Communication method and device and computer readable storage medium
By sending key information under a serviced RAN architecture to encrypt data transmission between the terminal device and the network element node, the business security problem caused by the inability to implement the encryption function of AMF is solved, and data transmission security is achieved without AMF transit.
Patent Information
- Application Number
- CN202311731505.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-14
- Publication Date
- 2025-06-24
AI Technical Summary
Under the service-based RAN architecture, AMF cannot implement encryption functions, resulting in the service security between the terminal equipment and the core network elements being unable to be guaranteed.
By receiving the request information and sending the key information, it is ensured that the terminal device and the network element node can encrypt the data transmitted between the network element node and the terminal device using the first key.
It provides a suitable encryption mechanism for the service-based RAN architecture to ensure that data transmission between core network elements and terminal devices can still be guaranteed without AMF.
Smart Images

Figure CN120201421A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technologies, and particularly to a communication method, an apparatus, and a computer-readable storage medium. Background Art
[0002] Currently, the interaction between a terminal device and a network element of a core network needs to be forwarded through an Access and Mobility Management Function (AMF), and the security is protected by the encryption mechanism of the AMF.
[0003] In the future, there is a high probability of introducing a service-based Radio Access Network (RAN). The nested relationship between the core network element and the AMF will be broken, and the terminal device can directly interact with the core network element without passing through the AMF for transfer. At this time, the AMF can no longer implement the encryption function, and the service security between the terminal device and the core network element cannot be guaranteed. Summary of the Invention
[0004] The technical problem solved by the present application is how to ensure the service security in a service-based RAN architecture.
[0005] To solve the above technical problem, an embodiment of the present application provides a communication method, including: receiving request information for requesting a first service; sending key information for indicating a first key, where the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
[0006] Optionally, the sending of the key information includes: sending a first message to the network element node, where the first message includes the first key.
[0007] Optionally, before sending the first message to the network element node, the method further includes: selecting the network element node from multiple candidate network element nodes, where the multiple candidate network element nodes are all associated with the first service.
[0008] Optionally, the sending of the key information includes: sending a second message to the terminal device, where the second message includes input parameters for generating the first key.
[0009] Optionally, the input parameters include: an identifier of the network element node and / or an address of the network element node.
[0010] Optionally, the request information is received from a server or the terminal device.
[0011] Optionally, the network element node is selected from: a positioning management function node and a sensing function node.
[0012] To solve the above technical problems, an embodiment of the present application further provides a communication method, including: receiving key information, where the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; processing the data of the first service using the first key, and transmitting it to the network element node via a radio access network.
[0013] Optionally, the receiving key information includes: receiving second information, where the second information includes input parameters, and the input parameters are used to generate the first key.
[0014] Optionally, the input parameters include: an identifier of the network element node and / or an Internet Protocol address of the network element node for network interconnection.
[0015] Optionally, the method further includes: sending request information, where the request information is used to request the first service.
[0016] To solve the above technical problems, an embodiment of the present application further provides a communication method, including: receiving key information, where the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; processing the data of the first service using the first key, and transmitting it to the terminal device via a radio access network.
[0017] Optionally, the receiving key information includes: receiving first information, where the first information includes the first key.
[0018] Optionally, the network element node is selected from: a positioning management function node and a sensing function node.
[0019] To solve the above technical problems, an embodiment of the present application further provides a communication device, including: a receiving module, configured to receive request information, where the request information is used to request the first service; a sending module, configured to send key information, where the key information is used to indicate a first key, and the first key is used to encrypt the data of the first service transmitted between a network element node and a terminal device.
[0020] To solve the above technical problems, an embodiment of the present application further provides a communication device, including: a receiving module, configured to receive key information, where the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; a transmission module, configured to process the data of the first service using the first key, and transmit it to the network element node via a radio access network.
[0021] To solve the above technical problems, an embodiment of the present application further provides a communication device, including: a receiving module, configured to receive key information, where the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; a transmitting module, configured to process the data of the first service using the first key and transmit it to the terminal device via a radio access network.
