Communication methods, apparatus, devices and readable storage media

By dynamically updating the GUTI counter results for authentication, the risk of GUTI leakage during air interface transmission is resolved, thereby improving the security and accuracy of network communication and authentication.

CN120434638BActive Publication Date: 2025-11-14HONOR DEVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510933153.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-08
Publication Date
2025-11-14
Estimated Expiration
2045-07-08

AI Technical Summary

Technical Problem

In 4G and 5G mobile communication technologies, the Globally Unique Temporary User Equipment Identifier (GUTI) is at risk of being leaked during air interface transmission, which poses security threats to terminal equipment and core network equipment, such as information leakage and malicious monitoring.

Method used

By designing a counter to dynamically update the GUTI, and using the counter result to replace the GUTI for authentication, plaintext transmission is avoided and network communication security is enhanced.

Benefits of technology

It effectively prevents GUTI leakage, improves the security of network communication and the accuracy of identity authentication, and reduces potential security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434638B_ABST
    Figure CN120434638B_ABST
Patent Text Reader

Abstract

This application provides a communication method, apparatus, device, and readable storage medium. The method is applied to a first mobility management device and includes: upon receiving an i-th first non-access stratum (NAS) message, updating an i-th first counter result based on the i-th NAS message to obtain an (i+1)-th first counter result; and sending an i-th second NAS message containing the (i+1)-th first counter result to a terminal device to guide the terminal device in generating a corresponding temporary identifier based on the i-th first counter result. That is, by designing a counter, updating the Global Unknown Identifier (GUTI) in real time based on the counter's update result, and using the counter result to replace the GUTI sent to the terminal device, the terminal device can use the previously received counter result to generate the GUTI each time it performs authentication, avoiding plaintext transmission of the GUTI and improving network communication security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and more particularly to a communication method, apparatus, device, and readable storage medium. Background Technology

[0002] With the development of communication technology, under the network architecture of fourth-generation mobile communication technology (4G) or fifth-generation mobile communication technology (5G), when a terminal device performs an initial registration process, a periodic update registration process, or a service node switching process, the core network equipment will assign a globally unique temporary UE identity (GUTI) to the terminal device to replace the permanent identifier of the terminal device, so as to prevent the information leakage of the terminal device.

[0003] In related technologies, a random number is generated by the mobility management device and combined with the Global Mobility Management Network (GMU) element identifier to form a Global Mobile Management Information (GUTI), which is then sent to the terminal device. This enables the terminal device to subsequently authenticate itself by sending the GUTI to the mobility management device. After successful authentication, a communication connection is established to enable data transmission.

[0004] However, due to the risk of GUTI leakage during air interface transmission, if GUTI is intercepted by attackers, terminal devices and core network equipment will face more potential security risks. These include attacks, leakage of sensitive information, and malicious monitoring or tampering with operational status. Therefore, ensuring network communication security is an urgent problem to be solved. Summary of the Invention

[0005] This application provides a communication method, apparatus, device, and readable storage medium. The solution designs a counter to update the GUTI in real time based on the counter's update result. The counter result is then used to replace the GUTI and sent to the terminal device, so that the terminal device can use the GUTI generated by the previously received counter result each time it performs authentication, avoiding plaintext transmission of the GUTI and improving network communication security.

[0006] A first aspect provides a communication method applied to a first mobility management device, the method comprising: receiving an i-th first non-access stratum (NAS) message, where i is a positive integer; updating an i-th first counter result based on the i-th first NAS message to obtain an (i+1)-th first counter result, wherein the first counter result is related to the number of first NAS messages received by the first mobility management device, and the (i+1)-th first counter result is used to update an i-th second temporary identifier stored by the first mobility management device to obtain an (i+1)-th second temporary identifier, wherein the (i+1)-th second temporary identifier is used to authenticate the terminal device upon receiving the (i+1)-th first NAS message sent by the terminal device; and sending an i-th second NAS message to the terminal device, wherein the i-th second NAS message includes the (i+1)-th first counter result.

[0007] In the technical solution of this application embodiment, when the first mobility management device receives the i-th first NAS message carrying the i-th first temporary identifier, it updates the i-th first counter result stored locally on the first mobility management device according to the i-th first NAS message to obtain the (i+1)-th first counter result. The (i+1)-th first counter result is then sent to the terminal device, so that the terminal device, upon receiving the (i+1)-th first counter result, generates the (i+1)-th first temporary identifier for the next authentication. In other words, by setting a counter and dynamically updating the counter result based on the number of NAS messages received by the mobility management device, the counter result replaces the GUTI and is allocated to the terminal device. This ensures that during the authentication process, the GUTI is generated locally by the terminal device based on the latest received counter result and sent to the mobility management device for verification, avoiding plaintext transmission of the GUTI during allocation and maintaining dynamic updates, thereby improving network communication security.

[0008] In conjunction with the first aspect, in some implementations of the first aspect, updating the i-th first counter result based on the i-th first NAS message includes: incrementing the i-th first counter result by n based on the i-th first NAS message to obtain the (i+1)-th first counter result, where n is a positive integer. By using the above method to update the counter result of the first counter according to the received first NAS message, dynamic updates of the GUTI can be achieved, making it difficult to obtain and thus improving the security performance of the GUTI.

[0009] In conjunction with the first aspect, in some implementations of the first aspect, the terminal device corresponds to a permanent identifier, and the first mobility management device corresponds to a Global Mobility Management Network (GMU) identifier. The method further includes: performing an encryption operation on the (i+1)th first counter result, the permanent identifier, and the GMU identifier to obtain a first encryption result; obtaining the (i+1)th second temporary identifier based on the first encryption result and the GMU identifier; and storing the (i+1)th second temporary identifier. Through the above method, by integrating the real-time updated first counter result into the GUTI encryption generation process, dynamic updating of the GUTI can be achieved, thereby improving network communication security.

[0010] In conjunction with the first aspect, in some implementations of the first aspect, the (i+1)th first counter result corresponds to a first timestamp, which is used to indicate the valid time corresponding to the (i+1)th first counter result. The method further includes: performing encryption operations on the (i+1)th first counter result, the permanent identifier, the Global Mobility Management Network (GMO) element identifier, and the (i+1)th timestamp to obtain a first encryption result. By adding the timestamp corresponding to the first counter result to the GUTI, the time validity of the GUTI is achieved. This ensures that even if an attacker intercepts an old GUTI, the receiver can determine the validity of the GUTI based on the timestamp in the received GUTI, thereby improving network communication security.

[0011] In conjunction with the first aspect, in some implementations of the first aspect, the i-th second NAS message includes a first timestamp. By carrying the first timestamp in the second NAS message using the above method, the terminal device can be assisted in determining the validity of the first counter result in the second NAS message, thereby improving network communication security.

[0012] In conjunction with the first aspect, some implementations of the first aspect include hash value operations. By using hash value operations to generate the GUTI, the attacker cannot decrypt the GUTI without knowing the counter result, thus improving the data confidentiality of the GUTI.

[0013] In conjunction with the first aspect, in some implementations of the first aspect, the first NAS message includes at least one of the following: an initial registration request message; a location update request message; a handover request message; a periodic registration request message; and a service request message. By enumerating the message types of the first NAS message using the above method, the aforementioned GUTI generation method can meet various communication transmission scenarios.

[0014] In conjunction with the first aspect, in certain implementations of the first aspect, when the i-th first NAS message is an initial registration request message, the i-th first temporary identifier is the Subscription Hidden Identifier (SUCI) or User Identifier (IMSI) corresponding to the terminal device; when the i-th first NAS message includes any one of a handover request message, a location update request message, a periodic registration request message, or a service request message, the i-th first temporary identifier is the i-th first GUTI, which is obtained by the terminal device based on the result of the i-th second counter, and the result of the i-th second counter is related to the result of the i-th first counter. Through the above method, when the first NAS message is implemented as different message types, the identifier type of the temporary identifier also differs, thereby satisfying various communication scenarios.

[0015] In conjunction with the first aspect, in some implementations of the first aspect, the first counter result includes multiple bits, among which the first bit is included; the method further includes: if the other bits in the first counter result, excluding the first bit, meet the overflow condition, setting the first bit to 1 and resetting the other bits to obtain the reset result corresponding to the first counter result, which is used as the (i+1)th first counter result. Through the above method, by setting an overflow bit for the first counter result, the first counter result has a corresponding counting range, and can cyclically count within the counting range, avoiding the first counter result from increasing indefinitely and saving communication overhead.

[0016] In conjunction with the first aspect, in some implementations of the first aspect, after sending the i-th second NAS message to the terminal device, the method further includes: receiving the (i+1)-th first NAS message sent by the terminal device, the (i+1)-th first NAS message including the (i+1)-th first temporary identifier; setting the first bit to 0 based on the (i+1)-th first temporary identifier, and updating the other bits based on the (i+1)-th first temporary identifier to obtain the (i+2)-th first counter result. Through the above method, when the first counter result satisfies the overflow condition, different setting methods for the overflow bit are used to synchronously update the results between the mobility management device and the terminal device, ensuring the synchronization of the counter results and improving the accuracy of identity authentication.

