Communication method and device
By negotiating the use of preconfigured keys between the terminal device and the user plane function, the key used to protect the MPQUIC connection data is derived, which solves the security problem when establishing MPQUIC connections between the terminal device and the user plane function, and achieves safe and efficient data transmission.
Patent Information
- Application Number
- CN202311603343.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-27
- Publication Date
- 2025-05-27
AI Technical Summary
In the process of establishing MPQUIC connection between terminal devices and user surface functions, how to implement security solutions is an urgent problem to be solved at present.
By negotiating the use of preconfigured keys between the terminal device and the user plane function, the keys used to protect the MPQUIC connection data are derived and data is transmitted over multiple paths to achieve a secure connection.
In the process of establishing MPQUIC connection between the terminal device and the user surface function, this method realizes secure data transmission, reduces connection complexity, and improves the security of data transmission.
Smart Images

Figure CN120050800A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of wireless communications, and in particular, to a communication method and device. Background Art
[0002] When the terminal device uses the access traffic steering, switching, splitting (ATSSS) function, the terminal device establishes a multiple access protocol data unit (MA PDU) session with the user plane function (UPF), which supports multiple access paths (for example, including paths accessed through 3GPP and paths accessed through non-3GPP), and data can be transmitted on different access paths. The ATSSS function further supports the multipath quick user datagram protocol internet connections (MPQUIC) function. That is, the terminal device supports establishing an MPQUIC connection associated with the MA PDU session with the user plane function.
[0003] In the process of establishing an MPQUIC connection between a terminal device and a user plane function, how to implement a security solution is an issue that needs to be solved urgently. Summary of the invention
[0004] The present application provides a communication method and device for implementing a security solution during the process of establishing an MPQUIC connection between a terminal device and a user plane function.
[0005] In a first aspect, the present application provides a communication method, which is executed by a first terminal device. The first terminal device may be a terminal device or a module (such as a chip) in the terminal device.
[0006] The method includes: after the establishment of a first MA PDU session of a first terminal device is completed, the first terminal device negotiates with a first user plane function to establish a first MPQUIC connection, and the first MPQUIC connection is associated with the first MA PDU session. The first terminal device derives a key for protecting data of the first MPQUIC connection based on a preconfigured key, and the data of the first MPQUIC connection is transmitted by multiple paths between the first terminal device and the first user plane function. The preconfigured key is also used for the first terminal device to establish a second MPQUIC connection with a second user plane function, and the first user plane function and the second user plane function are located in the same public land mobile network.
[0007] In the above technical solution, after the first MA PDU session of the first terminal device is established, the first terminal device establishes a first MPQUIC connection according to the preconfigured key, and security is achieved in the process of establishing the first MPQUIC connection between the first terminal device and the first user plane function. Further, the preconfigured key is not only used for the first terminal device to establish the first MPQUIC connection with the first user plane function, but also used for the first terminal device to establish the second MPQUIC connection with the second user plane function. The first user plane function and the second user plane function are located in the same public land mobile network, that is, the preconfigured key can be used for the first terminal device to establish an MPQUIC connection with multiple user plane functions located in the same public land mobile network, thereby reducing the complexity of the first terminal device to establish an MPQUIC connection.
[0008] In a possible implementation manner, the first terminal device negotiates with the first user plane function to establish a first MPQUIC connection. Specifically, the first terminal device sends an identifier of a preconfigured key to the first user plane function.
[0009] In the above technical solution, the first terminal device sends an identifier of a preconfigured key to the first user plane function to negotiate with the first user plane function to establish a first MPQUIC connection, which helps to be compatible with the way in which the client and the server establish a connection in the existing transport layer security (TLS) protocol. Here, the client is equivalent to the first terminal device, and the server is equivalent to the first user plane function.
[0010] In a possible implementation, the messages transmitted during the negotiation are protected based on 3GPP security.
[0011] In the above technical solution, before the first terminal device establishes an MPQUIC connection with the first user plane function, the first MA PDU session of the first terminal device has been established, that is, 3GPP security protection has been established, and the messages transmitted between the first terminal device and the first user plane function can be protected based on 3GPP security protection. This helps to improve the security of message transmission.
[0012] In one possible implementation, the preconfigured key used by the first terminal device when negotiating with the first user plane function to establish the first MPQUIC connection is the same as the preconfigured key used by the second terminal device when negotiating with the first user plane function to establish the third MPQUIC connection, wherein the first terminal device and the second terminal device belong to the same home public land mobile network.
[0013] In the above technical solution, the preconfigured key can also be used for the second terminal device to establish a third MPQUIC connection with the first user plane function. That is, the preconfigured key can be used for the first user plane function to establish an MPQUIC connection with multiple terminal devices located in the same home public land mobile network, thereby reducing the complexity of the first user plane function in establishing the MPQUIC connection.
[0014] In a possible implementation, after the first MA PDU session of the first terminal device is established, the first terminal device further negotiates with the first user plane function to establish a fourth MPQUIC connection, and the fourth MPQUIC connection is associated with the first MA PDU session. The first terminal device derives a key for protecting data of the fourth MPQUIC connection based on the preconfigured key, wherein the key for protecting the data of the first MPQUIC connection is different from the key for protecting the data of the fourth MPQUIC connection.
[0015] In the above technical solution, the first MA PDU session can be associated with multiple MPQUIC connections, and the first terminal device can deduce a key for each MPQUIC connection to protect the data of the MPQUIC connection, which helps to improve the security of data transmission.
[0016] In a possible implementation, after the second MAPDU session of the first terminal device is established, the first terminal device further negotiates with the second user plane function to establish a second MPQUIC connection, and the second MPQUIC connection is associated with the second MAPDU session. The first terminal device derives a key for protecting data of the second MPQUIC connection based on the preconfigured key.
[0017] In a second aspect, the present application provides a communication method, which is performed by a first user plane function, and the first user plane function can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the first user plane function can be implemented by one device, or by multiple devices together, or it can also be a functional module in one device.
[0018] The method includes: after the first MA PDU session of the first terminal device is established, the first user plane function negotiates with the first terminal device to establish a first MPQUIC connection, and the first MPQUIC connection is associated with the first MA PDU session. The first user plane function derives a key for protecting data of the first MPQUIC connection based on a preconfigured key, and the data of the first MPQUIC connection is transmitted by multiple paths between the first terminal device and the first user plane function. The preconfigured key is also used for the first terminal device to establish a second MPQUIC connection with a second user plane function, and the first user plane function and the second user plane function are located in the same public land mobile network.
[0019] In a possible implementation manner, the first user plane function negotiates with the first terminal device to establish a first MPQUIC connection. Specifically, the first user plane function receives an identifier of a preconfigured key from the first terminal device.
[0020] In a possible implementation, the messages transmitted during the negotiation are protected based on 3GPP security.
[0021] In one possible implementation, the preconfigured key used when the first user plane function negotiates with the first terminal device to establish the first MPQUIC connection is the same as the preconfigured key used when the first user plane function negotiates with the second terminal device to establish the third MPQUIC connection. The first terminal device and the second terminal device belong to the same home public land mobile network.
[0022] In a possible implementation, after the first MAPDU session of the first terminal device is established, the first user plane function further negotiates with the first terminal device to establish a fourth MPQUIC connection, where the fourth MPQUIC connection is associated with the first MAPDU session. The first user plane function derives a key for protecting data of the fourth MPQUIC connection based on a preconfigured key, wherein the key for protecting data of the first MPQUIC connection is different from the key for protecting data of the fourth MPQUIC connection.
[0023] The technical effects that can be achieved in the above-mentioned second aspect can refer to the description of the beneficial effects in the above-mentioned first aspect, and will not be repeated here.
[0024] In a third aspect, the present application provides a communication method, which is applicable to the process of establishing an MA PDU session for a terminal device. The communication method is performed by a session management function, which can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualization function instantiated on a platform (e.g., a cloud platform). Optionally, the session management function can be implemented by one device, or by multiple devices, or it can be a functional module within a device.
[0025] The method includes: a session management function obtains a shared key from a first function. The session management function sends a shared key to a user plane function, the shared key is used to derive a key for protecting data in an MPQUIC connection between a terminal device and the user plane function, the MPQUIC connection is associated with an MA PDU session, and the data of the MPQUIC connection is transmitted by multiple paths between the terminal device and the user plane function.
[0026] In the above technical solution, the session management function sends a shared key to the user plane function, and the user plane function can establish an MPQUIC connection with the terminal device based on the shared key, thereby achieving security in the process of establishing the MPQUIC connection between the terminal device and the user plane function.
[0027] In a possible implementation, the session management function further sends a first indication to the terminal device, and the first indication is used to indicate that the MPQUIC connection is established by means of a shared key. Exemplarily, the first indication is used to instruct the terminal device to establish an MPQUIC connection with the user plane function by means of a shared key. In the above technical solution, the terminal device can obtain the shared key according to the first indication, and then the terminal device establishes an MPQUIC connection with the user plane function according to the shared key, so as to achieve security in the process of establishing the MPQUIC connection between the terminal device and the user plane function.
[0028] In a possible implementation, before the session management function obtains the shared key from the first function, it also determines to enable the function corresponding to the MPQUIC connection. In a possible implementation, the session management function determines to enable the function corresponding to the MPQUIC connection, specifically, the session management function receives capability information from the terminal device, and determines that the terminal device supports establishing the MPQUIC connection according to the capability information of the terminal device; and / or the session management function determines to support the function corresponding to the MPQUIC connection.
[0029] In the above technical solution, the session management function may first determine the function corresponding to enabling the MPQUIC connection, and then obtain the shared key from the first function, providing the session management function with the judgment conditions for determining whether an MPQUIC connection can be established between the terminal device and the user plane function.
[0030] In a possible implementation, the session management function obtains the shared key from the first function, specifically, the session management function sends a second instruction to the first function, the second instruction is used to instruct the first function to derive the shared key, and the session management function receives the shared key from the first function. Exemplarily, the second instruction is used to instruct the first function to derive the shared key.
[0031] In a possible implementation, after the session management function obtains the shared key from the first function, it also sends the identifier of the shared key to the user plane function. In one example, the identifier of the shared key is determined by the session management function according to the identifier of the MAPDU session, and accordingly, the session management function also sends the identifier of the shared key to the first function, and / or the session management function sends the identifier of the shared key to the terminal device. In another example, the identifier of the shared key is determined by the first function according to the identifier of the MA PDU session, and accordingly, the session management function sends the identifier of the MA PDU session to the first function, and the session management function also receives the identifier of the shared key from the first function.
[0032] In the above technical solution, a method is provided for the session management function to obtain the identifier of the shared key.
[0033] In a possible implementation manner, the identifier of the shared key is an identifier of the MA PDU session.
[0034] In the above technical solution, since the terminal device records the identifier of the MA PDU session, the session management function does not need to send the identifier of the shared key (ie the identifier of the MAPDU session) to the terminal device, which helps to reduce signaling interaction.
[0035] In a possible implementation manner, the first function is an access management function, a security anchor function, or an authentication server function.
[0036] In a fourth aspect, the present application provides a communication method, which is applicable to the process of establishing an MA PDU session for a terminal device. The communication method is performed by a user plane function, which can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the user plane function can be implemented by one device, or by multiple devices, or it can be a functional module within a device.
[0037] The method includes: a user plane function receives a shared key from a session management function. The user plane function derives a key for protecting data in an MPQUIC connection between a terminal device and the user plane function based on the shared key, the MPQUIC connection is associated with an MA PDU session, and the data of the MPQUIC connection is transmitted by multiple paths between the terminal device and the user plane function.
[0038] In one possible implementation, the user plane function also receives an identifier of a shared key from a session management function, and the identifier of the shared key is determined by the session management function or the first function according to the identifier of the MAPDU session. The user plane function stores the identifier of the shared key in correspondence with the shared key. In one possible implementation, the identifier of the shared key is an identifier of the MAPDU session. Exemplarily, the first function is an access management function, a security anchor function, or an authentication server function.
[0039] The technical effects that can be achieved in the fourth aspect can be referred to the description of the beneficial effects in the third aspect, and will not be repeated here.
[0040] In a fifth aspect, the present application provides a communication method, which is applicable to a process of establishing an MA PDU session for a terminal device. The communication method is executed by the terminal device, which may be a terminal device or a module (such as a chip) in the terminal device.
[0041] The method includes: a terminal device receives a first indication from a session management function, the first indication is used to indicate that an MPQUIC connection is established with a user plane function in a shared key manner, and the MPQUIC connection is associated with an MA PDU session. The terminal device derives the shared key according to the first indication, and further, the terminal device derives a key for protecting data in the MPQUIC connection according to the shared key, and the data of the MPQUIC connection is transmitted by multiple paths between the terminal device and the user plane function.
[0042] In a possible implementation, the terminal device also sends capability information of the terminal device to the session management function, where the capability information of the terminal device is used to indicate that the terminal device supports establishing an MPQUIC connection.
[0043] In a possible implementation, the terminal device derives a shared key according to the first indication, and specifically, the terminal device derives a shared key according to the first indication and one or more of the following parameters: an identifier of the terminal device, an identifier of the MA PDU session, and a superior key. Exemplarily, the superior key includes one or more of the following: a security anchor function key, a radio access node (RAN) key, an access management function key, and an authentication server function key.
[0044] In the above technical solution, a method for a terminal device to deduce a shared key is provided.
[0045] In a possible implementation, the identifier of the shared key is determined by the session management function according to the identifier of the MA PDU session, and the terminal device also receives the identifier of the shared key from the session management function.
[0046] In a possible implementation manner, the identifier of the shared key is determined by the terminal device according to the identifier of the MA PDU session, that is, the terminal device also determines the identifier of the shared key according to the identifier of the MA PDU session.
[0047] In a possible implementation manner, the terminal device further stores the correspondence between the identifier of the shared key and the shared key.
[0048] In a possible implementation manner, the identifier of the shared key is an identifier of the MA PDU session.
[0049] The technical effects that can be achieved in the fifth aspect can be referred to the description of the beneficial effects in the third aspect, and will not be repeated here.
[0050] In a sixth aspect, the present application provides a communication method, which is applicable to the process of establishing an MA PDU session for a terminal device. The communication method is performed by a first function, and the first function can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualization function instantiated on a platform (e.g., a cloud platform). Optionally, the first function can be implemented by one device, or by multiple devices, or it can be a functional module within a device.
[0051] The method includes: a first function receives a second indication from a session management function, the first function derives a shared key based on the second indication, and the first function sends the shared key to the session management function, wherein the shared key is used to derive a key for protecting data in an MPQUIC connection between a terminal device and a user plane function, the MPQUIC connection is associated with a MAPDU session, and data of the MPQUIC connection is transmitted by multiple paths between the terminal device and the user plane function.
[0052] In a possible implementation, the identifier of the shared key is determined by the session management function according to the identifier of the MA PDU session, and the first function also receives the identifier of the shared key from the session management function. In a possible implementation, the identifier of the shared key is determined by the first function according to the identifier of the MAPDU session, that is, the first function also receives the identifier of the MA PDU session from the session management function, and determines the identifier of the shared key according to the identifier of the MAPDU session.
[0053] In a possible implementation, the first function derives a shared key according to the second indication. Specifically, the first function derives a shared key according to the second indication and one or more of the following parameters: an identifier of the terminal device, an identifier of the MA PDU session, and an upper-level key. Exemplarily, when the first function is an access management function, the upper-level key may include one or more of the following: a wireless access node key and an access management function key; when the first function is a security anchor function, the upper-level key may be a security anchor function key; when the first function is an authentication server function, the upper-level key may be an authentication server function key.
[0054] In the above technical solution, a method for deriving a shared key by the first function is provided.
[0055] The technical effects that can be achieved in the sixth aspect mentioned above can be referred to the description of the beneficial effects in the third aspect mentioned above, and will not be repeated here.
[0056] In a seventh aspect, the present application provides a communication method, which is performed by a session management function, which can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualization function instantiated on a platform (e.g., a cloud platform). Optionally, the session management function can be implemented by one device, or by multiple devices together, or it can also be a functional module in one device.
[0057] The method includes: a session management function receives a session establishment request from a terminal device, the session establishment request is used to request to establish an MA PDU session of the terminal device. The session management function sends a certificate application instruction to a user plane function according to the session establishment request, the certificate application instruction is used to instruct to request a certificate of the user plane function from a certificate certification authority. The certificate of the user plane function is used for: during the establishment of an MPQUIC connection between the terminal device and the user plane function, the terminal device authenticates the user plane function, the MPQUIC connection is associated with the MA PDU session, and the data of the MPQUIC connection is transmitted by multiple paths between the terminal device and the user plane function.
[0058] In the above technical solution, the session management function sends a certificate application indication to the user plane function, and the certificate application indication is used to instruct the certificate certification authority to request a certificate for the user plane function. The certificate of the user plane function is used for: during the establishment of the MPQUIC connection between the terminal device and the user plane function, the terminal device authenticates the user plane function, so that security is achieved during the process of establishing the MPQUIC connection between the terminal device and the user plane function.
[0059] In a possible implementation, after the session management function sends the certificate application indication to the user plane function, it also receives a confirmation indication from the user plane function, where the confirmation indication is used to indicate that the user plane function successfully requested the certificate of the user plane function. Exemplarily, the session management function determines that the user plane function successfully requested the certificate of the user plane function based on the confirmation indication.
[0060] In the above technical solution, after receiving the confirmation indication, the session management function continues to execute the subsequent MA PDU session establishment process, and then the terminal device can initiate the process of establishing an MPQUIC connection with the user plane function after the MAPDU session establishment process is completed. In this way, it is avoided that the terminal device initiates the process of establishing an MPQUIC connection with the user plane function when the user plane function has not yet requested the certificate of the user plane function, resulting in the problem that the terminal device fails to establish an MPQUIC connection with the user plane function.
[0061] In a possible implementation, the session management function also sends a first certificate request to the certificate authentication authority, the first certificate request includes a public key of the terminal device, the public key of the terminal device is used to generate a certificate of the terminal device, and illustratively, the public key of the terminal device is used by the certificate authentication authority to generate a certificate of the terminal device. The session management function receives the certificate of the terminal device from the certificate authentication authority, and sends the certificate of the terminal device to the terminal device, and the certificate of the terminal device is used to authenticate the terminal device during the establishment of the MPQUIC connection. The above technical solution provides an implementation method in a two-way authentication method.
[0062] In a possible implementation, before the session management function sends the first certificate request to the certificate authentication authority, it also sends a two-way authentication indication to the terminal device, where the two-way authentication indication is used to indicate that the authentication method in the process of establishing the MPQUIC connection is a two-way authentication method. Subsequently, the session management function receives the public key of the terminal device. Exemplarily, the two-way authentication indication can be carried in a radio resource control reconfiguration message.
[0063] In the above technical solution, the session management function sends a two-way authentication instruction to the terminal device, then receives the public key of the terminal device, and requests the certificate of the terminal device from the certificate authority based on the public key of the terminal device. This avoids the situation in which the terminal device also sends the public key of the terminal device to the session management function in the one-way authentication mode, resulting in unnecessary data transmission.
[0064] In a possible implementation, the session establishment request includes a public key of the terminal device. Exemplarily, the certificate of the terminal device may be carried in a radio resource control reconfiguration message.
[0065] In the above technical solution, the terminal device can use the two-way authentication indication by default, and then carry the public key of the terminal device in the session establishment request, so as to avoid the session management function instructing the terminal device to generate the public key of the terminal device, which helps to improve the efficiency of establishing the MPQUIC connection.
[0066] In a possible implementation, the first certificate request also includes an MA PDU session identifier, and the MA PDU session identifier is used to determine the certificate identifier of the terminal device. Exemplarily, the MA PDU session identifier is used by the certificate certification authority to determine the certificate identifier of the terminal device.
[0067] In one possible implementation, the session management function also sends an MA PDU session identifier to the user plane function, and the MA PDU session identifier is used to determine the certificate identifier of the user plane function. Exemplarily, the MA PDU session identifier is used by the certificate certification authority to determine the certificate identifier of the user plane function.
[0068] In the above technical solution, the identifier of the MA PDU session is used to determine the identifier of the certificate, and the certificate is implemented for each MA PDU session, which helps to improve the security of the MPQUIC connection.
[0069] In a possible implementation, before the session management function sends the certificate application indication to the user plane function, it also determines to enable the function corresponding to the MPQUIC connection. Exemplarily, the session management function determines to enable the function corresponding to the MPQUIC connection, specifically, the session management function receives capability information from the terminal device, and determines that the terminal device supports establishing the MPQUIC connection according to the capability information of the terminal device, and / or the session management function determines to support the function corresponding to the MPQUIC connection.