[0022] To solve the above technical problems, an embodiment of the present application further provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transitory storage medium, on which a computer program is stored, and when the computer program is run by a processor, it executes the steps of the above method.
[0023] To solve the above technical problems, an embodiment of the present application further provides a communication device, including a memory and a processor, where a computer program that can run on the processor is stored on the memory, and when the processor runs the computer program, it executes the steps of the above method.
[0024] Compared with the prior art, the technical solution of the embodiment of the present application has the following beneficial effects:
[0025] On the AMF side, an embodiment of the present application provides a communication method, including: receiving request information, where the request information is used to request a first service; sending key information, where the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
[0026] Compared with the prior art where the AMF acts as a relay node to complete encryption when forwarding messages / data between a terminal device and a core network element, the first service involved in this implementation scheme is a service carried out under a service-based RAN architecture. Since the AMF does not perform a data relay function at this time, by sending the key information to both parties of the communication (for example, a terminal device and a network element node), it is ensured that each communication party can correctly encrypt and decrypt the transmitted data. Thus, a suitable encryption mechanism is provided for the service-based RAN architecture, and the security can still be guaranteed when the data transmission between the core network element and the terminal device does not pass through the AMF.
[0027] On the terminal device side, an embodiment of the present application further provides a communication method, including: receiving key information, where the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; using the first key to process the data of the first service and transmitting it to the network element node via a radio access network.
[0028] Compared with the prior art where the terminal device only needs to send and receive data decrypted and encrypted by the AMF, in this implementation, by indicating the first key configured on the AMF side to the terminal device, the terminal device can correctly encrypt and decrypt the transmitted data during communication with the network element node through the RAN. Thus, a suitable encryption mechanism is provided for the service-based RAN architecture, and the security can still be ensured when the data transmission between the core network element and the terminal device does not pass through the AMF.
[0029] On the core network side, an embodiment of the present application further provides a communication method, including: receiving key information for indicating a first key, where the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; processing the data of the first service using the first key and transmitting it to the terminal device via the radio access network.
[0030] Compared with the prior art where the network element node only needs to send and receive data decrypted and encrypted by the AMF, in this implementation, by indicating the first key configured on the AMF side to the network element node, the network element node can correctly encrypt and decrypt the transmitted data during communication with the terminal device through the RAN. Thus, a suitable encryption mechanism is provided for the service-based RAN architecture, and the security can still be ensured when the data transmission between the core network element and the terminal device does not pass through the AMF. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 is a schematic diagram of the architecture of the first service-based RAN of the present application;
[0032] Figure 2 is a schematic diagram of the architecture of the second service-based RAN of the present application;
[0033] Figure 3 is a schematic diagram of the architecture of the third service-based RAN of the present application;
[0034] Figure 4 is a signaling interaction diagram of a communication method according to an embodiment of the present application;
[0035] Figure 5 is a schematic structural diagram of a communication device according to an embodiment of the present application;
[0036] Figure 6 is a schematic structural diagram of another communication device according to an embodiment of the present application;
[0037] Figure 7 is a schematic structural diagram of yet another communication device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0038] As described in the background art, in a service-based RAN architecture, the existing encryption function implemented through the AMF is no longer applicable, and the service security between the terminal device and the core network element cannot be guaranteed.
[0039] Specifically, the interaction between the existing terminal device and the core network element is forwarded through the AMF. Taking the positioning service as an example, there is no direct interface between the positioning management server (also known as the Location Management Function, LMF) and the terminal device. For security reasons, the data of the positioning service (e.g., including positioning requests and positioning reports) needs to be encrypted. Since the interaction between the terminal device and the LMF necessarily passes through the AMF, it can be encrypted through the AMF.
[0040] Considering that 6G will introduce a service-based architecture, one option is that the RAN directly accesses the core network without forwarding through the AMF. Therefore, a new encryption mechanism needs to be designed for the service-based RAN architecture.