[0017] Secondly, a communication method is provided, which is applied to a terminal device. The method includes: sending an i-th first NAS message to a first mobility management device, wherein the i-th first NAS message includes an i-th first temporary identifier corresponding to the terminal device, and i is a positive integer; receiving an i-th second NAS message sent by the first mobility management device, wherein the i-th second NAS message includes an (i+1)-th first counter result, the (i+1)-th first counter result being obtained by the first mobility management device updating the i-th first counter result based on the i-th NAS message, and the first counter result being related to the number of first NAS messages received by the first mobility management device; updating the i-th second temporary identifier based on the (i+1)-th first counter result to obtain an (i+1)-th second temporary identifier, wherein the first mobility management device is used to authenticate the terminal device based on the (i+1)-th first temporary identifier when receiving the (i+1)-th first NAS message sent by the terminal device.

[0018] It should be understood that the technical effects of the second aspect of the technical solution can be referred to the relevant description in the first aspect, and will not be repeated here.

[0019] In conjunction with the second aspect, in some implementations of the second aspect, the first mobility management device is used to increment the first counter result by one based on the i-th first NAS message to obtain the (i+1)-th first counter result.

[0020] In conjunction with the second aspect, in some implementations of the second aspect, the terminal device corresponds to a permanent identifier, and the first mobility management device corresponds to a Global Mobility Management Network (GMN) identifier; the first mobility management device is used to perform encryption operations on the (i+1)th first counter result, the permanent identifier, and the GMN identifier to obtain a first encryption result; based on the first encryption result and the GMN identifier, the (i+1)th second temporary identifier is obtained; and the (i+1)th second temporary identifier is stored.

[0021] In conjunction with the second aspect, in some implementations of the second aspect, the (i+1)th first counter result corresponds to the first timestamp, and the first timestamp is used to indicate the valid time corresponding to the (i+1)th first counter result; the first mobility management device is used to perform encryption operations on the (i+1)th first counter result, the permanent identifier, the Global Mobility Management Network element identifier and the (i+1)th timestamp to obtain the first encryption result.

[0022] In conjunction with the second aspect, in some implementations of the second aspect, the i-th second NAS message includes a first timestamp.

[0023] In conjunction with the second aspect, in some implementations of the second aspect, the current timestamp is obtained; if the current timestamp fails to match the first timestamp, the i-th second NAS message is discarded.

[0024] In conjunction with the second aspect, in some implementations of the second aspect, the encryption operation includes hash value operation methods.

[0025] In conjunction with the second aspect, in some implementations of the second aspect, the terminal device stores the i-th second counter result, which is related to the number of NAS messages received or sent by the terminal device; updating the i-th second temporary identifier based on the (i+1)-th first counter result to obtain the (i+1)-th second temporary identifier includes: when the (i+1)-th first counter result is greater than the i-th second counter result, and the difference between the (i+1)-th first counter result and the i-th second counter result meets a preset difference condition, updating the i-th second counter result based on the (i+1)-th first counter result to obtain the (i+1)-th second counter result; updating the i-th first temporary identifier based on the (i+1)-th second counter result to obtain the (i+1)-th first temporary identifier.

[0026] In conjunction with the second aspect, in some implementations of the second aspect, the first NAS message includes at least one of the following: an initial registration request message; a periodic registration request message; a service request message.

[0027] In conjunction with the second aspect, in some implementations of the second aspect, when the i-th first NAS message is an initial registration request message, the i-th first temporary identifier is the SUCI or IMSI corresponding to the terminal device; when the i-th first NAS message includes either a periodic registration request message or a service request message, the i-th first temporary identifier is the i-th globally unique temporary identifier (GUTI), the i-th GUTI is obtained by the terminal device based on the i-th second counter result, and the i-th second counter result is related to the i-th first counter result.

[0028] In conjunction with the second aspect, in some implementations of the second aspect, the first counter result includes multiple bits, among which the multiple bits include the first bit; the first mobility management device is further configured to, when the other bits in the first counter result, excluding the first bit, meet the overflow condition, set the first bit to 1 and reset the other bits to obtain the reset result corresponding to the first counter result, as the (i+1)th first counter result.

[0029] In conjunction with the second aspect, in some implementations of the second aspect, after receiving the i-th second NAS message sent by the first mobility management device, the method further includes: sending the (i+1)-th first NAS message to the first mobility management device, wherein the (i+1)-th first NAS message includes the (i+1)-th first temporary identifier, and the first mobility management device is used to set the first bit to 0 based on the (i+1)-th first temporary identifier, and to update the other bits based on the (i+1)-th first temporary identifier, thereby obtaining the (i+2)-th first counter result.

[0030] Thirdly, a communication method is provided, wherein the method is a second mobility management device, the method comprising: sending an i-th first NAS message to a first mobility management device, where i is a positive integer; wherein, the first mobility management device is configured to send an i-th second NAS message to the terminal device when the first NAS message includes an i-th first temporary identifier corresponding to the terminal device, the i-th second NAS message including an (i+1)-th first counter result, the (i+1)-th first counter result being obtained by the first mobility management device updating the i-th first counter result based on the i-th NAS message, the first counter result being related to the number of first NAS messages received by the first mobility management device; the terminal device is configured to update the i-th first temporary identifier based on the (i+1)-th first counter result to obtain an (i+1)-th first temporary identifier, and the first mobility management device is configured to perform identity authentication on the terminal device based on the (i+1)-th first temporary identifier when receiving the (i+1)-th first NAS message sent by the terminal device.

[0031] Fourthly, a communication device is provided, the device comprising:

[0032] The receiving unit is used to receive the i-th first non-access stratum (NAS) message, where i is a positive integer;

[0033] The update unit is configured to update the i-th first non-access stratum counter result based on the i-th NAS message when the first NAS message includes the i-th first temporary identifier corresponding to the terminal device, to obtain the (i+1)-th first counter result. The first counter result is related to the number of first NAS messages received by the first mobility management device. The (i+1)-th first counter result is used to update the i-th second temporary identifier to obtain the (i+1)-th second temporary identifier. The (i+1)-th second temporary identifier is used to authenticate the terminal device when the (i+1)-th first NAS message sent by the terminal device is received.

[0034] The sending unit is used to send the i-th second NAS message to the terminal device, wherein the i-th second NAS message includes the (i+1)-th first counter result.

[0035] Fifthly, a communication device is provided, the device comprising:

[0036] The sending unit is used to send the i-th first NAS message to the first mobility management device. The i-th NAS message includes the i-th first temporary identifier corresponding to the terminal device, where i is a positive integer.

[0037] The receiving unit is configured to receive the i-th second NAS message sent by the first mobility management device. The i-th second NAS message includes the (i+1)-th first counter result. The (i+1)-th first counter result is obtained by the first mobility management device updating the i-th first counter result based on the i-th NAS message. The first counter result is related to the number of first NAS messages received by the first mobility management device.

[0038] The update unit is used to update the i-th second temporary identifier based on the i+1-th first counter result to obtain the i+1-th second temporary identifier. The first mobility management device is used to authenticate the terminal device based on the i+1-th first temporary identifier when it receives the i+1-th first NAS message sent by the terminal device.

[0039] Sixthly, a communication device is provided, the device comprising:

[0040] The sending unit is configured to send the i-th first NAS message to the first mobility management device, wherein the i-th NAS message includes the i-th first temporary identifier corresponding to the terminal device, and i is a positive integer; wherein the first mobility management device is configured to send the i-th second NAS message to the terminal device, wherein the i-th second NAS message includes the (i+1)-th first counter result, the (i+1)-th first counter result is obtained by the first mobility management device updating the i-th first counter result based on the i-th NAS message, and the first counter result is related to the number of first NAS messages received by the first mobility management device; the terminal device is configured to update the i-th first temporary identifier based on the (i+1)-th first counter result to obtain the (i+1)-th first temporary identifier, and the first mobility management device is configured to perform identity authentication on the terminal device based on the (i+1)-th first temporary identifier when receiving the (i+1)-th first NAS message sent by the terminal device.

[0041] In a sixth aspect, a communication device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it is able to implement any of the methods of the first aspect.

[0042] In a seventh aspect, a communication device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it is able to implement any of the methods of the second aspect.

[0043] Eighthly, a communication device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it is able to implement any of the methods of the third aspect.

[0044] In a ninth aspect, a chip is provided, including a processor for reading and executing a computer program stored in a memory, wherein the computer program, when executed by the processor, is capable of implementing any one of the methods of the first aspect or the second aspect.

[0045] Optionally, the chip also includes a memory electrically connected to the processor.

[0046] Optionally, the chip may also include a communication interface.

[0047] In a tenth aspect, a computer-readable storage medium is provided that stores a computer program that, when executed by a processor, can implement any one of the methods of the first, second, or third aspect.

[0048] Eleventhly, a computer program product is provided, comprising a computer program that, when executed by a processor, can implement any one of the methods of the first, second, or third aspects. Attached Figure Description

[0049] Figure 1 This is a schematic diagram of a network architecture according to an embodiment of this application.

[0050] Figure 2 This is a schematic diagram of the architecture of a mobile communication system according to an embodiment of this application.

[0051] Figure 3 This is a schematic diagram illustrating the application process of GUTI in a 4G scenario according to an embodiment of this application.

[0052] Figure 4 This is a schematic diagram illustrating the application process of GUTI in a 5G scenario according to an embodiment of this application.