[0070] In the above technical solution, the session management function may first determine the function corresponding to enabling the MPQUIC connection, and then send a certificate application instruction to the user plane function, providing the session management function with the judgment conditions for determining whether an MPQUIC connection can be established between the terminal device and the user plane function.
[0071] In an eighth aspect, the present application provides a communication method, which is executed by a terminal device, and the terminal device may be a terminal device or a module (such as a chip) in the terminal device.
[0072] The method includes: a terminal device sends a session establishment request to a session management function, the session establishment request is used to request the establishment of an MA PDU session of the terminal device; after the MA PDU session is established, the terminal device can establish an MPQUIC connection with a user plane function. Further, during the establishment of the MPQUIC connection between the terminal device and the user plane function, the terminal device receives a certificate of the user plane function from the user plane function, and authenticates the user plane function according to the certificate of the user plane function; wherein the MPQUIC connection is associated with the MA PDU session, and the data of the MPQUIC connection is transmitted by multiple paths between the terminal device and the user plane function.
[0073] In one possible implementation, the terminal device also receives a certificate of the terminal device from the session management function; during the establishment of the MPQUIC connection between the terminal device and the user plane function, the terminal device sends the certificate of the terminal device to the user plane function, and the certificate of the terminal device is used by the user plane function to authenticate the terminal device.
[0074] There are three ways in which the terminal device receives the certificate from the terminal device of the session management function:
[0075] Mode 1, the terminal device uses a two-way authentication mode by default, the terminal device first generates a public key of the terminal device, and then when sending a session establishment request, the public key of the terminal device is carried in the session establishment request, wherein the public key of the terminal device is used to request the certificate of the terminal device from the certificate authentication authority. Accordingly, the session management function can obtain the public key of the terminal device from the session establishment request, request the certificate of the terminal device from the certificate authentication authority according to the public key of the terminal device, and send the certificate of the terminal device to the terminal device. Exemplarily, the PDU session establishment process further includes an access network specific resource establishment (AN-specific resource setup) process, in which the terminal device receives the certificate of the terminal device, and optionally, the terminal device also receives an indication that the MA PDU session establishment is completed. For example, the terminal device receives a radio resource control reconfiguration message, and the radio resource control reconfiguration message includes the certificate of the terminal device. Optionally, the radio resource control reconfiguration message may also carry the indication information.
[0076] Mode 2: The terminal device does not carry the public key of the terminal device in the session establishment request, but generates the public key of the terminal device after receiving the two-way authentication indication from the session management function, that is, the two-way authentication indication is used to indicate that the authentication method in the establishment process of the MPQUIC connection is a two-way authentication method. Exemplarily, the PDU session establishment process further includes an AN-specific resource setup process, in which the terminal device receives the two-way authentication indication, and optionally, the terminal device also receives the indication information of the completion of the MA PDU session establishment, for example, the terminal device receives a radio resource control reconfiguration message, and the radio resource control reconfiguration message includes a two-way authentication indication, and optionally, the radio resource control reconfiguration message may also carry the indication information. Further, the terminal device sends the public key of the terminal device to the session management function, and the public key of the terminal device is used to request the certificate of the terminal device from the certificate certification authority. Accordingly, the session management function can request the certificate of the terminal device from the certificate certification authority based on the certificate of the terminal device, and send the certificate of the terminal device to the terminal device.
[0077] Mode 3, the terminal device does not carry the public key of the terminal device in the session establishment request, but generates the public key of the terminal device after receiving the two-way authentication indication from the session management function, that is, the two-way authentication indication is used to indicate that the authentication method in the establishment process of the MPQUIC connection is a two-way authentication method. Exemplarily, the PDU session establishment process further includes an authentication method notification process, in which the terminal device receives a two-way authentication indication, for example, the terminal device receives a radio resource control reconfiguration message, and the radio resource control reconfiguration message includes a two-way authentication indication. Further, the terminal device sends the public key of the terminal device to the session management function, and the public key of the terminal device is used to request the certificate of the terminal device from the certificate certification authority. Accordingly, the session management function can request the certificate of the terminal device from the certificate certification authority based on the certificate of the terminal device, and send the certificate of the terminal device to the terminal device. Exemplarily, the PDU session establishment process further includes an AN-specific resource setup process, in which the terminal device receives a certificate of the terminal device. Optionally, the terminal device also receives indication information that the MA PDU session establishment is complete. For example, the terminal device receives a wireless resource control reconfiguration message, and the wireless resource control reconfiguration message includes the certificate of the terminal device. Optionally, the wireless resource control reconfiguration message may also carry indication information.
[0078] Exemplarily, the indication information of the completion of the MA PDU session establishment is, for example, PDU session establishment acceptance.
[0079] In a possible implementation, the terminal device also generates a private key of the terminal device, and the private key of the terminal device is used to sign the transmitted message during the establishment of the MPQUIC connection.
[0080] In a possible implementation manner, the terminal device further receives an identifier of a certificate of a user plane function from the user plane function; the identifier of the certificate of the user plane function is determined according to an identifier of the MA PDU session.
[0081] In a possible implementation, the terminal device further sends capability information of the terminal device to the session management function, where the capability information of the terminal device is used to indicate that the terminal device supports establishing an MPQUIC connection.
[0082] The technical effects that can be achieved in the eighth aspect can be referred to the description of the beneficial effects in the seventh aspect, and will not be repeated here.
[0083] In a ninth aspect, the present application provides a communication method, which is performed by a user plane function, which can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the user plane function can be implemented by one device, or by multiple devices together, or it can also be a functional module in one device.
[0084] The method includes: during the process of establishing an MA PDU session of a terminal device, a user plane function receives a certificate application instruction from a session management function, and requests a certificate of the user plane function from a certificate certification authority according to the certificate application instruction. During the process of establishing an MPQUIC connection between the terminal device and the user plane function, the user plane function sends the certificate of the user plane function to the terminal device, and the certificate of the user plane function is used by the terminal device to authenticate the user plane function, that is, the certificate of the user plane function is used by the terminal device to authenticate the user plane function during the process of establishing an MPQUIC connection between the terminal device and the user plane function; wherein the MPQUIC connection is associated with the MA PDU session, and the data of the MPQUIC connection is transmitted by multiple paths between the terminal device and the user plane function.
[0085] In one possible implementation, the user plane function requests a certificate of the user plane function from a certificate authentication authority. Specifically, the user plane function sends a second certificate request to the certificate authentication authority, where the second certificate request is used to request a certificate of the user plane function from the certificate authentication authority; the user plane function receives the certificate of the user plane function from the certificate authentication authority.
[0086] In a possible implementation, during the establishment of the MPQUIC connection between the terminal device and the user plane function, the user plane function also receives a certificate of the terminal device, and authenticates the terminal device according to the certificate of the terminal device.
[0087] In a possible implementation, the second certificate request includes a public key of the user plane function, and the public key of the user plane function is used to determine the certificate of the user plane function. Furthermore, before sending the second certificate request, the user plane function also generates the public key of the user plane function.
[0088] In a possible implementation, the user plane function also generates a private key of the user plane function, and the private key of the user plane function is used to sign the transmitted message during the establishment of the MPQUIC connection.
[0089] In a possible implementation, the second certificate request also includes an MA PDU session identifier, which is used to determine the identifier of the certificate of the user plane function. Furthermore, before sending the second certificate request, the user plane function also receives the MA PDU session identifier from the session management function.
[0090] In a possible implementation, after successfully acquiring the certificate of the user plane function from the certificate authentication authority, the user plane function sends a confirmation indication to the session management function, where the confirmation indication is used to indicate that the user plane function successfully requested the certificate of the user plane function.
[0091] The technical effects that can be achieved in the above-mentioned ninth aspect can refer to the description of the beneficial effects in the above-mentioned seventh aspect, and will not be repeated here.
[0092] In a tenth aspect, an embodiment of the present application provides a communication device,
[0093] The device may be the first terminal device in the above-mentioned first aspect or any possible implementation manner of the first aspect.
[0094] The device may be the first user plane function in the above-mentioned second aspect or any possible implementation manner of the second aspect.
[0095] The device may be the session management function in the third aspect or any possible implementation manner of the third aspect.
[0096] The device may be a user plane function in the fourth aspect or any possible implementation manner of the fourth aspect.
[0097] The device may be a terminal device in the fifth aspect or any possible implementation of the fifth aspect.
[0098] The device may be the first function in the sixth aspect or any possible implementation of the sixth aspect.
[0099] The device may be the session management function in the seventh aspect or any possible implementation of the seventh aspect.
[0100] The device may be a terminal device in the eighth aspect or any possible implementation of the eighth aspect.
[0101] The device may be the user plane function in the ninth aspect or any possible implementation of the ninth aspect.
[0102] The functions of the above communication device can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules or units or means corresponding to the above functions.
[0103] In one possible implementation, the structure of the device includes a processing module and a transceiver module, wherein the processing module is configured to support the device to execute the method in any implementation of any aspect of the first aspect to the ninth aspect. The transceiver module is used to support communication between the device and other communication devices. For example, when the device is the first terminal device in the first aspect or any possible implementation of the first aspect, it can transmit data with the first user plane function. The communication device may also include a storage module, which is coupled to the processing module and stores program instructions and data necessary for the device. As an example, the processing module may be a processor, the communication module may be a transceiver, and the storage module may be a memory. The memory may be integrated with the processor or may be separately provided from the processor.
[0104] In another possible implementation, the structure of the device includes a processor and may also include a memory. The processor is coupled to the memory and can be used to execute computer program instructions stored in the memory so that the device executes the method in any implementation of any aspect of the first to ninth aspects above. Optionally, the device also includes a communication interface, and the processor is coupled to the communication interface. When the device is a network device or a terminal device, the communication interface may be a transceiver or an input / output interface; when the device is a chip included in a network device or a chip included in a terminal device, the communication interface may be an input / output interface of the chip. Optionally, the transceiver may be a transceiver circuit, and the input / output interface may be an input / output circuit.
[0105] In the eleventh aspect, an embodiment of the present application provides a chip system, comprising: a processor and a memory, wherein the processor is coupled to the memory, and the memory is used to store programs or instructions. When the programs or instructions are executed by the processor, the chip system executes a method in any implementation of any aspect from the first to the ninth aspect.
[0106] Optionally, the chip system also includes an interface circuit, which is used to interact with code instructions to the processor.
[0107] Optionally, there may be one or more processors in the chip system, and the processor may be implemented by hardware or software. When implemented by hardware, the processor may be a logic circuit, an integrated circuit, etc. When implemented by software, the processor may be a general-purpose processor implemented by reading software code stored in a memory.
[0108] Optionally, the memory in the chip system may be one or more. The memory may be integrated with the processor or may be separately provided with the processor. Exemplarily, the memory may be a non-transient processor, such as a read-only memory ROM, which may be integrated with the processor on the same chip or may be provided on different chips.
[0109] In the twelfth aspect, the present application provides a computer-readable storage medium, in which a computer program or instruction is stored. When the computer program or instruction is executed by a communication device, the communication device performs the functions of any one of the implementation methods of any one of the above-mentioned first to ninth aspects.
[0110] In a thirteenth aspect, the present application provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are executed by a communication device, it performs the functions of any implementation method of any aspect from the first to the ninth aspect.
[0111] In a fourteenth aspect, an embodiment of the present application provides a communication system,
[0112] The communication system includes: the first terminal device in the first aspect or any possible implementation of the first aspect; and the first user plane function in the second aspect or any possible implementation of the second aspect.
[0113] The communication system includes: the session management function in the third aspect or any possible implementation of the third aspect; the user plane function in the fourth aspect or any possible implementation of the fourth aspect; the terminal device in the fifth aspect or any possible implementation of the fifth aspect; and the first function in the sixth aspect or any possible implementation of the sixth aspect. Or,
[0114] The communication system includes: the session management function in the seventh aspect or any possible implementation of the seventh aspect; the terminal device in the eighth aspect or any possible implementation of the eighth aspect; and the user plane function in the ninth aspect or any possible implementation of the ninth aspect.
[0115] The technical effects that can be achieved in any of the tenth to fourteenth aspects mentioned above can be referred to the description of the beneficial effects in the first to ninth aspects mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0116] Figure 1 A schematic diagram of a communication system architecture;
[0117] Figure 2 It is the first 5G system architecture supported by ATSSS;
[0118] Figure 3 It is the 5G system architecture supported by the second ATSSS;
[0119] Figure 4 It is the 5G system architecture supported by the third ATSSS;
[0120] Figure 5 A protocol stack architecture diagram for an MPQUIC connection;
[0121] Figure 6 A flowchart of the first communication method provided in this application;
[0122] Figure 7 A schematic diagram of the algorithm suite provided for this application;
[0123] Figure 8 A flowchart of a specific implementation of the first communication method provided in this application;
[0124] Fig. 9 A flow chart of the second communication method provided by this application;
[0125] Fig.10 A schematic diagram of the direction of key deduction provided for this application;
[0126] Fig.11 A flowchart of a first specific implementation of the second communication method provided in this application;
[0127] Fig.12 A flowchart of a second specific implementation of the second communication method provided in this application;
[0128] Fig.13A flowchart of a third communication method provided in this application;
[0129] Fig.14 A flowchart of a first specific implementation of the third communication method provided in this application;
[0130] Fig.15 A flowchart of a second specific implementation of the third communication method provided in this application;
[0131] Fig.16 A schematic diagram of the structure of the first communication device provided by the present application;
[0132] Fig.17 A schematic diagram of the structure of a second communication device provided in this application. DETAILED DESCRIPTION
[0133] The following first explains the relevant technical features involved in the embodiments of the present application. It should be noted that these explanations are intended to make the embodiments of the present application easier to understand and should not be regarded as limiting the scope of protection claimed by the present application.
[0134] 1. Transport layer security (TLS protocol)
[0135] TLS is a widely adopted security protocol designed to protect the privacy and data security of Internet communications.
[0136] The main purpose of the TLS protocol is to protect the communication between the client (Client, also known as the Web application) and the server (Server), and to encrypt and protect the integrity of the related communication data.
[0137] The TLS protocol mainly includes the handshake protocol and the record layer protocol. The handshake protocol mainly performs identity authentication and key negotiation between the two parties, and the record layer protocol uses the key negotiated by the handshake protocol to provide security protection for application layer data (including encryption protection and integrity protection).
[0138] In the handshake protocol, the client and server mainly include two rounds of interaction:
[0139] The first round of interaction: Both parties exchange keys.
[0140] The TLS protocol supports two modes of key exchange:
[0141] (1) Pre-shared key exchange modes (psk key exchange modes): The client sends a ClientHello to the server, which carries two extended options: psk_key_share_modes and pre-shared key (PSK). psk_key_share_modes is used to indicate the use of the pre-shared key exchange mode for key negotiation, and pre_shared_key is used to indicate the pre-shared key that the client wants to use. Similarly, the server sends a ServerHello to the client, which also carries the above two extended options. Thus, the client and the server can negotiate the pre-shared key used by the two in the second round of interaction.
[0142] (2) Key sharing modes (key_share modes): The Client generates a temporary private key and a temporary public key for the Client. The Client sends a ClientHello to the Server, which carries the Client's temporary public key. The Server generates a temporary private key and a temporary public key for the Server, and sends a ServerHello to the Client, which carries the Server's temporary public key. Furthermore, the Server obtains the Client's temporary public key from the ClientHello, and generates a shared key based on the Server's temporary private key and the Client's temporary public key. The Client obtains the Server's temporary public key from the ServerHello, and generates a shared key based on the Server's temporary public key and the Client's temporary private key. It can be understood that the shared key generated by the Client is the same as the shared key generated by the Server, that is, the Client and the Server negotiate a shared key to be used by both in the subsequent authentication phase.
[0143] The second round of interaction: both parties perform identity authentication.
[0144] There are currently two ways of identity authentication:
[0145] (1) Pre-shared key authentication: corresponds to the pre-shared key exchange mode in the first round of interaction.
[0146] The client uses the handshake key derived from the pre-shared key to calculate the message authentication code (MAC) of the previous interactive information to form a Finished message 1 (it can be understood that the Finished message 1 includes the MAC calculated by the client), and sends the Finished message 1 to the server. Correspondingly, the server verifies the MAC in the Finished message 1 based on the handshake key derived from its own pre-shared key. If the verification is successful, it is determined that the client and itself have the same pre-shared key.
[0147] Similarly, the server uses the handshake key derived from the pre-shared key to calculate the MAC of the previous interactive information, forms Finished message 2 (it can be understood that Finished message 2 includes the MAC calculated by the server), and sends Finished message 2 to the client. Correspondingly, the client verifies the MAC in Finished message 2 based on the handshake key derived from its own pre-shared key. If the verification passes, it is determined that the server and itself have the same pre-shared key.
[0148] (2) Certificate authentication: corresponds to the key sharing mode in the first round of interaction. Certificate can also be called digital certificate.
[0149] Two-way authentication can include the server authenticating the client, and the client authenticating the server.
[0150] During the process of Server authenticating Client: Client uses the private key corresponding to its certificate to sign the previous interactive information to obtain the signature information (certificate verification), and uses the handshake key derived from the negotiated shared key to calculate the MAC of the previous interactive information to form Finished message 1. Client sends the Client's certificate, signature information and Finished message 1 to Server. Correspondingly, Server verifies the identity of Client based on the Client's certificate and signature information, and determines that the shared key derived by itself is the same as the shared key derived by Client based on the MAC in Finished message 1.
[0151] In the process of Client authenticating Server: Server uses the private key corresponding to its certificate to sign the previous interactive information to obtain the signature information, and uses the handshake key derived from the shared key to calculate the MAC of the previous interactive information to form Finished message 2 (it can be understood that Finished message 2 includes the MAC calculated by the Server), and Server sends the Server's certificate, signature information and Finished message 2 to Client. Correspondingly, Client verifies the identity of Server based on the Server's certificate and signature information, and determines that the shared key derived by itself is the same as the shared key derived by Server based on the MAC in Finished message 2.
[0152] One-way authentication is specifically the Client authenticating the Server, which will not be explained in detail.
[0153] Here, the previous interaction information refers to the information transmitted during the previous interaction between the client and the server. For example, before the client uses the handshake key derived from the pre-shared key to calculate the MAC of the previous interaction information, the client has sent ClientHello to the server, and the server has also sent ServerHello to the client, so the previous interaction information includes ClientHello and ServerHello.
[0154] After two rounds of interaction, both parties can derive a common protection key to protect subsequent application layer data.
[0155] 2. Security Mechanism of Quick User Datagram Protocol Internet Connection (QUIC) Protocol
[0156] The QUIC protocol uses the handshake protocol of the TLS protocol to establish a protection key, which is used to subsequently protect the QUIC data packet. The premise of the TLS protocol handshake protocol is that the client and the server pre-share a key, and the client and the server each authenticate each other's identity based on the pre-shared key; or, the client and the server pre-configure their own certificates, and the client and the server each authenticate each other's identity based on the other's certificate; or, the server unilaterally pre-configures the server's certificate, and the client authenticates the server's identity based on the server's certificate. In other words, it can be understood that before the server and the client transmit data based on the QUIC protocol, they also need to negotiate a pre-shared key, or both or one party pre-configures a certificate to establish a relevant security mechanism.
[0157] 3. 5G Network Architecture
[0158] Figure 1 A schematic diagram of a communication system architecture. Figure 1 The communication system architecture shown may include three parts, namely, the terminal equipment part, the data network (DN) and the operator network part. The functions of some network elements are briefly introduced below.
[0159] The operator network may include one or more of the following network elements:
[0160] Authentication server function (AUSF), network exposure function (NEF), policy control function (PCF), unified data management (UDM), unified data repository (UDR), network repository function (NRF), access and mobility management function (AMF), session management function (SMF), user plane function (UPF), security anchor function (SEAF), authentication repository and processing function (ARPF), and access network, etc.
[0161] In the above-mentioned operator network, the part other than the wireless access network part can be called the core network part. In a possible implementation method, the operator network also includes an application function (AF). Alternatively, the AF may not belong to the operator network, but to a third party. The main function of the AF is to tell the PCF the latest third-party business requirements for a certain application. The PCF will generate corresponding quality of service (QoS) rules based on the requirements to ensure that the services provided by the network meet the requirements of the third party.