[0041] To solve the above technical problems, an embodiment of the present application provides a communication method, including: receiving request information for requesting a first service; sending key information for indicating a first key, where the first key is used to encrypt the data of the first service transmitted between the network element node and the terminal device.
[0042] The first service involved in this implementation scheme is a service carried out in a service-based RAN architecture. Since the AMF does not play a data transfer function at this time, by sending the key information to both parties of the communication (e.g., the terminal device and the network element node), it is ensured that all parties to the communication can correctly encrypt and decrypt the transmitted data. Thus, a suitable encryption mechanism is provided for the service-based RAN architecture, and the security can still be guaranteed when the data transmission between the core network element and the terminal device does not pass through the AMF.
[0043] The service-based RAN architecture in the embodiment of the present application can be as Figures 1 to 3 shown in any one of
[0044] Figure 1An exemplary network architecture under the full service enablement of the N2 interface is shown, which can realize direct service calls between the access network network functions (RAN Network Function, RAN NF) and the core network network functions (Core Network NF, CN NF). Specifically, the terminal device (identified as UE in the figure) can access the core network through the AMF access bus. Further, the terminal device can also directly access the core network through the RAN, thus breaking through the existing mechanism of the sole forwarding by the AMF. The RAN includes the control plane RAN (identified as RAN-C in the figure) and the user plane RAN (identified as RAN-U in the figure). Further, Figure 1 In the shown architecture, the application function (AF), network repository function (NRF), policy control function (PCF), and unified data management function (UDM) on the core network side also directly access the bus. Further, the user plane function (User Plane Function, abbreviated as UPF) and the data network (Data Network, DN) can access the bus through the session management function (Session Management Function, abbreviated as SMF).
[0045] Figure 2 An exemplary network architecture for the service enablement of traditional RAN functions is shown, where the functions (also known as RAN capabilities) are split into services, and further the integration design of RAN and CN related function services and processes is realized to better meet the design principles of high cohesion and loose coupling and streamline the network design. Specifically, the terminal device (identified as UE in the figure) can access the bus through the AMF. Further, the terminal device can also access the RAN through the radio unit (RU) and directly access the core network via the RAN, where the RU is responsible for processing the digital front end (DFE) and part of the physical (PHY) layer functions. Further, the RAN is split into the RAN control plane service (implemented based on the control plane service (CPS)) and the RAN user plane service (implemented based on the user plane service (UPS)). Further, a core network user plane service (implemented based on the UPS) is set up to communicate with the RAN and directly access the bus. Further, other core network elements such as AF, NRF, PCF, and UDM directly access the bus. Further, the SMF can also directly access the bus. Further, the DN accesses the bus through the core network user plane service.
[0046] Figure 3 An exemplary network architecture for the service-oriented addition of DOICT capabilities is presented. In this architecture, functions such as artificial intelligence (AI), computing, and data are defined as services. Among them, DOICT simplifies the on-site network deployment through communication technology (CT); achieves high reliability through in-depth collaboration with industrial protocols using operational technology (OT); realizes intelligence through data technology (DT) to ensure a low-latency experience in a closed loop; and enables more industrial applications through information technology (IT) to reduce construction costs and achieve flexible networking. Specifically, the terminal device accesses the RAN through the RU and directly accesses the core network via the RAN. Further, the RAN is split into an RAN control plane service (implemented based on the cyber physical system (CPS)), an RAN user plane service (implemented based on the user physical system (UPS)), and multi-dimensional capability service orientation (including AI services, computing services, and data services). Further, the AMF accesses the bus and is decoupled from the terminal device. Further, other core network elements such as the network exposure function (NEF), AF, NRF, PCF, and UDM directly access the bus. Further, the SMF can also directly access the bus. Further, the DN accesses the bus through the UPF, and the UPF communicates with the RAN.
