Apparatus, method, apparatus and computer readable medium for network slice security
By processing slice-specific security information and key management in network slices, the security isolation and service continuity problems of network slices during base station handover are solved, and secure transmission and uninterrupted service between network slices are achieved.
Patent Information
- Application Number
- CN202280102199.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-29
- Publication Date
- 2025-07-08
AI Technical Summary
In network slices, weak network slice isolation may endanger the entire network security, especially in mobility scenarios, when user equipment switches at base stations, sensitive data may be exposed to other network slices through side channel attacks, resulting in discontinuity of network services.
By implementing slice-specific security information processing in terminal devices and network devices, including receiving and deriving slice keys, selecting appropriate targets to access network devices, and performing slice remapping during the handover process to ensure the transmission of secure information and key updates, ensuring the continuity of network services.
It realizes the secure isolation and service continuity of network slices during base station handover, prevents sensitive data leakage, and ensures the security and uninterrupted service between network slices.
Smart Images

Figure CN120283424A_ABST
Abstract
Description
Technical Field
[0001] Various embodiments relate to devices, methods, apparatuses, and computer-readable media for network slice security. Background Art
[0002] A network slice, which can also be simply referred to as a slice, can be understood as a logical network over a shared infrastructure. For example, by co-existing multiple network slice instances on the same network infrastructure, various communication service instances with different requirements for data rate, reliability, latency, communication range, and speed can be supported. Different service types may include different levels of isolation and security requirements. Weak network slice isolation may endanger the entire network, such as the security of the fifth-generation system (5GS). For example, sensitive data of one network slice may be exposed to applications running in other network slices through side-channel attacks. For example, in a mobility scenario, a user equipment (UE) may hand over from one base transceiver station (BTS) (such as an evolved Node B (eNB), a next-generation Node B (gNB), etc.) to another BTS, and network slice isolation also needs to be addressed to ensure reliable and guaranteed services while providing network slice service continuity. Summary of the Invention
[0003] A brief overview of each exemplary embodiment is provided below to provide a basic understanding of some aspects of the various embodiments. It should be noted that this overview is not intended to identify the key features of the basic elements or to define the scope of the embodiments, and its sole purpose is to introduce some concepts in a simplified form as a preamble to the more detailed description provided below.
[0004] In a first aspect, a terminal device is disclosed. The terminal device may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the terminal device to at least perform: receiving slice-specific security information from a source access network device associated with a handover of the terminal device; and deriving at least one key specific to the slice based on the slice-specific security information.
[0005] In some example embodiments, the slice may be a first slice or a second slice remapped from the first slice.
[0006] In some example embodiments, the second slice may be equivalent to the first slice, the security information specific to the first slice may include at least one of the following: an identity of the first slice, or encryption algorithm information specific to the first slice, and the security information specific to the second slice may include at least one of the following: an identity of the second slice, or encryption algorithm information specific to the second slice.
[0007] In a second aspect, a network device is disclosed. The network device may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the network device to at least perform: selecting a target access network device associated with a handover of a terminal device based on security capabilities specific to a first slice used by the terminal device of the target access network device; and transmitting security information specific to the first slice or security information specific to a second slice remapped from the first slice to the target access network device.
[0008] In some example embodiments, the security information specific to the first slice may include at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice.
[0009] In some example embodiments, the network device may be a source access network device associated with the handover, and when the instructions are executed by the at least one processor, cause the network device to further perform: receiving, from the target access network device, corresponding security capabilities specific to one or more slices supported by the target access network device.
[0010] In some example embodiments, the corresponding security capabilities specific to the one or more slices may include at least one of the following: corresponding identifiers of the one or more slices or corresponding encryption algorithm information specific to the one or more slices.
[0011] In some example embodiments, when the instructions are executed by the at least one processor, cause the network device to further perform: receiving, from the target access network device, security information specific to a second slice remapped from the first slice; and transmitting the security information specific to the second slice to the terminal device.
[0012] In some example embodiments, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
[0013] In some example embodiments, the network device may be a target core network device associated with the handover, and when the instructions are executed by the at least one processor, cause the network device to further perform: receiving, from the target access network device or another core network device, corresponding security capabilities specific to one or more slices supported by the target access network device.
[0014] In some example embodiments, the respective security capabilities specific to the one or more slices may include at least one of the following: the respective identity of the one or more slices or the respective encryption algorithm information specific to the one or more slices.
[0015] In some example embodiments, when the instruction is executed by the at least one processor, the network device may be further caused to: receive the security information specific to the first slice from a source core network device associated with the handover.
[0016] In some example embodiments, when the instruction is executed by at least one processor, the network device may be further caused to: determine a second slice remapped from the first slice in a case where the target access network device does not support the first slice; and transmit an indication to the target access network device indicating that the second slice is remapped from the first slice.
[0017] In some example embodiments, when the instruction is executed by at least one processor, the network device may be further caused to: receive the security information specific to a second slice remapped from the first slice from the target access network device; and transmit the security information specific to the second slice to the source core network device.
[0018] In some example embodiments, when the instruction is executed by at least one processor, the network device may be further caused to: determine the security information specific to the second slice remapped from the first slice in a case where the target access network device does not support the first slice; and transmit the security information specific to the second slice to the source core network device and may transmit the security information specific to the second slice to the target access network device.
[0019] In some example embodiments, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: the identity of the second slice or the encryption algorithm information specific to the second slice.
[0020] In a third aspect, an access network device is disclosed. The access network device may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the access network device, as a target access network device associated with a handover of a terminal device, to at least: receive the security information specific to a first slice used by the terminal device or the security information specific to a second slice remapped from the first slice from another network device associated with the handover of the terminal device.
[0021] In some example embodiments, the security information specific to the first slice may include at least one of the following: the identity of the first slice, or encryption algorithm information specific to the first slice.
[0022] In some example embodiments, when the instruction is executed by the at least one processor, the access network device may be further caused to perform: in a case where the target access network device does not support the first slice, determining security information specific to a second slice remapped from the first slice, the second slice being equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: the identity of the second slice, or encryption algorithm information specific to the second slice.
[0023] In some example embodiments, when the instruction is executed by the at least one processor, the access network device may be further caused to perform: transmitting the security information specific to the second slice to the other network device; and deriving at least one key specific to the second slice based on the security information specific to the second slice.
[0024] In some example embodiments, when the instruction is executed by the at least one processor, the access network device may be further caused to perform: in a case where the target access network device does not support the first slice, determining a second slice remapped from the first slice; and deriving at least one key specific to the first slice based on the security information specific to the first slice.
[0025] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and when the instruction is executed by the at least one processor, the access network device may be further caused to perform: in a case where the target access network device does not support the first slice, receiving the security information specific to the second slice remapped from the first slice from the target core network device; and deriving at least one key specific to the second slice based on the security information specific to the second slice, the second slice being equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: the identity of the second slice or encryption algorithm information specific to the second slice.
[0026] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and when the instruction is executed by the at least one processor, it may cause the access network device to further perform: receiving from the target core network device an indication that a second slice is remapped from the first slice; and deriving at least one key specific to the first slice based on the security information specific to the first slice.
[0027] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and when the instruction is executed by the at least one processor, it may cause the access network device to further perform: in the case of receiving the security information specific to the second slice from the target core network device, deriving at least one key specific to the second slice based on the security information specific to the second slice, and the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0028] In some example embodiments, the other network device may be a source access network device associated with the handover of the terminal device, and when the instruction is executed by the at least one processor, it may cause the access network device to further perform: transmitting to the source access network device the corresponding security capabilities specific to one or more slices supported by the target access network device.
[0029] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and when the instruction is executed by the at least one processor, it may cause the access network device to further perform: transmitting to the target core network device or another core network device the corresponding security capabilities specific to one or more slices supported by the target access network device.
[0030] In some example embodiments, the corresponding security capabilities specific to the one or more slices may include at least one of the following: the corresponding identifiers of the one or more slices or the corresponding encryption algorithm information specific to the one or more slices.
[0031] In a fourth aspect, a method executed by a terminal device is disclosed. The method may include: receiving from a source access network device associated with the handover of the terminal device security information specific to a slice; and deriving at least one key specific to the slice based on the security information specific to the slice.
[0032] In some example embodiments, the slice may be a first slice or a second slice remapped from the first slice.
[0033] In some example embodiments, the second slice may be equivalent to the first slice, the security information specific to the first slice may include at least one of the following: the identifier of the first slice, or the encryption algorithm information specific to the first slice, and the security information specific to the second slice may include at least one of the following: the identifier of the second slice, or the encryption algorithm information specific to the second slice.
[0034] In a fifth aspect, a method performed by a network device is disclosed. The method may include: selecting a target access network device associated with a handover of a terminal device based on the security capabilities specific to a first slice used by the terminal device of the target access network device; and transmitting the security information specific to the first slice or the security information specific to a second slice remapped from the first slice to the target access network device.
[0035] In some example embodiments, the security information specific to the first slice may include at least one of the following: the identifier of the first slice, or the encryption algorithm information specific to the first slice.
[0036] In some example embodiments, the network device may be a source access network device associated with the handover, and the method may further include: receiving, from the target access network device, the corresponding security capabilities specific to one or more slices supported by the target access network device.
[0037] In some example embodiments, the corresponding security capabilities specific to the one or more slices may include at least one of the following: the corresponding identifiers of the one or more slices or the corresponding encryption algorithm information specific to the one or more slices.
[0038] In some example embodiments, the method may further include: receiving, from the target access network device, the security information specific to a second slice remapped from the first slice; and transmitting the security information specific to the second slice to the terminal device.
[0039] In some example embodiments, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: the identifier of the second slice or the encryption algorithm information specific to the second slice.
[0040] In some example embodiments, the network device may be a target core network device associated with the handover, and the method may further include: receiving, from the target access network device or another core network device, corresponding security capabilities specific to one or more slices supported by the target access network device.
[0041] In some example embodiments, the corresponding security capabilities specific to the one or more slices may include at least one of the following: corresponding identifiers of the one or more slices or corresponding encryption algorithm information specific to the one or more slices.
[0042] In some example embodiments, the method may further include: receiving, from a source core network device associated with the handover, security information specific to the first slice.
[0043] In some example embodiments, the method may further include: determining a second slice remapped from the first slice in the case where the target access network device does not support the first slice; and transmitting an indication to the target access network device indicating that the second slice is remapped from the first slice.
[0044] In some example embodiments, the method may further include: receiving, from the target access network device, security information specific to a second slice remapped from the first slice; and transmitting the security information specific to the second slice to the source core network device.
[0045] In some example embodiments, the method may further include: determining the security information specific to the second slice remapped from the first slice in the case where the target access network device does not support the first slice; and transmitting the security information specific to the second slice to the source core network device, and may transmit the security information specific to the second slice to the target access network device.
[0046] In some example embodiments, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
[0047] In a sixth aspect, a method performed by an access network device that is a target access network device associated with a handover of a terminal device is disclosed. The method may include: receiving, from another network device associated with the handover of the terminal device, security information specific to a first slice used by the terminal device or security information specific to a second slice remapped from the first slice.
[0048] In some example embodiments, the security information specific to the first slice may include at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice.
[0049] In some example embodiments, the method may further include: in a case where the target access network device does not support the first slice, determining security information specific to a second slice remapped from the first slice, the second slice being equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0050] In some example embodiments, the method may further include: transmitting the security information specific to the second slice to the other network device; and deriving at least one key specific to the second slice based on the security information specific to the second slice.
[0051] In some example embodiments, the method may further include: in a case where the target access network device does not support the first slice, determining a second slice remapped from the first slice; and deriving at least one key specific to the first slice based on the security information specific to the first slice.
[0052] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and the method may further include: in a case where the target access network device does not support the first slice, receiving the security information specific to the second slice remapped from the first slice from the target core network device; and deriving at least one key specific to the second slice based on the security information specific to the second slice, the second slice being equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
[0053] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and the method may further include: receiving an indication from the target core network device that a second slice is remapped from the first slice; and deriving at least one key specific to the first slice based on the security information specific to the first slice.
[0054] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and the method may further include: upon receiving the security information specific to the second slice from the target core network device, deriving at least one key specific to the second slice based on the security information specific to the second slice, and the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0055] In some example embodiments, the other network device may be a source access network device associated with the handover of the terminal device, and the method may further include: transmitting corresponding security capabilities specific to one or more slices supported by the target access network device to the source access network device.
[0056] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and the method may further include: transmitting corresponding security capabilities specific to one or more slices supported by the target access network device to the target core network device or another core network device.
[0057] In some example embodiments, the corresponding security capabilities specific to the one or more slices may include at least one of the following: corresponding identifiers of the one or more slices or corresponding encryption algorithm information specific to the one or more slices.
[0058] In a seventh aspect, a device is disclosed. The device, as a terminal device, may include: means for receiving security information specific to a slice from a source access network device associated with the handover of the terminal device; and means for deriving at least one key specific to the slice based on the security information specific to the slice.
[0059] In some example embodiments, the slice may be a first slice or a second slice remapped from the first slice.
[0060] In some example embodiments, the second slice may be equivalent to the first slice, and the security information specific to the first slice may include at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
[0061] In an eighth aspect, a device is disclosed. The device, as a network device, may include: means for selecting a target access network device associated with a handover of a terminal device based on security capabilities specific to a first slice used by the terminal device for the target access network device; and means for transmitting security information specific to the first slice or security information specific to a second slice remapped from the first slice to the target access network device.