[0162] Terminal device, also known as user equipment (UE), is a device with wireless transceiver function. It can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on the water (such as ships); it can also be deployed in the air (such as airplanes, balloons and satellites). Terminal devices can be mobile phones, tablets (pads), computers with wireless transceiver functions, virtual reality (VR) terminals, augmented reality (AR) terminals, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, etc. The terminal device stores long-term keys and related functions. When performing two-way authentication, the terminal device will use the long-term keys and related functions to verify the authenticity of the network. For the convenience of description, the following takes the terminal device as UE as an example. UE can be replaced by the terminal device in this application.
[0163] The above-mentioned UE can establish a connection with the operator network through the interface provided by the operator network (such as N1, etc.), and use the data and / or voice services provided by the operator network. The UE can also access the DN through the operator network, use the operator services deployed on the DN, and / or services provided by a third party. Among them, the above-mentioned third party may be a service provider other than the operator network and the UE, and can provide data and / or voice services to the UE. Among them, the specific form of expression of the above-mentioned third party can be determined according to the actual application scenario, and is not limited here.
[0164] The core network part includes user plane functions and control plane functions.
[0165] The user plane function is UPF. As an interface with the data network, UPF completes functions such as forwarding of user plane data (such as packet data), QoS control, session / flow-level billing statistics, and bandwidth limitation.
[0166] The control plane functions mainly perform user registration and authentication, mobility management, and delivery of data packet forwarding strategies and QoS control strategies to the user plane functions. The control plane functions can be further refined to include other network elements besides UPF, such as AMF, SMF, SEAF, etc.
[0167] AMF mainly performs the registration process when the user accesses, as well as location management, access authentication / authorization and other functions during user mobility. In addition, it is also responsible for transmitting user policies between UE and PCF.
[0168] SMF is mainly responsible for establishing corresponding session connections when users initiate services and providing specific services to users, such as sending data packet forwarding policies and QoS policies to UPF based on the NG4 interface between SMF and UPF.
[0169] SEAF is mainly responsible for initiating authentication requests to AUSF and completing the network side's authentication of UE in the authentication and key agreement (AKA) process. Optionally, SEAF is part of AMF.
[0170] AUSF is mainly responsible for authenticating users and determining the legitimacy of UEs to determine whether to allow UEs to access the network. For example, AUSF can be used to receive authentication requests sent by SEAF; select authentication methods; complete network-side authentication of UEs when using the AKA process; request authentication vectors from ARPF; reply authentication responses to SEAF, generate anchor keys, etc.
[0171] ARPF, stores long-term keys; receives authentication vector requests from AUSF; calculates authentication vectors using long-term keys; and sends authentication vectors to AUSF.
[0172] UDM is mainly responsible for storing UE's subscription data, user access authorization and other functions.
[0173] UDR is mainly responsible for the storage and access of contract data, policy data, application data and other types of data.
[0174] PCF is mainly responsible for issuing business-related policies to AMF or SMF.
[0175] NEF is mainly used to support the opening of capabilities and events. For example, NEF is used to interact with a third party, so that the third party can indirectly interact with network elements within certain 3GPP networks.
[0176] AF mainly transmits the application side's requirements on the network side to PCF, so that PCF generates corresponding policies. AF can be a third-party functional entity or an application service deployed by an operator, such as the Internet Protocol (IP) Multimedia Subsystem (IMS) voice call service.
[0177] NRF can be used to provide network element discovery functions and provide network element information corresponding to the network element type based on requests from other network elements. NRF also provides network element management services, such as network element registration, update, deregistration, and network element status subscription and push.
[0178] DN is a network outside the operator network. The operator network can access multiple DNs. Multiple services can be deployed on DN, which can provide data and / or voice services to UE. For example, DN is the private network of a smart factory. The sensors installed in the workshop of the smart factory can be UEs. The control server of the sensors is deployed in DN, and the control server can provide services for the sensors. The sensors can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions. For another example, DN is the internal office network of a company. The mobile phones or computers of the company's employees can be UEs. The employees' mobile phones or computers can access information, data resources, etc. on the company's internal office network.
[0179] Figure 1 Among them, Nausf, Nnef, Nnrf, Npcf, Nudm, Naf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface serial numbers. The meanings of these interface serial numbers can be found in the meanings defined in the 3GPP protocol and are not limited here.
[0180] It can be understood that the above-mentioned network elements or functions can be network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (for example, a cloud platform). Optionally, the above-mentioned network elements or functions can be implemented by one device, or by multiple devices together, or can be a functional module within a device, which is not limited in the embodiments of the present application. The functions in the present application can also be referred to as functional entities, entities, network elements, functional network elements, etc. For example, the session management function can be referred to as a session management entity, a session management network element, etc. The access and mobility management function (also referred to as the access management function), the user plane function, and the session management function in the embodiments of the present application are respectively Figure 1 The AMF, UPF, and SMF in the figure are used as examples for explanation. Of course, it can also be a network element with the functions of the above-mentioned AMF, UPF, and SMF in future communications such as the sixth generation (6th generation, 6G) network, and the embodiments of the present application are not limited to this.
[0181] The access network is a sub-network of the operator network and is the implementation system between the service nodes and UEs in the operator network. To access the operator network, the UE first passes through the access network and then can connect to the service nodes of the operator network through the access network.
[0182] The access network may include a 3GPP access network and / or a non-3GPP access network, that is, the UE may access the core network through a 3GPP access network and / or a non-3GPP access network. A non-3GPP access network refers to an access network other than 3GPP, such as wireless local area networks (WLAN), wireless fidelity (Wi-Fi) networks, worldwide interoperability for microwave access (WiMAX), fixed networks, etc. The access type of the UE in the 3GPP access network may be referred to as 3GPP access, and the access type of the UE in the non-3GPP access network may be referred to as non-3GPP access. For a schematic diagram of the UE accessing the core network through 3GPP access and non-3GPP access respectively, please refer to the following description of the ASSS function.
[0183] The access equipment of the 3GPP access network may include, but is not limited to: the next generation base station (g nodeB, gNB) in 5G, evolved node B (eNB), radio network controller (RNC), node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (e.g., home evolved nodeB, or home node B, HNB), baseband unit (BBU), transmission point (TRP), transmission point (TP), mobile switching center, etc. The message transmitted between the UE and the access equipment of the 3GPP access network may be a radio resource control (RRC) message, a user plane (UP) message, etc. For the convenience of description, the access equipment of the 3GPP access network may be collectively referred to as a radio access node (RAN).
[0184] The access equipment of the non-3GPP access network may include, but is not limited to: non-3GPP interworking function (N3IWF) equipment, next generation packet data gateway (ngPDG). N3IWF is similar to the evolved packet data gateway (ePDG) in long term evolution (LTE). In 5G, it is used to establish an Internet Protocol security (IPsec) tunnel with the UE when the UE accesses the core network through a non-3GPP access network. For example, the N3IWF device may include a router, etc.
[0185] 4. ATSSS
[0186] In the ATSSS scenario, the UE supports one or more steering functions, such as the multipath transmission control protocol (MPTCP) function, the multipath quick user datagram protocol internet connections (MPQUIC) function, the ATSSS lower layer (ATSSS lower layer, ATSSS-LL) function, etc. When the UE uses one of the above steering functions, specifically, the UE allows the steering, switching and diversion of service traffic across 3GPP access and non-3GPP access according to the ASSSS rules provided by the network.
[0187] The UPF may support the MPTCP proxy function, which communicates with the MPTCP function in the UE by using the MPTCP protocol. The UPF may support the MPQUIC proxy function, which communicates with the MPQUIC function in the UE by using the MPQUIC protocol. The UPF may also support the ASSSS-LL function, which is similar to the ASSSS-LL function defined for the UE. In addition, the UPF supports the performance measurement function (PMF), and the UE may use the PMF to measure the performance of the corresponding access on the user plane of the 3GPP access and / or on the user plane of the non-3GPP access.
[0188] A multi-access protocol data unit (PDU) connection service is implemented in the ATSSS scenario, which can use one 3GPP access network and one non-3GPP access network at the same time to exchange PDUs between the UE and the DN. The multi-access PDU connection service is implemented by establishing an MA PDU session, that is, establishing a PDU session for user plane resources on two access networks. This assumes that the single network slice selection assistance information (S-NSSAI) of the PDU session allows both 3GPP access and non-3GPP access. In other words, an MA PDU session is a PDU session that provides a multi-access PDU connection service, which can use one access at a time or a 3GPP access and a non-3GPP access at the same time.
[0189] A UE may request an MA PDU session when it is registered over a 3GPP access and a non-3GPP access, or when it is registered over only one access. After an MA PDU session is established, when user plane resources are available on both access networks, the UE applies network-provided policies (e.g., ASSS rules) and considers local conditions (e.g., network interface availability, signal loss conditions, user preferences, etc.) to decide how to allocate uplink traffic over the two access networks. Similarly, the UPF anchor for the MA PDU session applies network-provided policies (e.g., N4 rules) and feedback information received from the UE over the user plane (e.g., access network unavailability or availability) to decide how to allocate downlink traffic over the two N3 / N9 tunnels and the two access networks. When user plane resources are available on only one access network, the UE applies ASSS rules and considers local conditions that trigger the establishment or activation of user plane resources on the other access.
[0190] In the same MA PDU session of the UE, the MPTCP function can be used to steer TCP flows, the MPQUIC function can be used to steer user datagram protocol (UDP) flows, and the ATSSS-LL function can be used to steer all other flows. Only one steering function should be used for the same packet flow. All steering functions in the UE should use the same set of ATSSS rules to make ASSS decisions (i.e., decide how to steer, switch, and split traffic). Similarly, all ATSSS decisions in the UPF should be made by applying the same set of N4 rules that support ASSSS. When the MA PDU session is established, the ATSSS rules and the N4 rules that support ASSSS are provided to the UE and UPF, respectively. If the UE supports multiple steering functions, such as MPTCP function and ATSSS-LL function, or MPTCP function, MPQUIC function and ATSSS-LL function, it should use the provided ATSSS rules to decide the steering function to apply to a specific packet flow.
[0191] Combination Figure 1 ,like Figure 2 It is the 5G system architecture supported by ATSSS when the UE is registered to the public land mobile network (PLMN) through 3GPP access and non-3GPP access in non-roaming and roaming with local breakout architecture.
[0192] Combination Figure 1 ,like Figure 3 ATSSS supports the 5G system architecture when the UE is registered to the same visit public land mobile network (V-PLMN) through 3GPP access and non-3GPP access in roaming. In this case, the MPTCP proxy function, MPQUIC proxy function, ASSSS-LL proxy function and PMF are located in the home UPF (H-UPF).
[0193] Combination Figure 1 ,like Figure 4A 5G system architecture that supports ASSSS in roaming situations when the UE is registered to a V-PLMN via 3GPP access and to a home public land mobile network (H-PLMN) via non-3GPP access (i.e., the UE is registered to different PLMNs). In this case, the MPTCP proxy function, MPQUIC proxy function, ASSSS-LL proxy function, and PMF are located in the H-UPF.
[0194] For a description of each network element, see Figure 1 Description of the related embodiments.
[0195] 5. Protocol stack for MPQUIC connection
[0196] See also Figure 5 An exemplary diagram of the protocol stack architecture of an MPQUIC connection is shown. Compared with the traditional 5G user plane protocol stack, the bold frame part is the newly added protocol stack. Taking the UE sending data (i.e., PDU packet) to the UPF as an example, when the PDU packet passes through the MPQUIC layer, the MPQUIC layer encrypts the PDU packet by TLS to obtain the PDU packet after TLS encryption. Subsequently, the PDU packet after TLS encryption is encapsulated into an IP packet via the UDP layer and the Internet Protocol (IP) layer in turn. The UE transmits the IP packet to the RAN through air interface security protection. RAN decrypts and decapsulates layer by layer based on air interface security protection to obtain the GTP-U packet of the GPRS tunneling protocol for user plane (GTP-U) layer. Subsequently, the GTP-U layer encrypts the GTP-U packet with IPsec security protection, and transmits the GTP-U packet encrypted with IPsec security protection to the UPF through the IPsec tunnel. The UPF decrypts the GTP-U packet encrypted with IPsec security protection to obtain the GTP-U packet, and then decrypts it according to the TLS protocol at the MPQUIC layer to obtain the real PDU packet. It can be seen that after the UE and UPF establish an MPQUIC connection, they will go through two layers of security protection, one of which is the MPQUIC layer security protection based on TLS technology (or it is called end-to-end security protection between UE and UPF), and the other is 3GPP security protection, which specifically includes air interface security protection and IPsec security protection.
[0197] Based on the above explanation of the relevant technical features involved in the embodiments of the present application, the embodiments of the present application are described in detail as follows.
[0198] The UE and UPF can establish an MA PDU session, which supports multiple access paths (for example, including paths accessed through 3GPP and paths accessed through non-3GPP), and data can be transmitted on different access paths. The ATSSS function further supports the MPQUIC function. That is, for UEs that support the ATSSS function, the UE can support establishing an MPQUIC connection associated with the MA PDU session with the UPF. In the process of establishing an MPQUIC connection between the UE and the UPF, how to implement a security solution is a technical problem that needs to be solved urgently.
[0199] To this end, the present application provides three communication methods for implementing a security solution in the process of establishing an MPQUIC connection between the UE and the UPF. The MPQUIC connection between the UE and the UPF is referred to as the MPQUIC connection below.
[0200] In the first communication method, the UE and UPF are each pre-configured with the same key (which may be referred to as a pre-configured key), and the UE and UPF may establish an MPQUIC connection based on the pre-configured key.
[0201] In the second communication method, the SMF instructs the first function and the UE to derive the same key (which may be referred to as a shared key), and the SMF also sends the shared key derived by the first function to the UPF. In this way, both the UE and the UPF store the shared key, and the UE and the UPF can establish an MPQUIC connection based on the shared key. The first function may be an AMF, an AUSF, or a SEAF. In this application, the first function may also be referred to as a first entity, a first network element, a first functional entity, a first functional network element, etc.
[0202] In the third communication method, SMF instructs UPF to apply for UPF's certificate from CA, UPF sends UPF's certificate to UE, and UE can authenticate UPF based on UPF's certificate. In one-way authentication, after determining that UPF has passed the authentication, UE can establish an MPQUIC connection with UPF based on the shared key negotiated by both parties. In two-way authentication, SMF also applies for UE's certificate from CA, sends UE's certificate to UE, UE then sends UE's certificate to UPF, and UPF authenticates UE based on UE's certificate. After determining that UPF has passed the authentication, UE establishes an MPQUIC connection with UPF based on the shared key negotiated by both parties; after determining that UE has passed the authentication, UPF establishes an MPQUIC connection with UE based on the shared key negotiated by both parties.
[0203] The first to third communication methods are described in turn as follows:
[0204] See also Figure 6A schematic diagram of a flow chart of a first communication method provided exemplarily:
[0205] Step 601: After the first MA PDU session of the first UE is established, the first UE negotiates with the first UPF to establish a first MPQUIC connection, and the first MPQUIC connection is associated with the first MA PDU session.
[0206] The process of establishing the first MA PDU session of the first UE may refer to the description in the 3GPP TS23.502 protocol.
[0207] The same preconfiguration key is stored in both the first UE and the first UPF. Optionally, the identifier of the preconfiguration key is also stored in the first UE and the first UPF. In one possible manner, when the first UE negotiates with the first UPF to establish a first MPQUIC connection, specifically, when the first UE wishes to use the preconfiguration key to establish the first MPQUIC connection with the first UPF, the first UE sends the identifier of the preconfiguration key to the first UPF. Accordingly, the first UPF determines the preconfiguration key based on the identifier of the preconfiguration key, and then sends the identifier of the preconfiguration key to the first UE when agreeing to use the preconfiguration key to establish the first MPQUIC connection with the first UE. In this way, the two parties agree on the key (i.e., the preconfiguration key) used to establish the first MPQUIC connection.
[0208] Exemplarily, the first UE and the first UPF are the Client and Server in the TLS protocol, respectively. When the first UE wishes to use the preconfigured key to establish the first MPQUIC connection with the first UPF, the first UE sends a first message (e.g., ClientHello) to the first UPF, and the first message carries the identifier of the preconfigured key. Correspondingly, the first UPF receives the first message from the first UE, determines the preconfigured key according to the identifier of the preconfigured key in the first message, that is, learns that the first UE wishes to use the preconfigured key to establish the first MPQUIC connection with the first UPF. Further, the first UPF agrees to use the preconfigured key to establish the first MPQUIC connection with the first UE, and sends a second message (e.g., ServerHello) to the first UE, and the second message carries the identifier of the preconfigured key. It can be considered that the second message is sent by the first UPF in response to the first message. In this way, the first UE and the first UPF negotiate that the two can use the preconfigured key to establish the first MPQUIC connection. This method helps to better compatibility with the existing method of establishing a connection between the Client and the Server in the TLS protocol.
[0209] The first MPQUIC connection is associated with the first MA PDU session. Specifically, the MPQUIC connection is a connection in the first MA PDU session, or the MPQUIC connection is used to transmit data in the first MA PDU session, etc.
[0210] In addition, the first UE and the first UPF can also negotiate the cipher-suite used when the two transmit data. Exemplarily, the first UE sends the identifiers of one or more algorithm suites it supports to the first UPF, and the first UPF selects an algorithm suite it supports from the one or more algorithm suites, and sends the identifier of the selected algorithm suite to the first UE. In this way, the two parties negotiate an algorithm suite that both support and can be used for data transmission. Exemplarily, the algorithm suite includes one or more of an encryption algorithm, an encryption mode, an integrity protection algorithm, and a hash algorithm.
[0211] like Figure 7 For multiple algorithm suites provided as examples in this application, the algorithm suite TLS_CHACHA20_POLY1305_SHA256 is used as an example, where CHACHA20 is an encryption algorithm, POLY1305 is an integrity protection algorithm, SHA256 is a hash algorithm, and the identifier of the algorithm suite is {0x13, 0x03}; TLS_AES_128_GCM_SHA256 is used as an example, where AES_128 is an encryption algorithm, GCM is an encryption mode, SHA256 is a hash algorithm, and the identifier of the algorithm suite is {0x13, 0x01}. For example, if the algorithm suites supported by the first UE are TLS_CHACHA20_POLY1305_SHA256 and TLS_AES_128_GCM_SHA256, then the first UE can send the identifiers of the two algorithm suites, namely {0x13, 0x03} and {0x13, 0x01}, to the first UPF. Correspondingly, if the first UPF determines that it supports TLS_CHACHA20_POLY1305_SHA256, it sends {0x13, 0x03} to the first UE. In this way, the two parties negotiate that they can use the algorithm set TLS_CHACHA20_POLY1305_SHA256 for data transmission.
[0212] Exemplarily, when the first UE sends the identifier of the algorithm suite supported by the first UE to the first UPF, specifically, the first UE sends a first message to the first UPF, and the first message carries the identifier of the algorithm suite supported by the first UE, that is, the first message can carry not only the identifier of the preconfigured key, but also the identifier of the algorithm suite supported by the first UE. When the first UPF sends the identifier of the algorithm suite selected by the first UPF to the first UE, specifically, the first UPF sends the second message to the first UE, and the second message carries the identifier of the algorithm suite selected by the first UPF, that is, the second message can carry not only the identifier of the preconfigured key, but also the identifier of the algorithm suite selected by the first UPF.
[0213] In the present application, the pre-configured key may also be referred to as a pre-shared key (PSK). Optionally, the first message may further include a psk_key_share_modes extension item, which is used to instruct the first UE to perform authentication using a pre-shared key (ie, a pre-configured key).
[0214] In step 602, the first UE derives a key (referred to as a first protection key) for protecting data of the first MPQUIC connection based on a preconfigured key. The data of the first MPQUIC connection is transmitted via multiple paths between the first UE and the first UPF.
[0215] Among them, the first protection key is used for the first UE to transmit the data of the first MPQUIC connection with the first UPF. Specifically, the first protection key includes an uplink protection key and a downlink protection key. The uplink protection key in the first protection key can be used by the first UE to protect the uplink data sent by the first UE to the first UPF. The protection here includes encryption protection and / or integrity protection; the downlink protection key in the first protection key can be used by the first UE to decrypt and / or verify the downlink data received by the first UE from the first UPF. The first protection key is, for example, a 1-round-trip time (RTT) key.
[0216] Alternatively, it can be understood that multiple UPFs located in the same PLMN all store the same preconfiguration key. In this way, the preconfiguration key can be used not only for the first UE to establish a first MPQUIC connection with the first UPF, but also for the first UE to establish a second MPQUIC connection with the second UPF, wherein the first UPF and the second UPF are located in the same PLMN. Optionally, the identifier of the preconfiguration key is also stored in multiple UPFs located in the same PLMN.