[0053] Figure 5 This is a flowchart illustrating the interaction of a communication method according to an embodiment of this application.

[0054] Figure 5A This is a schematic diagram of GUTI content according to an embodiment of this application.

[0055] Figure 6 This is an interactive flowchart of a temporary identifier allocation method according to an embodiment of this application.

[0056] Figure 7 This is a schematic diagram of a temporary identifier generation method according to an embodiment of this application.

[0057] Figure 8 This is a schematic diagram of an overflow process according to an embodiment of this application.

[0058] Figure 9 This is a schematic diagram of the hardware structure of a communication device according to an embodiment of this application. Detailed Implementation

[0059] The solutions of the embodiments of this application are described below with reference to the accompanying drawings. The communication method provided by this application can be applied to various wireless communication systems.

[0060] First, the relevant terms and technologies in this application will be explained.

[0061] • Globally unique temporary identifier (GUTI)

[0062] GUTI refers to a parameter used in 4G and 5G networks to temporarily represent user equipment (UE), and is usually used to replace the permanent identifier of the terminal device for communication transmission.

[0063] In 4G network scenarios, the core network includes a mobility management entity (MME). Therefore, the Globally Unique MME Identity (GUMMEI) consists of a globally unique MME identity (GUMMEI) and a temporary mobile subscriber identity (M-TMSI). The GUMMEI comprises a public land mobile network (PLMN) ID, an MME group ID, and a specific MME code within that group. The GUMMEI is typically a 24-bit structured identifier. The M-TMSI is a randomly generated number by the MME, also known as a random number, used to uniquely identify the terminal device. The MME group ID indicates the MME group to which the MME entity belongs, and the specific MME code within that group uniquely identifies the MME entity within that MME group.

[0064] In 5G network scenarios, the core network includes the Access and Mobility Management Function (AMF) entity. Therefore, the Global Unique Mobile Network Element Identifier (GUTI) consists of a globally unique AMF ID (GUAMI) and a Temporary Mobile Subscriber Identifier (5G-TMSI). The GUTI comprises a PLMN ID, an AMF Region ID, an AMF Set ID, and an AMF Pointer. The GUAMI is typically a 24-bit structured identifier. The 5G-TMSI is a randomly generated number by the MME, also known as a random number, used to uniquely identify the terminal device.

[0065] • Subscription permanent identifier (SUPI)

[0066] SUPI is used as a unique identifier for terminal devices in 5G network scenarios. During communication, SUPI is typically encrypted to generate a subscription concealed identifier (SUCI) to prevent user identity from being traced.

[0067] International Mobile Subscriber Identity (IMSI)

[0068] IMSI is used as an identifier to uniquely represent a terminal device in 2G, 3G, and 4G network scenarios. During communication, it is usually transmitted directly using IMSI.

[0069] The network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0070] The technical solutions of this application embodiment can be applied to various communication systems, such as: Long Term Evolution (LTE) system, Advanced Long Term Evolution (LTE-A) system, New Radio (NR) system, evolution system of NR system, LTE-based access to unlicensed spectrum (LTE-U) system, NR-based access to unlicensed spectrum (NR-U) system, Non-Terrestrial Networks (NTN) system, Universal Mobile Telecommunication System (UMTS), Wireless Local Area Networks (WLAN), Wireless Fidelity (WiFi), 5th Generation (5G) system, B5G (Beyound 5G) system, 6th Generation (6G) system, or other communication systems, etc. Traditional communication systems typically support a limited number of connections and are easy to implement. However, with the development of communication technology, mobile communication systems will not only support traditional communication but also, for example, device-to-device (D2D) communication, machine-to-machine (M2M) communication, machine-type communication (MTC), vehicle-to-vehicle (V2V) communication, or vehicle-to-everything (V2X) communication. The embodiments of this application can also be applied to these communication systems.

[0071] Please refer to Figure 1, which shows a schematic diagram of a network architecture 100 provided in one embodiment of this application. The network architecture 100 may include: terminal device 10, access network device 20, and core network element 30. Terminal device 10 may refer to user equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, wireless communication device, user agent, or user equipment. In some embodiments, terminal device 10 may also be a cellular phone, cordless phone, SIP (Session Initiation Protocol) phone, WLL (Wireless Local Loop) station, PDA (Personal Digital Assistant), handheld device with wireless communication capabilities, computing device or other processing device connected to a wireless modem, in-vehicle device, wearable device, terminal device in 5GS (5th Generation System), terminal device in 6GS (6th Generation System), or terminal device in a future evolved PLMN (Public Land Mobile Network), etc., and this application embodiment is not limited thereto. For ease of description, the devices mentioned above are collectively referred to as terminal devices. The number of terminal devices 10 is usually multiple, and one or more terminal devices 10 can be distributed within the cell managed by each access network device 20. Terminal devices may also be simply referred to as terminals or UEs, the meaning of which will be understood by those skilled in the art. Access network device 20 is a device deployed in the access network to provide wireless communication capabilities to terminal device 10. Access network equipment 20 may include various forms of macro base stations, micro base stations, relay stations, access points, etc. In systems employing different wireless access technologies, the names of devices with access network equipment functions may differ; for example, in a 5G NR system, they are called gNodeB or gNB. As communication technologies evolve, the name "access network equipment" may change. For ease of description, in this embodiment, the aforementioned devices providing wireless communication functions for terminal device 10 are collectively referred to as access network equipment. In some embodiments, a communication relationship can be established between terminal device 10 and core network element 30 through access network equipment 20.For example, in an LTE (Long Term Evolution) system, access network device 20 can be one or more eNodeBs within an EUTRAN (Evolved Universal Terrestrial Radio Access Network) or EUTRAN; in a 5G NR system, access network device 20 can be one or more gNBs within an RAN (Radio Access Network). In this embodiment, unless otherwise specified, "network device" refers to access network device 20, such as a base station. Core network elements 30 are network elements deployed in the core network. The main functions of core network elements 30 are to provide user connectivity, manage users, and carry out service delivery, serving as an interface to external networks. For example, core network elements in a 5G NR system may include AMF entities, UPF (User Plane Function) entities, and SMF (Session Management Function) entities. In some embodiments, the access network device 20 and the core network element 30 communicate with each other through some air interface technology, such as the NG(N) interface in a 5G NR system. The access network device 20 and the terminal device 10 communicate with each other through some air interface technology, such as the Uu interface. The "5G NR system" in the embodiments of this application can also be called a 5G system or an NR system, but those skilled in the art will understand its meaning. The technical solutions described in the embodiments of this application can be applied to LTE systems, 5G NR systems, and subsequent evolution systems of 5G NR systems (such as B5G (Beyond 5G, a fifth-generation mobile communication technology) systems, 6G systems (6th Generation System, a sixth-generation mobile communication system)), and other communication systems such as NB-IoT (Narrow Band Internet of Things) systems. This application does not limit these applications.

[0072] Figure 2This illustration shows a schematic diagram of the architecture of a mobile communication system provided in an embodiment of this application. The architecture includes User Equipment (UE), (R)AN, Core Network (CN) network elements, and Data Network (DN), where RAN represents Radio Access Network and AN represents Access Network. Theoretically, this architecture can be divided into two parts: the user plane and the control plane. The control plane is responsible for the management of the mobile network, while the user plane is responsible for the transmission of service data. Figure 2 In this context, the N2 reference point is located between the (R)AN control plane and the core network control plane, the N3 reference point is located between the (R)AN user plane and the core network user plane, and the N6 reference point is located between the core network user plane and the data network.

[0073] The UE (User Equipment) serves as the entry point for mobile users to interact with the network. It provides basic computing and storage capabilities, displays service windows to users, and receives user input. The UE uses air interface technology to establish signal and data connections with the (R)AN (Radio and Mobile Network), thereby transmitting control signals and service data to the mobile network.

[0074] The (R)AN is deployed close to the UE to provide network access for authorized users in specific areas. It can transmit user data using transmission tunnels of different quality depending on the user's level and service requirements. The (R)AN can manage its own resources, make reasonable use of them, and provide access services to the UE on demand, forwarding control signals and user data between the UE and the core network.

[0075] The core network user plane includes the following core network elements: User Plane Function (UPF). In addition to forwarding and receiving user data, the UPF also has domain name lookup functions.

[0076] The core network control plane includes one or more of the following core network elements: Authentication Server Function (AUSF), AMF, Session Management Function (SMF), Network Slice Selection Function (NSSF), Network Exposure Function (NEF), Network Repository Function (NRF), Unified Data Management (UDM), Policy Control Function (PCF), and Application Function (AF). Among these, the AMF is primarily responsible for mobility management in the mobile network, such as user location updates, user registration with the network, and user handover. The SMF is primarily responsible for session management in the mobile network, such as session establishment, modification, and release. The PCF primarily supports providing a unified policy framework to control network behavior, providing policy rules to the control layer network functions, and is also responsible for obtaining user subscription information related to policy decisions. The AUSF is used to perform terminal security authentication. The NEF is primarily used to support the exposure of capabilities and events. The NRF is used to provide storage and selection functions for network function entity information for other network elements. The UDM is used to store user data, such as subscription data and authentication / authorization data. The AF interacts with the core network to provide application-layer services, such as providing application-layer data routing, providing access network capability exposure functions, interacting with the policy framework to provide policy control, and interacting with the IMS. Optionally, the core network control plane may also include network elements specifically deployed for A-IoT services.