[0062] In some example embodiments, the security information specific to the first slice may include at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice.
[0063] In some example embodiments, the network device may be a source access network device associated with the handover, and the device may further include: means for receiving, from the target access network device, corresponding security capabilities specific to one or more slices supported by the target access network device.
[0064] In some example embodiments, the corresponding security capabilities specific to the one or more slices may include at least one of the following: corresponding identifiers of the one or more slices or corresponding encryption algorithm information specific to the one or more slices.
[0065] In some example embodiments, the device may further include: means for receiving, from the target access network device, security information specific to a second slice remapped from the first slice; and means for transmitting the security information specific to the second slice to the terminal device.
[0066] In some example embodiments, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
[0067] In some example embodiments, the network device may be a target core network device associated with the handover, and the device may further include: means for receiving, from the target access network device or another core network device, corresponding security capabilities specific to one or more slices supported by the target access network device.
[0068] In some example embodiments, the corresponding security capabilities specific to the one or more slices may include at least one of the following: corresponding identifiers of the one or more slices or corresponding encryption algorithm information specific to the one or more slices.
[0069] In some example embodiments, the device may further include: means for receiving the security information specific to the first slice from a source core network device associated with the handover across areas.
[0070] In some example embodiments, the device may further include: means for determining a second slice remapped from the first slice in the case where the target access network device does not support the first slice; and means for transmitting an indication to the target access network device indicating that the second slice is remapped from the first slice.
[0071] In some example embodiments, the device may further include: means for receiving the security information specific to the second slice remapped from the first slice from the target access network device; and means for transmitting the security information specific to the second slice to the source core network device.
[0072] In some example embodiments, the device may further include: means for determining the security information specific to the second slice remapped from the first slice in the case where the target access network device does not support the first slice; and means for transmitting the security information specific to the second slice to the source core network device, and may transmit the security information specific to the second slice to the target access network device.
[0073] In some example embodiments, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0074] In a ninth aspect, a device is disclosed. The device is an access network device, and the access network device is a target access network device associated with a handover across areas of a terminal device. The device may include: means for receiving the security information specific to the first slice used by the terminal device or the security information specific to the second slice remapped from the first slice from another network device associated with the handover across areas of the terminal device.
[0075] In some example embodiments, the security information specific to the first slice may include at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice.
[0076] In some example embodiments, the device may further include: means for determining security information specific to a second slice remapped from the first slice in a case where the target access network device does not support the first slice, the second slice being equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
[0077] In some example embodiments, the device may further include: means for transmitting the security information specific to the second slice to the other network device; and means for deriving at least one key specific to the second slice based on the security information specific to the second slice.
[0078] In some example embodiments, the device may further include: means for determining a second slice remapped from the first slice in a case where the target access network device does not support the first slice; and means for deriving at least one key specific to the first slice based on the security information specific to the first slice.
[0079] In some example embodiments, the other network device may be a target core network device associated with a handover of the terminal device, and the device may further include: means for receiving, from the target core network device, the security information specific to the second slice remapped from the first slice in a case where the target access network device does not support the first slice; and means for deriving at least one key specific to the second slice based on the security information specific to the second slice, the second slice being equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0080] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and the device may further include: means for receiving an indication from the target core network device indicating that a second slice has been remapped from the first slice; and means for deriving the at least one key specific to the first slice based on the security information specific to the first slice.
[0081] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and the device may further include: means for deriving at least one key specific to the second slice based on the security information specific to the second slice when receiving the security information specific to the second slice from the target core network device, and the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0082] In some example embodiments, the other network device may be a source access network device associated with the handover of the terminal device, and the device may further include: means for transmitting the corresponding security capabilities specific to one or more slices supported by the target access network device to the source access network device.
[0083] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and the device may further include: means for transmitting the corresponding security capabilities specific to one or more slices supported by the target access network device to the target core network device or another core network device.
[0084] In some example embodiments, the corresponding security capabilities specific to the one or more slices may include at least one of the following: the corresponding identifiers of the one or more slices or the corresponding encryption algorithm information specific to the one or more slices.
[0085] In a tenth aspect, a computer-readable medium is disclosed. The computer-readable medium may include program instructions that, when executed by a terminal device, cause the terminal device to at least perform: receiving security information specific to a slice from a source access network device associated with the handover of the terminal device; and deriving at least one key specific to the slice based on the security information specific to the slice.
[0086] In some example embodiments, the slice may be a first slice or a second slice remapped from the first slice.
[0087] In some example embodiments, the second slice may be equivalent to the first slice, the security information specific to the first slice may include at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0088] In an eleventh aspect, a computer-readable medium is disclosed. The computer-readable medium may include program instructions that, when executed by a network device, cause the network device to at least perform: selecting a target access network device associated with a handover of a terminal device based on security capabilities specific to a first slice used by the terminal device for the target access network device; and transmitting security information specific to the first slice or security information specific to a second slice remapped from the first slice to the target access network device.
[0089] In some example embodiments, the security information specific to the first slice may include at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice.
[0090] In some example embodiments, the network device may be a source access network device associated with the handover, and the computer-readable medium may further include instructions that, when executed by the network device, cause the network device to further perform: receiving, from the target access network device, corresponding security capabilities specific to one or more slices supported by the target access network device.
[0091] In some example embodiments, the corresponding security capabilities specific to one or more slices may include at least one of the following: corresponding identifiers of the one or more slices or corresponding encryption algorithm information specific to the one or more slices.
[0092] In some example embodiments, the computer-readable medium may further include instructions that, when executed by the network device, cause the network device to further perform: receiving, from the target access network device, security information specific to a second slice remapped from the first slice; and transmitting the security information specific to the second slice to the terminal device.
[0093] In some example embodiments, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
[0094] In some example embodiments, the network device may be a target core network device associated with the handover, and the computer-readable medium may further include instructions that, when executed by the network device, cause the network device to further perform: receiving, from the target access network device or another core network device, corresponding security capabilities specific to one or more slices supported by the target access network device.
[0095] In some example embodiments, the respective security capabilities specific to the one or more slices may include at least one of the following: the respective identifier of the one or more slices or the respective encryption algorithm information specific to the one or more slices.
[0096] In some example embodiments, the computer-readable medium may further include instructions that, when executed by the network device, may cause the network device to further perform: receiving the security information specific to the first slice from a source core network device associated with the handover.
[0097] In some example embodiments, the computer-readable medium may further include instructions that, when executed by the network device, may cause the network device to further perform: determining a second slice remapped from the first slice in a case where the target access network device does not support the first slice; and transmitting an indication to the target access network device indicating that the second slice is remapped from the first slice.
[0098] In some example embodiments, the computer-readable medium may further include instructions that, when executed by the network device, may cause the network device to further perform: receiving the security information specific to the second slice remapped from the first slice from the target access network device; and transmitting the security information specific to the second slice to the source core network device.
[0099] In some example embodiments, the computer-readable medium may further include instructions that, when executed by the network device, may cause the network device to further perform: determining the security information specific to the second slice remapped from the first slice in a case where the target access network device does not support the first slice; and transmitting the security information specific to the second slice to the source core network device and may transmit the security information specific to the second slice to the target access network device.
[0100] In some example embodiments, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: the identifier of the second slice or the encryption algorithm information specific to the second slice.
[0101] In a twelfth aspect, a computer-readable medium is disclosed. The computer-readable medium may include program instructions that, when executed by an access network device that is a target access network device associated with a handover of a terminal device, cause the access network device to at least perform: receiving the security information specific to the first slice used by the terminal device or the security information specific to the second slice remapped from the first slice from another network device associated with the handover of the terminal device.
[0102] In some example embodiments, the security information specific to the first slice may include at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice.
[0103] In some example embodiments, the computer-readable medium may further include instructions that, when executed by the access network device, may cause the access network device to further perform: determining security information specific to a second slice remapped from the first slice in a case where the target access network device does not support the first slice, the second slice being equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0104] In some example embodiments, the computer-readable medium may further include instructions that, when executed by the access network device, may cause the access network device to further perform: transmitting the security information specific to the second slice to the other network device; and deriving at least one key specific to the second slice based on the security information specific to the second slice.
[0105] In some example embodiments, the computer-readable medium may further include instructions that, when executed by the access network device, may cause the access network device to further perform: determining a second slice remapped from the first slice in a case where the target access network device does not support the first slice; and deriving at least one key specific to the first slice based on the security information specific to the first slice.
[0106] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and the computer-readable medium may further include instructions that, when executed by the access network device, may cause the access network device to further perform: receiving, from the target core network device, the security information specific to a second slice remapped from the first slice in a case where the target access network device does not support the first slice; and deriving at least one key specific to the second slice based on the security information specific to the second slice, the second slice being equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
[0107] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and the computer-readable medium may further include instructions that, when executed by the access network device, cause the access network device to further perform: receiving, from the target core network device, an indication that a second slice is remapped from the first slice; and deriving at least one key specific to the first slice based on the security information specific to the first slice.
[0108] In some example embodiments, the other network device is a target core network device associated with the handover of the terminal device, and the computer-readable medium may further include instructions that, when executed by the access network device, cause the access network device to further perform: in a case where the security information specific to the second slice is received from the target core network device, deriving at least one key specific to the second slice based on the security information specific to the second slice, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0109] In some example embodiments, the other network device may be a source access network device associated with the handover of the terminal device, and the computer-readable medium may further include instructions that, when executed by the access network device, cause the access network device to further perform: transmitting to the source access network device the corresponding security capabilities specific to one or more slices supported by the target access network device.
[0110] In some example embodiments, the other network device may be a target core network device associated with the handover of the terminal device, and the computer-readable medium may further include instructions that, when executed by the access network device, cause the access network device to further perform: transmitting to the target core network device or another core network device the corresponding security capabilities specific to one or more slices supported by the target access network device.
[0111] In some example embodiments, the corresponding security capabilities specific to the one or more slices may include at least one of the following: the corresponding identifiers of the one or more slices or the corresponding encryption algorithm information specific to the one or more slices.
[0112] When read in conjunction with the accompanying drawings, other features and advantages of the example embodiments of the present disclosure will also become apparent from the following description of the specific embodiments, which illustrate the principles of the example embodiments of the present disclosure by way of example. Brief Description of the Drawings
[0113] Some example embodiments will now be described by way of non - limiting examples with reference to the accompanying drawings.
[0114] Figure 1 An exemplary sequence diagram showing the exchange of slice - specific security capabilities during Xn setup according to an example embodiment of the present disclosure is shown.
[0115] Figure 2 An exemplary sequence diagram showing slice - specific key update during an Xn - based handover procedure according to an example embodiment of the present disclosure is shown.
[0116] Figure 3 An exemplary sequence diagram showing slice - specific key update during an Xn - based handover procedure according to an example embodiment of the present disclosure is shown.
[0117] Figure 4 An exemplary sequence diagram showing slice - specific key update during an Xn - based handover procedure according to an example embodiment of the present disclosure is shown.
[0118] Figure 5 An exemplary sequence diagram showing the exchange of slice - specific security capabilities during NG setup according to an example embodiment of the present disclosure is shown.
[0119] Figure 6 An exemplary sequence diagram showing slice - specific key update during an N2 - based handover procedure according to an example embodiment of the present disclosure is shown.
[0120] Figure 7 An exemplary sequence diagram showing slice - specific key update during an N2 - based handover procedure according to an example embodiment of the present disclosure is shown.
[0121] Figure 8 An exemplary sequence diagram showing slice - specific key update during an N2 - based handover procedure according to an example embodiment of the present disclosure is shown.
[0122] Figure 9 An exemplary sequence diagram showing slice - specific key update during an N2 - based handover procedure according to an example embodiment of the present disclosure is shown.
[0123] Figure 10 An exemplary sequence diagram showing slice - specific key update during an N2 - based handover procedure according to an example embodiment of the present disclosure is shown.
[0124] Figure 11 A flowchart showing an example method 1100 for network slice security according to an example embodiment of the present disclosure is shown.
[0125] Figure 12 Displays a flowchart showing an example method 1200 for network slice security according to an example embodiment of the present disclosure.
[0126] Figure 13 Displays a flowchart showing an example method 1300 for network slice security according to an example embodiment of the present disclosure.
[0127] Figure 14 Displays a block diagram showing an example device 1400 for network slice security according to an example embodiment of the present disclosure.
[0128] Figure 15 Displays a block diagram showing an example device 1500 for network slice security according to an example embodiment of the present disclosure.
[0129] Figure 16 Displays a block diagram showing an example device 1600 for network slice security according to an example embodiment of the present disclosure.
[0130] Figure 17 Displays a block diagram showing an example device 1700 for network slice security according to an example embodiment of the present disclosure.
[0131] Figure 18 Displays a block diagram showing an example device 1800 for network slice security according to an example embodiment of the present disclosure.
[0132] Figure 19 Displays a block diagram showing an example device 1900 for network slice security according to an example embodiment of the present disclosure.
[0133] Throughout the drawings, the same or similar reference numerals denote the same or similar elements. A repeated description of the same elements will be omitted. Detailed Description
[0134] Hereinafter, some example embodiments will be described in detail with reference to the drawings. The following description includes specific details intended to provide a thorough understanding of various concepts. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some cases, well-known circuits, techniques, and components are shown in block diagram form to avoid obscuring the described concepts and features.