[0217] In a specific example, after the second MA PDU session of the first UE is established, the first UE negotiates with the second UPF to establish a second MPQUIC connection, and the second MPQUIC connection is associated with the second MA PDU session. The first UE derives a key for protecting the data of the second MPQUIC connection based on the preconfigured key. Similarly, the second UPF derives a key for protecting the data of the second MPQUIC connection based on the preconfigured key. The data of the second MPQUIC connection is transmitted by multiple paths between the first UE and the second UPF.
[0218] In a specific example, during the establishment of the second MA PDU session of the first UE, the first UE sends a PDU session establishment request to the SMF, and the PDU session establishment request includes a data network name (data network name, DNN) requested by the UE. The data network name is different from the data network name corresponding to the first MA PDU session. The SMF selects the UPF (i.e., the second UPF) that provides services for the data network name based on the data network name requested by the UE, and then establishes a second MA PDU session for the UE.
[0219] Step 603: The first UPF derives a key (referred to as a second protection key) for protecting data of the first MPQUIC connection based on the preconfigured key.
[0220] The second protection key is used for the first UPF to transmit data of the first MPQUIC connection with the first UE. Specifically, the second protection key includes an uplink protection key and a downlink protection key. The uplink protection key in the second protection key can be used by the first UPF to decrypt and / or verify the uplink data received by the first UPF from the first UE; the downlink protection key in the first protection key can be used by the first UPF to protect the downlink data sent by the first UPF to the first UE. The protection here includes encryption protection and / or integrity protection. The second protection key is, for example, a 1-RTT key.
[0221] Or it can be understood that multiple UEs located in the same H-PLMN all store the same preconfiguration key. In this way, the preconfiguration key can be used not only for the first UPF to establish a first MPQUIC connection with the first UE, but also for the first UPF to establish a third MPQUIC connection with the second UE, wherein the first UE and the second UE are located in the same H-PLMN. Optionally, the identifier of the preconfiguration key is also stored in multiple UEs located in the same H-PLMN.
[0222] In a specific example, after the third MA PDU session of the second UE is established, the first UPF negotiates with the second UE to establish a third MPQUIC connection, and the third MPQUIC connection is associated with the third MA PDU session. The first UPF derives a key for protecting the data of the third MPQUIC connection based on the preconfigured key. Similarly, the second UE derives a key for protecting the data of the third MPQUIC connection based on the preconfigured key. The data of the third MPQUIC connection is transmitted by multiple paths between the second UE and the first UPF.
[0223] It should be noted that the pre-configured key can also be used to establish an MPQUIC connection between a third UE and a third UPF, wherein the third UE and the first UE belong to the same H-PLMN, and / or the third UPF and the first UPF belong to the same PLMN. The manner in which the third UE establishes an MPQUIC connection with the third UPF can be referred to the description in steps 601 to 603 above.
[0224] It should also be noted that the present application does not limit the order of step 602 and step 603, that is, the order in which the UE derives the first protection key and the UPF derives the second protection key is not limited. This description can also be applied to the following embodiments, for example, the following Fig.11 In the related embodiments, the order of step 1107 and step 1108 is not limited. For example, Fig.12 In the relevant embodiments, the order of step 1213 and step 1214 is not limited. In addition, there is no strict execution order between the steps that have no time-sequence dependency in the present application.
[0225] Optionally, also include:
[0226] Step 604: The first UE and the first UPF transmit data of the first MPQUIC connection.
[0227] The first UE and the first UPF transmit data of the first MPQUIC connection, which may specifically include: the first UE uses the uplink key in the first protection key to protect the uplink data sent to the first UPF, and accordingly, the first UPF uses the uplink key in the second protection key to decrypt and / or verify the uplink data from the first UE; and / or, the first UPF uses the downlink key in the second protection key to protect the downlink data sent to the first UE, and accordingly, the first UE uses the downlink key in the first protection key to decrypt and / or verify the downlink data from the first UPF.
[0228] Furthermore, when the first UE negotiates an algorithm suite with the first UPF, the first UE and the first UPF can also use the negotiated algorithm suite to transmit data of the first MPQUIC connection. That is, the first UE can use the uplink key in the first protection key and the negotiated algorithm suite to protect the uplink data sent to the first UPF, and the first UPF uses the uplink key in the second protection key and the negotiated algorithm suite to decrypt and / or verify the uplink data from the first UE; and / or, the first UPF uses the downlink key in the second protection key and the negotiated algorithm suite to protect the downlink data sent to the first UE, and the first UE uses the downlink key in the first protection key and the negotiated algorithm suite to decrypt and / or verify the downlink data from the first UPF.
[0229] For example, the algorithm suite is TLS_CHACHA20_POLY1305_SHA256. When the first UE sends uplink data to the first UPF, the first UE encrypts the uplink data according to CHACHA20 and the uplink key in the first protection key, and hashes the uplink data according to POLY1305, SHA256 and the uplink key in the first protection key to obtain MAC, and sends the encrypted uplink data and MAC to the first UPF. The first UPF decrypts the received uplink data according to CHACHA20 and the uplink key in the second protection key, and performs integrity check on the received uplink data according to SHA256, POLY1305 and the uplink key in the second protection key.
[0230] Further, the first MPQUIC connection may include multiple transmission paths, that is, the first MPQUIC connection may be used to transmit data between the first UE and the first UPF through multiple paths. Exemplarily, the first UE may use multiple transmission paths to transmit data at the same time, or may select one transmission path from the multiple transmission paths to transmit data.
[0231] For example, the first MPQUIC connection includes transmission path 1 and transmission path 2. Further, transmission path 1 is a transmission path corresponding to 3GPP access, and transmission path 2 is a transmission path corresponding to non-3GPP access, wherein the devices involved in transmission path 1 may include: a first UE, an access device of a 3GPP access network (such as gNB, eNB, etc.), and a first UPF; the devices involved in transmission path 2 may include: a first UE, a non-3GPP access device (such as N3IWF or ngPDG, etc.), and a first UPF. Alternatively, transmission path 1 is a transmission path corresponding to 3GPP access, and transmission path 2 is also a transmission path corresponding to 3GPP access, wherein the devices involved in transmission path 1 may include: a first UE, an access device 1 of a 3GPP access network, and a first UPF; the devices involved in transmission path 2 may include: a first UE, an access device 2 of a 3GPP access network, and a first UPF. Further, the first UE and the first UPF may transmit data through transmission path 1 and transmission path 2 at the same time, such as using transmission path 1 to transmit data 1, and using transmission path 2 to transmit data 2. Alternatively, the first UE and the first UPF may also select one of transmission path 1 and transmission path 2 to transmit data, such as selecting transmission path 1 to transmit data 3.
[0232] It should be noted that the first MA PDU session includes M QoS flows, each QoS flow can correspond to an MPQUIC connection, and M is an integer greater than or equal to 1. In a specific implementation, after the first MA PDU session of the first UE is established, the first UE establishes M MPQUIC connections, and each MPQUIC connection is used to carry data of UDP traffic in the corresponding QoS flow. For example, the first MA PDU session includes QoS flows 1 to QoS flows 3. After the first MA PDU session of the first UE is established, the first UE establishes MPQUIC connections 1 to MPQUIC connections 3, and the MPQUIC connections 1 to MPQUIC connections 3 correspond to QoS flows 1 to QoS flows 3, respectively, that is, MPQUIC connection 1 can be used to transmit UDP traffic of QoS flow 1, MPQUIC connection 2 can be used to transmit UDP traffic of QoS flow 2, and MPQUIC connection 3 can be used to transmit UDP traffic of QoS flow 3. As an optional method, the first UE establishes N MPQUIC connections, where N is greater than M. It can also be understood that the first MA PDU session is associated with M MPQUIC connections (or N MPQUIC connections), and the M MPQUIC connections (or N MPQUIC connections) include the first MPQUIC connection and the fourth MPQUIC connection. Subsequently, the first UE derives the keys for protecting the data of the first MPQUIC connection and the fourth MPQUIC connection based on the preconfigured keys, and the first UPF derives the keys for protecting the data of the first MPQUIC connection and the fourth MPQUIC connection based on the preconfigured keys. Furthermore, different MPQUIC connections correspond to different protection keys, that is, the key used to protect the data of the first MPQUIC connection is different from the key used to protect the data of the fourth MPQUIC connection.
[0233] Combination Figure 6 Described in the relevant embodiments, Figure 8 This is a specific implementation of the first communication method exemplarily provided in the present application. In this specific implementation, the first UE and the first UPF can negotiate through the negotiation method in the TLS protocol, and the first UE and the first UPF are the Client and Server in the TLS protocol, respectively. It can be considered that the following steps 801 to 806 are a specific implementation method of step 601. After the first UE and the first UPF negotiate through the negotiation method in the TLS protocol, the first UE and the first UPF establish a first MPQUIC connection.
[0234] See also Figure 8 Medium flow chart:
[0235] Step 801: After the first MA PDU session of the first UE is established, the first UE sends a first message to the first UPF, and correspondingly, the first UPF receives the first message from the first UE.
[0236] Exemplarily, the first message carries the identifier of the algorithm suite supported by the first UE, the identifier of the preconfigured key, and psk_key_share_modes. The identifier of the preconfigured key is, for example, 0x00. The identifier of the algorithm suite supported by the first UE is, for example, {0x13, 0x03}.
[0237] For the description of the first MA PDU session, the pre-configured key, and the identifier of the pre-configured key, refer to the description in the above step 601.
[0238] Step 802: The first UPF sends a second message to the first UE, and correspondingly, the first UE receives the second message from the first UPF.
[0239] In a specific implementation, the first UPF obtains the identifier of the algorithm suite supported by the first UE, the identifier of the preconfigured key, and psk_key_share_modes from the first message, wherein the identifier of the preconfigured key is 0x00 and the identifier of the algorithm suite is {0x13, 0x03}. Based on psk_key_share_modes and the identifier of the preconfigured key 0x00, the first UPF determines that the first UE wishes to establish a first MPQUIC connection with the first UPF using the preconfigured key, and the identifier of the preconfigured key used is 0x00. The first UPF also selects the algorithm suite supported by the first UPF from the identifiers of the algorithm suites supported by the first UE, for example, the identifier of the selected algorithm suite is {0x13, 0x03}. The first UPF sends a second message to the first UE, and the second message includes the identifier of the preconfigured key 0x00 and the identifier of the algorithm suite {0x13, 0x03}.
[0240] In step 801 and step 802, the first UE and the first UPF negotiate the preconfigured keys and algorithm suites used when establishing the first MPQUIC connection. Furthermore, the first UE authenticates the first UPF (see step 803 to step 804) to determine whether the preconfigured key used by the first UPF is consistent with the preconfigured key used by itself; and the first UPF authenticates the first UE (see step 805 to step 806) to determine whether the preconfigured key used by the first UE is consistent with the preconfigured key used by itself.
[0241] Step 803: The first UPF sends a third message (eg Finished message 2) to the first UE, and correspondingly, the first UE receives the third message from the first UPF, wherein the third message carries the second MAC.
[0242] Exemplarily, the first UPF derives the second handshake key based on the preconfigured key, and then determines the second MAC based on the second preceding interaction information and the second handshake key. The second preceding interaction information includes the first message and the second message, that is, the second preceding interaction information includes the identifier of the algorithm suite supported by the first UE, the identifier of the preconfigured key, psk_key_share_modes, the identifier of the algorithm suite selected by the first UPF, and the identifier of the preconfigured key.
[0243] Step 804: The first UE authenticates the first UPF according to the third message, the second previous interaction information and the first handshake key. In the present application, authenticating the first UPF may specifically be authenticating the identity of the first UPF.
[0244] In a specific implementation, the first UE derives the first handshake key based on the preconfigured key. The first UE obtains the second MAC from the third message, and then authenticates the second MAC based on the second previous interaction information and the first handshake key. When the second MAC authentication passes, the first UE determines that the first UPF authentication passes, that is, it determines that the preconfigured key used by the first UPF is consistent with the preconfigured key used by itself. When the second MAC authentication fails, the first UE determines that the first UPF authentication fails, that is, it determines that the preconfigured key used by the first UPF is inconsistent with the preconfigured key used by itself.
[0245] Step 805: After determining that the first UPF is authenticated, the first UE sends a fourth message (eg Finished message 1) to the first UPF, where the fourth message carries the first MAC. Accordingly, the first UPF receives the fourth message from the first UE.
[0246] In a specific implementation, the first UE determines the first MAC based on the first preceding interaction information and the first handshake key. The first preceding interaction information includes the second message and the first message, that is, the first preceding interaction information includes the identifier of the algorithm suite supported by the first UE, the identifier of the preconfigured key, psk_key_share_modes, the identifier of the algorithm suite selected by the first UPF, and the identifier of the preconfigured key. In addition, the first preceding interaction information may also include a third message, namely, the second MAC.
[0247] Step 806: The first UPF authenticates the first UE according to the fourth message, the first previous interaction information and the second handshake key. In the present application, authenticating the first UE may specifically be identity authentication of the first UE.
[0248] In a specific implementation, the first UPF obtains the first MAC from the fourth message, and then authenticates the first MAC based on the first previous interaction information and the second handshake key. When the first MAC authentication passes, the first UPF determines that the first UE authentication passes, that is, it determines that the preconfigured key used by the first UE is consistent with the preconfigured key used by itself. When the first MAC authentication fails, the first UPF determines that the first UE authentication fails, that is, it determines that the preconfigured key used by the first UE is inconsistent with the preconfigured key used by itself.
[0249] Step 807: The first UE derives a first protection key according to the preconfigured key.
[0250] For specific implementation, please refer to the description in the above step 602.
[0251] Step 808: The first UPF derives a second protection key based on the preconfigured key.
[0252] For specific implementation, please refer to the description in the above step 603.
[0253] Step 809: The first UE and the first UPF transmit data of the first MPQUIC connection.
[0254] For specific implementation, please refer to the description in the above step 604.
[0255] It can be understood that the embodiment of the present application is explained by taking the first UE first authenticating the first UPF, and the first UPF then authenticating the first UE as an example. Of course, it can also be that the first UPF first authenticates the first UE, and the first UE then authenticates the first UPF. Exemplarily, the first UE determines the first MAC based on the first preceding interaction information and the first handshake key, and sends a fourth message to the first UPF, and the fourth message carries the first MAC. The first UPF obtains the first MAC from the fourth message, and authenticates the first MAC based on the first preceding interaction information and the second handshake key, that is, authenticates the first UE. Further, after the first UPF determines that the first UE is authenticated, it determines the second MAC based on the second preceding interaction information and the second handshake key, and sends a third message to the first UE, wherein the third message carries the second MAC. Correspondingly, the first UE obtains the second MAC from the third message, and authenticates the second MAC based on the second preceding interaction information and the first handshake key, that is, authenticates the first UPF. After the first UE determines that the first UPF is authenticated, the first UE and the first UPF establish a first MPQUIC connection.
[0256] It should be explained that after the above step 602 (or step 807), it can be considered that the first UE has established a first MPQUIC connection with the first UPF according to the preconfigured key; after the above step 603 (or step 808), it can be considered that the first UPF has established a first MPQUIC connection with the first UE according to the preconfigured key. Alternatively, in the above step 804, the first UE determines that the first UPF has passed the authentication, which can be considered that the first UE has established a first MPQUIC connection with the first UPF according to the preconfigured key; in the above step 806, the first UPF determines that the first UE has passed the authentication, which can be considered that the first UPF has established a first MPQUIC connection with the first UE according to the preconfigured key. This description can also be applied to the second communication method and the third communication method described below. The difference is that in the second communication method and the third communication method, the key used by the UE and the UPF when establishing the MPQUIC connection is a shared key, not a preconfigured key; and in the second communication method and the third communication method, there is no need to distinguish between the first UE, the second UE and the third UE, and there is no need to distinguish between the first UPF, the second UPF and the third UPF.
[0257] In the above-mentioned first communication method, after the first MA PDU session of the first UE is established, the first UE and the first UPF establish a first MPQUIC connection according to the preconfigured key, and security is achieved in the process of establishing the first MPQUIC connection between the first UE and the first UPF.
[0258] Furthermore, since the first MA PDU session has been established, if user plane security protection is enabled, the messages transmitted by the first UE and the first UPF during the negotiation process are already based on 3GPP security protection. Specifically, in the above step 601, the identifier of the pre-configured key sent by the first UE to the first UPF, or the identifier of the pre-configured key sent by the first UPF to the first UE, are all based on 3GPP security protection. Alternatively, in the above steps 801 to 805, the first message, the second message, the third message, and the fourth message are all based on 3GPP security protection. For details, see Figure 5 This is described in the relevant embodiments. This helps to improve the security of message transmission.
[0259] And because 3GPP security protection has been established, the embodiment of the present application sets the first UE and the first UPF to use the preconfigured key to establish the MPQUIC connection, so as to avoid unnecessary interactions and calculations when the first UE and the first UPF establish the MPQUIC connection. The preconfigured key is not only used for the first UE to establish the first MPQUIC connection with the first UPF, but also used for the first UE to establish the second MPQUIC connection with the second UPF. The first UPF and the second UPF are located in the same PLMN, that is, the preconfigured key can be used for the UE to establish the MPQUIC connection with multiple UPFs located in the same PLMN, thus reducing the complexity of the UE to establish the MPQUIC connection. In addition, the preconfigured key is not only used for the first UPF to establish the first MPQUIC connection with the first UE, but also used for the first UPF to establish the third MPQUIC connection with the second UE. The first UE and the second UE are located in the same H-PLMN, that is, the preconfigured key can be used for the UPF to establish the MPQUIC connection with multiple UEs located in the same H-PLMN, thus reducing the complexity of the UPF to establish the MPQUIC connection.
[0260] See also Fig. 9 The schematic flow chart of the second communication method provided exemplarily, the second communication method can be specifically applied to the process of establishing an MA PDU session for a UE. The process of establishing an MA PDU session can be described in the 3GPP TS23.502 protocol.
[0261] Step 901, SMF obtains a shared key from the first function.
[0262] The shared key is used to derive the key used to protect the data in the MPQUIC connection between the UE and the UPF. The role of the shared key is similar to that of the preconfigured key in the first communication method and will not be repeated here. The MPQUIC connection is associated with the MA PDU session. The data of the MPQUIC connection is transmitted by multiple paths between the UE and the UPF. For the relationship between the MPQUIC connection, the MA PDU session, the MPQUIC connection and the MA PDU session, refer to the description of the relationship between the first MPQUIC connection, the first MA PDU session, the first MPQUIC connection and the first MA PDU session in the first communication method.
[0263] The first function may be AMF, SEAF or AUSF.
[0264] In one possible implementation, the SMF obtains a shared key from the first function, specifically, the SMF sends a second indication to the first function. The first function receives the second indication from the SMF, derives the shared key according to the second indication, and sends the shared key to the SMF. Accordingly, the SMF receives the shared key from the first function. The second indication is used to instruct the first function to derive the shared key. Exemplarily, the second indication may be a key derivation indication, an end-to-end key derivation indication from UE to UPF, an MPQUIC key derivation indication, a pre-shared key mode (PSK mode), etc. Exemplarily, the second indication is included in the key derivation request.
[0265] In one possible implementation, the SMF sends a second indication and a first parameter to the first function, and the first function determines that a shared key needs to be derived according to the second indication, and then derives the shared key according to the first parameter and the superior key. Exemplarily, the first parameter may be included in the key derivation request. The first parameter includes at least one or more of the following: an identifier of the UE, an identifier of the MA PDU session, and an identifier of the shared key.
[0266] Further, when the first function is AMF, the upper key includes at least one or more of the following: RAN key, AMF key, that is, AMF can derive the shared key from the AMF key. For details, see Fig.10 Alternatively, the AMF can also derive the shared key from the RAN key. For details, see Fig.10 In the second direction; when the first function is SEAF, the superior key can be the SEAF key, that is, SEAF can derive the shared key from the SEAF key. For details, see Fig.10 Direction 3: When the first function is AUSF, the superior key may be the AUSF key, that is, AUSF can derive the shared key from the AUSF key. For details, see Fig.10 In the direction of four. Fig.10 In, K AUSF , K SEAF , K AMF , K gNB , K NASenc , K NASint They are AUSF key, SEAF key, AMF key, gNB key (i.e. RAN key), non-access stratum (NAS) encryption protection key, and NAS integrity protection key. The arrow indicates the direction of deduction.