[0077] exist Figure 2 In the architecture shown, the N1 interface serves as the reference point between the UE and the AMF; the N2 interface serves as the reference point between the RAN and the AMF, used for sending Non-Access Stratum (NAS) messages; the N3 interface serves as the reference point between the RAN and the UPF, used for transmitting user plane data; the N4 interface serves as the reference point between the SMF and the UPF, used for transmitting information such as tunnel identification information for N3 connections, data buffer indication information, and downlink data notification messages; the N6 interface serves as the reference point between the UPF and the DN, used for transmitting user plane data. The NG interface is the interface between the RAN and the CN.

[0078] It should be noted that, Figure 2The interface names between the various network elements are just examples. In actual implementations, the interface names may be different, and this application does not specifically limit them. Figure 2 The names of the various network elements included (such as SMF, AF, UPF, etc.) are merely examples and do not limit the functions of the network elements themselves. In related networks and future networks, the aforementioned network elements may also have other names, and this application does not specifically limit them. For example, in a 6G network, some or all of the aforementioned network elements may use the terminology from 5G, or may use other names, etc. This is explained uniformly here and will not be repeated below. Furthermore, it should be understood that the names of the messages (or signaling) transmitted between the aforementioned network elements are also merely examples and do not limit the functions of the messages themselves.

[0079] In related technologies, the use cases for GUTI typically include the following:

[0080] (1) Initial registration scenario

[0081] When a terminal device accesses the network for the first time, it needs to send an initial registration request to the AMF device (or network element) or MME device, and include SUCI or IMSI in the initial registration request. This allows the AMF device to authenticate the terminal device based on SUCI, or the MME device to authenticate the terminal device based on IMSI. After successful authentication, the AMF device or MME device assigns a GUTI to the terminal device to replace SUCI or IMSI in performing subsequent authentication processes.

[0082] (2) Switching scenes

[0083] Once the terminal device successfully accesses the network and connects to the first AMF device or the first MME device, taking a 5G scenario as an example, the first AMF device corresponds to the first location area, and the second AMF device corresponds to the second location area. When the terminal device moves from the first location area to the second location area, the second AMF device needs to assign a new GUTI to the terminal device so that the terminal device can subsequently perform the identity authentication process with the second AMF device through the new GUTI.

[0084] (3) Periodic update scenario

[0085] The GUTI has a timer mechanism, which means that when the duration for which the AMF device or MME device allocates the GUTI to the terminal device reaches a certain threshold, the AMF device or MME device will update the GUTI and allocate the updated GUTI to the terminal device.

[0086] (4) Service establishment scenario

[0087] Once the terminal device successfully accesses the network, under one feasible scenario, when the terminal device is in an idle or inactive state, if it needs to initiate data transmission (or establish a session), receive downlink data, or respond to a paging message sent by a network device, the terminal device initiates connection establishment or restoration by carrying the GUTI assigned by the AMF device or MME device in the service request. After receiving the GUTI, the AMF device or MME device uses the GUTI to authenticate the terminal device.

[0088] The following is illustrative; please refer to it. Figure 3 This illustrates a schematic diagram of the application process of GUTI in a 4G scenario provided by an exemplary embodiment of this application, such as... Figure 3 As shown, the method includes the following steps.

[0089] Initial registration phase:

[0090] S310, the terminal device sends an initial registration request to the MME device.

[0091] When a terminal device accesses a 4G network for the first time, it sends an initial registration request to the MME device to request access to the MME device.

[0092] The initial registration request includes the IMSI and HSS device identifiers corresponding to the terminal device.

[0093] In the S320, the MME device sends an authentication request to the Home Subscriber Server (HSS) device.

[0094] After receiving the initial registration request, the MME device sends an authentication request to the designated HSS device based on the HSS device identifier to request authentication of the terminal device. The authentication request carries the IMSI corresponding to the terminal device. In addition, the authentication request also includes the network identifier, network type (e.g., E-UTRAN), and specifies the number of authentication sets to be obtained.

[0095] HSS devices are used to store user identity information (such as user ID, number, and address), security information (such as authentication and authorization information for user network access control), location information, and subscribed service information. When a user attempts to access the 4G network, the HSS device performs the user's identity authentication and authorization process to ensure that only legitimate users can access the network and enjoy services.

[0096] S330, HSS device generates authentication information.

[0097] After receiving an authentication request, the HSS device generates an authentication vector. The authentication vector mainly includes four components: a random number (RAND), an authentication token (AUTN), an expected response (XRES), and the Access Security Management Entity Key (KASME).

[0098] Among them, the random number refers to the random number provided by the network device to the terminal device; the authentication token is used to provide information to the terminal device so that the terminal device can use the authentication token to authenticate the network device; the expected response refers to the expected terminal authentication response parameters, which are used to compare whether the authentication is successful.

[0099] After receiving the authentication request, the HSS device looks up the IMSI in the existing database and verifies the validity of the IMSI. If the verification is successful, it generates an authentication vector group AV(1,...,n).

[0100] In the process of generating the authentication vector group, the HSS device generates a random number for each authentication process of each terminal device, and combines it with parameters such as the serial number (SQN), authentication management domain, and key to generate the authentication vector.

[0101] S340, the HSS device sends an authentication response to the MME device.

[0102] The HSS device sends the generated authentication vector group AV(1,...,n) back to the MME device as an authentication response.

[0103] S350, MME device generates GUTI.

[0104] After receiving the authentication response, the MME device first randomly generates a data point as the TMSI. The TMSI and GUMMEI are then used to construct the GUTI. Finally, the GUTI, IMSI, and KASME are stored as a triplet in the MME device's database.

[0105] S360, the MME device sends a registration success message to the terminal device.

[0106] After generating the GUTI, the MME device sends a registration success message to the terminal device, indicating that the terminal device has successfully accessed the 4G network for the first time, and the registration success message carries the GUTI.

[0107] Subsequent registration phase:

[0108] S370, the terminal device sends a request message to the MME device.

[0109] The request message includes at least one of the following: Tracking Area Update (TAU) request message, service request message, Detach request message, or Reattach request message.

[0110] When a terminal device moves from one tracking area (TA) to another, it needs to re-register its location on the new TA to notify the network device to change the location information stored by the terminal device, thereby generating a TAU request message.

[0111] The disconnect request is used to request the terminal device to disconnect from the currently accessed 4G network.

[0112] The reconnection request is used to indicate reconnection to the 4G network when the terminal device is in an idle or inactive state.

[0113] The terminal device carries the GUTI recently allocated by the MME device in the request message.

[0114] In one mode, if the MME device can determine the IMSI of the terminal device based on the GUTI, then S381 to S391 are executed; if the MME device cannot determine the IMSI of the terminal device based on the GUTI, then S382 to S393 are executed.

[0115] S381, the MME device determines the IMSI corresponding to the terminal device based on the GUTI.

[0116] When the MME device receives the request message, it determines the GUTI based on the request message, retrieves the triplet data corresponding to the GUTI from the database, and obtains the IMSI corresponding to the terminal device based on the triplet data.

[0117] S391, the MME device sends an authentication request to the HSS device.

[0118] An authentication request is sent to the designated HSS device based on the HSS device identifier to request authentication of the terminal device. The authentication request carries the IMSI and SNID of the MME device corresponding to the terminal device.

[0119] S382, MME device cannot find IMSI.

[0120] When the MME device receives the request message, it determines the GUTI based on the request message. If the triplet data corresponding to the GUTI cannot be obtained from the database, it means that the MME device cannot find the IMSI.

[0121] S392, the MME device sends an identity request to the terminal device.

[0122] If the MME device cannot determine the IMSI of the terminal device, it sends an identity request to the terminal device to request the acquisition of the terminal device's IMSI.

[0123] S393, the terminal device sends an identity response to the MME device.

[0124] After receiving the identity request, the terminal device sends an identity response to the MME device. At this time, the identity response carries the IMSI.

[0125] S394, the MME device sends an authentication request to the HSS device.

[0126] After receiving the identity response carrying the IMSI of the terminal device, the MME device sends an authentication request to the HSS device. The content of this authentication request can be found in the relevant content in S320 above, and will not be repeated here.

[0127] S395, the HSS device sends an authentication response to the MME device.

[0128] The certification process and response for HSS devices can be referenced in S330 and S340 above, and will not be repeated here.

[0129] The following is illustrative; please refer to it. Figure 4 This illustrates a schematic diagram of the application process of GUTI in a 5G scenario provided by an exemplary embodiment of this application, such as... Figure 4 As shown, the method includes the following steps.

[0130] Initial registration phase:

[0131] In S400, the terminal device encrypts SUPI to obtain SUCI.

[0132] The terminal device encrypts its own SUPI to obtain the SUCI corresponding to the SUPI.

[0133] SUCI includes the following:

[0134] (1) SUPI Type: Range 0 to 7. Used to indicate the type of SUPI hidden in SUCI. Among them, 0 represents IMSI, 1 represents Network Specific Identifier (NSI), 2 represents Global Line Identifier (GLI), 3 represents Global Cable Identifier (GCI), and 4 to 7 are reserved values.

[0135] (2) Home Network Identifier: Used to indicate the home network of the terminal device.