[0135] Various example embodiments of the present disclosure provide solutions for network slice security. According to various example embodiments of the present disclosure, slice-specific key sharing problems for mobility and service continuity can be solved. Various example embodiments of the present disclosure can be applied to mobility scenarios, such as Xn-based handovers (HOs), where Xn can be an interface between BTSs in a radio access network (RAN), and / or N2-based handovers, where N2 can be an interface between a BTS and a function in a core network (CN), such as an access and mobility management function (AMF). Additionally, in the case where a target BTS associated with a handover does not support the slice used by a UE, service continuity can still be achieved according to an example embodiment of the present disclosure.
[0136] Figure 1 Shows an exemplary sequence diagram for exchanging slice-specific security capabilities during Xn setup according to an example embodiment of the present disclosure. Refer to Figure 1 , access network device 110 and access network device 160 can be used as BTSs, such as eNBs and / or gNBs in a wireless communication network. In one example, a BTS (e.g., access network device 100) can perform an Xn setup process to set up an Xn interface with another BTS (e.g., access network device 160) to facilitate potential handovers of a UE between the two BTSs. Alternatively or additionally, access network device 110 and / or access network device 160 can be used as a centralized unit (CU) of a BTS.
[0137] During the Xn setup process, access network device 110 can transmit an Xn setup request message 112 to access network device 160. The Xn setup request message 112 can include corresponding security capabilities 114 specific to one or more slices supported by access network device 110. The corresponding security capabilities 114 can include at least one of the following: corresponding identifiers of one or more slices supported by access network device 110, or corresponding encryption algorithms specific to one or more slices. For example, the identifier of a slice can be a single network slice selection assistance information (S-NSSAI) value, and the slice-specific encryption algorithm can be related to at least one of the following: an algorithm for user plane (UP) integrity specific to the slice, or an algorithm for UP encryption specific to the slice. The corresponding security capabilities 114 can be in the form of a list of S-NSSAI and corresponding encryption algorithms.
[0138] Then, in response to the Xn setup request message 112, access network device 160 can transmit an Xn setup response message 162 to access network device 110.
[0139] It is understandable that in a wireless communication network, multiple access network devices may respectively transmit corresponding security capabilities specific to one or more slices supported by the multiple access network devices to the access network device 160. The access network device 160 may use the security capabilities of the corresponding multiple access network devices to select an appropriate target access network device for potential handovers of the UE. Here, the access network device 110 may represent any one of the multiple access network devices.
[0140] The access network device 160 may obtain information about the security capabilities of the corresponding multiple access network devices through an Xn setup procedure. It is understandable that the access network device 110 may transmit the corresponding security capabilities 114 specific to one or more slices supported by the access network device 100 via other messages not limited to the Xn setup request message 112 during the Xn setup procedure.
[0141] Figure 2 Shows an exemplary sequence diagram for slice - specific key update during an Xn - based handover procedure according to an example embodiment of the present disclosure. Refer to Figure 2 , the UE 230 may represent any terminal device in the wireless communication network that will perform a handover from the access network device 160. Before the handover procedure, it is assumed that the UE 230 is connected to the access network device 160, and thus the access network device 160 may be the source access network device for this handover. Additionally, during the registration process, a slice - specific encryption algorithm may be negotiated between the UE 230 and a core network device (e.g., an AMF in the core network (not shown) of the wireless communication network).
[0142] In operation 262, the source access network device 160 may decide to hand over the UE 230 to a target access network device. Assume that the UE 230 is currently using one or more slices, and the first slice may represent any one of the one or more slices. In the description, the first slice is taken as an example, and it is understandable that the example embodiments of the present disclosure may be applied to any one of the one or more slices. In operation 262, the source access network device 160 may select a target access network device based on the security capabilities of the target access network device specific to the first slice used by the UE 230, and this security capability may be exchanged during, for example, the Xn setup discussed above with reference to Figure 1 Assume that among these multiple access network devices, according to the security capabilities specific to the first slice of, for example, the access network device 110, the access network device 110 is selected as the target access network device for the handover. In one example, this selection may be made together with other information such as measurement reports and radio resource management (RRM) information.
[0143] Then, the source access network device 160 may transmit a handover request message 264 having information required to prepare for a handover at the target side to the target access network device 110. For example, the handover request 264 may include security information 266 specific to the first slice used by the UE 230. In one embodiment, the security information 266 specific to the first slice may include, for example, at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice.
[0144] In one embodiment, the identifier of the first slice may be the S-NSSAI value of the first slice. The source access network device 160 may determine the encryption algorithm information specific to the first slice based on the security capabilities of the target access network device 110 such that the target access network device 110 can support the same or a similar encryption algorithm for the first slice. The encryption algorithm information specific to the first slice may be related to, for example, at least one of the following: an algorithm for UP integrity specific to the first slice, or an algorithm for UP encryption specific to the first slice.
[0145] The target access network device 110 may perform admission control in response to the handover request 264 to determine whether it can serve the UE 230. When accepting the handover request 264, the target access network device 110 may transmit a handover request confirmation 212 to the source access network device 160. The confirmation 212 may include the necessary information required for the UE 230 to perform the handover.
[0146] When performing the handover procedure, the source access network device 160 may transmit the security information 266 specific to the first slice to the UE 230 for the UE 230 to derive a key specific to the first slice. In one embodiment, the security information 266 may be included in a Radio Resource Control (RRC) reconfiguration message together with other information required for the UE 230 to access the target access network device 110.
[0147] Based on the slice-specific security information 226 received from the source access network device 160, the access network device 110 and the UE 230 can derive at least one slice-specific security key for the first slice. For example, in operation 214, the target access network device 110 can derive a security key by inputting the identifier of the first slice (e.g., S-NSSAI) and / or the slice-specific encryption algorithm into a key derivation function (KDF). In one example, the slice-specific encryption algorithm for the first slice can include one or more encryption and integrity algorithms for protecting the UP data respectively. One or more slice-specific security keys can be derived accordingly. On the UE side, in operation 232, the UE 230 can derive at least one slice-specific security key for the first slice in a similar manner. For example, the UE 230 can derive at least one slice-specific security key by inputting the slice-specific security information 226 into the KDF. The UE 230 and the access network device 110 can use the derived slice-specific security key to protect the uplink and downlink data.
[0148] Figure 3 Shows an exemplary sequence diagram for slice-specific key update during an Xn-based handover procedure according to an example embodiment of the present disclosure. Figure 3 The processes shown in can be performed by, for example, the UE 230, the access network device 160, and the access network device 110. Details that have been described with respect to the previous figures are briefly described or omitted.
[0149] Reference Figure 3 , the source access network device 160 can, in operation 262, select the target access network device 110 based on the security capabilities of the target access network device 110 specific to the first slice used by the UE 230. Then, the source access network device 160 can transmit the slice-specific security information 266 to the selected target access network device 110 via, for example, a handover request 264.
[0150] In response to the handover request 264, the target access network device 110 may perform admission control to determine whether it can serve the first slice used by the UE 230. In the case where the target access network device 110 does not support the first slice, for example, if the target access network device 110 cannot support the first slice or the first slice is overloaded in the target access network device 110, then in operation 312, the target access network device 110 may determine a second slice remapped from the first slice instead of rejecting the handover request to provide service continuity for the UE 230. The second slice may be equivalent to the first slice. For example, the second slice and the first slice may have the same or similar security levels. For example, if the slice S-NSSAI#1 used by the UE 230 is not supported at the target access network device 110, the target access network device 110 may determine to use a second slice S-NSSAI#2 that is also supported by the source access network device 160 and the UE 230, thereby enabling temporary slice service continuity for the UE 230.
[0151] Since the target access network device 110 can provide temporary service for the UE 230 by using the remapped second slice, the target access network device 110 may transmit a handover request confirmation 212 to the access network device 160 to indicate that the handover request is accepted and provide the necessary information required for the UE 230 to perform the handover.
[0152] As an option, the network side may choose to perform slice remapping without the UE 230 being aware. For example, the target access network device 110 may decide not to let the UE 230 know that the first slice has been remapped to the second slice. This decision may be made considering the capabilities, policies, etc. of the UE 230. In this case, the handover request confirmation 212 may, for example, not have information about the remapping.
[0153] In this case, when performing the handover process, the source access network device 160 may transmit slice-specific security information 266 for the first slice to the UE 230 for the UE 230 to derive a slice-specific key for the first slice. For example, in operation 232, the UE 230 may use the slice-specific security information 266 for the first slice as an input to the KDF to derive a slice-specific security key for the first slice. For example, the UE 230 may derive at least one slice-specific security key for the first slice by inputting the identifier of the first slice (e.g., S-NSSAI) and / or the slice-specific encryption algorithm into the KDF. Since the UE 230 is not aware of the slice remapping at the access network device 110, for slice-specific security, in operation 214, the target access network device 100 may continue to use the slice-specific security information 266 for the first slice as an input to the KDF to derive a slice-specific security key for the first slice.
[0154] Figure 4 Shows an exemplary sequence diagram for slice - specific key update during an Xn - based handover procedure according to an example of the present disclosure. Figure 4 The procedures shown therein can be performed by, for example, UE 230, access network device 160, and access network device 110. Details that have been described with respect to previous figures are briefly described or omitted.
[0155] Referring to Figure 4 , the source access network device 160 can, in operation 262, select the target access network device 110 based on the security capabilities of the target access network device 110 specific to the first slice used by the UE 230. Then, the source - source access network device 160 can transmit security information 266 specific to the first slice to the selected target access network device 110 via, for example, a handover request 264.
[0156] The target access network device 110 can perform admission control in response to the handover request 264 to determine whether it can serve the UE 230. In the case where the target access network device 110 does not support the first slice, in operation 412, the access network device 100 can determine security information 416 specific to a second slice remapped from the first slice to provide service continuity for the UE 230. The second slice can be equivalent to the first slice, and the security information 416 specific to the second slice can include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0157] In one embodiment, the identifier of the second slice can be the S - NSSAI value of the second slice. The encryption algorithm information specific to the second slice can be related to, for example, at least one of the following: an algorithm for UP integrity specific to the second slice, or an algorithm for UP encryption specific to the second slice.
[0158] The second slice can be equivalent to the first slice. For example, the second slice and the first slice can have the same or similar security levels. For example, if the slice S - NSSAI#1 used by the UE 230 is not supported at the target access network device 110, the target access network device 110 can determine to use a second slice S - NSSAI#2 that is also supported by the source access network device 160 and the UE 230, thereby enabling temporary slice service continuity for the UE 230.
[0159] As an option, the network side may choose to perform slice remapping with the UE 230's knowledge. For example, the target access network device 110 may decide to let the UE 230 know that the first slice has been remapped to the second slice. In this case, the target access network device 110 may transmit the security information 416 specific to the second slice to the source access network device 160. For example, the security information 416 specific to the second slice may be transmitted via the handover request confirmation 414. The handover request confirmation 414 may indicate that the handover request is accepted and may include the necessary information required for the UE 230 to perform the handover.
[0160] In this case, when performing the handover procedure, the source access network device 160 may transmit the security information 416 specific to the second slice to the UE 230 so that the UE 230 can derive the key specific to the second slice. For example, in operation 432, the UE 230 may use the security information 416 specific to the second slice as an input to the KDF to derive the second slice-specific security key. For example, the UE 230 may derive at least one security key specific to the second slice by inputting the identity of the second slice (e.g., S-NSSAI) and / or the encryption algorithm specific to the second slice into the KDF. Before, after, or in parallel with operation 432, in operation 418, the target access network device 110 may use the security information 416 specific to the second slice as an input to the KDF to derive the second slice-specific security key.
[0161] Various example embodiments of the present disclosure have been described above in connection with Xn-based handover. It should be understood that these embodiments are merely examples and are not intended to limit the scope of the present disclosure. In fact, the present disclosure can also be applied to other mobility scenarios. For example, the scenario where the UE can switch from the source RAN to the target RAN during the N2-based handover process.
[0162] Figure 5 An exemplary sequence diagram for exchanging slice-specific security capabilities during NG setup according to an example embodiment of the present disclosure is shown. Refer to Figure 5 , the access network device 510 may be used as a BTS, such as an eNB and / or gNB in a wireless communication network. The core network device 520 may be used as an AMF in the CN of a wireless communication network. In one example, the access network device 510 may utilize the core network device 520 to perform an NG setup process such as the 3rd Generation Partnership Project (3GPP) Technical Specification (TS) 38.413 to exchange application-level data (e.g., security capabilities) to facilitate the core network device 520 in selecting a target access network device during the N2 handover process.
[0163] During the NG setup process, the access network device 510 may transmit an NG setup request message 512 to the core network device 520. The NG setup request message 512 may include the respective security capabilities 514 specific to one or more slices supported by the access network device 510. The respective security capabilities 514 may include at least one of the following: the respective identifiers of one or more slices supported by the access network device 510, or the respective encryption algorithms specific to one or more slices. For example, the identifier of a slice may be an S-NSSAI value, and the slice-specific encryption algorithm may be related to at least one of the following: the algorithm for slice-specific UP integrity, or the slice-specific UP encryption algorithm. The respective security capabilities 514 may be in the form of a list of S-NSSAI and the corresponding encryption algorithms.