[0267] In the present application, the SMF can not only instruct the first function to derive a shared key, but also instruct the UE to derive a shared key. Exemplarily, the SMF sends a first indication to the UE, and accordingly, the UE receives the first indication from the SMF, and the UE derives a shared key according to the first indication. Among them, the first indication is used to instruct the UE to establish an MPQUIC connection with the UPF using a shared key, or it is understood that the first indication is used to instruct the UE to derive a shared key. Exemplarily, the first indication can be a key derivation indication, an end-to-end key derivation indication from the UE to the UPF, an MPQUIC key derivation indication, a pre-shared key mode, etc.
[0268] In one possible implementation, the SMF sends a first indication to the UE, which may be, specifically, during the MA PDU session establishment process of the UE, the SMF sends the first indication to the UE. In a possible example, the SMF sends an N1N2 message transfer to the AMF, and the N1N2 message transfer includes the first indication; the AMF responds to the N1N2 message transfer and sends an N2 PDU session request to the RAN, and the N2 PDU session request includes the first indication; the RAN responds to the N2 PDU session request and sends an RRC reconfiguration message to the UE, and the RRC reconfiguration message includes the first indication.
[0269] In one possible implementation, the UE determines that it needs to derive a shared key based on the first indication, and then derives the shared key based on the first parameter and the superior key. The first parameter includes at least one or more of the following: the UE identifier, the MA PDU session identifier, and the shared key identifier. Here, since the UE stores the UE identifier and the MAPDU session identifier, when the first parameter includes the UE's stored parameters, the SMF may not send the first parameter to the UE. The superior key includes at least one or more of the following: SEAF key, RAN key, AMF key. For the specific deduction method of the AUSF key, please refer to the method of deriving the shared key from the above-mentioned first function.
[0270] In one possible implementation, before the SMF obtains the shared key from the first function and / or before the SMF sends the first indication to the UE, the SMF may determine to enable the function corresponding to the MPQUIC connection.
[0271] Exemplarily, when SMF determines to enable the function corresponding to the MPQUIC connection, it may be one of the following three examples:
[0272] Example 1: The UE sends the UE capability information to the SMF, where the UE capability information is used to indicate that the UE supports establishing an MPQUIC connection. The SMF receives the capability information from the UE and determines, based on the UE capability information, that the UE supports establishing an MPQUIC connection.
[0273] Among them, the UE capability information may specifically be the UE's ATSSS capability, and the ASSSS capability includes the MPQUIC capability.
[0274] Exemplarily, the UE sends a session establishment request to the SMF, and correspondingly, the SMF receives the session establishment request from the UE, and the session establishment request carries the capability information of the UE. Further, the UE sends a session establishment request to the SMF, and specifically, the UE sends a session establishment request to the AMF, the AMF selects the SMF, the AMF sends a session context request to the SMF, and correspondingly, the SMF receives the session context request from the AMF, wherein the session context request carries the session establishment request, that is, the session context request carries the capability information of the UE. The session establishment request is specifically a PDU session establishment request (PDU session establishment request), and the session context request is specifically a PDU session create session management context request (PDU session create SM context request), and this description is also applicable to other embodiments.
[0275] Example 2: SMF determines to support the function corresponding to the MPQUIC connection. Alternatively, SMF enables the function corresponding to the MPQUIC connection, that is, the state of the function corresponding to the MPQUIC connection of SMF is "enabled".
[0276] Example 3: The UE sends the UE capability information to the SMF, and the SMF receives the capability information from the UE, and determines, based on the UE capability information, that the UE supports establishing an MPQUIC connection and supports the functions corresponding to the MPQUIC connection. For details, see Example 1 and Example 2.
[0277] Step 902: SMF sends a shared key to UPF, and UPF receives the shared key from SMF.
[0278] In one possible implementation, the SMF also sends the shared key identifier to the UPF, and accordingly, the UPF receives the shared key identifier from the SMF, and the UPF stores the shared key identifier and the shared key in correspondence. Exemplarily, the SMF sends the shared key and the shared key identifier to the UPF via a message, and the message may specifically be an N4 session establishment request.
[0279] The identifier of the shared key may be determined by the identifier of the MAPDU session, and specifically may be as follows: Example a and Example b.
[0280] Example a: The identity of the shared key is generated by the first function and the UE respectively.
[0281] For the first function, the SMF sends the identifier of the MAPDU session to the first function, wherein the identifier of the MAPDU session may be included in the first parameter or may be sent to the first function as a separate parameter. After the first function derives the shared key, it may also generate the identifier of the shared key according to the identifier of the MA PDU session, and send the identifier of the shared key to the SMF. For the UE, after the UE derives the shared key, it may also generate the identifier of the shared key according to the identifier of the MA PDU session, and store the shared key and the identifier of the shared key.
[0282] The first function and the UE use the same determination method to determine the identifier of the shared key, that is, the identifiers of the shared key determined by the two are the same. Exemplarily, the first function and the UE determine the identifier of the MA PDU session as the identifier of the shared key.
[0283] In example b, the shared key identifier is generated by SMF.
[0284] The SMF generates a shared key identifier according to the identifier of the MA PDU session, and sends the shared key identifier to the first function and the UE respectively, wherein the shared key identifier may be included in the first parameter or may be sent as a separate parameter. Exemplarily, the SMF determines the identifier of the MA PDU session as the shared key identifier. It is worth noting that in this case, the SMF only needs to send the shared key identifier to the first function, and does not need to send the shared key identifier to the UE, which helps to reduce signaling interaction.
[0285] As mentioned above, both the UE and UPF can obtain the shared key, or both can obtain the shared key and the identifier of the shared key. The UE and UPF can negotiate to establish an MPQUIC connection based on the shared key or according to the shared key and the identifier of the shared key. For specific instructions, please refer to the description in the above step 601, and the "pre-configured key" can be replaced with "shared key" for understanding.
[0286] In step 903, the UPF derives a key (i.e., a second protection key) for protecting data in the MPQUIC connection between the UE and the UPF based on the shared key, and the MPQUIC connection is associated with the MAPDU session. For details, see the description in step 603.
[0287] Optionally, the UE further derives a key (ie, a first protection key) for protecting data in the MPQUIC connection based on the shared key. For details, see the description in step 602.
[0288] Optionally, the UE and UPF transmit data of the MPQUIC connection, for details, please refer to the description in step 604.
[0289] Combination Fig. 9 Described in the relevant embodiments, Fig.11 The first specific implementation of the second communication method provided as an example in this application. In this first specific implementation, an interaction mode between SMF, UE, the first function and UPF devices is provided.
[0290] See also Fig.11 Medium flow chart:
[0291] Step 1101: SMF sends a second indication to the first function, and correspondingly, the first function receives the second indication from the SMF.
[0292] Optionally, after determining to enable the function corresponding to the MPQUIC connection, the SMF sends a second indication to the first function.
[0293] Step 1102: The first function derives a shared key according to the second instruction.
[0294] Step 1103: The first function sends a shared key to the SMF, and correspondingly, the SMF receives the shared key from the first function.
[0295] Step 1104, SMF sends a shared key to UPF, and correspondingly, UPF receives the shared key from SMF.
[0296] Optionally, the SMF also sends an identifier of the shared key to the UPF, where the identifier of the shared key is determined according to the identifier of the MA PDU session. Optionally, the UPF stores the shared key and the identifier of the shared key.
[0297] Step 1105: The SMF sends a first indication to the UE, and correspondingly, the UE receives the first indication from the SMF.
[0298] Step 1106: The UE derives a shared key according to the first instruction.
[0299] Step 1107: The UE derives a first protection key based on the shared key.
[0300] Step 1108: UPF derives a second protection key based on the shared key.
[0301] Step 1109, UE and UPF transmit data of MPQUIC connection.
[0302] Understandably, Fig.11 For any content not described in detail in Fig. 9 Described in the relevant embodiments. Specifically, for the contents not described in detail in steps 1101 to 1103, refer to the description in step 901. For the contents not described in detail in step 1104, refer to the description in step 902. For the contents not described in detail in steps 1105 and 1106, refer to the description in step 901. For the contents not described in detail in steps 1107 to 1109, refer to the description in step 903. The order of steps 1107 and 1108 is not limited, and the order of steps 1101 and 1105 is not limited.
[0303] Combination Fig. 9 and Fig.11 Described in the relevant embodiments, Fig.12 The second specific implementation of the second communication method provided by the present application is as follows. In the second specific implementation, the first function is specifically AMF, which is explained in conjunction with the establishment process of the MA PDU session.
[0304] Step 1201, the UE sends a PDU session establishment request to the AMF, and accordingly, the AMF receives the PDU session establishment request from the UE.
[0305] Among them, the PDU session establishment request is an example of a session establishment request.
[0306] The PDU session establishment request carries the PDU session identifier, request type and UE's ASSSS capability (an example of UE capability information). Among them, the request type is MA PDU request (MA PDU request), which indicates that the PDU session requested by the UE is an MA PDU session. Correspondingly, the PDU session identifier is the identifier of the MA PDU session. The UE's ATSSS capability includes MPQUIC capability to indicate that the UE supports the MPQUIC capability. Optionally, the UE's ATSSS capability also includes MPTCP capability and ASSSS-LL capability.
[0307] Step 1202: AMF selects SMF. Specifically, AMF selects SMF that supports ATSSS capability.
[0308] Step 1203, AMF sends a PDU session creation session management context request to SMF, and the PDU session creation session management context request carries a PDU session establishment request. Correspondingly, SMF receives the PDU session creation session management context request from AMF.
[0309] Among them, the PDU session creation session management context request is an example of a session context request.
[0310] Step 1204, SMF creates a session management context request based on the PDU session, and determines to enable the function corresponding to the MPQUIC connection.
[0311] Specifically, SMF obtains the PDU session establishment request from the PDU session creation session management context request, and then obtains the request type and the UE's ATSSS capability from the PDU session establishment request. SMF determines that the UE requests a MAPDU session based on the request type, and then queries the UDM for the UE's corresponding subscription information, and determines that the UE has subscribed to the MA PDU session based on the UE's corresponding subscription information. Furthermore, SMF also determines that the UE supports the establishment of an MPQUIC connection based on the UE's ATSSS capability, and determines that it enables the corresponding functions of the MPQUIC connection. Therefore, SMF determines to enable the corresponding functions of the MPQUIC connection.
[0312] Step 1205: SMF sends a key derivation request to AMF, and accordingly, AMF receives the key derivation request from SMF. The key derivation request carries a second indication and a first parameter, wherein the first parameter includes the identifier of the UE and the identifier of the MA PDU session, the identifier of the UE and the identifier of the MAPDU session can be used by the AMF to derive a shared key, and the identifier of the MA PDU session can be used as the identifier of the shared key.
[0313] Step 1206: AMF sends the shared key and the shared key identifier to SMF. Correspondingly, SMF receives the shared key and the shared key identifier from AMF.
[0314] Among them, when AMF sends the shared key and the identifier of the shared key to SMF, specifically, AMF obtains the second indication and the first parameter from the key derivation request, determines that the shared key needs to be deduced according to the second indication, and then obtains the UE identifier and the MA PDU session identifier from the first parameter, and derives the shared key according to the UE identifier, the MA PDU session identifier, and the superior key. AMF also determines the MA PDU session identifier as the shared key identifier, and AMF sends the shared key and the MA PDU session identifier to SMF.
[0315] Step 1207: SMF sends an N4 session establishment request to UPF, where the N4 session establishment request includes a shared key and an identifier of the shared key. Accordingly, UPF receives the N4 session establishment request from SMF.
[0316] Step 1208: UPF stores the shared key and the shared key identifier. In addition, UPF also establishes an N4 session with SMF.
[0317] Step 1209, SMF sends an N1N2 message transmission to AMF, and accordingly, AMF receives an N1N2 message transmission from SMF, where the N1N2 message transmission includes a first indication.
[0318] Exemplarily, the N1N2 message transmission also includes ATSSS rules, which can be obtained by the SMF from the PCF. The ATSSS rules can be used by the UE to decide the steering function to be applied to a specific data packet flow (such as using the MPQUIC function after establishing the MPQUIC connection).
[0319] Step 1210: AMF sends an N2 PDU session request to RAN. Correspondingly, RAN receives the N2 PDU session request from AMF, and the N2 PDU session request includes the first indication. Exemplarily, the N2 PDU session request also includes ATSSS rules.
[0320] Step 1211, the RAN sends an RRC reconfiguration message to the UE, and correspondingly, the UE receives the RRC reconfiguration message from the RAN, the RRC reconfiguration message including the first indication. Exemplarily, the RRC reconfiguration message also includes the ATSSS rule.
[0321] In a specific example, the MA PDU session establishment process further includes an AN-specific resource setup process. In the AN-specific resource setup process, the RAN sends an RRC reconfiguration message to the UE. The RRC reconfiguration message also includes indication information that the MA PDU session establishment is completed, such as PDU session establishment accept.
[0322] In step 1212, the UE determines that a shared key needs to be derived according to the first indication in the RRC reconfiguration message, and then obtains the UE identifier and the MAPDU session identifier, and derives the shared key according to the UE identifier, the MAPDU session identifier, and the superior key. Further, the UE stores the shared key and the shared key identifier. It can be understood that the key derivation method used by the UE is the same as the key derivation method used by the AMF in step 1206.
[0323] Step 1213: The UE derives a first protection key based on the shared key.
[0324] Step 1214: UPF derives a second protection key based on the shared key.
[0325] Step 1215, UE and UPF transmit data of MPQUIC connection.
[0326] Understandably, Fig.12 For any content not described in detail in Fig. 9 For example, the contents not described in detail in steps 1204 to 1206 can refer to the description in step 901. The contents not described in detail in steps 1207 to 1208 can refer to the description in step 902. The contents not described in detail in steps 1209 to 1212 can refer to the description in step 901. The contents not described in detail in steps 1213 to 1215 can refer to the description in step 903.
[0327] In the second communication method described above, the SMF instructs the first function and the UE to derive the same shared key, and the SMF also sends the shared key derived by the first function to the UPF. In this way, the same shared key is stored in both the UPF and the UE. The UPF and the UE can establish an MPQUIC connection based on the same shared key, thereby achieving security in the process of establishing an MPQUIC connection between the UE and the UPF.
[0328] See also Fig.13 The schematic diagram of the process of the third communication method provided exemplarily, the third communication method can be specifically applied to the process of establishing a MAPDU session for a UE. The process of establishing a MAPDU session can be described in the 3GPP TS23.502 protocol.
[0329] Step 1301, the UE sends a session establishment request to the SMF, and correspondingly, the SMF receives the session establishment request from the UE. The session establishment request is used to request to establish the MA PDU session of the UE.
[0330] The way in which the UE sends a session establishment request to the SMF can be found in the description in step 901.
[0331] The session establishment request includes a request type, and the request type is an MA PDU request, which indicates that the PDU session requested by the UE is an MA PDU session, or it is understood that the UE requests to establish an MA PDU session. The session establishment request is specifically a PDU session establishment request. For a description of the PDU session establishment request, please refer to the description in step 1201.
[0332] Step 1302: SMF sends a certificate application instruction to UPF according to the session establishment request. Correspondingly, UPF receives the certificate application instruction from SMF.
[0333] The certificate application indication is used to indicate requesting the certificate of the UPF. Specifically, the certificate application indication is used to indicate requesting the certificate of the UPF from the certificate certification authority.
[0334] In one possible manner, the SMF determines, based on the session establishment request, that the PDU session requested by the UE is an MA PDU session, and then sends a certificate application indication to the UPF. Exemplarily, the certificate application indication is sent to the UPF during the process of establishing an N4 session between the SMF and the UPF, and the certificate application indication is carried in the N4 session establishment request. Exemplarily, the N4 session establishment request includes an information element (IE), which is a certificate application indication, that is, the IE is used to indicate the request for a certificate from the UPF.
[0335] In one possible approach, before the SMF sends a certificate application indication to the UPF, it may also determine to enable the function corresponding to the MPQUIC connection.
[0336] Exemplarily, when SMF determines to enable the function corresponding to the MPQUIC connection, it may be one of the following three examples:
[0337] Example 1: The UE sends the UE capability information to the SMF, where the UE capability information is used to indicate that the UE supports establishing an MPQUIC connection. The SMF receives the capability information from the UE and determines, based on the UE capability information, that the UE supports establishing an MPQUIC connection.
[0338] Example 2: SMF determines that the functions corresponding to the MPQUIC connection are supported.
[0339] Example 3: The UE sends the UE capability information to the SMF, and the SMF receives the capability information from the UE. According to the UE capability information, the SMF determines that the UE supports establishing an MPQUIC connection and supports the functions corresponding to the MPQUIC connection.
[0340] For detailed descriptions of Examples 1 to 3, please refer to the descriptions of Examples 1 to 3 in step 901 .
[0341] In addition, the UE's capability information may be included in the session establishment request. In this case, after receiving the session establishment request, the SMF can not only determine that the PDU session requested by the UE is an MA PDU session, but also determine, based on the UE's capability information, that the UE supports the establishment of an MPQUIC connection (i.e., Example 1), and then send a certificate application indication to the UPF. Alternatively, after receiving the session establishment request, the SMF can not only determine that the PDU session requested by the UE is an MA PDU session, but also determine, based on the UE's capability information, that the UE supports the establishment of an MPQUIC connection, and that it supports the functions corresponding to the MPQUIC connection (i.e., Example 3), and then send a certificate application indication to the UPF.
[0342] Step 1303: UPF requests the UPF certificate from the CA according to the certificate application instructions.
[0343] Among them, the UPF certificate can be used for the UE to authenticate the UPF during the establishment of the MPQUIC connection between the UE and the UPF. For details, please refer to the following steps 1304 and 1305. It can be considered that steps 1304 and 1305 occur during the establishment of the MPQUIC connection between the UE and the UPF.
[0344] In one possible example, based on the certificate application indication, UPF determines that it needs to request the UPF certificate from CA, and then sends a second certificate request to CA, the second certificate request is used to request the UPF certificate, and accordingly, CA receives the second certificate request from UPF, generates the UPF certificate based on the second certificate request, sends the UPF certificate to UPF, and UPF receives the UPF certificate from CA. Optionally, CA also determines the identifier of UPF's certificate, sends the identifier of UPF's certificate to UPF, and UPF receives the identifier of UPF's certificate from CA. Alternatively, CA may also carry the identifier of UPF's certificate in UPF's certificate.
[0345] The second certificate request includes the public key (pk) of the UPF. Optionally, the second certificate request may also include one or more of the following parameters: an identifier of the MA PDU session, and a third indication. The parameters are described as follows:
[0346] (1) UPF public key: used by CA to generate UPF certificate, that is, when UPF determines that it needs to request UPF certificate from CA, it first generates UPF public key and sends a second certificate request containing UPF public key to CA. For CA, CA can generate UPF certificate based on UPF public key. Optionally, UPF can generate not only UPF public key, but also UPF private key (secret key, sk), or understand that UPF generates UPF public-private key pair (pk, sk), where UPF private key is used by UPF to sign the transmitted message during the establishment of MPQUIC connection (see the description in step 1305 below).
[0347] (2) Identifier of MA PDU session: an identifier used by CA to generate the certificate of UPF. Specifically, CA can determine the identifier of UPF's certificate based on the identifier of MA PDU session. Exemplarily, CA can determine the identifier of UPF's certificate based on the identifier of MA PDU session and the type of UPF, such as using the identifier of MA PDU session + UPF type as the identifier of UPF's certificate. In another exemplary manner, CA can determine the identifier of MA PDU session as the identifier of UPF's certificate. In this manner, UPF requests the CA for the certificate of UPF corresponding to each MA PDU session, and each MA PDU session corresponds to a certificate of UPF.
[0348] It should be added that the CA may not determine the identifier of the UPF certificate based on the identifier of the MAPDU session, but may generate a random string and use the random string as the identifier of the UPF certificate, or directly use the identifier of the UPF as the identifier of the UPF certificate. In this way, the UPF requests a UPF certificate from the CA, and the certificate of the UPF can be used by the UPF to establish MPQUIC connections associated with multiple MA PDU sessions. In this way, the UPF does not need to request the UPF certificate from the CA multiple times, reducing the complexity of the process. Accordingly, the identifier of the MA PDU session may not be included in the second certificate request. Optionally, after receiving the second certificate request from the SMF, the UPF first determines whether it has requested the UPF certificate from the CA. If so, there is no need to request the UPF certificate from the CA; otherwise, the UPF certificate is requested from the CA.