[0047] In the embodiments of the present application, the network element node can be a core network element that performs functions related to the first service. The first service can be a service implemented based on the service-oriented RAN architecture. For example, the first service can be a positioning service, and the corresponding network element node can be a location management function (LMF) node (abbreviated as SMF). Another example is that the first service can be a sensing (also known as perception) service, and the corresponding network element node can be a sensing function (SF) node (abbreviated as SF).
[0048] In the embodiments of the present application, although the AMF no longer forwards data between the terminal device and the network element node, it still performs a management function.
[0049] To make the above objects, features, and beneficial effects of the present application more obvious and understandable, the following detailed description of the specific embodiments of the present application will be given in conjunction with the accompanying drawings.
[0050] Figure 4It is a signaling interaction diagram of a communication method according to an embodiment of the present application.
[0051] This implementation solution can be applied to a communication scenario under a service-based RAN architecture. The terminal device directly interacts with the network element node via the RAN to transmit data of the first service, without going through the AMF for transit.
[0052] In a specific implementation, in the communication method provided by the following steps S101 to S102, the steps implemented by the terminal device can be executed by a chip with communication functions in the terminal device, or can be executed by the baseband chip in the terminal device; the steps implemented by the AMF can be executed by a chip with communication functions in the AMF, or can be executed by the baseband chip in the AMF; the steps implemented by the network element node can be executed by a chip with communication functions in the network element node, or can be executed by the baseband chip in the network element node.
[0053] Specifically, referring to Figure 4 , the communication method described in this implementation solution may include the following steps:
[0054] Step S101, the terminal device sends a request message to the AMF. Correspondingly, the AMF receives the request message. Among them, the request message is used to request the first service.
[0055] For example, the first service may be a positioning service. Correspondingly, the request message may be a positioning request message.
[0056] In some embodiments, the sending of the request message can be actively triggered by the terminal device.
[0057] In some embodiments, the server can trigger the terminal device to send a request message to the AMF. Among them, the server can be, for example, an external server for implementing the first service.
[0058] In some embodiments, the server can directly send a request message to the AMF.
[0059] In some embodiments, the requested first service can be an uplink service or a downlink service.
[0060] In some embodiments, the request message may include relevant information for implementing the first service, such as the identifier of the terminal device (used to uniquely identify the terminal device), Quality of Service (QoS).
[0061] Still taking the terminal device requesting a positioning service as an example, the positioning request message sent in step S101 may include the identifier of the terminal device and the QoS of the positioning (such as positioning accuracy requirements, latency requirements, etc.).
[0062] In a specific implementation, continue to refer toFigure 4 In response to receiving the request information, the AMF may execute step S102 to send key information to the terminal device and the network element node respectively. Correspondingly, the network element node and the terminal device each receive the key information. The key information is used to indicate a first key, and the first key is used to encrypt the data of the first service transmitted between the network element node and the terminal device.
[0063] In some embodiments, for the interaction between the network element node and the AMF, step S102 may specifically include step S1021 and step S1022.
[0064] In step S1021, the AMF selects a network element node from multiple candidate network element nodes, and all the multiple candidate network element nodes are associated with the first service.
[0065] Specifically, the core network may deploy multiple network element nodes for the first service, and these network element nodes serve as candidate network element nodes. After receiving the request information, the AMF selects one from the multiple candidate network element nodes and determines it as the network element node communicating with the terminal device.
[0066] Still taking the positioning request information as an example, the AMF may select one from multiple candidate LMFs nearby and determine it as the LMF communicating with the terminal device to implement the positioning service.
[0067] For another example, the request information may be used to request a sensing service, and the AMF may select one from multiple candidate SFs and determine it as the SF communicating with the terminal device to implement the sensing service.
[0068] Further, after determining the network element node, the AMF may continue to execute step S1022 to send a first piece of information to the network element node. Correspondingly, the network element node receives the first piece of information. The first piece of information includes the first key.
[0069] Thus, the AMF directly provides the generated first key to the network element node.
