual 3GPP access scenarios but also to multi-3GPP access scenarios. The implementation method of the multi-3GPP access scenario is similar to that of the dual 3GPP access scenario. The first AMF can be considered as an AMF that has already established a NAS connection with the terminal device, while the second AMF is an AMF that has not yet established a NAS connection with the terminal device. For example, there is a NAS connection 1 established based on the 3GPP access type between the terminal device and AMF1, and a NAS connection 2 established based on the 3GPP access type between the terminal device and AMF2. Furthermore, when the terminal device needs to establish a NAS connection 3 with AMF3 based on the 3GPP access type, it can send a registration request to AMF3. The registration request includes indication information used to indicate multi-3GPP access. Correspondingly, AMF3 sends a first request to AMF1, which includes a registration request. AMF1 generates an AMF key corresponding to NAS connection 3 based on the first request and sends the generated AMF key to AMF3. Here, AMF3 and AMF1 are the second AMF and the first AMF in this application, respectively. Furthermore, AMF3 can also send the first request to AMF2, where AMF3 and AMF2 are the second AMF and the first AMF in this application, respectively. Figures 5 to 7 In the relevant embodiments, "dual 3GPP access" is replaced with "multiple 3GPP access" to understand the communication method corresponding to this scenario.
[0279] The various embodiments described herein can be independent solutions or combinations thereof based on their inherent logic, and all such solutions fall within the protection scope of this application. It is understood that the methods and operations implemented by the terminal device in the above method embodiments can also be implemented by components (e.g., chips or circuits) that can be used in the terminal device.
[0280] Based on the above content and the same concept, Figure 8 and Figure 9 This is a schematic diagram of the possible communication devices provided in this application. These communication devices can be used to implement the functions of the terminal device or AMF in the above method embodiments, and therefore can also achieve the beneficial effects of the above method embodiments. In this application, the communication device can be as follows: Figure 1 or Figure 4 The terminal device shown can also be as follows: Figure 1 or Figure 4 The AMF shown.
[0281] like Figure 8 As shown, the communication device 800 includes a processing module 801 and a transceiver module 802.
[0282] When the communication device 800 is used to achieve the above Figures 5 to 7In the method embodiment shown, the function of the first AMF is as follows:
[0283] The transceiver module 802 is configured to: receive a first message from the second AMF, the first message including a registration request from the terminal device, the registration request including indication information indicating dual 3GPP access, and a first NAS connection based on 3GPP access type existing between the terminal device and the first AMF. The processing module 801 is configured to: generate a second AMF key based on the first AMF key. The transceiver module 802 is further configured to: send a second message to the second AMF, the second message being a response to the first message, and the second message including the second AMF key. The first AMF key is used to deduce a first security protection key, which is used to securely protect messages transmitted on the first NAS connection; the second AMF key is used to deduce a second security protection key, which is used to securely protect messages transmitted on the second NAS connection; the second NAS connection is a 3GPP access type-based connection between the terminal device and the second AMF.
[0284] In one possible implementation, the first message also includes a first MAC. Before the transceiver module 802 sends the second message to the second AMF, the processing module 801 is further configured to: successfully verify the registration request based on the first security protection key and the first MAC.
[0285] In one possible implementation, the processing module 801 is further configured to: retain a first security context of the first NAS connection, the first security context including a first AMF key and a first security protection key.
[0286] In one possible implementation, the second message further includes a second key set identifier, which identifies a second security context of the second NAS connection, including a second AMF key and a second security protection key. The processing module 801 is further configured to: generate a second key set identifier based on the first key set identifier, wherein the first key set identifier identifies a first security context of the first NAS connection. In one possible implementation, the second message further includes a first key set identifier.
[0287] In one possible implementation, when the processing module 801 generates the second AMF key based on the first AMF key, it is specifically used to: generate the second AMF key based on the first AMF key and first information; wherein the first information includes one or more of the following: an identifier of the key generation function; a count value of messages transmitted on the first NAS connection; the direction of messages transmitted on the first NAS connection; an identifier of the 3GPP access type; an identifier of the public land mobile network to which the first AMF belongs; and an identifier of the public land mobile network to which the second AMF belongs.