[0349] It can be understood that in the method of using a random string as the identifier of the UPF certificate, the UE can obtain the random string corresponding to the certificates of the multiple UPFs by establishing an MPQUIC connection with multiple UPFs, that is, it can know the number of UPFs included in the core network; in the method of using the identifier of the UPF as the identifier of the UPF certificate, the UE can obtain the identifier of the multiple UPFs by establishing an MPQUIC connection with multiple UPFs, that is, it can know the number of UPFs included in the core network and the identifier of the UPF, so that the UE can infer the network topology of the core network, which is not conducive to security protection. In the scheme of using the identifier of the MAPDU session as the identifier of the UPF certificate, the UE cannot know the number of UPFs included in the core network, that is, it cannot infer the network topology of the core network, which is helpful to achieve security protection of the core network.
[0350] (3) The third indication: used to indicate that the certificate requested by the second certificate request is used to establish an MPQUIC connection between UPF and UE, or used to indicate that the CA does not need to authenticate a device (here is UPF) before generating a certificate for the device. It can be understood that the third communication method is applicable to the PDU session establishment process, and before the PDU session is established, the AKA process has been completed, that is, the CA has authenticated the UPF and determined that the UPF authentication has passed. Therefore, when the UPF sends the second certificate request to the CA, the CA does not need to authenticate the UPF again, avoiding unnecessary authentication process. For the CA, after obtaining the third indication from the second certificate request, the CA does not need to authenticate the UPF, but directly generates a UPF certificate for the UPF.
[0351] In one possible example, after UPF obtains the certificate of UPF from CA, it may also send a confirmation indication to SMF, and the confirmation indication is used to indicate that UPF has successfully requested the certificate of UPF. Accordingly, after SMF receives the confirmation indication from UPF, it determines that UPF has successfully requested the certificate of UPF, and then executes the subsequent MA PDU session establishment process. After determining that the MA PDU session establishment process is completed, UE initiates the process of establishing an MPQUIC connection with UPF. Among them, the confirmation indication is, for example, an affirmative response (acknowledgement, ACK). Exemplarily, the confirmation indication is carried in the N4 session establishment response. Exemplarily, the N4 session establishment response includes an IE, which is a confirmation indication, that is, the IE is used to indicate that UPF has successfully requested the certificate of UPF. In this way, the problem that the UE initiates the process of establishing an MPQUIC connection with UPF when UPF has not yet requested the certificate of UPF is avoided, resulting in the failure of UE to establish an MPQUIC connection with UPF.
[0352] Step 1304: UPF sends the UPF certificate to the UE, and correspondingly, the UE receives the UPF certificate.
[0353] Step 1305: The UE authenticates the UPF based on the UPF certificate.
[0354] In one possible example, UPF uses UPF's private key to sign the previous interaction information to obtain UPF's signature information, and sends UPF's signature information and UPF's certificate to UE. Correspondingly, UE receives UPF's signature information and UPF's certificate, and authenticates UPF based on UPF's signature information and UPF's certificate. Here, the previous interaction information includes information exchanged between UPF and UE before UPF sends UPF's signature information and UPF's certificate to UE. For details, please refer to the TLS protocol regarding the two rounds of interaction between the two parties for key exchange and identity authentication. UPF can be considered as Server and UE as Client.
[0355] In one possible example, when the identifier of the UPF certificate is determined by the CA based on the identifier of the MA PDU session, the UPF may also send the identifier of the UPF certificate to the UE. Accordingly, the UE may also receive the identifier of the UPF certificate and determine that the identifier of the UPF certificate is determined based on the identifier of the MAPDU session, that is, determine that the UPF certificate is used for the MA PDU session, thereby avoiding abuse of the UPF certificate.
[0356] UPF may send the UPF certificate identifier, UPF signature information and UPF certificate to UE via a verification message.
[0357] Optionally, also include:
[0358] Step 1306: The UE derives a key (i.e., a first protection key) for protecting data of the MPQUIC connection based on the shared key. The shared key is determined by the UE based on the temporary private key of the UE and the temporary public key of the UPF.
[0359] Please refer to the description in step 602 for details, and it can be understood that the pre-configured key can be replaced with the shared key.
[0360] Step 1307: UPF derives a key (i.e., a second protection key) for protecting data of the MPQUIC connection based on the shared key. The shared key is determined by UPF based on the temporary public key of the UE and the temporary private key of UPF.
[0361] Please refer to the description in step 603 for details, and it can be understood that the pre-configured key can be replaced with the shared key.
[0362] Among them, the temporary public key of UE is sent by UE to UPF in the first round of interaction of TLS protocol, and the temporary public key of UPF is sent by UPF to UE in the first round of interaction of TLS protocol, that is, UE and UPF can exchange their temporary public keys in the first round of interaction of TLS protocol. Afterwards, each of them can deduce the shared key based on their own temporary private key and the temporary public key of the other party.
[0363] Step 1308: The UE and UPF transmit data of the MPQUIC connection.
[0364] Among them, the MPQUIC connection is associated with the MAPDU session, and the data of the MPQUIC connection is transmitted through multiple paths between the UE and the UPF. The relationship between the MPQUIC connection, the MA PDU session, and the MPQUIC connection and the MA PDU session can be seen in the description in step 601; the way in which the UE and the UPF transmit the data of the MPQUIC connection can be seen in the description in step 604.
[0365] It should be added that Fig.13 The relevant embodiment is that the UE authenticates the UPF only based on the UPF's certificate, that is, one-way authentication. In this scenario, the SMF can determine that the UE and UPF use one-way authentication when establishing the MPQUIC connection, and then instruct the UPF to request the UPF's certificate from the CA. In one example, the UE uses one-way authentication by default. After the UE receives the certificate from the UPF, it can authenticate the UPF based on the UPF's certificate. In another example, the SMF can also send a one-way authentication indication to the UE, which is used to instruct the UE and UPF to use one-way authentication when establishing the MPQUIC connection. Subsequently, after the UE receives the certificate from the UPF, it can authenticate the UPF based on the UPF's certificate.
[0366] In addition, the present application can also support two-way authentication. Compared with one-way authentication, two-way authentication can add the following steps a to d.
[0367] The timing sequence of steps a to d can be seen below Fig.15 The description in the relevant embodiments. Of course, Fig.15 The timing in the relevant embodiments is only an example of the present application and does not constitute a limitation of the present application. For example, the SMF may first instruct the UPF to request the UPF certificate from the CA, then request the UE certificate from the CA, and send the UE certificate to the UE; or, the SMF may first request the UE certificate from the CA, send the UE certificate to the UE, and then instruct the UPF to request the UPF certificate from the CA.
[0368] Step a: SMF requests the UE's certificate from the CA.
[0369] Optionally, the SMF determines that the UE and UPF use two-way authentication when establishing the MPQUIC connection, and then requests the UE's certificate from the CA.
[0370] In the process of SMF requesting the UE's certificate from CA, specifically, the UE generates the UE's public key and sends the UE's public key to the SMF. The SMF sends a first certificate request to the CA, and the first certificate request includes the UE's public key. Correspondingly, the CA receives the first certificate request from the SMF, generates the UE's certificate according to the UE's public key in the first certificate request, and sends the UE's certificate to the SMF. Optionally, the CA also determines the identifier of the UE's certificate, sends the identifier of the UE's certificate to the SMF, or the identifier of the UE's certificate may be carried in the UE's certificate.
[0371] Exemplarily, before generating the UE's public key, the UE may determine, based on the UE's capability information, that the UE supports establishing an MPQUIC connection and / or determine to use bidirectional authentication. The UE's capability information may refer to the description of the UE's capability information in step 901.
[0372] Exemplarily, the UE may also generate a private key of the UE. Exemplarily, the UE generates a public key and a private key of the UE at the same time (that is, a public-private key pair (pk, sk) of the UE). The private key of the UE is used by the UE to sign the transmitted message during the establishment of the MPQUIC connection. For details, see the following step d.
[0373] Exemplarily, the UE sends the UE's public key to the SMF. Specifically, the UE sends a PDU session establishment request to the AMF, and the PDU session establishment request carries the UE's public key. The AMF then sends a PDU session to create a session management context request to the SMF, and the PDU session to create a session management context request carries the PDU session establishment request, that is, the session management context creation request carries the UE's public key. For the SMF, the SMF receives the session management context creation request and obtains the UE's public key from the session management context creation request.
[0374] The first certificate request may also include one or more of the following parameters: an identifier of the MA PDU session and a third indication. The identifier of the MA PDU session and the third indication are explained as follows:
[0375] (1) MA PDU session identifier: used for CA to generate the UE certificate identifier. For CA, CA can determine the UE certificate identifier based on the MA PDU session identifier. Exemplarily, CA can determine the UE certificate identifier based on the MA PDU session identifier and the UE type, such as using the MA PDU session identifier + UE type as the UE certificate identifier. In this way, the UE requests the CA for the UE certificate corresponding to each MA PDU session, and each MA PDU session corresponds to a UE certificate.
[0376] It is worth noting that in two-way authentication, the CA needs to generate the UPF certificate identifier and the UE certificate identifier respectively. In order to distinguish the UPF certificate identifier and the UE certificate identifier, the CA can use the MA PDU session identifier + UPF type as the UPF certificate identifier, and use the MA PDU session identifier + UE type as the UE certificate identifier.
[0377] Optionally, the CA may not determine the identifier of the UE's certificate based on the identifier of the MA PDU session, but may generate a random string and use the random string as the identifier of the UE's certificate, or directly use the UE's identifier as the identifier of the UE's certificate. In this way, the SMF requests a UE certificate from the CA and sends the certificate of the UE to the UE. The certificate of the UE can be used for the UE to establish multiple MPQUIC connections, and the multiple MPQUIC connections can correspond to multiple MAPDU sessions. In this way, the SMF does not need to request the UE's certificate from the CA multiple times, reducing the complexity of the process. Accordingly, the identifier of the MA PDU session may not be included in the first certificate request. Optionally, after receiving the session establishment request from the UE, the SMF may determine whether to request the UE's certificate from the CA. If so, it is determined that there is no need to send the first certificate request to the CA. Otherwise, the first certificate request is sent to the CA.
[0378] (2) The third indication: used to indicate that the certificate requested by the first certificate request is used to establish an MPQUIC connection between the UE and the UPF, or used to indicate that the CA does not need to authenticate a device (here, the UE) before generating a certificate for the device. It can be understood that the third communication method is applicable to the PDU session establishment process, and before the PDU session is established, the AKA process has been completed, that is, the CA has authenticated the UE and determined that the UE authentication has passed. Therefore, when the SMF sends the first certificate request to the CA, the CA does not need to authenticate the UE again, avoiding unnecessary authentication processes. For the CA, after obtaining the third indication from the first certificate request, the CA does not need to authenticate the UE, but directly generates a UE certificate for the UE.
[0379] Step b, SMF sends the UE's certificate to the UE.
[0380] Exemplarily, SMF sends N1N2 message transmission to AMF, and N1N2 message transmission includes UE's certificate; AMF sends N2 PDU session request to RAN, and N2 PDU session request includes UE's certificate; RAN sends RRC reconfiguration message to UE, and RRC reconfiguration message includes UE's certificate. For UE, UE receives RRC reconfiguration message and obtains UE's certificate from RRC reconfiguration message. The RRC reconfiguration message can be considered as RRC reconfiguration message in AN-specific resource setup process.
[0381] Optionally, the SMF also sends the identifier of the UE's certificate to the UE, and the UE's certificate and the identifier of the UE's certificate are carried in one message. Alternatively, the identifier of the UE's certificate is carried in the UE's certificate.
[0382] Step c, during the establishment of the MPQUIC connection between the UE and the UPF, the UE sends the UE certificate to the UPF.
[0383] In one example, the UE uses a two-way authentication method by default. After receiving the UE's certificate from the SMF, the UE may send the UE's certificate to the UPF for the UPF to authenticate the UE. In another example, the SMF may also send a two-way authentication indication to the UE, which is used to instruct the UE and the UPF to use two-way authentication when establishing an MPQUIC connection. Subsequently, after receiving the UE's certificate from the SMF, the UE may send the UE's certificate to the UPF for the UPF to authenticate the UE. The sending method of the two-way authentication indication may be similar to the above-mentioned UE certificate method, that is, the SMF may send the two-way authentication indication and the UE's certificate to the UE through one message, for example, the two-way authentication indication and the UE's certificate are included in the RRC reconfiguration message.
[0384] In addition, when the UE sends a session establishment request, the session establishment request does not carry the UE's public key, but after the UE receives a two-way authentication indication from the SMF, the UE sends the UE's public key to the SMF.
[0385] In a specific implementation, the SMF sends a two-way authentication indication to the UE, and the sending method of the two-way authentication indication can be similar to the method of the UE certificate mentioned above, for example, the two-way authentication indication is included in the RRC reconfiguration message of the AN-specific resource setup process (the RRC configuration message does not contain the UE certificate at this time). Subsequently, the UE generates the UE's public key in response to the two-way authentication indication, and sends the UE's public key to the SMF. The SMF sends a first certificate request to the CA based on the UE's public key to request the UE's certificate, and then the SMF sends the UE's certificate to the UE. Exemplarily, when the UE sends the UE's public key to the SMF, it can be that the UE sends a first NAS message to the AMF, and the first NAS message carries the UE's public key. Subsequently, the AMF obtains the UE's public key in the first NAS message and forwards the UE's public key to the SMF; Exemplarily, when the SMF sends the UE's certificate to the UE, it can be that the SMF sends the UE's certificate to the AMF, and the AMF carries the UE's certificate in the second NAS message and sends the second NAS message to the UE.
[0386] In another specific implementation, the MA PDU session process further includes an authentication mode notification process, in which the SMF sends a two-way authentication indication to the UE, for example, the two-way authentication indication is included in the RRC reconfiguration message of the authentication mode notification process. Subsequently, the UE generates a public key of the UE in response to the two-way authentication indication, and sends the public key of the UE to the SMF. The SMF sends a first certificate request to the CA based on the public key of the UE to request the certificate of the UE, and then the SMF sends the certificate of the UE to the UE. Exemplarily, when the UE sends the UE's public key to the SMF, specifically, the UE sends a first NAS message to the AMF, and the first NAS message carries the UE's public key. Subsequently, the AMF obtains the UE's public key in the first NAS message and forwards the UE's public key to the SMF; Exemplarily, when the SMF sends the UE's certificate to the UE, specifically, the SMF sends the UE's certificate to the AMF via an N1N2 message, the AMF sends the UE's certificate to the RAN via an N2 PDU session request, and the RAN sends an RRC reconfiguration message to the UE via an RRC reconfiguration message, that is, the UE's certificate is included in the RRC reconfiguration message of the AN-specific resource setup process. It can be understood that the authentication method notification process occurs before the AN-specific resource setup process and after the UE sends the session establishment request.
[0387] In one possible example, the UE uses the UE's private key to sign the previous interaction information to obtain the UE's signature information, and sends the UE's signature information and the UE's certificate to the UPF. Exemplarily, the UE's signature information and the UE's certificate are carried in one message. Here, the previous interaction information includes the information exchanged between the UE and the UPF before the UE sends the signature information and certificate to the UPF. For details, please refer to the TLS protocol regarding the two rounds of interaction between the two parties for key exchange and identity authentication. The UPF can be considered as the Server and the UE can be considered as the Client.
[0388] Step d: UPF authenticates the UE based on the UE's certificate.
[0389] In one possible example, the UPF authenticates the UE based on the UE's signature information and the UE's certificate.
[0390] Combination Fig.13 Described in the relevant embodiments, Fig.14 The first specific implementation of the third communication method provided by the present application is illustrative. The first specific implementation is for one-way authentication, and the UE uses the one-way authentication mode by default.
[0391] Step 1401, the UE sends a PDU session establishment request to the AMF, and accordingly, the AMF receives the PDU session establishment request from the UE.
[0392] For details, please refer to the description in the above step 1201.
[0393] Step 1402: AMF selects SMF. Specifically, AMF selects SMF that supports ATSSS capability.
[0394] Step 1403, AMF sends a PDU session creation session management context request to SMF, and the PDU session creation session management context request carries a PDU session establishment request. Correspondingly, SMF receives the PDU session creation session management context request from AMF.
[0395] Step 1404, SMF creates a session management context request based on the PDU session, and determines to enable the function corresponding to the MPQUIC connection.
[0396] For details, please refer to the description in the above step 1204.
[0397] Step 1405, SMF sends an N4 session establishment request to UPF. Accordingly, UPF receives the N4 session establishment request from SMF, and the N4 session establishment request includes a certificate application indication. Optionally, the N4 session establishment request also includes an N4 session identifier and an identifier of the MA PDU session. SMF locally stores the correspondence between the N4 session identifier and the identifier of the MA PDU session.
[0398] Step 1406, UPF generates a public key and a private key of UPF.
[0399] Optionally, UPF also establishes an N4 session with SMF based on the N4 session establishment request.
[0400] Step 1407: UPF sends a second certificate request to CA. Accordingly, CA receives the second certificate request from UPF, wherein the second certificate request includes the public key of UPF. Optionally, the second certificate request also includes the identifier of the MA PDU session and / or the third indication.
[0401] Step 1408, the CA generates a certificate for the UPF based on the public key of the UPF.
[0402] When the second certificate request also includes the identifier of the MA PDU session, the CA can also determine the identifier of the UPF certificate based on the identifier of the MA PDU session; when the second certificate request also includes a third indication, the CA can also determine that there is no need to verify the UPF based on the third indication.
[0403] Step 1409, the CA sends the UPF certificate to the UPF, and correspondingly, the UPF receives the UPF certificate from the CA.
[0404] Step 1410, UPF sends ACK (an example of confirmation indication) to SMF, and correspondingly, SMF receives ACK from UPF.
[0405] Step 1411, SMF sends N1N2 message transmission to AMF, and accordingly, AMF receives N1N2 message transmission from SMF.
[0406] Among them, the N1N2 message transmission includes ATSSS rules, and the ASSSS rules can be specifically obtained by the SMF from the PCF. The ASSSS rules can be used by the UE to decide the steering function applied to a specific data packet flow (such as using the MPQUIC function after establishing the MPQUIC connection).
[0407] In step 1412, the AMF sends an N2 PDU session request to the RAN. Accordingly, the RAN receives the N2 PDU session request from the AMF, and the N2 PDU session request includes the ATSSS rule.
[0408] Step 1413, the RAN sends an RRC reconfiguration message to the UE. Correspondingly, the UE receives the RRC reconfiguration message from the RAN, and the RRC reconfiguration message includes the ATSSS rule.
[0409] In a specific example, in the AN-specific resource setup process, the RAN sends an RRC reconfiguration message to the UE. The RRC reconfiguration message also includes indication information that the MA PDU session establishment is completed, such as PDU session establishment acceptance.
[0410] Step 1414, UPF sends the UPF certificate to the UE, and correspondingly, the UE receives the UPF certificate.
[0411] Step 1415, the UE authenticates the UPF based on the UPF certificate.
[0412] Step 1416: The UE derives a first protection key based on the shared key.
[0413] Step 1417: UPF derives a second protection key based on the shared key.
[0414] Step 1418, UE and UPF transmit data of MPQUIC connection.
[0415] Understandably, Fig.14 For any content not described in detail in Fig.13 Described in the relevant embodiments.
[0416] For example, for the contents not described in detail in step 1401 to step 1404, refer to the description in step 1301. For the contents not described in detail in step 1405, refer to the description in step 1302. For the contents not described in detail in steps 1406 to 1410, refer to the description in step 1303. For the contents not described in detail in steps 1414 and 1415, refer to the description in steps 1304 and 1305. For the contents not described in detail in step 1416, refer to the description in step 1306. For the contents not described in detail in step 1417, refer to the description in step 1307. For the contents not described in detail in step 1418, refer to the description in step 1308.
[0417] In addition, when the UE does not use the one-way authentication method by default, that is, when the SMF needs to send a one-way authentication indication to the UE, the one-way authentication indication can be carried in the N1N2 message transmission, N2 PDU session request and RRC reconfiguration message respectively. Correspondingly, the UE determines to use the one-way authentication method when establishing an MPQUIC connection with the UPF based on the one-way authentication indication.
[0418] Combination Fig.13 and Fig.14 Described in the relevant embodiments, Fig.15 The second specific implementation of the third communication method provided by the present application is exemplified. The second specific implementation is for two-way authentication, and the UE uses the two-way authentication mode by default.