[0164] Then, in response to the NG setup request message 512, the core network device 520 may transmit an NG setup response message 522 to the access network device 510.
[0165] It can be understood that in a wireless communication network, multiple access network devices may respectively transmit the respective security capabilities specific to one or more slices supported by the multiple access network devices to the core network device 520. The security capabilities of the respective multiple access network devices may be used by the core network device 520 or another core network device to select an appropriate target access network device from the multiple access network devices for potential handover of a UE. Here, the access network device 510 may represent any one of the multiple access network devices.
[0166] Through the NG setup process, the core network device 520 may obtain information about the security capabilities of the respective multiple access network devices. It can be understood that during the NG setup process, the access network device 510 may transmit the respective security capabilities 514 specific to one or more slices supported by the access network device 510 via other messages not limited to the NG setup request message 512.
[0167] In one example, when the core network device 520 already knows the security capabilities of the access network device 510 through the NG process, it may share this information with other core network devices (not shown). For the same reason, the core network device 520 may receive the security capabilities of another access network device from other core network devices.
[0168] Figure 6 An exemplary sequence diagram for slice-specific key update during an N2-based handover process according to an example embodiment of the present disclosure is shown. Refer to Figure 6, the UE 630 may represent any terminal device in a wireless communication network that will perform a handover from the access network device 660 serving the UE 630. Thus, the access network device 660 may be the source access network device for the handover. In addition, during the registration process, a slice-specific encryption algorithm may be negotiated between the UE 630 and the core network device 640 (such as the AMF) in the core network of the wireless communication network. Thus, the core network device 640 may be the source core network device associated with this handover.
[0169] When the source core network device 640 is unable to serve the UE 630, it may select a target core network device 680 for the handover and transmit the UE context information of the UE 630 to the target core network device 680. The UE context information may be conveyed via, for example, the Namf_Communication_CreateUEContext request defined in 3GPP TS23.502. Assume that the UE 630 is currently using one or more slices, and the first slice may represent any one of the one or more slices. In the description, the first slice is taken as an example, and it can be understood that the exemplary embodiments of the present disclosure can be applied to any one of the one or more slices.
[0170] The source core network device 640 may transmit the security information 642 specific to the first slice to the target core network device 680. In one embodiment, the security information 642 specific to the first slice may be transmitted via the UE context information of the UE 630. In one embodiment, the security information 642 specific to the first slice may include, for example, at least one of the following: the identifier of the first slice, or the encryption algorithm information specific to the first slice.
[0171] In one embodiment, the identifier of the first slice may be the S-NSSAI value of the first slice. The encryption algorithm information specific to the first slice may be related to, for example, at least one of the following: the algorithm for UP integrity specific to the first slice, or the algorithm for UP encryption specific to the first slice.
[0172] Then, in operation 682, the target core access network device 680 may select a target access network device based on the security capabilities of the target access network device specific to the first slice used by the UE 630. If the target core network device 680 is the core network device 520, the target core network device 680 may obtain the security capabilities of the target access network device, for example, during the NG setup discussed above Figure 5 Alternatively, the core network device 520 may share the received security capability information with the target core network device 680.
[0173] For example, the target core network device 680 may select, from multiple access network devices, a target access network device that can support the same or similar security capabilities as those specific to the first slice. Assume that, according to the security capabilities specific to the first slice of the access network device 510, for example, the access network device 510 is selected as the target access network device for handover among multiple access network devices.
[0174] When the target access network device 510 is determined, the target core network device 680 may transmit security information 642 specific to the first slice used by the UE 630 to the target access network device 510, so that the target access network device 510 can update the security key for the first slice. In one embodiment, the target core network device 680 may include the security information 642 in the handover request 684. In response to the handover request 684, the target access network device 510 may transmit a handover request confirmation 612 to the target core network device 680.
[0175] When performing the handover process, the source core network device 640 may transmit, for example, via a handover command 644, security information 642 specific to the first slice to the source access network device 660. Then, the source access network device 660 may forward the security information 642 to the UE 630, so that the UE 630 and the target access network device 510 can synchronize to derive a key specific to the first slice.
[0176] In one embodiment, based on the security information 642 specific to the first slice received from the source core network device 640, the target access network device 510 and the UE 630 may derive at least one security key specific to the first slice. For example, in operation 614, the target access network device 510 may derive a security key by inputting the identifier of the first slice (e.g., S-NSSAI) and / or the encryption algorithm specific to the first slice into the KDF. In one example, the encryption algorithm specific to the first slice may include one or more encryption and integrity algorithms for protecting the UP data respectively. One or more security keys specific to the first slice can be derived accordingly. On the UE side, in operation 632, the UE 630 may derive at least one security key specific to the first slice in a similar manner. For example, the UE 630 may derive at least one security key specific to the first slice by inputting the security information 226 specific to the first slice into the KDF. With the derived security key specific to the first slice, the UE 630 and the access network device 510 can protect the uplink and downlink data.
[0177] Figure 7 An exemplary sequence diagram for slice-specific key update during the N2-based handover process according to an example embodiment of the present disclosure is shown.Figure 7 Some of the operations shown may be similar to some of the operations shown in and described with respect to the previous figures. Accordingly, details that have been described with respect to the previous figures are briefly described or omitted.
[0178] Reference Figure 7 , the source core network device 640 may transmit security information 642 specific to the first slice to the target core network device 680. Then, in operation 682, the target core network device 680 may select the target access network device 510 based on the security capabilities of the target access network device 510 specific to the first slice used by the UE 630.
[0179] In one embodiment, if the target core network device 680 knows, for example, based on the security capabilities of the target access network device 510 or due to overload of the first slice in the target access network equipment 510, that the target access network device 510 does not support the first slice, then in operation 782, the target core network device 680 may determine a second slice remapped from the first slice to provide service continuity for the UE 630. The second slice may be equivalent to the first slice. For example, the second slice and the first slice may have the same or similar security levels. For example, if the slice S-NSSAI#1 used by the UE 630 is not supported at the target access network device 510, the target core network device 680 may determine, for the target access network device 510, a second slice S-NSSAI#2 that is also supported by the source access network device 660 and the UE 630, such that temporary slice service continuity for the UE 630 can be achieved.
[0180] Since the target access network device 510 can provide temporary services to the UE 630 by using the remapped second slice, the target core network device 680 can transmit a handover request 784 to the target access network device 510 to indicate the handover of the UE 630. As an option, the network side can choose to perform slice remapping without the UE 630's knowledge. For example, the target core network device 680 can decide not to let the UE 230 know that the first slice has been remapped to the second slice. This decision can be made considering the capabilities, policies, etc. of the UE 230. In this case, the target core network device 680 can still transmit the security information 642 specific to the first slice used by the UE 630, for example, via the handover request 784. In addition, the target core network device 680 can transmit an indication 786 indicating the remapping of the second slice from the first slice to the target access network device 510, so that the target access network device 510 can use the remapped second slice to provide service continuity for the UE 630. The indication 786 can also instruct the target access network device 510 to use the security information 642 specific to the first slice to derive a security key specific to the first slice. In response to the handover request 784, the target access network device 510 can transmit a handover request confirmation 612 to the target core network device 680.
[0181] When performing the handover process, the source core network device 640 can transmit the security information 642 specific to the first slice to the source access network device 660, for example, via the handover command 644, and then can forward the security information 642 to the UE 630 for the UE 630 to derive a key specific to the first slice. For example, in operation 632, the UE 630 can use the security information 642 specific to the first slice as an input to the KDF to derive a first-slice specific security key. For example, the UE 630 can derive at least one security key specific to the first slice by inputting the identity of the first slice (e.g., S-NSSAI) and / or the encryption algorithm specific to the first slice into the KDF. On the network side, the target access network device 510 can map the packet data unit (PDU) session associated with the UE 630 to the remapped second slice to allow service continuity. However, since the UE 230 is not aware of the slice remapping at the target access network device 510, for slice-specific security, in operation 614, the target access network device 510 can continue to use the security information 642 specific to the first slice as an input to the KDF to derive a first-slice specific security key.
[0182] Figure 8 Shows an exemplary sequence diagram for slice-specific key update during an N2-based handover process according to an example embodiment of the present disclosure. Figure 8Some of the operations shown may be similar to some of the operations shown in and described with respect to the previous figures. Accordingly, details that have been described with respect to the previous figures are briefly described or omitted.
[0183] Referring Figure 8 , the source core network device 640 may transmit security information 642 specific to the first slice to the target core network device 680. Then, in operation 682, the target core network device 680 may select the target access network device 510 based on the security capabilities of the target access network device 510 for the first slice used by the UE 630. Additionally, the target core network device 680 may transmit the security information 642 specific to the first slice used by the UE 630 to the target access network device 510, e.g., via a handover request 684.
[0184] In one embodiment, if the target access network device 510 does not support the first slice, then in operation 812, the target access network device 510 may determine a second slice remapped from the first slice to provide service continuity for the UE 630. For example, the second slice may be equivalent to the first slice, e.g., having the same or similar security level as the first slice.
[0185] In one embodiment, the network side may select to perform slice remapping without the UE 630's knowledge. For example, the target access network device 510 may decide not to let the UE 230 know that the first slice has been remapped to the second slice. In this case, the handover request confirmation 612 may not have security information specific to the second slice, for example. Alternatively, for example, the target core network device 680 may decide not to let the UE 230 know about the slice remapping and may indicate the slice remapping to the target access network device 510 via, e.g., a handover request 684 such that after operation 812, the target access network device 510 may not include security information specific to the second slice in the handover request confirmation 612. This decision made by the target access network device 510 or the target core network device 680 may be made considering the capabilities, policies, etc. of the UE 230, and in either case, as an option, the target access network device 510 may share the slice remapping information with the target core network device 680.
[0186] When the handover procedure is performed, the source core network device 640 may transmit security information 642 specific to the first slice to the source access network device 660, for example, via a handover command 644, and then may forward the security information 642 to the UE 630 for the UE 630 to derive a key specific to the first slice. For example, in operation 632, the UE 630 may use the security information 642 specific to the first slice as an input to the KDF to derive a first slice-specific security key. For example, the UE 630 may derive at least one security key specific to the first slice by inputting the identifier of the first slice (e.g., S-NSSAI) and / or the encryption algorithm specific to the first slice into the KDF. Before, after, or in parallel with operation 632, in operation 614, the target access network device 510 may also use the security information 642 specific to the first slice as an input to the KDF to derive a first slice-specific security key.
[0187] Figure 9 Shows an exemplary sequence diagram for slice-specific key update during an N2-based handover procedure according to an exemplary embodiment of the present disclosure. Figure 9 Some of the operations shown may be similar to some of the operations shown in the previous figures and described for the previous figures. Therefore, the details described with respect to the previous figures are briefly described or omitted.
[0188] Reference Figure 9 , the source core network device 640 may transmit security information 642 specific to the first slice to the target core network device 680. Then, in operation 682, the target core network device 680 may select the target access network device 510 based on the security capabilities of the first slice used by the UE 630 of the target access network device 510.
[0189] In one embodiment, if the target core network device 680 knows that the target access network device 510 does not support the first slice, for example, based on the security capabilities of the target access network device 510 or due to overload of the first slice in the target access network device 510, then in operation 982, the target core network device 680 may determine security information 986 specific to a second slice remapped from the first slice to provide service continuity for the UE 630. The second slice may be equivalent to the first slice, and the security information 986 specific to the second slice may include at least one of the following: the identifier of the second slice, or encryption algorithm information specific to the second slice.
[0190] In one embodiment, the identifier of the second slice may be the S-NSSAI value of the second slice. The encryption algorithm information specific to the second slice may be related to, for example, at least one of the following: the algorithm for UP integrity specific to the second slice, or the algorithm for UP encryption specific to the second slice.
[0191] The second slice may be equivalent to the first slice. For example, the second slice and the first slice may have the same or similar security levels. For example, if the slice S-NSSAI #1 used by the UE 630 is not supported at the target access network device 510, the target core network device 680 may determine for the target access network device 510 a second slice S-NSSAI #2 that is also supported by the source access network device 660 and the UE 630, so that temporary slice service continuity for the UE 630 can be achieved.
[0192] As an option, the network side may choose to perform slice remapping with the knowledge of the UE 630. For example, the target core network device 680 may decide to let the UE 230 know about the slice remapping. This decision may be made considering the capabilities, policies, etc. of the UE 230. In this case, the target core network device 680 may transmit the security information 986 specific to the second slice to the target access network device 510 and the source core network device 640. For example, the security information 986 specific to the second slice may be transmitted to the target access network device 510 via the handover request 984, and may be transmitted to the core network device 640 via the Namf_Communication_CreateUEContext response defined in 3GPP TS23.502. In response to the handover request 984, the target access network device 510 may respond with a handover request acknowledgment 612, which may indicate that the handover request is accepted and includes the necessary information required for the UE 630 to perform the handover.
[0193] In this case, when performing the handover process, the source core network device 640 may transmit the security information 986 specific to the second slice to the source access network device 660, for example, via the handover command 912. Then, the source access network device 660 may forward the security information 986 specific to the second slice to the UE 630, so that the UE 630 and the target access network device 510 can synchronize to derive the key specific to the second slice.