[0288] When the communication device 800 is used to achieve the above Figures 5 to 7 The terminal device functions as shown in the method embodiment:
[0289] The transceiver module 802 is configured to: send a registration request to the second AMF, the registration request including indication information indicating dual 3GPP access, and that a first NAS connection based on 3GPP access type exists between the terminal device and the first AMF. The processing module 801 is configured to: generate a second AMF key based on the first AMF key, the first AMF key being used to derive a first security protection key, which is used to securely protect messages transmitted on the first NAS connection; and the second AMF key being used to derive a second security protection key, which is used to securely protect messages transmitted on the second NAS connection, where the second NAS connection is a 3GPP access type-based connection between the terminal device and the second AMF.
[0290] In one possible implementation, when the transceiver module 802 sends a registration request to the second AMF, it is specifically used to: generate a first MAC for verifying the registration request based on the first security protection key and the registration request, and send the registration request and the first MAC to the second AMF.
[0291] In one possible implementation, the transceiver module 802 is further configured to: receive a second key set identifier from the second AMF, or receive a first key set identifier and a second key set identifier from the second AMF; wherein the first key set identifier is used to identify a first security context of the first NAS connection, the first security context including a first AMF key and a first security protection key; and the second key set identifier is used to identify a second security context of the second NAS connection, the second security context including a second AMF key and a second security protection key.
[0292] In one possible implementation, the processing module 801 is used to: initialize the count value of messages transmitted on the second NAS connection.
[0293] In one possible implementation, when the processing module 801 generates the second AMF key based on the first AMF key, it is specifically used to: generate the second AMF key based on the first AMF key and first information; wherein the first information includes one or more of the following: an identifier of the key generation function; a count value of messages transmitted on the first NAS connection; the direction of messages transmitted on the first NAS connection; an identifier of the 3GPP access type; an identifier of the public land mobile network to which the first AMF belongs; and an identifier of the public land mobile network to which the second AMF belongs.
[0294] When the communication device 800 is used to achieve the above Figures 5 to 7The function of the second AMF in the method embodiment shown is as follows:
[0295] The transceiver module 802 is configured to: receive a registration request from a terminal device, the registration request including indication information used to indicate dual 3GPP access; and send a first message to a first AMF, the first message including the registration request from the terminal device, indicating that a first NAS connection based on 3GPP access type exists between the terminal device and the first AMF. The transceiver module 802 is further configured to: receive a second message from the first AMF, the second message including a second AMF key. The processing module 801 is further configured to: generate a second security protection key based on the second AMF key, the second security protection key being used to securely protect messages transmitted on the second non-access stratum connection, the second non-access stratum connection being a 3GPP access type-based connection between the terminal device and the second AMF.
[0296] In one possible implementation, the second AMF key is generated based on the first AMF key, which is used to derive the first security protection key, which is used to securely protect messages transmitted on the first NAS connection.
[0297] In one possible implementation, the first message also includes a first MAC, which is used to verify the registration request. The transceiver module 802 is also used to receive the first MAC from the terminal device.
[0298] In one possible implementation, the second message further includes a second key set identifier, which identifies a second security context of the second NAS connection. The second security context includes a second AMF key and a second security protection key. The second key set identifier is generated based on a first key set identifier. The first key set identifier identifies a first security context of the first NAS connection, which includes a first AMF key and a first security protection key. The transceiver module 802 is further configured to send the second key set identifier to the terminal device. For example, the second message also includes a first key set identifier; the transceiver module 802 is further configured to send the first key set identifier to the terminal device.
[0299] In one possible implementation, the second message further includes a first key set identifier. The processing module 801 is further configured to: generate a second key set identifier based on the first key set identifier, the second key set identifier being used to identify a second security context of the second NAS connection, the second security context including a second AMF key and a second security protection key; the transceiver module 802 is further configured to: send the second key set identifier to the terminal device, or send the first key set identifier and the second key set identifier to the terminal device.
[0300] In one possible implementation, the processing module 801 is also used to: initialize the count value of messages transmitted on the second NAS connection.
[0301] like Figure 9 The image shown is of the apparatus 900 provided in an embodiment of this application. Figure 9 The device shown can be Figure 8 The illustrated device represents one hardware circuit implementation. This device can be applied to the flowchart shown above to perform the functions of the first AMF, terminal device, or second AMF in the method embodiments described above. For ease of explanation, Figure 9 Only the main components of the device are shown.
[0302] Figure 9 The illustrated device 900 includes a communication interface 910, a processor 920, and a memory 930, wherein the memory 930 is used to store program instructions and / or data. The processor 920 may operate in conjunction with the memory 930. The processor 920 may execute the program instructions stored in the memory 930. When the instructions or program stored in the memory 930 are executed, the processor 920 is used to perform the operations performed by the processing module 801 in the above embodiments, and the communication interface 910 is used to perform the operations performed by the transceiver module 802 in the above embodiments.