[0419] Step 1501: The UE generates a public key and a private key of the UE. Specifically, the UE generates a public key and a private key of the UE when determining, according to the UE capability information, that the UE supports establishing an MPQUIC connection and / or when determining that the UE and the UPF use two-way authentication when establishing an MPQUIC connection.
[0420] Step 1502: The UE sends a PDU session establishment request to the AMF, and accordingly, the AMF receives the PDU session establishment request from the UE.
[0421] For details, please refer to the description in the above step 1201.
[0422] Step 1503: AMF selects SMF. Specifically, AMF selects SMF that supports ATSSS capability.
[0423] Step 1504, AMF sends a PDU session creation session management context request to SMF, and the PDU session creation session management context request carries a PDU session establishment request. Correspondingly, SMF receives the PDU session creation session management context request from AMF.
[0424] Step 1505, SMF creates a session management context request based on the PDU session, and determines to enable the function corresponding to the MPQUIC connection.
[0425] For details, please refer to the description in the above step 1204.
[0426] Step 1506: SMF sends an N4 session establishment request to UPF. Correspondingly, UPF receives the N4 session establishment request from SMF, and the N4 session establishment request includes a certificate application instruction. For details, please refer to the description in the above step 1405.
[0427] Step 1507: UPF generates a public key and a private key of UPF. For details, please refer to the description in the above step 1406.
[0428] In step 1508, UPF sends a second certificate request to CA. Correspondingly, CA receives the second certificate request from UPF. For details, please refer to the description in the above step 1407.
[0429] Step 1509: CA generates a certificate of UPF according to the public key of UPF. For details, please refer to the description in the above step 1408.
[0430] Step 1510, the CA sends the UPF certificate to the UPF, and correspondingly, the UPF receives the UPF certificate from the CA.
[0431] Step 1511, UPF sends ACK (an example of confirmation indication) to SMF, and correspondingly, SMF receives ACK from UPF.
[0432] Step 1512: SMF sends a first certificate request to CA, and accordingly, CA receives the first certificate request from SMF, wherein the first certificate request includes the public key of UE. Optionally, the first certificate request also includes the identifier of MA PDU session and / or the third indication.
[0433] Step 1513: The CA generates a certificate for the UE based on the public key of the UE.
[0434] When the first certificate request also includes the identifier of the MA PDU session, the CA can also determine the identifier of the UE's public key based on the identifier of the MA PDU session; when the first certificate request also includes a third indication, the CA can also determine that there is no need to verify the UE based on the third indication.
[0435] Step 1514, the CA sends the UE's certificate to the SMF, and correspondingly, the SMF receives the UE's certificate from the CA.
[0436] Step 1515, SMF sends an N1N2 message transmission to AMF, and accordingly, AMF receives an N1N2 message transmission from SMF, where the N1N2 message transmission includes the UE's certificate.
[0437] The N1N2 message transmission also includes ATSSS rules, which can be obtained by SMF from PCF. The ATSSS rules can be used by UE to decide the steering function applied to a specific data packet flow (such as using the MPQUIC function after establishing an MPQUIC connection).
[0438] Step 1516: AMF sends an N2 PDU session request to RAN. RAN receives the N2 PDU session request from AMF, which includes the UE's certificate and ATSSS rules.
[0439] Step 1517, RAN sends an RRC reconfiguration message to UE, and accordingly, UE receives an RRC reconfiguration message from RAN, and the RRC reconfiguration message includes the UE's certificate. The RRC reconfiguration message also includes ATSSS rules. In a specific example, in the AN-specific resource setup process, RAN sends an RRC reconfiguration message to UE, and the RRC reconfiguration message also includes indication information of completion of MA PDU session establishment, such as PDU session establishment acceptance.
[0440] Step 1518, the UE sends the UE certificate to the UPF, and accordingly, the UPF receives the UE certificate.
[0441] Step 1519, UPF authenticates the UE based on the UE's certificate.
[0442] Step 1520, UPF sends the UPF certificate to the UE, and correspondingly, the UE receives the UPF certificate.
[0443] Step 1521, the UE authenticates the UPF based on the UPF certificate.
[0444] Step 1522: The UE derives a first protection key based on the shared key.
[0445] Step 1523: UPF derives the second protection key based on the shared key.
[0446] Step 1524, UE and UPF transmit data of MPQUIC connection.
[0447] Understandably, Fig.15 For details not described in detail, see Fig.13Described in the relevant embodiments. Exemplarily, the contents not described in detail in step 1501 may refer to the description in step a. The contents not described in detail in steps 1502 to 1505 may refer to the description in step 1301. The contents not described in detail in step 1506 may refer to the description in step 1302. The contents not described in detail in steps 1507 to 1511 may refer to the description in step 1303. The contents not described in detail in steps 1512 to 1514 may refer to the description in step a. The contents not described in detail in steps 1515 to 1517 may refer to the description in step b. The contents not described in detail in steps 1518 and 1519 may refer to the description in steps c and d. The contents not described in detail in steps 1520 and 1521 may refer to the description in steps 1304 and 1305. For the contents not described in detail in step 1522, please refer to the description in step 1306. For the contents not described in detail in step 1523, please refer to the description in step 1307. For the contents not described in detail in step 1524, please refer to the description in step 1308.
[0448] In addition, when the UE does not use the two-way authentication method by default, that is, when the SMF needs to send a two-way authentication indication to the UE, the N1N2 message transmission, N2 PDU session request and RRC reconfiguration message do not carry the UE's certificate, but carry a two-way authentication indication. Accordingly, the UE determines to use the two-way authentication method when establishing an MPQUIC connection with the UPF based on the two-way authentication indication. Further, step 1501, step 1512 to step 1514 occur after step 1517 and before step 1518.
[0449] In the one-way authentication of the third communication method described above, SMF sends a certificate application instruction to UPF, and UPF requests the certificate of UPF from CA according to the certificate application instruction. During the establishment of the MPQUIC connection between UE and UPF, UPF sends the certificate of UPF to UE, and UE can use the certificate of UPF to authenticate UPF. In this way, security is achieved during the establishment of the MPQUIC connection between UE and UPF.
[0450] In the two-way authentication of the third communication method described above, SMF sends a certificate application instruction to UPF, and UPF requests UPF's certificate from CA according to the certificate application instruction. During the establishment of the MPQUIC connection between UE and UPF, UPF sends UPF's certificate to UE, and UE can use UPF's certificate to authenticate UPF. SMF also requests UE's certificate from CA and sends UE's certificate to UE. During the establishment of the MPQUIC connection between UE and UPF, UE sends UE's certificate to UPF, and UPF can use UE's certificate to authenticate UE. In this way, security is achieved in the process of establishing the MPQUIC connection between UE and UPF.
[0451] It should be added that the step numbers of the flowcharts described in the first communication method to the third communication method are only examples of the execution process and do not constitute a limitation on the order of execution of the steps. There is no strict execution order between the steps that have no timing dependency relationship with each other in the embodiment of the present application. Not all the steps shown in the flowcharts are required to be executed. Some steps can be deleted based on each flowchart according to actual needs, or other possible steps can be added based on each flowchart according to actual needs.
[0452] The above focuses on describing the differences between different embodiments in the first communication method to the third communication method. Except for other contents of the differences, the first communication method to the third communication method can refer to each other; in addition, in the same communication method, different implementation methods or different examples can also refer to each other.
[0453] It is understandable that in the above-mentioned various method embodiments, the methods and operations implemented by the terminal device (i.e., UE) may also be implemented by a module (e.g., a chip or a circuit) of the terminal device, and the terminal device and the module of the terminal device may be collectively referred to as a terminal device. That is, the "UE" in the above-mentioned communication method may be replaced by "terminal device". In the following device embodiments, the UE is still used as an example for explanation.
[0454] Based on the above content and the same idea, Fig.16 and Fig.17 This is a schematic diagram of the structure of possible communication devices provided in the present application. These communication devices can be used to implement the functions of the UE, the first function (such as AMF), SMF or UPF in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments.
[0455] like Fig.16 In the embodiment, the communication device 1600 may include a transceiver module 1601 and a processing module 1602.
[0456] When the communication device 1600 is used to execute the method of the first UE in the first communication method:
[0457] The communication device 1600 may be Figures 1 to 4 UE in.
[0458] The processing module 1602 is used to: after the first MA PDU session of the first UE is established, control the transceiver module 1601 to negotiate with the first UPF to establish a first MPQUIC connection, and the first MPQUIC connection is associated with the first MA PDU session.
[0459] The processing module 1602 is used to: derive a key for protecting data of a first MPQUIC connection according to a preconfigured key, where the data of the first MPQUIC connection is transmitted by multiple paths between the first UE and the first UPF. The preconfigured key is also used for the first UE to establish a second MPQUIC connection with a second UPF, where the first UPF and the second UPF are located in the same PLMN.
[0460] In a possible implementation, when the processing module 1602 controls the transceiver module 1601 to negotiate with the first UPF to establish the first MPQUIC connection, the processing module 1602 is specifically used to: control the transceiver module 1601 to send an identifier of the preconfigured key to the first UPF.
[0461] In a possible implementation, the messages transmitted during the negotiation are protected based on 3GPP security.
[0462] In a possible implementation, the preconfiguration key used when the first UE negotiates with the first UPF to establish the first MPQUIC connection is the same as the preconfiguration key used when the second UE negotiates with the first UPF to establish the third MPQUIC connection. The first UE and the second UE belong to the same H-PLMN.
[0463] In one possible implementation, after the first MA PDU session of the first UE is established, the processing module 1602 is also used to: control the transceiver module 1601 to negotiate with the first UPF to establish a fourth MPQUIC connection, the fourth MPQUIC connection is associated with the first MA PDU session, and, based on the pre-configured key, derive a key for protecting the data of the fourth MPQUIC connection, wherein the key for protecting the data of the first MPQUIC connection is different from the key for protecting the data of the fourth MPQUIC connection.
[0464] In a possible implementation, after the second MA PDU session of the first UE is established, the processing module 1602 is further used to: control the transceiver module 1601 to negotiate with the second UPF to establish a second MPQUIC connection, and the second MPQUIC connection is associated with the second MA PDU session. The processing module 1602 is also used to: derive a key for protecting data of the second MPQUIC connection based on a preconfigured key.
[0465] When the communication device 1600 is used to execute the method of the first UPF in the first communication method:
[0466] The communication device 1600 may be Figure 1 or Figure 2 The UPF in, or Figure 3 or Figure 4 H-UPF in.
[0467] The processing module 1602 is used to: after the first MA PDU session of the first UE is established, control the transceiver module 1601 to negotiate with the first UE to establish a first MPQUIC connection, and the first MPQUIC connection is associated with the first MA PDU session.
[0468] The processing module 1602 is further used to: derive a key for protecting data of the first MPQUIC connection according to the preconfigured key, where the data of the first MPQUIC connection is transmitted by multiple paths between the first UE and the first UPF. The preconfigured key is also used for the first UE to establish a second MPQUIC connection with the second UPF, where the first UPF and the second UPF are located in the same PLMN.
[0469] In a possible implementation manner, when the processing module 1602 controls the transceiver module 1601 to negotiate with the first UE to establish the first MPQUIC connection, it is specifically used to: control the transceiver module 1601 to receive an identifier of the pre-configured key from the first UE.
[0470] In a possible implementation, the messages transmitted during the negotiation are protected based on 3GPP security.
[0471] In a possible implementation, the preconfiguration key used when the first UPF negotiates with the first UE to establish the first MPQUIC connection is the same as the preconfiguration key used when the first UPF negotiates with the second UE to establish the third MPQUIC connection. The first UE and the second UE belong to the same H-PLMN.
[0472] In a possible implementation, after the first MAPDU session of the first UE is established, the processing module 1602 is further used to: control the transceiver module 1601 to negotiate with the first UE to establish a fourth MPQUIC connection, where the fourth MPQUIC connection is associated with the first MAPDU session. And, based on the pre-configured key, derive a key for protecting data of the fourth MPQUIC connection, wherein the key for protecting data of the first MPQUIC connection is different from the key for protecting data of the fourth MPQUIC connection.
[0473] When the communication device 1600 is used to execute the SMF method in the second communication method:
[0474] The communication device 1600 may be Figure 1 or Figure 2 The SMF in, or Figure 3 or Figure 4 H-SMF in.
[0475] In the process of establishing an MA PDU session for the UE, the processing module 1602 is used to: obtain a shared key from the first function, send the shared key to the UPF, the shared key is used by the UPF to derive a key for protecting the data in the MPQUIC connection between the UE and the UPF, the MPQUIC connection is associated with the MA PDU session, and the data of the MPQUIC connection is transmitted by multiple paths between the UE and the UPF.
[0476] In a possible implementation, the processing module 1602 is further used to: control the transceiver module 1601 to send a first indication to the UE, where the first indication is used to instruct the UE to establish an MPQUIC connection with the UPF using a shared key.
[0477] In a possible implementation, the processing module 1602 is further configured to: determine whether to enable a function corresponding to an MPQUIC connection before obtaining the shared key from the first function. In a possible implementation, when the processing module 1602 determines whether to enable a function corresponding to an MPQUIC connection, it is specifically configured to: control the transceiver module 1601 to receive capability information from the UE, and determine, based on the capability information of the UE, that the UE supports establishing an MPQUIC connection; and / or determine whether to support a function corresponding to an MPQUIC connection.
[0478] In a possible implementation, when the processing module 1602 obtains the shared key from the first function, it is specifically used to control the transceiver module 1601 to send a second indication to the first function, where the second indication is used to instruct the first function to deduce the shared key; and control the transceiver module 1601 to receive the shared key from the first function.
[0479] In a possible implementation, after the processing module 1602 obtains the shared key from the first function, it is also used to: control the transceiver module 1601 to send the identifier of the shared key to the UPF. In one example, the identifier of the shared key is determined by the processing module 1602 according to the identifier of the MA PDU session, and accordingly, the processing module 1602 is also used to control the transceiver module 1601 to send the identifier of the shared key to the first function, and / or control the transceiver module 1601 to send the identifier of the shared key to the UE. In another example, the identifier of the shared key is determined by the first function according to the identifier of the MA PDU session, and accordingly, the processing module 1602 is also used to control the transceiver module 1601 to send the identifier of the MA PDU session to the first function, and receive the identifier of the shared key from the first function.
[0480] In a possible implementation, the identifier of the shared key is an identifier of the MAPDU session.
[0481] When the communication device 1600 is used to execute the UPF method in the second communication method:
[0482] The communication device 1600 may be Figure 1 or Figure 2 The UPF in, or Figure 3 or Figure 4 H-UPF in.
[0483] In the process of establishing an MA PDU session for the UE, the transceiver module 1601 is used to: receive a shared key from the SMF; the processing module 1602 is used to: deduce, based on the shared key, a key for protecting data in the MPQUIC connection between the UE and the UPF, the MPQUIC connection is associated with the MA PDU session, and the data of the MPQUIC connection is transmitted via multiple paths between the UE and the UPF.
[0484] In a possible implementation, the transceiver module 1601 is further used to: receive an identifier of a shared key from the SMF, where the identifier of the shared key is determined by the SMF or the first function according to the identifier of the MA PDU session; the processing module 1602 is further used to: store the identifier of the shared key in correspondence with the shared key. In a possible implementation, the identifier of the shared key is the identifier of the MA PDU session.
[0485] When the communication device 1600 is used to execute the UE method in the second communication method:
[0486] The communication device 1600 may be Figures 1 to 4 UE in.
[0487] In the process of establishing an MA PDU session for the UE, the transceiver module 1601 is used to: receive a first indication from the SMF, the first indication is used to instruct the UE to establish an MPQUIC connection with the UPF using a shared key, and the MPQUIC connection is associated with the MA PDU session; the processing module 1602 is used to: derive the shared key according to the first indication, and, according to the shared key, derive the key for protecting the data in the MPQUIC connection, and the data of the MPQUIC connection is transmitted by multiple paths between the UE and the UPF.
[0488] In a possible implementation, the transceiver module 1601 is further used to: send UE capability information to the SMF, where the UE capability information is used to indicate that the UE supports establishing an MPQUIC connection.
[0489] In a possible implementation, when the processing module 1602 derives the shared key according to the first indication, it is specifically used to: derive the shared key according to the first indication and one or more of the following parameters: the identifier of the UE, the identifier of the MA PDU session, and the superior key. Exemplarily, the superior key includes one or more of the following: AUSF key, SEAF key, RAN key, AMF key.
[0490] In a possible implementation, the identifier of the shared key is determined by the SMF according to the identifier of the MA PDU session, and the transceiver module 1601 is further used to receive the identifier of the shared key from the SMF.
[0491] In a possible implementation manner, the identifier of the shared key is determined by the UE according to the identifier of the MA PDU session, that is, the processing module 1602 is further configured to determine the identifier of the shared key according to the identifier of the MA PDU session.
[0492] In a possible implementation, the processing module 1602 is further configured to: store the identifier of the shared key in correspondence with the shared key.
[0493] In a possible implementation manner, the identifier of the shared key is an identifier of the MA PDU session.
[0494] When the communication device 1600 is used to perform the method of the first function in the second communication method:
[0495] Exemplarily, the communication device 1600 is AMF, SEAF or AUSF. Exemplarily, when the communication device 1600 is AMF, the communication device 1600 may be Figure 1 or Figure 2 AMF in, or Figure 3 V-AMF in, or Figure 4 In H-AMF or V-AMF. Figure 4 In the scenario, the communication device can specifically be the AMF corresponding to 3GPP access.
[0496] In the process of establishing an MA PDU session for the UE, the transceiver module 1601 is used to: receive a second indication from the SMF; the processing module 1602 is used to: deduce a shared key based on the second indication; the transceiver module 1601 is also used to: send a shared key to the SMF, wherein the shared key is used to derive a key for protecting data in the MPQUIC connection between the UE and the UPF, the MPQUIC connection is associated with the MA PDU session, and the data of the MPQUIC connection is transmitted by multiple paths between the UE and the UPF.
[0497] In a possible implementation, the identifier of the shared key is determined by the SMF according to the identifier of the MA PDU session, and the transceiver module 1601 is also used to: receive the identifier of the shared key from the SMF. In a possible implementation, the identifier of the shared key is determined by the AMF according to the identifier of the MA PDU session, that is, the transceiver module 1601 is also used to: receive the identifier of the MA PDU session from the SMF, and the processing module 1602 is also used to: determine the identifier of the shared key according to the identifier of the MA PDU session.
[0498] In a possible implementation, when the processing module 1602 derives the shared key according to the second indication, it is specifically used to: derive the shared key according to the second indication and one or more of the following parameters: UE identifier, MA PDU session identifier, and superior key. Exemplarily, when the first function is AMF, the superior key includes one or more of the following: RAN key, AMF key; when the first function is SEAF, the superior key may be a SEAF key; when the first function is AUSF, the superior key may be an AUSF key.
[0499] When the communication device 1600 is used to execute the SMF method in the third communication method:
[0500] The communication device 1600 may be Figure 1 or Figure 2 The SMF in, or Figure 3 or Figure 4 H-SMF in.
[0501] In the process of establishing an MA PDU session for the UE, the transceiver module 1601 is used to: receive a session establishment request from the UE, and the session establishment request is used to request the establishment of the UE's MA PDU session. The processing module 1602 is used to: according to the session establishment request, control the transceiver module 1601 to send a certificate application indication to the UPF, and the certificate application indication is used to indicate the request for the UPF certificate from the CA. Among them, in the process of establishing the MPQUIC connection between the UE and the UPF, the UPF certificate is used by the UE to authenticate the UPF, the MPQUIC connection is associated with the MA PDU session, and the data of the MPQUIC connection is transmitted by multiple paths between the UE and the UPF.
[0502] In a possible implementation, after the processing module 1602 controls the transceiver module 1601 to send a certificate application indication to the UPF, it is also used to: control the transceiver module 1601 to receive a confirmation indication from the UPF, where the confirmation indication is used to indicate that the UPF has successfully requested a certificate from the UPF. Exemplarily, the processing module 1602 is also used to: determine, based on the confirmation indication, that the UPF has successfully requested a certificate from the UPF.
[0503] In a possible implementation, the transceiver module 1601 is further used to: send a first certificate request to the CA, the first certificate request includes the UE's public key, and the UE's public key is used by the CA to generate a certificate for the UE. The transceiver module 1601 is also used to: receive the UE's certificate from the CA, send the UE's certificate to the UE, and the UE's certificate is used by the UPF to authenticate the UE during the establishment of the MPQUIC connection.