[0136] When the SUPI type is IMSI, the Home Network Identifier consists of the Mobile Area Code (MCC) and the Mobile Network Code (MNC), where the MNC is used to represent the home PLMN or SNPN of the mobile user.

[0137] When the SUPI type is NSI, GLI, or GCI, the home network identifier consists of a string of variable length.

[0138] (3) Routing Indicator: Consists of 1 to 4 decimal digits assigned by the network device and is used to identify the AUSF entity and UDM entity serving the terminal device.

[0139] (4) Protection Scheme Identifier: The range is 0 to 15, which represents the protection scheme defined by the empty scheme and the non-empty scheme. If the SUPI type is GLI or GCI, the empty scheme should be used.

[0140] (5) Home Network Public Key Identifier: Consists of a value between 0 and 255. It represents a public key used to identify the key used for SUPI protection. Core network devices need to find the corresponding private key to decrypt and obtain SUPI. This data field should be set to 0 only when using an empty protection scheme.

[0141] (6) Scheme Output: Consists of a variable-length string or hexadecimal number, depending on the protection scheme used. In the case of an empty scheme and SUPI type IMSI, the Scheme Output is the MSIN part of the IMSI.

[0142] S410, the terminal device sends an initial registration request to the AMF device.

[0143] When a terminal device accesses a 5G network for the first time, it sends an initial registration request to the AMF device to request access to the AMF device.

[0144] The initial registration request includes the SUCI corresponding to the terminal device.

[0145] S420, the AMF device sends an authentication request to the AUSF device.

[0146] After receiving the initial registration request, AMF will select a suitable AUSF and forward the SUCI to the AUSF. AUSF is responsible for interacting with the UDM device to complete the authentication process.

[0147] S430, the AUSF device requests the UDM to generate authentication information.

[0148] The AUSF device sends a request to the UDM device to generate an authentication vector. At this time, the AUSF device will pass the SUCI to the UDM device.

[0149] The S440 UDM device decrypts the SUCI and generates authentication information.

[0150] After receiving the SUCI, the UDM device will use the stored private key to decrypt it in order to obtain the SUPI.

[0151] Then, UDM generates an authentication vector based on SUPI. The process can be referred to in the relevant content on the generation of authentication information by HSS devices, and will not be repeated here.

[0152] S450, authentication process.

[0153] After generating the authentication vector, the UDM device sends the authentication vector to the AUSF device. Upon receiving the authentication vector, the AUSF sends RAND and AUTN to the AMF device, which then forwards them to the terminal device. The terminal device uses these parameters to perform authentication calculations and sends a response RES back to the AMF device.

[0154] The AMF device forwards the RES returned by the terminal device to the AUSF device. The AUSF device compares the RES with the XRES previously obtained from the UDM. If the comparison is successful, the authentication is successful.

[0155] Upon successful authentication, the AMF device sends the authentication result to the UDM device. Upon receiving the authentication result, the UDM device updates the authentication status of the terminal device and provides the decrypted SUPI to the AMF device. Simultaneously, the AMF device sends a registration success message to the terminal device and provides relevant network configuration information.

[0156] S460, AMF device generates GUTI.

[0157] The AMF device first randomly generates a data point as the TMSI. The TMSI and GUAMI are then used to construct the GUTI. A mapping relationship is then generated based on the GUTI and SUPI, and this mapping relationship is stored in the AMF device's database.

[0158] S470, the AMF device sends a registration success message to the terminal device.

[0159] After generating the GUTI, the AMF device sends a registration success message to the terminal device, indicating that the terminal device has successfully accessed the 5G network for the first time, and the registration success message carries the GUTI.

[0160] Subsequent stages:

[0161] S480, the terminal device sends a request message to the AMF device.

[0162] Optionally, the request message may include a periodic registration request, a service request, or a session request.

[0163] Among them, the periodic registration request is used to request the AMF device to periodically update the GUTI; the session request is used to request the core network to establish a data transmission channel.

[0164] S491, the AMF device determines the SUPI corresponding to the terminal device based on the GUTI.

[0165] When the AMF device receives the request message, it determines the GUTI based on the request message, retrieves the mapping relationship corresponding to the GUTI from the database, and retrieves the SUPI corresponding to the terminal device based on the mapping relationship.

[0166] In one mode, if the AMF device can determine the SUPI of the terminal device based on the GUTI, then S4101 is executed; if the AMF device cannot determine the SUPI of the terminal device based on the GUTI, then S4102 to S4103 are executed.

[0167] S4101, the AMF device sends an authentication request to the AUSF device.

[0168] After receiving the initial registration request, the AMF selects a suitable AUSF and forwards the SUCI to the AUSF. The AUSF device is responsible for interacting with the UDM device to complete the authentication process.

[0169] S492, AMF device cannot find SUPI.

[0170] When the AMF device receives the request message, it determines the GUTI based on the request message. If the mapping relationship corresponding to the GUTI cannot be obtained from the database, it means that the AMF device cannot determine the SUPI corresponding to the terminal device.

[0171] S4102, the AMF device sends an identity request to the terminal device.

[0172] If the AMF device cannot determine the SUPI corresponding to the terminal device, the AMF device sends an identity request to the terminal device to request the SUCI of the terminal device.

[0173] S4103, the terminal device sends an identity response to the AMF device.

[0174] After receiving the identity request, the terminal device sends an identity response carrying the SUCI to the AMF device.

[0175] S4104, the AMF device sends an authentication request to the AUSF device.

[0176] After receiving the identity response, the AMF device selects an appropriate AUSF and forwards the SUCI to the AUSF. The AUSF is responsible for interacting with the UDM device to complete the authentication process.

[0177] S4105, authentication process.

[0178] The authentication process can be referred to in S430 to S450 above, and will not be repeated here.

[0179] From the above Figure 3 and Figure 4 As can be seen, during the identity authentication process, taking a 5G scenario as an example, after authentication is completed, the AMF device generates a GUTI and needs to send the GUTI to the terminal device so that the terminal device can subsequently send a request message to the AMF, carrying the GUTI in the request message to complete the identity authentication process. On the one hand, directly transmitting the GUTI for communication poses a risk of data leakage. If an attacker intercepts the GUTI and sends it to the receiver, the receiver cannot distinguish whether the sender of the GUTI is an attacker, thus requiring the consumption of certain data resources for judgment, increasing communication overhead. On the other hand, since the GUTI is generated separately by the AMF device and can only be updated periodically under a timer mechanism, it is easy for attackers to obtain the location and behavior of the terminal device.

[0180] Based on this, embodiments of this application provide a communication method. When a first mobility management device receives an i-th first NAS message carrying an i-th first temporary identifier, it updates the i-th first counter result stored locally on the first mobility management device according to the i-th first NAS message to obtain an (i+1)-th first counter result. The (i+1)-th first counter result is then sent to a terminal device. Upon receiving the (i+1)-th first counter result, the terminal device generates an (i+1)-th first temporary identifier for the next authentication. In other words, by setting a counter and dynamically updating the counter result based on the number of NAS messages received by the mobility management device, the counter result replaces the GUTI when allocating it to the terminal device. During authentication, the GUTI is generated locally by the terminal device based on the latest received counter result and sent to the mobility management device for verification. This avoids plaintext transmission of the GUTI during allocation and ensures dynamic updates, thereby improving network communication security.

[0181] The communication method provided in this application will be described in detail below with reference to the accompanying drawings.

[0182] This is illustrative; please refer to it. Figure 5It illustrates a flowchart of the communication method interaction provided in an exemplary embodiment of this application, such as... Figure 5 As shown, the method is performed by a first mobility management device and a terminal device, and the method includes the following steps.

[0183] S510, the first mobility management device receives the i-th first NAS message.

[0184] The i-th first NAS message includes the i-th first temporary identifier corresponding to the terminal device, where i is a positive integer.

[0185] In illustrative terms, mobility management equipment (or mobility management network element) is a physical network element in the core network.

[0186] In the 4G network scenario, the first mobility management device is implemented as an MME device, and in the 5G network scenario, the first mobility management device is implemented as an AMF device.

[0187] To illustrate, in 4G or 5G network scenarios, the communication system is a layered system. The signaling (or message) type transmitted between the terminal device and the access network is radio resource control (RRC) signaling, and the signaling type transmitted between the terminal device and the mobility management device is non-access stratum (NAS) signaling.

[0188] For illustrative purposes, the NAS message received by the first mobility management device is taken as the first NAS message, and the NAS message sent by the first mobility management device is taken as the second NAS message. This distinction is made in the embodiments of this application and will not be repeated hereafter.

[0189] In some embodiments, the first NAS message includes at least one of the following: an initial registration request message; a location update request message; a handover request message; a periodic registration request message; and a service request message.

[0190] Optionally, the first NAS message includes at least one of the following message types:

[0191] (1) Initial registration request message;

[0192] This message indicates that the terminal device needs to perform an initial registration process when it first connects to the network. For details on the registration process, please refer to the above. Figure 3 and Figure 4 It has a process.

[0193] (2) Location update request message;

[0194] When a terminal device moves from its current TA to a target TA, it sends a location update request message to the first mobility management device to request re-registration of its location, thereby notifying the network device to change the location information stored by the terminal device.