[0070] In some embodiments, the first keys assigned to different candidate network element nodes may not be repeated.
[0071] In a specific implementation, for the interaction between the terminal device and the AMF, step S102 may specifically include step S1023, where the AMF sends a second piece of information to the terminal device. Correspondingly, the terminal device receives the second piece of information. The second piece of information includes input parameters, and the input parameters are used to generate the first key.
[0072] Specifically, a part of the input parameters may be pre-configured by the network or predefined by the protocol or determined by the terminal device itself, and the remaining part (for example, parameters related to the network element node) may be indicated by the AMF to the terminal device.
[0073] Still taking the first service as the targeted service as an example, the input parameters required for the derivation of the key (K LMF ) of the LMF may include:
[0074] - FC = 0x6E, which is used to distinguish different derivation algorithms;
[0075] - P0 = the uplink / downlink Non-Access Stratum (NAS) count (Uplink / Downlink NASCOUNT), which is the sequence number when the terminal device and the AMF transmit signaling;
[0076] - L0 = the length of the uplink / downlink NAS count, for example, 0x00 0x04;
[0077] - P1 = the Network function distinguisher, which is used to distinguish different network functions;
[0078] - L1 = the length of the Network function distinguisher, for example, 0x00 0x01.
[0079] In some embodiments, the input parameters carried in the second information may include the P1 parameter. Since the P1 parameter is used to distinguish different network functions, it can also be referred to as the identifier of the network element node (in this example, it can be understood as the type identifier) to distinguish network element nodes with different functions. For example, the P1 value corresponding to the LMF is 0x01, and the P1 value corresponding to the SF is 0x02.
[0080] In a variant, the content of the P1 parameter may be the Identification (ID) of the network element node, which is used to uniquely identify the candidate network element node. For example, the core network side includes multiple candidate LMFs, and each candidate LMF is assigned its own unique ID. After the AMF selects one from the multiple candidate LMFs, it indicates the ID of the selected LMF to the terminal device through the second information.
[0081] In a variant, the content of the P1 parameter may be replaced by the Network function address, and correspondingly, the content of the L1 parameter may be replaced by the length of the Network function address.
[0082] The address of the network element node can be, for example, an Internet Protocol (IP) address, or can also be, for example, a Medium Access Control (MAC) address.
[0083] In another variant, in addition to the P1 parameter, the input parameters required for the derivation of the key (K LMF ) of the LMF may further include P2 = network function address, and L2 = length of the network function address. Further, the second information may include the P1 parameter and the P2 parameter.
[0084] In a specific implementation, the AMF indicates, in the second information, the identity (including type identity and / or identity) and / or address of the network element node associated with the first service, for the terminal device to generate a first key for interacting with the network element node.
[0085] For example, in response to receiving the second information, the terminal device calculates K AMF based on the K value configured in the Universal Subscriber Identity Module (USIM) and the dynamic parameters provided by the network. Further, a first key is calculated in combination with the input parameters (including the content carried in the second information (such as P1 and / or P2) and the content determined by the terminal device itself).
[0086] In some embodiments, the action of sending the second information to the terminal device (corresponding to step S1023) can be performed before / after / simultaneously with the action of sending the first information to the network element node (corresponding to steps S1021 and S1022).
[0087] In a specific implementation, in response to receiving the first information and the second information respectively, the network element node and the terminal device can perform direct communication via the RAN using the first key.
[0088] Specifically, in response to receiving the second information, the terminal device can perform step S103 to process the data of the first service using the first key and transmit it to the network element node via the RAN.
[0089] Similarly, in response to receiving the first information, the network element node can perform step S104 to process the data of the first service using the first key and transmit it to the terminal device via the RAN.
[0090] In a variant, step S101 can be omitted, and the AMF can actively send the key information to the terminal device when it accesses. Further, the AMF can also actively send the key information to the network element node corresponding to the first service that the terminal device needs to implement.