[0504] In a possible implementation, before the transceiver module 1601 sends the first certificate request to the CA, it is also used to: send a two-way authentication indication to the UE, where the two-way authentication indication is used to indicate that the authentication method in the process of establishing the MPQUIC connection is a two-way authentication method. The transceiver module 1601 is also used to: receive the public key of the UE. Exemplarily, the two-way authentication indication can be carried in a radio resource control reconfiguration message.
[0505] In a possible implementation, the session establishment request includes the UE's public key. Exemplarily, the UE's certificate may be carried in a radio resource control reconfiguration message.
[0506] In a possible implementation, the first certificate request also includes an identifier of an MA PDU session, and the identifier of the MA PDU session is used to determine the identifier of the UE's certificate. In a possible implementation, the transceiver module 1601 is also used to: send the identifier of the MA PDU session to the UPF, and the identifier of the MA PDU session is used to determine the identifier of the UPF's certificate.
[0507] In a possible implementation, the processing module 1602 controls the transceiver module 1601 to send a certificate application indication to the UPF, and is further used to: determine to enable the function corresponding to the MPQUIC connection. Exemplarily, when determining to enable the function corresponding to the MPQUIC connection, the processing module 1602 is specifically used to: control the transceiver module 1601 to receive capability information from the UE, and determine, according to the capability information of the UE, that the UE supports establishing an MPQUIC connection, and / or determine to support the function corresponding to the MPQUIC connection.
[0508] When the communication device 1600 is used to execute the UE method in the third communication method:
[0509] The communication device 1600 may be Figures 1 to 4 UE in.
[0510] In the process of establishing an MA PDU session for the UE, the transceiver module 1601 is used to send a session establishment request to the SMF, and the session establishment request is used to request the establishment of the UE's MA PDU session; in the process of establishing the MPQUIC connection between the UE and the UPF, the transceiver module 1601 is used to receive the UPF certificate from the UPF, and the processing module 1602 is used to authenticate the UPF according to the UPF certificate; wherein, the MPQUIC connection is associated with the MA PDU session, and the data of the MPQUIC connection is transmitted by multiple paths between the UE and the UPF.
[0511] In one possible implementation, during the establishment of the MPQUIC connection between the UE and the UPF, the transceiver module 1601 is also used to receive the UE's certificate from the SMF, and to send the UE's certificate to the UPF, and the UE's certificate is used by the UPF to authenticate the UE.
[0512] In a possible implementation, the session establishment request includes the UE's public key, and the UE's public key is used by the SMF to request the UE's certificate from the CA. Before the transceiver module 1601 sends the session establishment request to the SMF, the processing module 1602 is also used to generate the UE's public key. Exemplarily, the UE's certificate is carried in the RRC reconfiguration message.
[0513] In a possible implementation, the transceiver module 1601 is further used to: receive a two-way authentication indication from the SMF, the two-way authentication indication is used to indicate that the authentication method in the process of establishing the MPQUIC connection is a two-way authentication method; the processing module 1602 is further used to: generate a public key of the UE according to the two-way authentication indication; the transceiver module 1601 is further used to: send the public key of the UE to the SMF, the public key of the UE is used by the SMF to request the UE's certificate from the CA. Exemplarily, the two-way authentication indication is carried in the RRC reconfiguration message.
[0514] In a possible implementation, the processing module 1602 is further used to: generate a private key of the UE, where the private key of the UE is used by the UE to sign a transmitted message during the establishment of the MPQUIC connection.
[0515] In a possible implementation, the transceiver module 1601 is further used to: receive the identifier of the UPF certificate from the UPF; the processing module 1602 is further used to: determine that the identifier of the UPF certificate is determined based on the identifier of the MA PDU session.
[0516] In a possible implementation, the transceiver module 1601 is further used to: send UE capability information to the SMF, where the UE capability information is used to indicate that the UE supports establishing an MPQUIC connection.
[0517] When the communication device 1600 is used to execute the UPF method in the third communication method:
[0518] The communication device 1600 may be Figure 1 or Figure 2 The UPF in, or Figure 3 or Figure 4 H-UPF in.
[0519] During the establishment of the UE's MA PDU session, the transceiver module 1601 is used to: receive a certificate application indication from the SMF; the processing module 1602 is also used to: control the transceiver module 1601 to request the UPF certificate from the CA according to the certificate application indication; during the establishment of the MPQUIC connection between the UE and the UPF, the transceiver module 1601 is also used to send the UPF certificate to the UE, and the UPF certificate is used by the UE to authenticate the UPF; wherein the MPQUIC connection is associated with the MA PDU session, and the data of the MPQUIC connection is transmitted by multiple paths between the UE and the UPF.
[0520] In a possible implementation, when the transceiver module 1601 requests a UPF certificate from the CA, it is specifically used to: send a second certificate request to the CA, where the second certificate request is used to request a UPF certificate from the CA; and receive the UPF certificate from the CA.
[0521] In a possible implementation, during the establishment of the MPQUIC connection between the UE and the UPF, the transceiver module 1601 is also used to: receive the UE's certificate; the processing module 1602 is also used to: authenticate the UE based on the UE's certificate.
[0522] In a possible implementation, the second certificate request includes the public key of the UPF, and the public key of the UPF is used by the CA to determine the certificate of the UPF. That is, before the transceiver module 1601 sends the second certificate request, the processing module 1602 is also used to generate the public key of the UPF.
[0523] In one possible implementation, the processing module 1602 is also used to generate a private key of the UPF, and the private key of the UPF is used by the UPF to sign the transmitted message during the establishment of the MPQUIC connection.
[0524] In a possible implementation, the second certificate request also includes an MA PDU session identifier, which is used to determine the UPF certificate identifier. That is, before sending the second certificate request, the transceiver module 1601 is also used to receive the MA PDU session identifier from the SMF.
[0525] In a possible implementation, after successfully obtaining the UPF certificate from the CA, the transceiver module 1601 is also used to send a confirmation indication to the SMF, where the confirmation indication is used to indicate that the UPF has successfully requested the UPF certificate.
[0526] like Fig.17 The device 1700 provided in an embodiment of the present application is shown. Fig.17 The device shown can be Fig.16 A hardware circuit implementation of the device shown in the figure. The device can be applied to the flowchart shown above to perform the functions of the UE, the first function (such as AMF), SMF or UPF in the above method embodiment. For the convenience of explanation, Fig.17 Only the main components of the device are shown.
[0527] Fig.17 The device 1700 shown includes a communication interface 1710, a processor 1720 and a memory 1730, wherein the memory 1730 is used to store program instructions and / or data. The processor 1720 may operate in conjunction with the memory 1730. The processor 1720 may execute program instructions stored in the memory 1730. When the instructions or programs stored in the memory 1730 are executed, the processor 1720 is used to execute the operations performed by the processing module 1602 in the above embodiment, and the communication interface 1710 is used to execute the operations performed by the transceiver module 1601 in the above embodiment.
[0528] The memory 1730 is coupled to the processor 1720. The coupling in the embodiment of the present application is an indirect coupling or communication connection between devices, units or modules, which can be electrical, mechanical or other forms, for information exchange between devices, units or modules. At least one of the memories 1730 may be included in the processor 1720.
[0529] In the embodiment of the present application, the communication interface may be a transceiver, a circuit, a bus, a module or other types of communication interfaces. In the embodiment of the present application, when the communication interface is a transceiver, the transceiver may include an independent receiver, an independent transmitter, or a transceiver with integrated transceiver functions or a communication interface.
[0530] The device 1700 may further include a communication line 1740. The communication interface 1710, the processor 1720, and the memory 1730 may be interconnected via the communication line 1740; the communication line 1740 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The communication line 1740 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.17 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0531] It is understandable that the processor in the embodiments of the present application may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0532] The method steps in the embodiments of the present application can be implemented by hardware, or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a base station or a terminal. Of course, the processor and the storage medium can also be present in a base station or a terminal as discrete components.
[0533] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When a computer program or instruction is loaded and executed on a computer, the process or function of the embodiment of the present application is executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device or other programmable device. The computer program or instruction can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instruction can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server, data center, etc. that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a tape; it can also be an optical medium, such as a digital video disc; it can also be a semiconductor medium, such as a solid-state hard disk. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.
[0534] In the various embodiments of the present application, unless otherwise specified or provided for in any logical conflict, the terms and / or descriptions between the different embodiments are consistent and may be referenced to each other, and the technical features in the different embodiments may be combined to form new embodiments according to their inherent logical relationships.
[0535] In the present application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of the present application, the character " / " generally indicates that the associated objects before and after are in an "or" relationship. "Including at least one of A, B and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B and C. It can be understood that the various digital numbers involved in the embodiments of the present application are only distinguished for the convenience of description and are not used to limit the scope of the embodiments of the present application. The size of the serial number of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic.
Claims
1. A communication method, characterized in that, it includes: After the establishment of the first multi-access protocol data unit (MAPDU) session of the first terminal device is completed, the first terminal device negotiates with the first user plane function to establish a first multi-path quick user datagram protocol internet connection (MPQUIC connection), and the first MPQUIC connection is associated with the first MAPDU session; The first terminal device derives a key for protecting the data of the first MPQUIC connection according to a pre-configured key, and the data of the first MPQUIC connection is transmitted through multiple paths between the first terminal device and the first user plane function; Wherein, the pre-configured key is also used for the first terminal device to establish a second MPQUIC connection with the second user plane function, and the first user plane function and the second user plane function are within the same public land mobile network.
2. The method according to claim 1, characterized in that, The first terminal device negotiates with the first user plane function to establish the first MPQUIC connection, including: The first terminal device sends an identifier of the pre-configured key to the first user plane function.
3. The method according to claim 1 or 2, characterized in that, The message transmitted in the negotiation is protected based on 3GPP security.
4. The method according to any one of claims 1-3, characterized in that, The pre-configured key used by the first terminal device to negotiate with the first user plane function to establish the first MPQUIC connection is the same as the pre-configured key used by the second terminal device to negotiate with the first user plane function to establish the third MPQUIC connection; The first terminal device and the second terminal device belong to the same home public land mobile network.
5. The method according to any one of claims 1-4, characterized in that, After the establishment of the first MAPDU session of the first terminal device is completed, it further includes: The first terminal device negotiates with the first user plane function to establish a fourth MPQUIC connection, and the fourth MPQUIC connection is associated with the first MAPDU session; The first terminal device derives a key for protecting the data of the fourth MPQUIC connection according to the pre-configured key, wherein the key for protecting the data of the first MPQUIC connection is different from the key for protecting the data of the fourth MPQUIC connection.
6. The method according to any one of claims 1-5, characterized in that, It further includes: After the establishment of the second MAPDU session of the first terminal device is completed, the first terminal device negotiates with the second user plane function to establish the second MPQUIC connection, and the second MPQUIC connection is associated with the second MAPDU session; The first terminal device derives a key for protecting the data of the second MPQUIC connection according to the pre-configured key.
7. A communication method, characterized in that, it includes: After the establishment of the first multi-access protocol data unit (MAPDU) session of the first terminal device is completed, the first user plane function negotiates with the first terminal device to establish a first multi-path quick user datagram protocol internet connection (MPQUIC connection), and the first MPQUIC connection is associated with the first MAPDU session; The first user plane function derives a key for protecting the data of the first MPQUIC connection according to a pre-configured key, and the data of the first MPQUIC connection is transmitted through multiple paths between the first terminal device and the first user plane function; Wherein, the pre-configured key is also used for the first terminal device and the second user plane function to establish a second MPQUIC connection, and the first user plane function and the second user plane function are located in the same public land mobile network.
8. The method according to claim 7, wherein, The negotiation between the first user plane function and the first terminal device to establish the first MPQUIC connection includes: The first user plane function receives an identifier of the pre-configured key from the first terminal device.
9. The method according to claim 7 or 8, wherein, The messages transmitted in the negotiation are protected based on 3GPP security.
10. The method according to any one of claims 7-9, wherein, The pre-configured key used by the first user plane function and the first terminal device to negotiate and establish the first MPQUIC connection is the same as the pre-configured key used by the first user plane function and the second terminal device to negotiate and establish the third MPQUIC connection; The first terminal device and the second terminal device belong to the same home public land mobile network.
11. The method according to any one of claims 7-10, wherein, After the establishment of the first MAPDU session of the first terminal device is completed, it further includes: The first user plane function negotiates with the first terminal device to establish a fourth MPQUIC connection, and the fourth MPQUIC connection is associated with the first MAPDU session; The first user plane function derives a key for protecting the data of the fourth MPQUIC connection according to the pre-configured key, wherein the key for protecting the data of the first MPQUIC connection is different from the key for protecting the data of the fourth MPQUIC connection.
12. A communication method, wherein, It is applicable to the process of establishing a multi-access protocol data unit (MAPDU) session for a terminal device, and the method includes: The session management function obtains a shared key from the first function; The session management function sends the shared key to the user plane function, and the shared key is used to derive a key for protecting the data in the multi-path quick user datagram protocol internet connection (MPQUIC connection) between the terminal device and the user plane function. The MPQUIC connection is associated with the MAPDU session, and the data of the MPQUIC connection is transmitted through multiple paths between the terminal device and the user plane function.
13. The method according to claim 12, characterized in that, further comprising: the session management function sends a first indication to the terminal device, and the first indication is used to instruct the terminal device to establish the MPQUIC connection with the user plane function in a shared key manner.
14. The method according to claim 12 or 13, characterized in that, before the session management function obtains the shared key from the first function, further comprising: the session management function determines to enable the function corresponding to the MPQUIC connection.
15. The method according to claim 14, characterized in that, the session management function determines to enable the function corresponding to the MPQUIC connection, including: the session management function receives capability information from the terminal device, and determines that the terminal device supports establishing the MPQUIC connection according to the capability information of the terminal device; and / or, the session management function supports the function corresponding to the MPQUIC connection.
16. The method according to any one of claims 12-15, characterized in that, the session management function obtains the shared key from the first function, including: the session management function sends a second indication to the first function, and the second indication is used to indicate deriving the shared key; the session management function receives the shared key from the first function.
17. The method according to any one of claims 12-16, characterized in that, further comprising: the session management function sends an identifier of the shared key to the user plane function.
18. The method according to any one of claims 12-17, characterized in that, the identifier of the shared key is determined by the session management function according to the identifier of the MA PDU session, and the method further comprises: the session management function sends the identifier of the shared key to the first function; and / or, the session management function sends the identifier of the shared key to the terminal device.
19. The method according to any one of claims 12-17, characterized in that, the identifier of the shared key is determined by the first function according to the identifier of the MA PDU session, and the method further comprises: the session management function sends the identifier of the MA PDU session to the first function; the session management function receives the identifier of the shared key from the first function.
20. The method according to any one of claims 12-19, characterized in that, the identifier of the shared key is the identifier of the MA PDU session.
21. The method according to any one of claims 12-20, characterized in that, the first function is an access management function, a security anchor function or an authentication server function.
22. A communication method, characterized in that, comprising: a session management function receives a session establishment request from a terminal device, and the session establishment request is used to request to establish a multi-access protocol data unit MA PDU session of the terminal device; The session management function sends a certificate application instruction to the user plane function according to the session establishment request, where the certificate application instruction is used to indicate requesting a certificate of the user plane function from a certificate authority; wherein, the certificate of the user plane function is used for: during the establishment process of a Multipath Quick User Datagram Protocol Internet Connection (MPQUIC) connection between the terminal device and the user plane function, the terminal device authenticates the user plane function; the MPQUIC connection is associated with the MAPDU session, and the data of the MPQUIC connection is transmitted through multiple paths between the terminal device and the user plane function.
23. The method according to claim 22, characterized in that, after the session management function sends the certificate application instruction to the user plane function, it further includes: the session management function receives a confirmation instruction from the user plane function, where the confirmation instruction is used to indicate that the user plane function has successfully requested the certificate of the user plane function.
24. The method according to claim 22 or 23, characterized in that, it further includes: the session management function sends the first certificate request to the certificate authority, where the first certificate request includes the public key of the terminal device, and the public key of the terminal device is used to generate the certificate of the terminal device; the session management function receives the certificate of the terminal device from the certificate authority and sends the certificate of the terminal device to the terminal device, where the certificate of the terminal device is used for the user plane function to authenticate the terminal device during the establishment process of the MPQUIC connection.
25. The method according to claim 24, characterized in that, before the session management function sends the first certificate request to the certificate authority, it further includes: the session management function sends a mutual authentication instruction to the terminal device, where the mutual authentication instruction is used to indicate that the authentication method during the establishment process of the MPQUIC connection is a mutual authentication method; the session management function receives the public key of the terminal device from the terminal device.
26. The method according to claim 24, characterized in that, the session establishment request includes the public key of the terminal device.
27. The method according to any one of claims 24 - 26, characterized in that, the first certificate request further includes the identifier of the MAPDU session, and the identifier of the MAPDU session is used to determine the identifier of the certificate of the terminal device.
28. The method according to any one of claims 22 - 27, characterized in that, it further includes: the session management function sends the identifier of the MAPDU session to the user plane function, and the identifier of the MAPDU session is used to determine the identifier of the certificate of the user plane function.
29. The method according to any one of claims 22 - 28, characterized in that, before the session management function sends the certificate application instruction to the user plane function, it further includes: the session management function determines to enable the function corresponding to the MPQUIC connection.
30. The method according to claim 29, characterized in that, The session management function determines to enable the functions corresponding to the MPQUIC connection, including: The session management function receives capability information from the terminal device, and determines that the terminal device supports establishing the MPQUIC connection according to the capability information of the terminal device; and / or, The session management function supports the functions corresponding to the MPQUIC connection.
31. A communication method, characterized in that, it includes: During the establishment process of the multi-access protocol data unit (MAPDU) session of the terminal device, the user plane function receives a certificate application instruction from the session management function, and requests a certificate of the user plane function from the certificate authority according to the certificate application instruction; During the establishment process of the MPQUIC connection between the terminal device and the user plane function, the user plane function sends the certificate of the user plane function to the terminal device, and the certificate of the user plane function is used for the terminal device to authenticate the user plane function; Wherein, the MPQUIC connection is associated with the MAPDU session, and the data of the MPQUIC connection is transmitted by multiple paths between the terminal device and the user plane function.
32. The method according to claim 31, characterized in that, The user plane function requests the certificate of the user plane function from the certificate authority, including: The user plane function sends a second certificate request to the certificate authority, and the second certificate request is used to request the certificate of the user plane function; The user plane function receives the certificate of the user plane function from the certificate authority.
33. The method according to claim 31 or 32, characterized in that, During the establishment process of the MPQUIC connection between the terminal device and the user plane function, the method further includes: The user plane function receives the certificate of the terminal device from the terminal device; The user plane function authenticates the terminal device according to the certificate of the terminal device.
34. The method according to any one of claims 31-33, characterized in that, The second certificate request includes the public key of the user plane function, and the public key of the user plane function is used to determine the certificate of the user plane function; The method further includes: The user plane function generates the public key of the user plane function.
35. The method according to any one of claims 31-34, characterized in that, The second certificate request further includes the identifier of the MAPDU session, and the identifier of the MAPDU session is used to determine the identifier of the certificate of the user plane function; The method further includes: The user plane function receives the identifier of the MAPDU session from the session management function.
36. The method according to any one of claims 31-35, characterized in that, it further includes: The user plane function sends a confirmation instruction to the session management function, and the confirmation instruction is used to indicate that the user plane function has successfully requested the certificate of the user plane function.
37. A communication device, characterized in that, it includes a module for executing the method according to any one of claims 1 to 36.
38. A communication device, characterized in that, it comprises a processor and an interface circuit, the interface circuit being configured to receive signals from other communication devices outside the communication device and transmit them to the processor or send signals from the processor to other communication devices outside the communication device, and the processor is configured to implement the method according to any one of claims 1 to 36 through logic circuits or by executing code instructions.
39. A computer-readable storage medium, characterized in that, the storage medium stores a computer program or instructions, and when the computer program or instructions are executed by a communication device, the method according to any one of claims 1 to 36 is implemented.
40. A computer program product, characterized in that, the computer program product comprises a computer program or instructions, and when the computer program or instructions are executed by a communication device, the method according to any one of claims 1 to 36 is implemented.
Citation Information
Cited By
QUIC protocol link establishment process and 5G NAS flow fusion design
CN120786732A
Method for fusing quic protocol link establishment process and 5g nas process
CN120786732B
Communication method and apparatus
EP4804713A1
Communication method and apparatus
WO2025113396A1