[0195] (3) Switching request message;

[0196] Multiple mobility management devices are installed in the core network equipment. Taking the connection between the current terminal device and the second mobility management device as an example, the first mobility management device corresponds to the first location area, and the second mobility management device corresponds to the second location area. When the terminal device moves from the second location area to the first location area, it needs to switch from the second mobility management device to the first mobility management device to connect. At this time, the second mobility management device sends a handover request message to the first mobility management device to request the terminal device to switch to the first mobility management device.

[0197] (4) Periodic registration request messages;

[0198] Because GUTI has a timer mechanism, when the preset time interval is reached, the terminal device sends a periodic registration request to the first mobility management device, requesting the first mobility management device to update GUTI.

[0199] (5) Service request message.

[0200] Once the terminal device has successfully accessed the network, when the terminal device is in an idle or inactive state, if it needs to initiate data transmission (or establish a session), receive downlink data, or receive a paging message from a network device and respond to it, the terminal device sends a service request message to the first mobility management device.

[0201] It is worth noting that the above-mentioned message type for the first NAS message is merely an illustrative example, and the embodiments of this application do not limit it.

[0202] Therefore, depending on the message type of the first NAS message, the first NAS message can be sent from the second mobility management device to the first mobility management device, or the first NAS message can be sent from the terminal device to the first mobility management device.

[0203] Optionally, if the first mobility management device receives multiple first NAS messages, all of the multiple first NAS messages are sent by the terminal device, or, among the multiple first NAS messages, there are first NAS messages sent by the second mobility management device and also first NAS messages sent by the terminal device.

[0204] S520, the first mobility management device updates the i-th first counter result based on the i-th first NAS message to obtain the (i+1)-th first counter result.

[0205] The result of the first counter is related to the number of first NAS messages received by the first mobility management device. The (i+1)th result of the first counter is used to update the ith second temporary identifier to obtain the (i+1)th second temporary identifier. The (i+1)th second temporary identifier is used to authenticate the terminal device when the terminal device receives the (i+1)th first NAS message sent by the terminal device.

[0206] Schematic, the first mobility management device is provided with a first counter, which serves as the first NAS ID COUNT, and therefore, the counter result serves as the first NAS ID COUNT value.

[0207] Indicatively, the update mechanism of the first counter result is related to the first NAS message received by the first mobility management device. That is, when a first NAS message carrying a temporary identifier is received, the first counter result is updated; if the received NAS message does not carry the temporary identifier of the terminal device, the first counter result is not updated.

[0208] In some embodiments, the first counter result is incremented by n based on the first NAS message to obtain the (i+1)th first counter result, where n is a positive integer.

[0209] To illustrate, taking the storage of the i-th first counter result in the current first mobility management device as an example, after receiving the first NAS message, the i-th first counter result is incremented by n to obtain the (i+1)-th first counter result.

[0210] In one example, if the result of the i-th first counter is 0x00000001, and n is 1, then the result of the (i+1)-th first counter is 0x00000001. For another example, if n is 15, then the result of the (i+1)-th first counter is 0x0000000F.

[0211] Optionally, the numerical differences between any two adjacent first counter results are the same, or the numerical differences between any two adjacent first counter results are different from the numerical differences between any two adjacent first counter results. For example, the numerical difference between the first and second first counter results is 2, meaning that the second first counter result is obtained by adding 2 to the first first counter result; the numerical difference between the third and fourth first counter results is 3, meaning that the fourth first counter result is obtained by adding 3 to the third first counter result.

[0212] Indicatively, after updating the i-th first counter result to obtain the i+1-th first counter result, the i+1-th first counter result is used to authenticate the terminal device after the first mobility management device receives the i+1-th first NAS message.

[0213] In some embodiments, when the i-th first NAS message is an initial registration request message, the i-th first temporary identifier is the Subscription Hidden Identifier (SUCI) or User Identifier (IMSI) corresponding to the terminal device; when the i-th first NAS message includes any one of a handover request message, a location update request message, a periodic registration request message, or a service request message, the i-th first temporary identifier is the i-th first GUTI, which is obtained by the terminal device based on the i-th second counter result, and the i-th second counter result is related to the i-th first counter result.

[0214] In one feasible approach, if the i-th first NAS message is an initial registration request message, then the i-th first temporary identifier is the SUCI (5G network scenario) or IMSI (4G network scenario) corresponding to the terminal device.

[0215] In the above scenarios, in the first case, when the first mobility management device receives the SUCI, it forwards the SUCI to the UDM device via the AUSF device for decryption to obtain the SUPI corresponding to the SUCI. The UDM device then provides the decrypted SUPI to the first mobility management device. After obtaining the SUPI, the first mobility management device performs encryption operations based on the SUPI corresponding to the terminal device, its own GUAMI, and the (i+1)th first counter result to obtain a first encryption result. The first encryption result and the GUAMI are used to construct the (i+1)th GUTI, which serves as the (i+1)th second temporary identifier. Furthermore, based on the (i+1)th second temporary identifier and the SUPI corresponding to the terminal device, the (i+1)th mapping relationship is generated. This mapping relationship is used to authenticate the terminal device when the first mobility management device receives the (i+1)th temporary identifier carrying the (i+1)th first temporary identifier.

[0216] In the second scenario described above, when the first mobility management device receives the IMSI, after authentication is completed through the HSS device, it performs an encryption operation based on the IMSI corresponding to the terminal device, its own GUMMEI, and the (i+1)th first counter result to obtain a first encryption result. The first encryption result and the GUMMEI are then used to construct the (i+1)th GUTI, which serves as the (i+1)th second temporary identifier. Furthermore, based on the (i+1)th second temporary identifier and the IMSI corresponding to the terminal device, an (i+1)th mapping relationship is generated. This mapping relationship is used to authenticate the terminal device when the first mobility management device receives the (i+1)th temporary identifier carrying the (i+1)th first temporary identifier.

[0217] This is illustrative; please refer to it. Figure 5A This illustrates a schematic diagram of a GUTI structure provided in an exemplary embodiment of this application, as shown below. Figure 5A As shown, taking a 5G network scenario as an example, in related technologies, GUTI501 consists of GUAMI and TMSI, while in this embodiment, GUTI502 includes GUAMI and encryption calculation results. The encryption calculation results refer to the results obtained by encrypting and calculating the SUPI, GUAMI, and NAS ID COUNTER (i.e., the counter result) of the terminal device.

[0218] In one implementation, if GUTI502 is generated by the first mobility management device, then NAS ID COUNTER is the first counter result; if GUTI502 is generated by the terminal device, then NAS ID COUNTER is the second counter result.

[0219] In one feasible implementation, if the i-th first NAS message is any one of a handover request message, a location update request message, a periodic registration request message, or a service request message, then the i-th first temporary identifier is the i-th first GUTI. The i-th first GUTI is generated locally by the terminal device.

[0220] In the above scenario, taking a 5G network as an example, for a terminal device, the terminal device performs encryption calculations based on the i-th first counter result received at a historical moment, its corresponding SUPI and GUAMI, to obtain a second calculation result. The GUAMI and the second calculation result constitute the i-th GUTI, which is used as the i-th first temporary identifier.

[0221] In this embodiment, to better distinguish between them, the GUTI generated by the first mobility management device can be used as the first GUTI, and the GUTI generated by the terminal device can be used as the second GUTI.

[0222] In some embodiments, the terminal device corresponds to a permanent identifier, and the first mobility management device corresponds to a Global Mobility Management Network (GMN) identifier; the (i+1)th first counter result, the permanent identifier, and the GMN identifier are encrypted to obtain a first encryption result; the (i+1)th second temporary identifier is obtained based on the first encryption result and the GMN identifier; and the (i+1)th second temporary identifier is stored.

[0223] For illustration purposes, in the 4G network scenario, the permanent identifier is implemented as IMSI, and the global mobility management element identifier is implemented as GUMMEI; in the 5G network scenario, the permanent identifier is implemented as SUPI, and the global mobility management element identifier is implemented as GUAMI.

[0224] In a schematic example, in a 4G network scenario, after the first mobility management device updates and obtains the (i+1)th first counter result, it performs an encryption operation on the (i+1)th first counter result, IMSI, and GUMMEI to obtain the first encryption result. The GUMMEI and the first encryption result constitute the (i+1)th GUTI, which serves as the (i+1)th second temporary identifier.

[0225] In a schematic example, in a 5G network scenario, after the first mobility management device updates and obtains the (i+1)th first counter result, it performs an encryption operation on the (i+1)th first counter result, SUPI, and GUAMI to obtain the first encryption result. The GUAMI and the first encryption result constitute the (i+1)th GUTI, which serves as the (i+1)th second temporary identifier.

[0226] In some embodiments, the (i+1)th first counter result corresponds to a first timestamp, which indicates the validity period of the (i+1)th first counter result. An encryption operation is performed on the (i+1)th first counter result, the permanent identifier, the Global Mobility Management Network (GMN) element identifier, and the (i+1)th timestamp to obtain a first encryption result. Illustratively, to enhance the timeliness of the temporary identifier, a first timestamp (or time identifier) ​​is added and integrated into the encryption operation, whereby the first timestamp represents the validity period of the (i+1)th first counter result.