[0303] The memory 930 and the processor 920 are coupled. The coupling in this embodiment is an indirect coupling or communication connection between devices, units, or modules, and can be electrical, mechanical, or other forms, used for information exchange between devices, units, or modules. At least one of the memories 930 may be included in the processor 920.
[0304] In this embodiment, the communication interface can be a transceiver, circuit, bus, module, or other type of communication interface. In this embodiment, when the communication interface is a transceiver, the transceiver can include an independent receiver, an independent transmitter, or a transceiver integrating transceiver functions, or simply a communication interface.
[0305] Device 900 may also include a communication line 940. The communication interface 910, processor 920, and memory 930 can be interconnected via the communication line 940. The communication line 940 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The communication line 940 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 9 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0306] The method steps in the embodiments of this application can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in a base station or terminal. Of course, the processor and storage medium can also exist as discrete components in the base station or terminal.
[0307] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer programs or instructions. When a computer program or instruction is loaded and executed on a computer, all or part of the processes or functions of the embodiments of this application are performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, a computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video optical disc; or it can be a semiconductor medium, such as a solid-state drive. Computer-readable storage media can be volatile or non-volatile, or may include both types of storage media.
[0308] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0309] Depending on whether the specification uses "optional": In this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. In the textual description of this application, the character " / " generally indicates an "or" relationship between the preceding and following related objects; in the formulas of this application, the character " / " indicates a "division" relationship between the preceding and following related objects. "Including at least one of A, B, and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B, and C.
[0310] It is understood that the various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. The order of the process numbers described above does not imply the order of execution; the execution order of each process should be determined by its function and internal logic.
Claims
1. A communication method, characterized in that, include: The first mobility management network element receives a first message from the second mobility management network element. The first message includes a registration request from the terminal device. The registration request includes indication information, which is used to indicate dual 3GPP access. There is a first non-access stratum connection based on 3GPP access type between the terminal device and the first mobility management network element. The first mobility management network element generates a second mobility management network element key based on the first mobility management network element key; The first mobility management network element sends a second message to the second mobility management network element, the second message including the key of the second mobility management network element; Wherein, the first mobility management element key is used to derive the first security protection key, which is used to provide security protection for messages transmitted on the first non-access stratum connection; the second mobility management element key is used to derive the second security protection key, which is used to provide security protection for messages transmitted on the second non-access stratum connection; and the second non-access stratum connection is a 3GPP access type-based connection between the terminal device and the second mobility management element.
2. The method as described in claim 1, characterized in that, The first message also includes a message authentication code. Before the first mobility management network element sends the second message to the second mobility management network element, the method further includes: The first mobility management network element successfully verifies the registration request based on the first security protection key and the message authentication code.
3. The method as described in claim 1, characterized in that, Also includes: The first mobility management network element retains the first security context of the first non-access stratum connection, the first security context including the first mobility management network element key and the first security protection key.
4. The method as described in claim 1, characterized in that, The second message also includes a second key set identifier, which is used to identify the second security context of the second non-access stratum connection. The second security context includes the second mobility management network element key and the second security protection key. The method further includes: The first mobility management network element generates a second key set identifier based on the first key set identifier, wherein the first key set identifier is used to identify the first security context of the first non-access stratum connection.
5. The method as described in claim 1, characterized in that, The second message also includes a first key set identifier, which is used to identify the first security context of the first non-access stratum connection.
6. The method as described in claim 4, characterized in that, The values of the type field included in the second key set identifier are the same as the values of the type field included in the first key set identifier; The values of the fields included in the second key set identifier are different from the values of the fields included in the first key set identifier.
7. The method as described in claim 1, characterized in that, The first message is a context transfer request, and the second message is a context transfer response; or, the first message is an N1 message notification, and the second message is a context creation response; or, the first message is a dual 3GPP access security context transfer request, and the second message is a dual 3GPP access security context transfer response.
8. The method according to any one of claims 1-7, characterized in that, The first mobility management network element generates a second mobility management network element key based on the first mobility management network element key, including: The first mobility management network element generates the second mobility management network element key based on the first mobility management network element key and the first information; wherein, the first information includes one or more of the following: Identifier of the key generation function; The count value of messages transmitted on the first non-access stratum connection; The direction of message transmission on the first non-access stratum connection; The identifier of the 3GPP access type; The identifier of the public land mobile network to which the first mobility management network element belongs; The identifier of the public land mobile network to which the second mobility management element belongs.