[0091] In a variant, step S102 may be omitted. For example, if there is only one network element node associated with the first service, the AMF may directly execute step S103 to send the key information to the network element node.
[0092] As described above, by sending the key information to both parties of the communication (e.g., the terminal device and the network element node), the AMF ensures that all parties to the communication can correctly encrypt and decrypt the transmitted data. In response to receiving the key information (e.g., the second information), the terminal device can correctly encrypt and decrypt the transmitted data during communication with the network element node via the RAN. In response to receiving the key information (e.g., the first information), the network element node can correctly encrypt and decrypt the transmitted data during communication with the terminal device via the RAN. Thus, a suitable encryption mechanism is provided for the service-based RAN architecture, and security can still be ensured even when the data transmission between the core network element and the terminal device does not pass through the AMF.
[0093] Figure 5 It is a schematic structural diagram of a communication device 2 according to an embodiment of the present application. Those skilled in the art understand that the communication device 2 described in this embodiment can be used to implement the above Figures 1 to 4 method technical solutions described in the above-mentioned embodiments.
[0094] Specifically, the communication device 2 described in this embodiment may include: a receiving module 21 for receiving a request message, where the request message is used to request a first service; a sending module 22 for sending key information, where the key information is used to indicate a first key, and the first key is used to encrypt the data of the first service transmitted between the network element node and the terminal device.
[0095] For more content regarding the working principle and working mode of the communication device 2, reference may be made to the relevant descriptions in the above Figures 1 to 4 and will not be elaborated here.
[0096] In a specific implementation, the above-mentioned communication device 2 may correspond to a chip with communication functions in a network device, or correspond to a chip with data processing functions, such as a System-On-a-Chip (SOC for short), a baseband chip, etc.; or correspond to a chip module including a chip with communication functions in a network device; or correspond to a chip module with a data processing function chip, or correspond to a network device. In this example, the network device may be, for example, an AMF.
[0097] Figure 6 It is a schematic structural diagram of another communication device 3 according to an embodiment of the present application. Those skilled in the art understand that the communication device 3 described in this embodiment can be used to implement the above Figures 1 to 4 method technical solutions described in the above-mentioned embodiments.
[0098] Specifically, referring to Figure 6 , the communication device 3 in this embodiment may include: a receiving module 31, configured to receive key information, where the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; a transmitting module 32, configured to process the data of the first service using the first key and transmit the data to the network element node via a radio access network.
[0099] For more content about the working principle and working mode of the communication device 3, reference may be made to the relevant descriptions in the above Figures 1 to 4 , which will not be elaborated here.
[0100] In a specific implementation, the above communication device 3 may correspond to a chip with a communication function in a terminal device, or a chip with a data processing function, such as a System-On-a-Chip (SOC for short), a baseband chip, etc.; or a chip module including a chip with a communication function in a terminal device; or a chip module with a data processing function chip, or a terminal device.
[0101] Figure 7 FIG. 15 is a schematic structural diagram of another communication device 4 according to an embodiment of the present application. Those skilled in the art understand that the communication device 4 in this embodiment may be used to implement the method technical solution described in the above Figures 1 to 4 embodiment.
[0102] Specifically, referring to Figure 7 , the communication device 4 in this embodiment may include: a receiving module 41, configured to receive key information, where the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; a transmitting module 42, configured to process the data of the first service using the first key and transmit the data to the terminal device via a radio access network.
[0103] For more content about the working principle and working mode of the communication device 4, reference may be made to the relevant descriptions in the above Figures 1 to 4 , which will not be elaborated here.
[0104] In a specific implementation, the above communication device 4 may correspond to a chip with a communication function in a network device, or a chip with a data processing function, such as a System-On-a-Chip (SOC for short), a baseband chip, etc.; or a chip module including a chip with a communication function in a network device; or a chip module with a data processing function chip, or a network device. In this example, the network device may be, for example, a core network element (i.e., a network element node).