[0194] For example, in operation 932, the UE 630 may use the security information 986 specific to the second slice as an input to the KDF to derive a second slice-specific security key. For example, the UE 630 may derive at least one security key specific to the second slice by inputting the identifier of the second slice (e.g., S-NSSAI) and / or the encryption algorithm specific to the second slice into the KDF. Before, after, or in parallel with operation 932, in operation 914, the target access network device 510 may use the security information 986 specific to the second slice as an input to the KDF to derive a second slice-specific security key.
[0195] Figure 10 Shows an exemplary sequence diagram for slice-specific key update during an N2-based handover procedure according to an example embodiment of the present disclosure. Figure 10 Some of the operations shown may be similar to some of the operations shown and described in the previous figures. Accordingly, details already described with respect to the previous figures are briefly described or omitted.
[0196] Reference Figure 10 , the source core network device 640 may transmit the security information 642 specific to the first slice to the target core network device 680. Then, in operation 682, the target core network device 680 may select the target access network device 510 based on the security capabilities of the target access network device 510 specific to the first slice used by the UE 630. Additionally, the target core network device 680 may transmit the security information 642 specific to the first slice used by the UE 630 to the target access network device 510, for example, via a handover request 684.
[0197] In one embodiment, if the target access network device 510 does not support the first slice, then in operation 1012, the target access network device 510 may determine the security information 986 specific to the second slice remapped from the first slice in order to provide service continuity for the UE 630. The second slice may be equivalent to the first slice, and the security information 986 specific to the second slice may include at least one of the following: the identifier of the second slice, or the encryption algorithm information specific to the second slice.
[0198] In one embodiment, the identifier of the second slice may be the S-NSSAI value of the second slice. The encryption algorithm information specific to the second slice may be related to, for example, at least one of the following: the algorithm for UP integrity specific to the second slice, or the algorithm for UP encryption specific to the second slice.
[0199] The second slice may be equivalent to the first slice. For example, the second slice and the first slice may have the same or similar security levels. For example, if the slice S-NSSAI #1 used by the UE 630 is not supported at the target access network device 510, the target access network device 510 may determine a second slice S-NSSAI #2 that is also supported by the source access network device 660 and the UE 630, so that temporary slice service continuity for the UE 630 can be achieved.
[0200] In one embodiment, the network side may choose to perform slice remapping with the knowledge of the UE 630. For example, the target access network device 510 may decide to let the UE 230 know that the first slice has been remapped to the second slice. In this case, the handover request confirmation 1014 may include, for example, the security information 986 specific to the second slice. Alternatively, for example, the target core network device 680 may decide to let the UE 230 know about the slice remapping and indicate the slice remapping to the target access network device 510 via, for example, the handover request 684, so that after operation 1012, the target access network device 510 may include, for example, the security information 986 specific to the second slice in the handover request confirmation 1014. This decision made by the target access network device 510 or the target core network device 680 may be made considering the capabilities, policies, etc. of the UE 230.
[0201] The target access network device 510 may transmit the security information 986 specific to the second slice to the target core network device 640 via, for example, the handover request confirmation 1014. Then, the target core network device 640 may transmit this security information 986 specific to the second slice to the source core network device 640 via, for example, the Namf_Communication_CreateUEContext response defined in 3GPP TS 23.502.
[0202] In this case, when performing the handover process, the source core network device 640 may transmit the security information 986 specific to the second slice to the source access network device 660 via, for example, the handover command 912. Then, the source access network device 660 may forward the security information 986 specific to the second slice to the UE 630, so that the UE 630 can synchronize with the target access network device 510 to derive the key specific to the second slice.
[0203] For example, in operation 932, the UE 630 may use the security information 986 specific to the second slice as an input to the KDF to derive a second slice-specific security key. For example, the UE 630 may derive at least one security key specific to the second slice by inputting the identifier of the second slice (e.g., S-NSSAI) and / or the encryption algorithm specific to the second slice into the KDF. Before, after, or in parallel with operation 932, in operation 914, the target access network device 510 may use the security information 986 specific to the second slice as an input to the KDF to derive a second slice-specific security key.
[0204] Figure 11 The flowchart shows an example method 1100 for network slice security according to an example embodiment of the present disclosure. The example method 1100 may be performed, for example, by a terminal device such as the UE 230 and / or the UE 630.
[0205] Reference Figure 11 , the example method 1100 may include: operation 1110, receiving slice-specific security information from a source access network device associated with a handover of the terminal device; and operation 1120, deriving at least one key specific to the slice based on the slice-specific security information.
[0206] In the above description, the details of operation 1110 have been described at least for the security information 266 specific to the first slice, the security information 416 specific to the second slice, the security information 642 specific to the first slice, and the security information 986 specific to the second slice, and their repeated descriptions are omitted here.
[0207] In the above description, the details of operation 1120 have been described at least for operation 232, operation 432, operation 632, and operation 932, and their repeated descriptions are omitted here.
[0208] In one embodiment, the slice may be the first slice or a second slice remapped from the first slice.
[0209] In one embodiment, the second slice may be equivalent to the first slice, the security information specific to the first slice may include at least one of the following: the identifier of the first slice, or the encryption algorithm information specific to the first slice, and the security information specific to the second slice may include at least one of the following: the identifier of the second slice or the encryption algorithm information specific to the second slice. In the above description, more details have been described at least for the security information 266 specific to the first slice, the security information 416 specific to the second slice, the security information 642 specific to the first slice, and the security information 986 specific to the second slice, and their repeated descriptions are omitted here.
[0210] Figure 12 Shows a flowchart of an example method 1200 for network slice security illustrating an example embodiment according to the present disclosure. The example method 1200 may be performed, for example, by a network device such as access network device 160, access network device 660, and / or core network device 680.
[0211] Referring Figure 12 , the example method 1200 may include: operation 1210 of selecting a target access network device associated with a handover of a terminal device based on the security capabilities of a first slice used by the terminal device specific to the target access network device; and operation 1220 of transmitting security information specific to the first slice or security information specific to a second slice remapped from the first slice to the target access network device.
[0212] In the above description, details of operation 1210 have been described at least for operations 262 and 682, and its repeated description is omitted here.
[0213] In the above description, details of operation 1220 have been described at least for the security information 266 specific to the first slice and the security information 642 specific to the first slice, and its repeated description is omitted here.
[0214] In one embodiment, the security information specific to the first slice may include at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice. In the above description, more details of the security information 266 specific to the first slice and the security information 642 specific to the first slice have been described at least, and its repeated description is omitted here.
[0215] In one embodiment, the network device may be a source access network device associated with a handover, and the example method 1200 may further include an operation of receiving, from the target access network device, the respective security capabilities of one or more slices supported by the target access network device. In the above description, more details of the respective security capabilities 114 of one or more slices supported by access network device 110 have been described at least, and its repeated description is omitted here.
[0216] In one embodiment, the respective security capabilities of the one or more slices may include at least one of the following: the respective identifiers of the one or more slices or the respective encryption algorithm information specific to the one or more slices. In the above description, more details of the respective security capabilities 114 specific to one or more slices have been described at least, and their repeated description is omitted here.
[0217] In one embodiment, the exemplary method 1200 may further include receiving, from a target access network device, security information specific to a second slice remapped from a first slice; and transmitting, to a terminal device, the security information specific to the second slice. In the above description, more details have been described at least for the security information 416 specific to the second slice, and its repeated description is omitted here.
[0218] In one embodiment, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice. In the above description, more details have been described at least for the security information 416 specific to the second slice, and its repeated description is omitted here.
[0219] In one embodiment, the network device may be a target core network device associated with handover, and the exemplary method 1200 may further include receiving, from the target access network device or another core network device, corresponding security capabilities specific to one or more slices supported by the target access network device. In the above description, more details have been described at least for the corresponding security capabilities 514 specific to one or more slices, and their repeated description is omitted here.
[0220] In one embodiment, the corresponding security capabilities specific to one or more slices may include at least one of the following: corresponding identifiers of the one or more slices or corresponding encryption algorithm information specific to the one or more slices. In the above description, more details have been described at least for the corresponding security capabilities 514 specific to one or more slices, and their repeated description is omitted here.
[0221] In one embodiment, the exemplary method 1200 may further include receiving, from a source core network device associated with handover, security information specific to the first slice. In the above description, more details have been described at least for the security information 642 specific to the first slice, and its repeated description is omitted here.
[0222] In one embodiment, the exemplary method 1200 may further include determining, when the target access network device does not support the first slice, a second slice remapped from the first slice; and transmitting, to the target access network device, an indication indicating that the second slice is remapped from the first slice. In the above description, more details have been described at least for the operation 782 and the indication 786, and their repeated description is omitted here.
[0223] In one embodiment, the example method 1200 may further include receiving, from a target access network device, security information specific to a second slice remapped from a first slice; and transmitting, to a source core network device, the security information specific to the second slice. In the above description, more details have been described at least for the security information 986 specific to the second slice, and its repeated description is omitted here.
[0224] In one embodiment, the example method 1200 may further include, in a case where the target access network device does not support the first slice, determining security information specific to a second slice remapped from the first slice; and transmitting, to the source core network device, the security information specific to the second slice, and the security information specific to the second slice may be transmitted to the target access network device. In the above description, more details have been described at least for the security information 986 specific to the second slice, and its repeated description is omitted here.
[0225] In one embodiment, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice. In the above description, more details have been described at least for the security information 986 specific to the second slice, and its repeated description is omitted here.
[0226] Figure 13 A flowchart showing an example method 1300 for network slice security according to an example embodiment of the present disclosure is shown. The example method 1300 may be performed, for example, by a network device that is a target access network device associated with a handover of a terminal device (such as access network device 110 and / or access network device 510).
[0227] Refer to Figure 13 , the example method 1300 may include operation 1310 of receiving, from another network device associated with a handover of a terminal device, security information specific to a first slice used by the terminal device or security information specific to a second slice remapped from the first slice.
[0228] In the above description, details of operation 1310 have been described at least for the security information 266 specific to the first slice and the security information 642 specific to the first slice, and its repeated description is omitted here.
[0229] In one embodiment, the security information specific to the first slice includes at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice. In the above description, more details have been described at least for the security information 266 specific to the first slice and the security information 642 specific to the first slice, and its repeated description is omitted here.
[0230] In one embodiment, the exemplary method 1300 may further include, when the target access network device does not support the first slice, an operation of determining security information specific to a second slice remapped from the first slice, and the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice. In the above description, more details have been described at least for operation 412, operation 1012, security information 416 specific to the second slice, and security information 986 specific to the second slice, and their repeated descriptions are omitted here.
[0231] In one embodiment, the exemplary method 1300 may further include an operation of transmitting security information specific to the second slice to another network device; and an operation of deriving at least one key specific to the second slice based on the security information specific to the second slice. In the above description, more details have been described at least for security information 416 specific to the second slice, security information 986 specific to the second slice, operation 418, and operation 914, and their repeated descriptions are omitted here.
[0232] In one embodiment, the exemplary method 1300 may further include, when the target access network device does not support the first slice, an operation of determining a second slice remapped from the first slice; and an operation of deriving at least one key specific to the first slice based on the security information specific to the first slice. In the above description, more details have been described at least for operation 312, operation 214, operation 812, and operation 614, and their repeated descriptions are omitted here.
[0233] In one embodiment, the another network device may be a target core network device associated with a handover of the terminal device, and the exemplary method 1300 may further include: when the target access network device does not support the first slice, an operation of receiving security information specific to a second slice remapped from the first slice from the target core network device; and an operation of deriving at least one key specific to the second slice based on the security information specific to the second slice, and the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice. In the above description, more details have been described at least for security information 986 specific to the second slice and operation 914, and their repeated descriptions are omitted here.
[0234] In one embodiment, the other network device may be a target core network device associated with a handover of a terminal device, and the exemplary method 1300 may further include: an operation of receiving, from the target core network device, an indication indicating a remapping of a second slice from a first slice; and an operation of deriving at least one key specific to the first slice based on security information specific to the first slice. In the above description, more details have been described at least for indication 786 and operation 614, and their repeated descriptions are omitted here.
[0235] In one embodiment, the other network device may be a source access network device associated with a handover of a terminal device, and the exemplary method 1300 may further include an operation of deriving at least one key specific to the second slice based on security information specific to the second slice in the case of receiving, from the target core network device, the security information specific to the second slice, where the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identity of the second slice, or encryption algorithm information specific to the second slice. In the above description, more details have been described at least for security information 986 specific to the second slice and operation 914, and their repeated descriptions are omitted here.
[0236] In one embodiment, the other network device may be a source access network device associated with a handover of a terminal device, and the exemplary method 1300 may further include an operation of transmitting, to the source access network device, corresponding security capabilities specific to one or more slices supported by the target access network device. In the above description, more details have been described at least for corresponding security capabilities 114 specific to one or more slices, and their repeated descriptions are omitted here.
[0237] In one embodiment, the other network device may be a target core network device associated with a handover of a terminal device, and the exemplary method 1300 may further include an operation of transmitting, to the target core network device or another core network device, corresponding security capabilities specific to one or more slices supported by the target access network device. In the above description, more details have been described at least for corresponding security capabilities 514 specific to one or more slices, and their repeated descriptions are omitted here.