[0227] Optionally, the first timestamp represents a moment in time, that is, before that moment, the (i+1)th first counter result and the parameters generated by the (i+1)th first counter result are all in a valid state; or, the first timestamp is a time range, that is, within that time range, the (i+1)th first counter result and the parameters generated by the (i+1)th first counter result are all in a valid state.

[0228] In this embodiment, in the first case, under a 4G network scenario, after the first mobility management device updates and obtains the (i+1)th first counter result, it generates a first timestamp based on the current time. The (i+1)th first counter result, IMSI, GUMMEI, and the first timestamp are then encrypted to obtain a first encryption result. The GUMMEI and the first encryption result constitute the (i+1)th GUTI, which serves as the (i+1)th second temporary identifier.

[0229] In this embodiment, in the first case, under a 5G network scenario, after the first mobility management device updates and obtains the (i+1)th first counter result, it generates a first timestamp based on the current time. The (i+1)th first counter result, SUPI, GUAMI, and the first timestamp are then encrypted to obtain a first encrypted result. The GUAMI and the first encrypted result constitute the (i+1)th GUTI, which serves as the (i+1)th second temporary identifier.

[0230] In some embodiments, the encryption operation includes a hash value operation method.

[0231] To illustrate, taking a hash operation as an example of encryption, the order of data input can affect the hash value result, thus changing the temporary identifier. Therefore, in a 5G network scenario, the hash value result (i.e., the first encryption result) includes the following possibilities:

[0232] (1) The hash value operation result h1 = H (SUPI + GUAMI + the result of the (i+1)th first counter);

[0233] (2) The hash value operation result h2 = H(SUPI + the result of the (i+1)th first counter + GUAMI);

[0234] (3) The hash value operation result h3 = H (the (i+1)th first counter result + GUAMI + SUPI).

[0235] (4) The hash value operation result h4 = H (the (i+1)th first counter result + SUPI + GUAMI);

[0236] (5) The hash value operation result h5 = H (GUAMI + SUPI + the result of the (i+1)th first counter);

[0237] (6) The hash value operation result h6 = H (GUAMI + the result of the (i+1)th first counter + SUPI).

[0238] Optionally, the hash value calculation method includes any one of the SHA-256 algorithm, MD5 algorithm, or CRC32 algorithm.

[0239] S530, the first mobility management device sends the i-th second NAS message to the terminal device.

[0240] The i-th second NAS message includes the (i+1)-th first counter result.

[0241] To illustrate, after the first mobility management device updates and obtains the (i+1)th first counter result, it sends the (i)th second NAS message to the terminal device, and carries the (i+1)th first counter result in the (i)th second NAS message.

[0242] In some embodiments, the i-th second NAS message includes a first timestamp.

[0243] As an illustration, if a first timestamp is added to the temporary identifier, the i-th second NAS message also carries the first timestamp, so that after receiving the i-th second NAS message, the terminal device compares the first timestamp with the current time. If the current time does not match the first timestamp, the i-th second NAS message is directly discarded.

[0244] In one feasible approach, after receiving the first counter result, the terminal device performs a hash operation on the first counter result, GUAMI, and SUPI (or based on the first counter result, GUMMEI, and IMSI) to obtain a second operation result. Based on the second operation result and GUAMI (or based on the operation result and GUMMEI), a second GUTI is generated and sent to the first mobility management device for identification.

[0245] Therefore, when the hash value operation method executed by the terminal device is consistent with the hash value operation method executed by the first mobility management device, and the data input order is the same and the data is consistent, the second GUTI generated by the terminal device can be consistent with the first GUTI stored by the first mobility management device. Thus, the first mobility management device will send a third NAS message to the terminal device. The third NAS message includes at least one of the encryption operation method, data input order, and GUAMI (or GUMMEI) corresponding to the first mobility management device.

[0246] Optionally, the third NAS message and the second NAS message are the same message, that is, the second NAS message carries at least one of the above contents; or, the third NAS message is an independent NAS message, which is sent separately by the first mobility management device to the terminal device.

[0247] In one feasible approach, the encryption operation method is a fixed hash value operation method, or the encryption operation method includes multiple different hash value operation methods. Therefore, when the first mobility management device updates the hash value operation method, it carries the updated hash value operation method in the third NAS message. For example, after the first mobility management device sends the i-th second NAS message to the terminal device, it sends the n-th third NAS message to the terminal device. The n-th third NAS message includes the SHA-256 algorithm. After the first mobility management device sends the (i+3)-th second NAS message to the terminal device, it sends the (n+1)-th third NAS message to the terminal device. The (n+1)-th third NAS message includes the CRC32 algorithm, where n is a positive integer.

[0248] One example provides a detailed explanation of how temporary identifiers are generated for terminal devices. Please refer to the provided illustration. Figure 6 It illustrates an interactive flowchart of a temporary identifier allocation method provided in an exemplary embodiment of this application, that is, after S530, it also includes S540 and S550, as follows. Figure 6 As shown, the method includes the following steps.

[0249] S540, if the terminal device updates the i-th second counter result based on the i+1 first counter result when the i+1 first counter result is greater than the i-th second counter result and the difference between the i+1 first counter result and the i-th second counter result meets the preset difference condition, the terminal device obtains the i+1 second counter result.

[0250] The terminal device stores the i-th second counter result, which is related to the number of first NAS messages received by the terminal device.

[0251] As an illustration, the terminal device has a second counter stored locally, which serves as the second NAS ID COUNT, and the counter result corresponding to the second counter is used as the second NAS ID COUNT value.

[0252] The result of the second counter is related to the first NAS message received by the terminal device. For example, when the terminal device receives the first NAS message, the result of the second counter is incremented by 1 to obtain the updated result of the second counter.

[0253] In one scenario, when the first mobility management device receives a first NAS message from the terminal device, the first counter in the first mobility management device will be updated, and the updated first counter will be sent to the terminal device as a second NAS message. If the terminal device receives the second NAS message, the second counter in the terminal device will be updated. At this time, if the counting methods of the first counter and the second counter are the same, then the update status of the first counter will be consistent with the update status of the second counter.

[0254] In another scenario, when the first mobility management device receives a first NAS message from the terminal device, the first counter in the first mobility management device will be updated, and the updated first counter will be sent to the terminal device as a second NAS message. If the terminal device does not receive the second NAS message, the second counter in the terminal device will not be updated. In this case, the update status of the first counter will differ from that of the second counter. Therefore, if the terminal device generates a second temporary identifier based solely on the update result of the second counter, the second temporary identifier will be different from the first temporary identifier stored in the first mobility management device, thus, authentication cannot be completed.

[0255] Therefore, when the terminal device receives the i-th second NAS message, it obtains the (i+1)-th first counter in the i-th second NAS message, compares the result of the (i+1)-th first counter with the result of the i-th second counter, and if the result of the (i+1)-th first counter is greater than the result of the i-th second counter and the difference reaches a preset difference threshold, it indicates that the terminal device has a first NAS message that has not been received. Therefore, the result of the (i+1)-th first counter replaces the result of the i-th second counter to obtain the result of the (i+1)-th second counter, thereby achieving synchronous updates of the first counter result and the second counter result.

[0256] S550, the terminal device updates the i-th first temporary identifier based on the i+1-th second counter result to obtain the i+1-th first temporary identifier.

[0257] Indicatively, after obtaining the (i+1)th second counter result, the terminal device performs encryption operations on the permanent identifier corresponding to the terminal device, the (i+1)th second counter result, and the Global Mobility Management Network element identifier corresponding to the first mobility management device to obtain a second encryption result. The second encryption result and the Global Mobility Management Network element identifier constitute a second temporary identifier, which serves as the (i+1)th first temporary identifier corresponding to the terminal device.

[0258] In some embodiments, the first counter result includes multiple bits, wherein the multiple bits include a first bit; the first mobility management device is further configured to, when the other bits in the first counter result, excluding the first bit, meet the overflow condition, set the first bit to 1 and reset the other bits to obtain the reset result corresponding to the first counter result, as the (i+1)th first counter result.

[0259] Indicatively, the result of the first counter is a 32-bit unsigned positive number with the structure: NAS ID COUNT value = most significant bit (OVERFLOW FLAG, OVF) + actual bit (ACTUAL_COUNTER).

[0260] The highest bit occupies 1 bit, and the actual bits occupy 31 bits.

[0261] The most significant bit is used to determine the overflow status of the first counter result. When the most significant bit is 1, it indicates that the first counter result has overflowed, meaning the current first counter result has reached its maximum countable value. For example, in hexadecimal, if OVF=1, the actual bit is 0xFFFFFFFF. When the most significant bit is 0, it indicates that the first counter result has not overflowed, meaning the current first counter result has not reached its maximum countable value.

[0262] In this embodiment, taking the first bit as the highest bit as an example, if other bits (that is, actual bits) have reached the maximum value of the count, it indicates that the other bits meet the overflow condition. At this time, the first bit is assigned the value 1 (i.e., OVF=1), and the other bits are reset from 0xFFFFFFFF to 0x00000000, and the reset results corresponding to the other bits are obtained. The set result and the reset result corresponding to the first bit are used as the (i+1)th first counter result.

[0263] Indicatively, when the (i+1)th first counter result is 0x00000000, when the terminal device receives the (i+1)th first counter result and detects OVF=1 based on the (i+1)th first counter result, regardless of whether other bits in the second counter result meet the overflow condition, the terminal device resets the other bits in the second counter result to obtain 0x00000000 and sets OVF to 0, generating the (i+1)th second counter result.