9. The method as described in claim 8, characterized in that, The direction of message transmission on the first non-access stratum connection is downlink; The count of messages transmitted on the first non-access stratum connection is equal to the number of times the first mobility management network element sends downlink messages to the terminal device on the first non-access stratum connection according to the first security protection key.
10. The method as described in claim 8, characterized in that, The direction of message transmission on the first non-access stratum connection is uplink; The count of messages transmitted on the first non-access stratum connection is equal to the number of times the first mobility management network element receives uplink messages from the terminal device on the first non-access stratum connection according to the first security protection key.
11. A communication method, characterized in that, Applications to terminal devices or modules of terminal devices include: A registration request is sent to the second mobility management network element. The registration request includes indication information, which indicates dual 3GPP access and that there is a first non-access stratum connection between the terminal device and the first mobility management network element based on the 3GPP access type. A second mobility management network element key is generated based on the first mobility management network element key. The first mobility management network element key is used to derive a first security protection key, which is used to provide security protection for messages transmitted on the first non-access stratum connection. The second mobility management network element key is used to derive a second security protection key, which is used to provide security protection for messages transmitted on the second non-access stratum connection. The second non-access stratum connection is a 3GPP access type-based connection between the terminal device and the second mobility management network element.
12. The method as described in claim 11, characterized in that, Send a registration request to the second mobility management network element, including: Based on the first security protection key and the registration request, a message authentication code is generated to verify the registration request; The registration request and the message authentication code are sent to the second mobility management network element.
13. The method as described in claim 11, characterized in that, Also includes: Receive the second key set identifier from the second mobility management network element, or, Receive the first key set identifier and the second key set identifier from the second mobility management network element; Wherein, the first key set identifier is used to identify the first security context of the first non-access stratum connection, and the first security context includes the first mobility management network element key and the first security protection key; The second key set identifier is used to identify the second security context of the second non-access stratum connection, the second security context including the second mobility management network element key and the second security protection key.
14. The method as described in claim 13, characterized in that, The second key set identifier is carried in the non-access stratum security mode command, or the first key set identifier and the second key set identifier are carried in the non-access stratum security mode command.
15. The method as described in claim 11, characterized in that, Also includes: Initialize the count value for messages transmitted on the second non-access stratum connection.
16. The method according to any one of claims 11-15, characterized in that, The step of generating a second mobility management network element key based on a first mobility management network element key includes: The second mobility management element key is generated based on the first mobility management element key and the first information; wherein the first information includes one or more of the following: Identifier of the key generation function; The count value of messages transmitted on the first non-access stratum connection; The direction of message transmission on the first non-access stratum connection; The identifier of the 3GPP access type; The identifier of the public land mobile network to which the first mobility management network element belongs; The identifier of the public land mobile network to which the second mobility management element belongs.
17. The method as described in claim 16, characterized in that, The direction of message transmission on the first non-access stratum connection is downlink; The count of messages transmitted on the first non-access stratum connection is equal to the number of times the terminal device receives downlink messages from the first mobility management element on the first non-access stratum connection according to the first security protection key.
18. The method as described in claim 16, characterized in that, The direction of message transmission on the first non-access stratum connection is uplink; The count of messages transmitted on the first non-access stratum connection is equal to the number of times the terminal device sends uplink messages to the first mobility management element on the first non-access stratum connection based on the first security protection key.
19. A communication method, characterized in that, include: The second mobility management network element receives a registration request from a terminal device, the registration request including indication information, the indication information being used to indicate dual 3GPP access; The second mobility management network element sends a first message to the first mobility management network element, the first message including the registration request, and there is a first non-access stratum connection between the terminal device and the first mobility management network element based on the 3GPP access type; The second mobility management network element receives a second message from the first mobility management network element, the second message including a second mobility management network element key; The second mobility management network element generates a second security protection key based on the second mobility management network element key. The second security protection key is used to protect the messages transmitted on the second non-access stratum connection. The second non-access stratum connection is a 3GPP access type-based connection between the terminal device and the second mobility management network element. The second mobility management element key is generated by the first mobility management element based on the first mobility management element key. The first mobility management element key is used to deduce the first security protection key, which is used to protect the messages transmitted on the first non-access stratum connection.
20. The method as described in claim 19, characterized in that, The first message also includes a message authentication code, which is used to verify the registration request. The method further includes: The second mobility management network element receives the message authentication code from the terminal device.