[0238] In one embodiment, the corresponding security capabilities specific to one or more slices may include at least one of the following: corresponding identities of the one or more slices or corresponding encryption algorithm information specific to the one or more slices. In the above description, more details have been described at least for corresponding security capabilities 114 specific to one or more slices and corresponding security capabilities 514 specific to one or more slices, and their repeated descriptions are omitted here.
[0239] Figure 14 Shows a block diagram of an example device 1400 for network slice security according to an example embodiment of the present disclosure. For example, the device may be at least a part of a terminal device such as the UE 230 and / or the UE 630 in the above examples.
[0240] As Figure 14 shown, the example device 1400 may include at least one processor 1410 and at least one memory 1420 that can store instructions 1430. When the instructions 1430 are executed by the at least one processor 1410, the device 1400 can be caused to at least execute the above example method 1100.
[0241] In various example embodiments, at least one processor 1410 in the example device 1400 may include, but is not limited to, at least one hardware processor, which includes at least one microprocessor, such as a central processing unit (CPU), a part of at least one hardware processor, and any other suitable dedicated processor, such as a processor developed based on a field programmable gate array (FPGA) and an application specific integrated circuit (ASIC). In addition, at least one processor 1410 may further include Figure 14 at least one other circuit or element not shown in
[0242] In various example embodiments, at least one memory 1420 in the example device 1400 may include various forms of at least one storage medium, such as volatile memory and / or non-volatile memory. Volatile memory may include, but is not limited to, for example, random access memory (RAM), cache, etc. Non-volatile memory may include, but is not limited to, read only memory (ROM), hard disk, flash memory, etc. As used herein, the term "non-volatile" is a limitation on the medium itself (i.e., tangible, rather than a signal), rather than a limitation on the persistence of data storage (e.g., RAM vs. ROM). In addition, at least the memory 1420 may include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or equipment, or any combination of the above.
[0243] In addition, in various example embodiments, the example device 1400 may further include at least one other circuit, element, and interface, such as at least one I / O interface, at least one antenna element, etc.
[0244] In various example embodiments, each circuit, component, element, and interface in the example device 1400 including at least one processor 1410 and at least one memory 1420 may be coupled together in any suitable manner, such as electrically, magnetically, optically, electromagnetically, etc., via any suitable connection including, but not limited to, a bus, a switching line, a wiring, and / or a wireless line.
[0245] It should be understood that the structure of the devices on the UE 230 and / or UE 630 side is not limited to the above example device 1400.
[0246] Figure 15 FIG. shows a block diagram of an example device 1500 for network slice security according to an example embodiment of the present disclosure. For example, the device may be at least a part of a network device such as the access network device 160, the access network device 660, and / or the core network device 680 in the above examples.
[0247] As Figure 15 shown, the example device 1500 may include at least one processor 1510 and at least one memory 1520 that can store instructions 1530. When the instructions 1530 are executed by the at least one processor 1510, the device 1500 can be caused to at least execute the above example method 1200.
[0248] In various example embodiments, at least one processor 1510 in the example device 1500 may include, but is not limited to, at least one hardware processor, which includes at least one microprocessor, such as a central processing unit (CPU), a part of at least one hardware processor, and any other suitable dedicated processor, such as a processor developed based on a field programmable gate array (FPGA) and an application specific integrated circuit (ASIC). In addition, the at least one processor 1510 may further include Figure 15 at least one other circuit or element not shown in
[0249] In various example embodiments, at least one memory 1520 in the example device 1500 may include at least one storage medium in various forms, such as volatile memory and / or non-volatile memory. Volatile memory may include, but is not limited to, for example, random access memory (RAM), cache, etc. Non-volatile memory may include, but is not limited to, for example, read only memory (ROM), hard disk, flash memory, etc. As used herein, the term "non-volatile" is a limitation on the medium itself (i.e., tangible, rather than a signal), rather than a limitation on the persistence of data storage (e.g., RAM vs. ROM). In addition, the at least memory 1520 may include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above.
[0250] In addition, in various example embodiments, the example device 1500 may further include at least one other circuit, element, and interface, such as at least one I / O interface, at least one antenna element, etc.
[0251] In various example embodiments, the circuits, components, elements, and interfaces in an example device 1500 including at least one processor 1510 and at least one memory 1520 may be coupled together via any suitable connection including but not limited to buses, switching lines, wirings, and / or wireless lines in any suitable manner such as electrically, magnetically, optically, electromagnetically, etc.
[0252] It should be understood that the structure of the devices on the access network device 160, access network device 660, and / or core network device 680 side is not limited to the above example device 1500.
[0253] Figure 16 A block diagram showing an example device 1600 for network slice security according to an example embodiment of the present disclosure is shown. For example, the device may be a network device that is a target access network device associated with handover of a terminal device, such as at least a part of the access network device 110 and / or access network device 510 in the above examples.
[0254] As Figure 16 shown, the example device 1600 may include at least one processor 1610 and at least one memory 1620 that can store instructions 1630. When the instructions 1630 are executed by the at least one processor 1610, the device 1600 can be caused to at least execute the above example method 1300.
[0255] In various example embodiments, the at least one processor 1610 in the example device 1600 may include but not be limited to at least one hardware processor, which includes at least one microprocessor, such as a central processing unit (CPU), a part of at least one hardware processor, and any other suitable dedicated processor, such as a processor developed based on a field programmable gate array (FPGA) and an application specific integrated circuit (ASIC). In addition, the at least one processor 1610 may further include Figure 16 at least one other circuit or element not shown in
[0256] In various example embodiments, the at least one memory 1620 in the example device 1600 may include at least one storage medium in various forms, such as volatile memory and / or non-volatile memory. Volatile memory may include but not be limited to, for example, random access memory (RAM), cache, etc. Non-volatile memory may include but not be limited to read only memory (ROM), hard disk, flash memory, etc. As used herein, the term "non-volatile" is a limitation on the medium itself (i.e., tangible, rather than a signal), rather than a limitation on the persistence of data storage (e.g., RAM vs. ROM). In addition, the at least memory 1620 may include but not be limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or apparatuses, or any combination of the above.
[0257] In addition, in various example embodiments, the example device 1600 may further include at least one other circuit, component, and interface, such as at least one I / O interface, at least one antenna element, and the like.
[0258] In various example embodiments, each circuit, component, element, and interface in the example device 1600 including at least one processor 1610 and at least one memory 1620 may be coupled together via any suitable connection including but not limited to a bus, switching lines, wiring, and / or wireless lines in any suitable manner such as electrically, magnetically, optically, electromagnetically, etc.
[0259] It should be understood that the structure of the access network device 110 and / or the device on the side of the access network device 510 is not limited to the above example device 1600.
[0260] Figure 17 A block diagram showing an example device 1700 for network slice security according to an example embodiment of the present disclosure is shown. For example, the device may be at least a part of a terminal device such as the UE 230 and / or the UE 630 in the above examples.
[0261] As Figure 17 shown, the example device 1700 may include a means 1710 for performing operation 1110 of the example method 1100 and a means 1720 for performing operation 1120 of the example process 1100. In one or more other example embodiments, the example device 1700 may further include at least one I / O interface, at least one antenna element, and the like.
[0262] In one embodiment, the slice may be a first slice or a second slice remapped from the first slice.
[0263] In one embodiment, the second slice may be equivalent to the first slice, and the security information specific to the first slice may include at least one of the following: the identifier of the first slice, or the encryption algorithm information specific to the first slice, and the security information specific to the second slice may include at least one of at least one of the following: the identifier of the second slice or the encryption algorithm information specific to the second slice.
[0264] In some example embodiments, the examples of the means in the example device 1700 may include circuits. For example, the example of the means 1710 may include a circuit configured to perform operation 1110 of the example method 1100, and the example of the means 1720 may include a circuit arranged to perform operation 1120 of the example process 1100.
[0265] Example device 1700 may also include a device having circuitry configured to perform example method 1100. In some example embodiments, examples of the device may also include software modules and any other suitable functional entities.
[0266] Figure 18 A block diagram showing an example device 1800 for network slice security according to example embodiments of the present disclosure is shown. For example, the device may be at least a part of a network device such as access network device 160, access network device 660, and / or core network device 680 in the above examples.
[0267] As Figure 18 shown, example device 1800 may include a device 1810 for performing operation 1210 of example method 1200 and a device 1820 for performing operation 1220 of example process 1200. In one or more other example embodiments, example device 1800 may further include at least one I / O interface, at least one antenna element, and the like.
[0268] In one embodiment, the security information specific to the first slice may include at least one of the following: an identity of the first slice, or encryption algorithm information specific to the first slice.
[0269] In one embodiment, the network device may be a source access network device associated with the handover, and example device 1800 may further include a device for receiving, from a target access network device, corresponding security capabilities specific to one or more slices supported by the target access network device.
[0270] In one embodiment, the corresponding security capabilities specific to one or more slices may include at least one of the following: corresponding identities of the one or more slices or corresponding encryption algorithm information specific to the one or more slices.
[0271] In one embodiment, example device 1800 may further include a device for receiving, from a target access network device, security information specific to a second slice remapped from a first slice; and a device for sending the security information specific to the second slice to a terminal device.
[0272] In one embodiment, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identity of the second slice, or encryption algorithm information specific to the second slice.
[0273] In one embodiment, the network device may be a target core network device associated with the handover, and the exemplary device 1800 may further include means for receiving, from a target access network device or another core network device, corresponding security capabilities specific to one or more slices supported by the target access network device.
[0274] In one embodiment, the corresponding security capabilities specific to one or more slices may include at least one of the following: corresponding identifiers of one or more slices or corresponding encryption algorithm information specific to one or more slices.
[0275] In one embodiment, the exemplary device 1800 may further include means for receiving, from a source core network device associated with the handover, security information specific to a first slice.
[0276] In one embodiment, the exemplary device 1800 may further include means for determining, in a case where the target access network device does not support the first slice, a second slice remapped from the first slice; and means for transmitting, to the target access network device, an indication indicating that the second slice is remapped from the first slice.
[0277] In one embodiment, the exemplary device 1800 may further include means for receiving, from the target access network device, security information specific to a second slice remapped from the first slice; and means for transmitting, to the source core network device, security information specific to the second slice.
[0278] In one embodiment, the exemplary device 1800 may further include means for determining, in a case where the target access network device does not support the first slice, security information specific to a second slice remapped from the first slice; and means for transmitting, to the source core network device, security information specific to the second slice, and may transmit the security information specific to the second slice to the target access network device.
[0279] In one embodiment, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0280] In some example embodiments, examples of the means in the exemplary device 1800 may include circuitry. For example, an example of means 1810 may include circuitry configured to perform operation 1210 of the exemplary method 1200, and an example of means 1820 may include circuitry arranged to perform operation 1220 of the exemplary method 1200.
[0281] The example device 1800 may also include a device having circuitry configured to perform the example method 1200. In some example embodiments, the example of the device may also include software modules and any other suitable functional entities.
[0282] Figure 19 A block diagram showing an example device 1900 for network slice security according to an example embodiment of the present disclosure is shown. For example, the device may be an access network device that is a target access network device associated with a handover of a terminal device, such as at least a part of the access network device 110 and / or the access network device 510 in the above examples.
[0283] As Figure 19 shown, the example device 1900 may include a device 1910 for performing operation 1310 of the example method 1300. In one or more other example embodiments, the example device 1900 may also include at least one I / O interface, at least one antenna element, and the like.
[0284] In one embodiment, the security information specific to the first slice includes at least one of the following: an identity of the first slice, or encryption algorithm information specific to the first slice.
[0285] In one embodiment, the example device 1900 may also include a device for determining security information specific to a second slice remapped from the first slice in a case where the target access network device does not support the first slice, and the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: a second slice identity, or encryption algorithm information specific to the second slice.
[0286] In one embodiment, the example device 1900 may also include a device for transmitting the security information specific to the second slice to another network device; and a device for deriving at least one key specific to the second slice based on the security information specific to the second slice.
[0287] In one embodiment, the example device 1900 may also include a device for determining a second slice remapped from the first slice in a case where the target access network device does not support the first slice; and a device for deriving at least one key specific to the first slice based on the security information specific to the first slice.
[0288] In one embodiment, the other network device may be a target core network device associated with the handover of the terminal device, and the exemplary device 1900 may further include: means for receiving, from the target core network device, security information specific to a second slice remapped from a first slice in the case where the target access network device does not support the first slice; and means for deriving at least one key specific to the second slice based on the security information specific to the second slice, where the second slice is equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0289] In one embodiment, the other network device may be a target core network device associated with the handover of the terminal device, and the exemplary device 1900 may further include: means for receiving, from the target core network device, an indication that the second slice is remapped from the first slice; and means for deriving at least one key specific to the first slice based on the security information specific to the first slice.
[0290] In one embodiment, the other network device may be a target core network device associated with the handover of the terminal device, and the exemplary device 1900 may further include means for deriving at least one key specific to a second slice based on the security information specific to the second slice in the case where the security information specific to the second slice is received from the target core network device, the second slice is equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: a second slice identifier, encryption algorithm information specific to the second slice.
[0291] In one embodiment, the other network device may be a source access network device associated with the handover of the terminal device, and the exemplary device 1900 may further include means for transmitting, to the source access network device, the corresponding security capabilities specific to one or more slices supported by the target access network device.