[0105] In specific implementations, for each of the devices and products described in the above embodiments, each module / unit included therein can be a software module / unit, a hardware module / unit, or can be partially a software module / unit and partially a hardware module / unit.
[0106] For example, for each of the devices and products applied to or integrated into a chip, each module / unit included therein can be implemented in a hardware manner such as a circuit, or at least some of the modules / units can be implemented in the form of a software program that runs on a processor integrated inside the chip, and the remaining (if any) part of the modules / units can be implemented in a hardware manner such as a circuit; for each of the devices and products applied to or integrated into a chip module, each module / unit included therein can be implemented in a hardware manner such as a circuit, and different modules / units can be located in the same component (such as a chip, a circuit module, etc.) or different components of the chip module, or at least some of the modules / units can be implemented in the form of a software program that runs on a processor integrated inside the chip module, and the remaining (if any) part of the modules / units can be implemented in a hardware manner such as a circuit; for each of the devices and products applied to or integrated into a terminal, each module / unit included therein can be implemented in a hardware manner such as a circuit, and different modules / units can be located in the same component (such as a chip, a circuit module, etc.) or different components inside the terminal, or at least some of the modules / units can be implemented in the form of a software program that runs on a processor integrated inside the terminal, and the remaining (if any) part of the modules / units can be implemented in a hardware manner such as a circuit.
[0107] An embodiment of the present invention further provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transitory storage medium, on which a computer program is stored, and when the computer program is run by a processor, it executes the steps of the communication method provided in any of the above embodiments. Preferably, the storage medium can include computer-readable storage media such as non-volatile memory or non-transitory memory. The storage medium can include ROM, RAM, a magnetic disk, or an optical disc, etc.
[0108] An embodiment of the present invention further provides another communication device, including a memory and a processor, where a computer program that can run on the processor is stored on the memory, and when the processor runs the computer program, it executes the steps of the communication method provided in the corresponding embodiment above. Figure 4 The communication device can be integrated into a terminal / network device, or the communication device can be, for example, a terminal / network device.
[0109] The technical solution of this application is applicable to the fifth-generation (5G) communication system, and is also applicable to the fourth-generation (4G), third-generation (3G) communication systems, and can also be applicable to various future new communication systems, such as the sixth-generation (6G), seventh-generation (7G), etc. The embodiments of this application do not limit this. th Generation,5G) communication system, and is also applicable to the fourth-generation (4 th Generation,4G), third-generation (3 rd Generation,3G) communication systems, and can also be applicable to various future new communication systems, such as the sixth-generation (6 th Generation,6G), seventh-generation (7th Generation,7G), etc. The embodiments of this application do not limit this.
[0110] The technical solution of this application is also applicable to different network architectures, including but not limited to relay network architectures, dual-link architectures, vehicle-to-everything (V2X) architectures, device-to-device (D2D) architectures, etc.
[0111] The devices in the embodiments of this application include network devices and terminal devices.
[0112] The network devices in the embodiments of this application include base stations and base station controllers in the access network, and may also include terminal devices. -
[0113] The base station (BS) in the embodiments of this application, also referred to as base station equipment, is a device deployed in the radio access network (RAN) to provide wireless communication functions. For example, the devices providing base station functions in the 2G network include base transceiver stations (BTSs), the devices providing base station functions in the 3G network include NodeBs, the devices providing base station functions in the 4G network include evolved NodeBs (eNBs), in wireless local area networks (WLANs), the device providing base station functions is an access point (AP), the device providing base station functions in 5G new radio (NR) is a gNB, and the next-generation evolved NodeB (ng-eNB). Among them, the gNB and the terminal device communicate using NR technology, and the ng-eNB and the terminal device communicate using evolved universal terrestrial radio access (E-UTRA) technology. Both the gNB and the ng-eNB can be connected to the 5G core network. The base stations in the embodiments of this application also include devices providing base station functions in future new communication systems, etc.