21. The method as described in claim 19, characterized in that, The second message also includes a second key set identifier, which is used to identify the second security context of the second non-access stratum connection. The second security context includes the second mobility management network element key and the second security protection key. The second key set identifier is generated based on the first key set identifier. The first key set identifier is used to identify the first security context of the first non-access stratum connection, and the first security context includes the first mobility management network element key and the first security protection key; The method further includes: The second mobility management network element sends a second key set identifier to the terminal device.
22. The method as described in claim 21, characterized in that, The second message also includes the identifier of the first key set; The method further includes: The second mobility management network element sends the first key set identifier to the terminal device.
23. The method as described in claim 19, characterized in that, The second message also includes a first key set identifier, which is used to identify the first security context of the first non-access stratum connection. The first security context includes the first mobility management network element key and the first security protection key. The method further includes: The second mobility management network element generates a second key set identifier based on the first key set identifier. The second key set identifier is used to identify the second security context of the second non-access stratum connection. The second security context includes the second mobility management network element key and the second security protection key. The second mobility management network element sends the second key set identifier to the terminal device, or sends the first key set identifier and the second key set identifier to the terminal device.
24. The method as described in claim 21, characterized in that, The values of the type field included in the second key set identifier are the same as the values of the type field included in the first key set identifier; The values of the fields included in the second key set identifier are different from the values of the fields included in the first key set identifier.
25. The method as described in claim 21, characterized in that, The second key set identifier is carried in the non-access stratum security mode command, or the first key set identifier and the second key set identifier are carried in the non-access stratum security mode command.
26. The method as described in claim 19, characterized in that, The first message is a context transfer request, and the second message is a context transfer request response; or, the first message is an N1 message notification, and the second message is a context creation response; or, the first message is a dual 3GPP access security context transfer request, and the second message is a dual 3GPP access security context transfer response.
27. The method according to any one of claims 19-26, characterized in that, The second mobility management element initializes the count value of messages transmitted on the second non-access stratum connection.
28. A communication device, characterized in that, It includes modules for performing the method as described in any one of claims 1 to 10, or modules for performing the method as described in any one of claims 11 to 18, or modules for performing the method as described in any one of claims 19 to 27.
29. A communication device, characterized in that, The device includes a processor and an interface circuit. The interface circuit is used to receive signals from other communication devices besides the communication device and transmit them to the processor, or to send signals from the processor to other communication devices besides the communication device. The processor is used to implement the method as described in any one of claims 1 to 10, or the method as described in any one of claims 11 to 18, or the method as described in any one of claims 19 to 27, through logic circuits or execution code instructions.
30. A computer-readable storage medium, characterized in that, The storage medium stores a computer program or instructions that, when executed by a communication device, implement the method as described in any one of claims 1 to 10, or the method as described in any one of claims 11 to 18, or the method as described in any one of claims 19 to 27.
31. A computer program product, characterized in that, The computer program product includes a computer program or instructions that, when executed by a communication device, implement the method as described in any one of claims 1 to 10, or the method as described in any one of claims 11 to 18, or the method as described in any one of claims 19 to 27.
32. A communication method, characterized in that, include: The second mobility management network element receives a registration request from the terminal device and sends a first message to the first mobility management network element. The first message includes the registration request, which includes indication information. The indication information is used to indicate dual 3GPP access. There is a first non-access stratum connection based on 3GPP access type between the terminal device and the first mobility management network element. The first mobility management network element generates a second mobility management network element key based on the first mobility management network element key, and sends a second message to the second mobility management network element. The first mobility management network element key is used to deduce a first security protection key, and the first security protection key is used to provide security protection for messages transmitted on the first non-access stratum connection. The second mobility management network element generates a second security protection key based on the second mobility management network element key included in the second message. The second security protection key is used to protect the messages transmitted on the second non-access stratum connection. The second non-access stratum connection is a 3GPP access type-based connection between the terminal device and the second mobility management network element.
33. The method as described in claim 32, characterized in that, Before the second mobility management network element receives the registration request from the terminal device, the method further includes: the terminal device sending the registration request to the second mobility management network element; After the second mobility management network element generates a second security protection key based on the second mobility management network element key included in the second message, the process further includes: the terminal device generating a second mobility management network element key based on the first mobility management network element key.
34. A communication system, characterized in that, include: First mobility management network element and second mobility management network element; Wherein, the first mobility management network element is used to implement the method as described in any one of claims 1 to 10; The second mobility management network element is used to implement the method as described in any one of claims 19 to 27.
35. The system as described in claim 34, characterized in that, Also includes: A terminal device, the terminal device being used to implement the method as described in any one of claims 11 to 18.