[0292] In one embodiment, the other network device may be a target core network device associated with the handover of the terminal device, and the exemplary device 1900 may further include means for transmitting, to the target core network device or another core network device, the corresponding security capabilities specific to one or more slices supported by the target access network device.
[0293] In one embodiment, the corresponding security capabilities specific to one or more slices may include at least one of the following: the corresponding identifiers of the one or more slices or the corresponding encryption algorithm information specific to the one or more slices.
[0294] Each exemplary embodiment of the present disclosure also provides a computer-readable medium, which includes program instructions that, when executed by a terminal device such as the UE 230 and / or UE 630 in the above examples, can cause the terminal device to at least perform: receiving slice-specific security information from a source access network device associated with a handover of the terminal device; and deriving at least one key specific to the slice based on the slice-specific security information.
[0295] In one embodiment, the slice may be a first slice or a second slice remapped from the first slice.
[0296] In one embodiment, the second slice may be equivalent to the first slice, and the security information specific to the first slice may include at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0297] Each exemplary embodiment of the present disclosure also provides a computer-readable medium, which includes program instructions that, when executed by a network device (such as the access network device 160, access network device 660, and / or core network device 680) in the above examples, can cause the network device to at least perform: selecting a target access network device associated with a handover of the terminal device based on the security capabilities specific to the first slice used by the terminal device; and transmitting the security information specific to the first slice or the security information specific to the second slice remapped from the first slice to the target access network device.
[0298] In one embodiment, the security information specific to the first slice may include at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice.
[0299] In one embodiment, the network device may be a source access network device associated with the handover, and the computer-readable medium may further include instructions that, when executed by the network device, can cause the network device to further perform: receiving the corresponding security capabilities specific to one or more slices supported by the target access network device from the target access network device.
[0300] In one embodiment, the corresponding security capabilities specific to one or more slices may include at least one of the following: the corresponding identifiers of the one or more slices, or the corresponding encryption algorithm information specific to the one or more slices.
[0301] In one embodiment, the computer-readable medium may further include instructions that, when executed by the network device, cause the network device to further perform: receiving security information specific to a second slice remapped from a first slice from a target access network device; and transmitting the security information specific to the second slice to a terminal device.
[0302] In one embodiment, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0303] In one embodiment, the network device may be a target core network device associated with the handover, and the computer-readable medium may further include instructions that, when executed by the network device, cause the network device to further perform: receiving corresponding security capabilities specific to one or more slices supported by the target access network device from the target access network device or another core network device.
[0304] In one embodiment, the corresponding security capabilities specific to one or more slices may include at least one of the following: corresponding identifiers of the one or more slices or corresponding encryption algorithm information specific to the one or more slices.
[0305] In one embodiment, the computer-readable medium may further include instructions that, when executed by the network device, cause the network device to further perform: receiving security information specific to the first slice from a source core network device associated with the handover.
[0306] In one embodiment, the computer-readable medium may further include instructions that, when executed by the network device, cause the network device to further perform: determining a second slice remapped from the first slice in a case where the target access network device does not support the first slice; and transmitting an indication to the target access network device indicating that the second slice is remapped from the first slice.
[0307] In one embodiment, the computer-readable medium may further include instructions that, when executed by the network device, cause the network device to further perform: receiving security information specific to a second slice remapped from a first slice from a target access network device; and transmitting the security information specific to the second slice to a source core network device.
[0308] In one embodiment, the computer-readable medium may further include instructions that, when executed by a network device, may cause the network device to further perform: determining security information specific to a second slice remapped from a first slice in a case where a target access network device does not support the first slice; and transmitting the security information specific to the second slice to a source core network device and may transmit the security information specific to the second slice to the target access network device.
[0309] In one embodiment, the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0310] Various example embodiments of the present disclosure also provide a computer-readable medium including program instructions that, when executed by an access network device (such as access network device 110 and / or access network device 510 in the above examples) that is a target access network device associated with a handover of a terminal device, may cause the access network device to at least perform: receiving security information specific to a first slice used by the terminal device or security information specific to a second slice remapped from the first slice from another network device associated with the handover of the terminal device.
[0311] In one embodiment, the security information specific to the first slice includes at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice.
[0312] In one embodiment, the computer-readable medium may further include instructions that, when executed by an access network device, may cause the access network device to further perform: determining security information specific to a second slice remapped from a first slice in a case where a target access network device does not support the first slice, and the second slice may be equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: a second slice identifier, or encryption algorithm information specific to the second slice.
[0313] In one embodiment, the computer-readable medium may further include instructions that, when executed by an access network device, may cause the access network device to further perform: transmitting the security information specific to the second slice to another network device; and deriving at least one key specific to the second slice based on the security information specific to the second slice.
[0314] In one embodiment, the computer-readable medium may further include instructions that, when executed by the access network device, cause the access network device to further perform: determining a second slice remapped from the first slice in a case where the target access network device does not support the first slice; and deriving at least one key specific to the first slice based on security information specific to the first slice.
[0315] In one embodiment, the other network device may be a target core network device associated with the handover of the terminal device, and the computer-readable medium may further include instructions that, when executed by the access network device, cause the access network device to further perform: receiving, from the target core network device, security information specific to a second slice remapped from the first slice in a case where the target access network device does not support the first slice; and deriving at least one key specific to the second slice based on the security information specific to the second slice, where the second slice is equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0316] In one embodiment, the other network device may be a target core network device associated with the handover of the terminal device, and the computer-readable medium may further include instructions that, when executed by the access network device, cause the access network device to further perform: receiving, from the target core network device, an indication that the second slice is remapped from the first slice; and deriving at least one key specific to the first slice based on the security information specific to the first slice.
[0317] In one embodiment, the other network device may be a target core network device associated with the handover of the terminal device, and the computer-readable medium may further include instructions that, when executed by the access network device, cause the access network device to further perform: deriving at least one key specific to the second slice based on the security information specific to the second slice in a case where the security information specific to the second slice is received from the target core network device, the second slice is equivalent to the first slice, and the security information specific to the second slice may include at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
[0318] In one embodiment, the other network device may be a source access network device associated with the handover of the terminal device, and the computer-readable medium may further include instructions that, when executed by the access network device, cause the access network device to further perform: transmitting to the source access network device corresponding security capabilities specific to one or more slices supported by the target access network device.
[0319] In one embodiment, the other network device may be a target core network device associated with the handover of the terminal device, and the computer-readable medium may further include instructions that, when executed by the access network device, cause the access network device to further perform: transmitting, to the target core network device or another core network device, the corresponding security capabilities specific to one or more slices supported by the target access network device.
[0320] In one embodiment, the corresponding security capabilities specific to one or more slices may include at least one of the following: the corresponding identifiers of one or more slices or the corresponding encryption algorithm information specific to the one or more slices.
[0321] As used herein, "at least one of the following: <list of two or more elements>" and "at least one of <list of two or more elements>" and similar phrases (where the list of two or more elements is joined by "and" or "or") refer to at least any one element, or at least any two or more elements, or at least all elements.
[0322] The term "terminal device" refers to any end device capable of wireless communication. By way of example and not limitation, a terminal device may also be referred to as a communication device, a user equipment (UE), a subscriber station (SS), a portable subscriber station, a mobile station (MS), or an access terminal (AT). Terminal devices may include, but are not limited to, mobile phones, cellular phones, smart phones, IP voice (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices (such as digital cameras), game terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer premise equipment (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and application software (e.g., robots and / or other wireless devices operating in an industrial and / or automated processing chain environment), consumer electronic devices, devices operating on commercial and / or industrial wireless networks, etc. A terminal device may also correspond to the mobile terminal (MT) part of an IAB node (e.g., a relay node). In the above description, the terms "terminal device", "communication device", "terminal", "user equipment", and "UE" may be used interchangeably.
[0323] Throughout this application, "circuit" may refer to one or more or all of the following: (a) a hardware-only circuit implementation (such as an implementation only in analog and / or digital circuits); and (b) a combination of hardware circuits and software, such as (if applicable) (i) a combination of analog and / or digital hardware circuits and software / firmware, and (ii) a hardware processor and software (including a digital signal processor), any part of the software and memory, which work together to enable a device such as a mobile phone or a server to perform various functions); and (c) a hardware circuit and / or a processor, such as a microprocessor or a part of a microprocessor, which requires software (e.g., firmware) to operate, but the software may not be present when it is not required to operate. This definition of a circuit applies throughout this disclosure, including any and all uses of the term in any claims. As a further example, as used in this disclosure, the term circuit also encompasses an implementation of only a hardware circuit or a processor (or processors) or a part of a hardware circuit or a processor and its (or their) accompanying software and / or firmware. The term circuit also encompasses, for example and if applicable to the claimed element, a baseband integrated circuit or a processor integrated circuit for a mobile device or a similar integrated circuit in a server, a cellular network device, or other computing or network devices.
[0324] Another example embodiment may relate to computer program code or instructions that may cause a device to perform at least each of the above-described methods. Another example embodiment may relate to a computer-readable medium having such computer program code or instructions stored thereon. In some example embodiments, such a computer-readable medium may include at least one storage medium in various forms, such as volatile memory and / or non-volatile memory. Volatile memory may include, but is not limited to, for example, RAM, cache, etc. Non-volatile memory may include, but is not limited to, ROM, hard disk, flash memory, etc. Non-volatile memory may also include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or apparatuses, or any combination of the above.
[0325] Unless the context clearly requires otherwise, throughout the specification and claims, words such as "comprise", "comprising", etc. shall be interpreted in an inclusive sense rather than an exclusive or exhaustive sense; that is, in the sense of "including but not limited to". As commonly used herein, the term "coupled" refers to two or more elements that may be directly connected or connected through one or more intermediate elements. Similarly, as commonly used herein, the term "connected" refers to two or more elements that may be directly connected or connected through one or more intermediate elements. In addition, the words "herein", "above", "below" and words of similar import used in this application shall refer to the entire application rather than any particular part of the application. Where the context permits, words used in the singular or plural in the specification may also include the plural or singular respectively. The word "or" refers to a list of two or more items, and this word encompasses all of the following interpretations of the word: any item in the list, all items in the list, and any combination of items in the list.
[0326] In addition, conditional language used herein, such as "may", "can", "might", "could", "for example", "for instance", "such as", etc., unless specifically stated otherwise or otherwise understood in the context in which it is used, generally is intended to convey that certain embodiments include, while other embodiments do not include certain features, elements, and / or states. Thus, such conditional language generally does not mean that a feature, element, and / or state is required in any way by one or more embodiments, or that one or more embodiments necessarily include logic for determining whether such feature, element, or state is included or will be implemented in any particular embodiment, with or without author input or prompting.
[0327] As used herein, the term "determine / determined" (and its grammatical variants) can include at least the following: calculating, computing, processing, deriving, measuring, investigating, looking up (e.g., looking up in a table, database, or other data structure), ascertaining, etc. In addition, "determine" can include receiving (e.g., receiving information), accessing (e.g., accessing data in a memory), obtaining, etc. In addition, "determine / determined" can include parsing, selecting, choosing, establishing, etc.
[0328] Although some embodiments have been described, these embodiments are presented by way of example and are not intended to limit the scope of the present disclosure. In fact, the apparatuses, methods, and systems described herein may be embodied in various other forms; furthermore, various omissions, substitutions, and changes may be made to the forms of the methods and systems described herein without departing from the spirit of the present disclosure. For example, although the blocks are presented in a given arrangement, alternative embodiments may utilize different components and / or circuit topologies to perform similar functions, and some blocks may be deleted, moved, added, subdivided, combined, and / or modified. At least one of these blocks may be implemented in various different ways. The order of these blocks may also be changed. Any suitable combination of the elements and actions of the above-described embodiments may be combined to provide further embodiments. The appended claims and their equivalents are intended to cover such forms or modifications that fall within the scope and spirit of the present disclosure. The abbreviations used in the specification and / or drawings are defined as follows:
[0329] 3GPP Third Generation Partnership Project
[0330] 5GS Fifth Generation System
[0331] AMF Access and Mobility Management Function
[0332] BTS Base Transceiver Station
[0333] CN Core Network
[0334] CU Centralized Unit
[0335] eNB evolved Node B
[0336] gNB Next Generation Node B
[0337] HO Handover
[0338] KDF Key Derivation Function
[0339] PDU Protocol Data Unit
[0340] RAN Radio Access Network
[0341] RRC Radio Resource Control
[0342] RRM Radio Resource Management
[0343] S-NSSAI Single Network Slice Selection Assistance Information
[0344] TS Technical Specification
[0345] UE User Equipment
[0346] UP User Plane
Claims
1. A terminal device, comprising: At least one processor; And At least one memory storing instructions that, when executed by the at least one processor, cause the terminal device to at least perform: Receiving slice-specific security information from a source access network device associated with a handover of the terminal device; And Deriving at least one key specific to the slice based on the slice-specific security information.
2. The terminal device according to claim 1, wherein, The slice is a first slice or a second slice remapped from the first slice.
3. The terminal device according to claim 2, wherein, The second slice is equivalent to the first slice, and the security information specific to the first slice includes at least one of the following: an identifier of the first slice or encryption algorithm information specific to the first slice, and the security information specific to the second slice includes at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
4. A network device, comprising: At least one processor; And At least one memory storing instructions that, when executed by the at least one processor, cause the network device to at least perform: Selecting a target access network device associated with a handover of the terminal device based on the security capabilities specific to a first slice used by the terminal device of the target access network device; And Transmitting the security information specific to the first slice or the security information specific to a second slice remapped from the first slice to the target access network device.