[0114] The base station controller in the embodiments of the present application, which can also be referred to as a base station controller device, is a device for managing base stations. For example, the base station controller (BSC) in a 2G network, the radio network controller (RNC) in a 3G network, and it can also refer to a device for controlling and managing base stations in future new communication systems.
[0115] The terminal device in the embodiments of the present application, which can also be referred to as a terminal, can refer to various forms of user equipment (UE), access terminal devices, user units, user stations, mobile stations (MS), remote stations, remote terminal devices, mobile devices, user terminal devices, wireless communication devices, user agents, or user devices. The terminal device can also be a cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), a handheld device with wireless communication function, a computing device, or other processing devices connected to a wireless modem, in-vehicle devices, wearable devices, terminal devices in future 5G networks, or terminal devices in future evolved public land mobile networks (PLMN). The embodiments of the present application are not limited thereto.
[0116] Although the present application is disclosed as above, the present application is not limited thereto. Any person skilled in the art can make various changes and modifications without departing from the spirit and scope of the present application. Therefore, the protection scope of the present application shall be subject to the scope defined by the claims.
Claims
1. A communication method, characterized in that, including: Receiving request information for requesting a first service; Sending key information for indicating a first key, where the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
2. The method according to claim 1, characterized in that, The sending key information includes: Sending a first message to the network element node, where the first message includes the first key.
3. The method according to claim 2, wherein Before sending the first message to the network element node, it further includes: Selecting the network element node from multiple candidate network element nodes, where the multiple candidate network element nodes are all associated with the first service.
4. The method according to any one of claims 1 to 3, characterized in that The sending key information includes: Sending a second message to the terminal device, where the second message includes input parameters for generating the first key.
5. The method according to claim 4, characterized in that, The input parameters include: an identifier of the network element node and / or an address of the network element node.
6. The method according to any one of claims 1 to 5, characterized in that, The request information is received from a server or the terminal device.
7. The method according to any one of claims 1 to 5, characterized in that The network element node is selected from: a positioning management function node and a sensing function node.
8. A communication method, characterized in that, including: Receiving key information for indicating a first key, where the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; Processing the data of the first service using the first key and transmitting it to the network element node via a radio access network.
9. The method according to claim 8, wherein The receiving key information includes: Receiving a second message, where the second message includes input parameters for generating the first key.
10. The method according to claim 9, wherein The input parameters include: an identifier of the network element node and / or an Internetwork Protocol address of the network element node.
11. The method according to any one of claims 8 to 10, characterized in that It further includes: Sending request information for requesting a first service.
12. A communication method, characterized in that, including: Receiving key information for indicating a first key, where the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; Processing the data of the first service using the first key and transmitting it to the terminal device via a radio access network.
13. The method according to claim 12, wherein The receiving key information includes: Receiving a first message, where the first message includes the first key.
14. The method according to claim 12 or 13, characterized in that, The network element node is selected from: a positioning management function node and a sensing function node.
15. A communication device, characterized in that, including: A receiving module for receiving request information for requesting a first service; A sending module for sending key information for indicating a first key, where the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
16. A communication device, characterized in that, including: A receiving module for receiving key information for indicating a first key, where the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; A transmission module for processing the data of the first service using the first key and transmitting it to the network element node via a radio access network.
17. A communication device, characterized in that, including: A receiving module for receiving key information for indicating a first key, where the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; A transmission module for processing the data of the first service using the first key and transmitting it to the terminal device via a radio access network.
18. A computer-readable storage medium, which is a non-volatile storage medium or a non-transitory storage medium, and has a computer program stored thereon, characterized in that, When the computer program is run by a processor, it executes the steps of the method according to any one of claims 1 to 14.
19. A communication device, comprising a memory and a processor, wherein a computer program capable of running on the processor is stored on the memory, characterized in that, When the processor runs the computer program, it executes the steps of the method according to any one of claims 1 to 14.
Citation Information
Cited By
Communication method and apparatus, and computer readable storage medium
WO2025124347A1