5. The network device according to claim 4, wherein, The security information specific to the first slice includes at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice.
6. The network device according to claim 4 or 5, wherein, The network device is a source access network device associated with the handover, and when the instructions are executed by the at least one processor, causes the network device to further perform: Receiving the corresponding security capabilities specific to one or more slices supported by the target access network device from the target access network device.
7. The network device according to claim 6, wherein, The corresponding security capabilities specific to the one or more slices include at least one of the following: the corresponding identifiers of the one or more slices or the corresponding encryption algorithm information specific to the one or more slices.
8. The network device according to claim 6 or 7, wherein, When the instructions are executed by the at least one processor, causes the network device to further perform: Receiving the security information specific to a second slice remapped from the first slice from the target access network device; And Transmitting the security information specific to the second slice to the terminal device.
9. The network device according to claim 8, wherein, The second slice is equivalent to the first slice, and the security information specific to the second slice includes at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
10. The network device according to claim 4 or 5, wherein The network device is a target core network device associated with the handover, and when the instructions are executed by the at least one processor, causes the network device to further perform: Receiving the corresponding security capabilities specific to one or more slices supported by the target access network device from the target access network device or another core network device.
11. The network device according to claim 10, wherein, The corresponding security capabilities specific to the one or more slices include at least one of the following: the corresponding identifier of the one or more slices or the corresponding encryption algorithm information specific to the one or more slices.
12. The network device according to claim 10 or 11, wherein, When the instructions are executed by the at least one processor, cause the network device to further perform: Receive the security information specific to the first slice from a source core network device associated with the handover.
13. The network device according to any one of claims 10 to 12, wherein When the instructions are executed by the at least one processor, cause the network device to further perform: Determine a second slice remapped from the first slice in a case where the target access network device does not support the first slice; And Transmit an indication to the target access network device indicating that the second slice is remapped from the first slice.
14. The network device according to claim 12, wherein, When the instructions are executed by the at least one processor, cause the network device to further perform: Receive the security information specific to the second slice remapped from the first slice from the target access network device; And Transmit the security information specific to the second slice to the source core network device.
15. The network device according to claim 12, wherein, When the instructions are executed by the at least one processor, cause the network device to further perform: Determine the security information specific to the second slice remapped from the first slice in a case where the target access network device does not support the first slice; And Transmit the security information specific to the second slice to the source core network device, wherein the security information specific to the second slice is transmitted to the target access network device.
16. The network device according to any one of claims 13 to 15, wherein, The second slice is equivalent to the first slice, and the security information specific to the second slice includes at least one of the following: the identifier of the second slice or the encryption algorithm information specific to the second slice.
17. An access network device, comprising: At least one processor; And At least one memory storing instructions which, when executed by the at least one processor, cause the access network device, as a target access network device associated with a handover of a terminal device, to at least perform: Receive the security information specific to the first slice used by the terminal device or the security information specific to the second slice remapped from the first slice from another network device associated with the handover of the terminal device.
18. The access network device according to claim 17, wherein, The security information specific to the first slice includes at least one of the following: the identifier of the first slice or the encryption algorithm information specific to the first slice.
19. The access network device according to claim 17 or 18, wherein, When the instructions are executed by the at least one processor, cause the access network device to further perform: Determine the security information specific to the second slice remapped from the first slice in a case where the target access network device does not support the first slice, wherein the second slice is equivalent to the first slice, and the security information specific to the second slice includes at least one of the following: the identifier of the second slice or the encryption algorithm information specific to the second slice.
20. The access network device according to claim 19, wherein, When the instructions are executed by the at least one processor, cause the access network device to further perform: Transmit the security information specific to the second slice to the other network device; and Derive at least one key specific to the second slice based on the security information specific to the second slice.
21. The access network device according to claim 17 or 18, wherein When the instruction is executed by the at least one processor, cause the access network device to further perform: Determine a second slice remapped from the first slice in a case where the target access network device does not support the first slice; and Derive at least one key specific to the first slice based on the security information specific to the first slice.
22. The access network device according to claim 17 or 18, wherein The other network device is a target core network device associated with the handover of the terminal device, and when the instruction is executed by the at least one processor, cause the access network device to further perform: Receive, from the target core network device, the security information specific to the second slice remapped from the first slice in a case where the target access network device does not support the first slice; and Derive at least one key specific to the second slice based on the security information specific to the second slice, The second slice is equivalent to the first slice, and the security information specific to the second slice includes at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
23. The access network device according to claim 17 or 18, wherein, The other network device is a target core network device associated with the handover of the terminal device, and when the instruction is executed by the at least one processor, cause the access network device to further perform: Receive an indication from the target core network device indicating that the second slice is remapped from the first slice; and Derive at least one key specific to the first slice based on the security information specific to the first slice.
24. The access network device according to any one of claims 17 to 21, wherein, The other network device is a source access network device associated with the handover of the terminal device, and when the instruction is executed by the at least one processor, cause the access network device to further perform: Transmit the corresponding security capabilities specific to one or more slices supported by the target access network device to the source access network device.
25. The access network device according to any one of claims 17 to 21, wherein, The other network device is a target core network device associated with the handover of the terminal device, and when the instruction is executed by the at least one processor, cause the access network device to further perform: Transmit the corresponding security capabilities specific to one or more slices supported by the target access network device to the target core network device or another core network device.
26. The access network device according to claim 24 or 25, wherein The corresponding security capabilities specific to the one or more slices include at least one of the following: the corresponding identifiers of the one or more slices or the corresponding encryption algorithm information specific to the one or more slices.
27. A method performed by a terminal device, comprising: Receive security information specific to a slice from a source access network device associated with a handover of the terminal device; and Derive at least one key specific to the slice based on the security information specific to the slice.
28. The method according to claim 27, wherein, The slice is the first slice or a second slice remapped from the first slice.
29. The method according to claim 28, wherein, The second slice is equivalent to the first slice. The security information specific to the first slice includes at least one of the following: the identifier of the first slice or the encryption algorithm information specific to the first slice, and the security information specific to the second slice includes at least one of the following: the identifier of the second slice or the encryption algorithm information specific to the second slice.
30. A method performed by a network device, including: Selecting a target access network device associated with a handover of a terminal device based on the security capabilities specific to the first slice used by the terminal device of the target access network device; And Transmitting the security information specific to the first slice or the security information specific to a second slice remapped from the first slice to the target access network device.
31. The method according to claim 30, wherein, The security information specific to the first slice includes at least one of the following: the identifier of the first slice, or the encryption algorithm information specific to the first slice.
32. The method according to claim 30 or 31, wherein, The network device is a source access network device associated with the handover, and the method further includes: Receiving, from the target access network device, the corresponding security capabilities specific to one or more slices supported by the target access network device.
33. The method according to claim 32, wherein, The corresponding security capabilities specific to the one or more slices include at least one of the following: the corresponding identifiers of the one or more slices or the corresponding encryption algorithm information specific to the one or more slices.
34. The method according to claim 32 or 33, further including: Receiving, from the target access network device, the security information specific to a second slice remapped from the first slice; And Transmitting the security information specific to the second slice to the terminal device.
35. The method according to claim 34, wherein, The second slice is equivalent to the first slice, and the security information specific to the second slice includes at least one of the following: the identifier of the second slice or the encryption algorithm information specific to the second slice.
36. The method according to claim 30 or 31, wherein, The network device is a target core network device associated with the handover, and the method further includes: Receiving, from the target access network device or another core network device, the corresponding security capabilities specific to one or more slices supported by the target access network device.
37. The method according to claim 36, wherein, The corresponding security capabilities specific to the one or more slices include at least one of the following: the corresponding identifiers of the one or more slices or the corresponding encryption algorithm information specific to the one or more slices.
38. The method according to claim 36 or 37, further including: Receiving the security information specific to the first slice from a source core network device associated with the handover.
39. The method according to any one of claims 36 to 38, further including: Determining a second slice remapped from the first slice when the target access network device does not support the first slice; And Transmitting an indication to the target access network device indicating that the second slice is remapped from the first slice.
40. The method according to claim 38, further including: Receiving security information specific to a second slice remapped from the first slice from the target access network device; And Transmitting the security information specific to the second slice to the source core network device.
41. The method according to claim 38, further comprising: Determining the security information specific to the second slice remapped from the first slice when the target access network device does not support the first slice; And Transmitting the security information specific to the second slice to the source core network device, The security information specific to the second slice is transmitted to the target access network device.
42. The method according to any one of claims 39 to 41, wherein The second slice is equivalent to the first slice, and the security information specific to the second slice includes at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
43. A method performed by an access network device that is a target access network device associated with a handover of a terminal device, comprising: Receiving security information specific to a first slice used by the terminal device or security information specific to a second slice remapped from the first slice from another network device associated with the handover of the terminal device.
44. The method according to claim 43, wherein, The security information specific to the first slice includes at least one of the following: an identifier of the first slice, or encryption algorithm information specific to the first slice.
45. The method according to claim 43 or 44, further comprising: Determining security information specific to a second slice remapped from the first slice when the target access network device does not support the first slice, The second slice is equivalent to the first slice, and the security information specific to the second slice includes at least one of the following: an identifier of the second slice or encryption algorithm information specific to the second slice.
46. The method according to claim 45, further comprising: Transmitting the security information specific to the second slice to the another network device; And Deriving at least one key specific to the second slice based on the security information specific to the second slice.
47. The method according to claim 43 or 44, further comprising: Determining a second slice remapped from the first slice when the target access network device does not support the first slice; And Deriving at least one key specific to the first slice based on the security information specific to the first slice.
48. The method according to claim 43 or 44, wherein, The another network device is a target core network device associated with the handover of the terminal device, and the method further comprises: Receiving the security information specific to the second slice remapped from the first slice from the target core network device when the target access network device does not support the first slice; and Deriving at least one key specific to the second slice based on the security information specific to the second slice, The second slice is equivalent to the first slice, and the security information specific to the second slice includes at least one of the following: an identifier of the second slice, or encryption algorithm information specific to the second slice.
49. The method according to claim 43 or 44, wherein, The other network device is a target core network device associated with the handover of the terminal device, and the method further includes: Receiving, from the target core network device, an indication that the second slice is remapped from the first slice; and Deriving at least one key specific to the first slice based on the security information specific to the first slice.
50. The method according to any one of claims 43 to 47, wherein, The other network device is a source access network device associated with the handover of the terminal device, and the method further includes: Transmitting, to the source access network device, corresponding security capabilities specific to one or more slices supported by the target access network device.
51. The method according to any one of claims 43 to 47, wherein, The other network device is a target core network device associated with the handover of the terminal device, and the method further includes: Transmitting, to the target core network device or another core network device, corresponding security capabilities specific to one or more slices supported by the target access network device.
52. The method according to claim 50 or 51, wherein, The corresponding security capabilities specific to the one or more slices include at least one of the following: corresponding identifiers of the one or more slices or corresponding encryption algorithm information specific to the one or more slices.
53. A device acting as a terminal device, comprising: Means for receiving slice-specific security information from a source access network device associated with a handover of the terminal device; And Means for deriving at least one key specific to the slice based on the slice-specific security information.
54. The device according to claim 53, further comprising means for performing the method according to claim 28 or 29.
55. A device acting as a network device, comprising: Means for selecting a target access network device associated with a handover of the terminal device based on the security capabilities specific to a first slice used by the terminal device of the target access network device; And Means for transmitting security information specific to the first slice or security information specific to a second slice remapped from the first slice to the target access network device.
56. The device according to claim 55, further comprising means for performing the method according to any one of claims 31 to 42.
57. A device acting as an access network device, the access network device being a target access network device associated with a handover of a terminal device, the device comprising: Means for receiving security information specific to a first slice used by the terminal device or security information specific to a second slice remapped from the first slice from another network device associated with the handover of the terminal device.
58. The device according to claim 57, further comprising means for performing the method according to any one of claims 44 to 52.
59. A computer-readable medium includes program instructions that, when executed by a terminal device, cause the terminal device to at least perform: Receiving slice-specific security information from a source access network device associated with a handover of the terminal device; and Deriving at least one key specific to the slice based on the slice-specific security information.
60. The computer-readable medium according to claim 59, further comprising instructions that, when executed by the terminal device, cause the terminal device to perform the method according to claim 28 or 29.
61. A computer-readable medium including program instructions that, when executed by a network device, cause the network device to at least perform: Selecting a target access network device associated with a handover of a terminal device based on the security capabilities specific to a first slice used by the terminal device of the target access network device; and Transmitting security information specific to the first slice or security information specific to a second slice remapped from the first slice to the target access network device.
62. The computer-readable medium according to claim 61, further comprising instructions that, when executed by the network device, cause the network device to perform the method according to any one of claims 31 to 42.
63. A computer-readable medium includes program instructions that, when executed by an access network device serving as a target access network device associated with a handover of a terminal device, cause the access network device to at least perform: Receiving security information specific to a first slice used by the terminal device or security information specific to a second slice remapped from the first slice from another network device associated with the handover of the terminal device.
64. The computer-readable medium according to claim 63, further comprising instructions that, when executed by the access network device, cause the access network device to perform the method according to any one of claims 44 to 52.