[0264] Indicatively, the terminal device updates the i-th first temporary identifier based on the i+1-th second counter result to obtain the i+1-th first temporary identifier, and sends the i+1-th first NAS message carrying the i+1-th first temporary identifier to the first mobility management device.

[0265] In some embodiments, the (i+1)th first NAS message is sent to the first mobility management device. The (i+1)th first NAS message includes the (i+1)th first temporary identifier. The terminal device is authenticated based on the (i+1)th first temporary identifier to obtain the authentication result corresponding to the terminal device. If the authentication result meets the success condition, the first bit is set to 0 and the other bits are updated to obtain the (i+2)th first counter result.

[0266] Indicatively, when the first mobility management device receives the (i+1)th first NAS message sent by the terminal device, it obtains the (i+1)th first temporary identifier from the (i+1)th first NAS message. Based on the (i+1)th first temporary identifier, it searches for the corresponding mapping relationship in the database. If a mapping relationship corresponding to the (i+1)th first temporary identifier exists in the database, it obtains the permanent identifier corresponding to the terminal device based on the mapping relationship. Based on the permanent identifier, it performs identity authentication on the terminal device. If the identity authentication is successful, it modifies the OVF bit in the second counter result from 1 to 0 and increments the other bits by 1 to obtain 0x00000001. Thus, OVF=0 and the other bits are 0x00000001 as the (i+2)th first counter result.

[0267] This is illustrative; please refer to it. Figure 7 This illustration shows a schematic diagram of a temporary identifier generation method provided in an exemplary embodiment of this application, taking a 5G network scenario as an example, such as... Figure 7 As shown, the method includes the following steps.

[0268] Initial registration phase:

[0269] In S710, the terminal device encrypts SUPI to obtain SUCI.

[0270] The terminal device encrypts its own SUPI to obtain the SUCI corresponding to the SUPI.

[0271] The terminal device stores a second counter. At this time, the corresponding result of the second counter is the first result of the second counter.

[0272] The result of the first second counter is represented by 0x00000001.

[0273] S720, the terminal device sends an initial registration request to the AMF device.

[0274] When a terminal device accesses a 5G network for the first time, it sends an initial registration request to the AMF device to request access to the AMF device.

[0275] The initial registration request includes the SUCI corresponding to the terminal device.

[0276] The AMF device stores a first counter. Before receiving the initial registration request, the first counter has the first result, represented by 0x00000001.

[0277] S730, the AMF device sends an authentication request to the AUSF device.

[0278] After receiving the initial registration request, AMF will select a suitable AUSF and forward the SUCI to the AUSF. AUSF is responsible for interacting with the UDM device to complete the authentication process.

[0279] S740, the AUSF device requests the UDM to generate authentication information.

[0280] The AUSF device sends a request to the UDM device to generate an authentication vector. At this time, the AUSF device will pass the SUCI to the UDM device.

[0281] The S750 UDM device decrypts the SUCI and generates authentication information.

[0282] After receiving the SUCI, the UDM device decrypts it using the stored private key to obtain the SUPI. Furthermore, the UDM generates an authentication vector based on the SUPI.

[0283] The authentication vector mainly includes four components: Random Challenge (RAND), Authentication Token (AUTN), Expected Response (XRES), and Access Security Management Entity Key (KASME).

[0284] S760, authentication process.

[0285] After generating the authentication vector, the UDM device sends the authentication vector to the AUSF device. Upon receiving the authentication vector, the AUSF sends RAND and AUTN to the AMF device, which then forwards them to the terminal device. The terminal device uses these parameters to perform authentication calculations and sends a response message RES to the AMF device.

[0286] The AMF device forwards the RES returned by the terminal device to the AUSF device. The AUSF device compares the RES with the XRES previously obtained from the UDM. If the comparison is successful, the authentication is successful.

[0287] Once authentication is successful, the AMF device will send the authentication result to the UDM device. After receiving the authentication result, the UDM device will update the authentication status of the terminal device and provide the decrypted SUPI to the AMF device.

[0288] S770, the AMF device updates to obtain the second first counter result and generates the first GUTI.

[0289] When the AMF device receives SUPI, it first increments the first first counter result by 1, obtaining 0x00000002, which is then used as the second first counter result.

[0290] Next, the GUAMI corresponding to the AMF device is generated, and the SUPI, GUAMI and the second first counter result are hashed to obtain the first operation result h1.

[0291] Next, GUAMI and h1 are combined to form the first first GUTI, and the first mapping result MAP1(SUPI, GUTI) is generated and stored based on the SUPI of the terminal device and the first first GUTI.

[0292] S780, the AMF device sends the second first counter result to the terminal device.

[0293] After generating the first mapping result, the AMF device sends a registration success message to the terminal device, indicating that the terminal device has successfully accessed the 5G network for the first time, and the registration success message also carries the second first counter result.

[0294] S790, the terminal device receives the second result of the first counter and generates the second GUTI.

[0295] After receiving the second result of the first counter, the terminal device first determines the size between the second result of the first counter and the first result of the second counter. Since the second result of the first counter is greater than the first result of the second counter, the first result of the second counter is updated to the second result of the first counter, which is then used as the second result of the second counter.

[0296] Perform a hash operation on SUPI, GUAMI, and the second result of the first counter to obtain the second result h2.

[0297] Next, GUAMI and h2 are combined to form the first second GUTI, which is used to send the first second GUTI to the AMF device during the next NAS message transmission. After receiving the first second GUTI, the AMF device searches for the corresponding mapping relationship based on the first second GUTI. If the first first GUTI is consistent with the second GUTI, then MAP1(SUPI, GUTI) can be used as the mapping result corresponding to the first second GUTI. Thus, the AMF device can obtain the SUPI corresponding to the terminal device for its identity authentication.

[0298] This is illustrative; please refer to it. Figure 8 This illustrates an overflow process diagram provided by an exemplary embodiment of this application, such as... Figure 8 As shown, taking a 5G network scenario as an example, the method includes the following steps.

[0299] S810, the terminal device sends the m-th first NAS message to the AMF device.

[0300] When the AMF device receives the m-th first NAS message, it increments the m-th first counter result by 1. If the result after counting is 0xFFFFFFFF, the highest bit (OVF bit) of the first counter result is set to 1.

[0301] S820, the AMF device resets the m-th first counter result and obtains the reset result.

[0302] When the AMF device detects that the OVF bit of the first counter result is 1, it resets the first counter result to get 0x00000000. As the reset result, OVF=1 and 0x00000001 are used as the (m+1)th first counter result.

[0303] S830, the AMF device sends the m-th second NAS message to the terminal device.

[0304] The AMF device sends the m-th second NAS message to the terminal device, and the m+1-th first counter result is carried in the m-th second NAS message.

[0305] S840, the terminal device resets the m-th second counter result and generates the (m+1)-th second GUTI.

[0306] After receiving the m-th second NAS message, the terminal device detects that OVF=1 in the (m+1)-th first counter result. At this time, it resets the other 31 bits in the m-th second counter result except for the OVF bit, and obtains 0x00000000 as the reset result. Based on the reset result, it generates the (m+1)-th second GUTI.

[0307] S850, the terminal device sends the (m+1)th first NAS message to the AMF device.

[0308] The terminal device sends the (m+1)th first NAS message to the AMF device, wherein the (m+1)th first NAS message carries the (m+1)th second GUTI.

[0309] S860, AMF device resets OVF bit to 0.

[0310] After receiving the (m+1)th first NAS message, the AMF device authenticates the terminal device based on the (m+1)th second GUTI. When the authentication is successful, it detects the reset result 0x00000000 in the (m+1)th second GUTI, resets the OVF bit to 0, and increments the count of 0x00000000 by 1 in the first counter result to obtain 0x00000001. It then uses OVF=0 and 0x00000001 as the result of the (m+2)th first counter, and repeats this process.

[0311] Figure 9 This is a schematic diagram of the hardware structure of a communication device according to an embodiment of this application. Figure 9 As shown, the communication device 4000 includes: at least one processor 4001 ( Figure 9 (Only one is shown in the diagram), memory 4002, and computer program 4003 stored in memory 4002 and executable on at least one processor 4001, wherein processor 4001 executes computer program 4003 to implement the steps in any of the above methods.

[0312] In one implementation, the communication device 4000 is a user equipment used to perform the steps executed by the user equipment in the above method.

[0313] In another implementation, the communication device 4000 is a network device used to perform the steps executed by the core network device in the above method.

[0314] Those skilled in the art will understand that Figure 9 This is merely an example of a communication device and does not constitute a limitation on communication devices. In practice, communication devices may include more or fewer components than those shown in the illustration, or combinations of certain components, or different components. For example, they may also include input / output devices, network access devices, etc.

[0315] Processor 4001 can be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.

[0316] In some embodiments, memory 4002 may be an internal storage unit of the communication device 4000, such as a hard disk or memory of the communication device 4000. In other embodiments, memory 4002 may be an external storage device of the communication device 4000, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the communication device 4000. Optionally, memory 4002 may include both internal and external storage units of the communication device 4000. Memory 4002 is used to store operating systems, applications, boot loaders, data, and other programs, such as program code for computer programs. Memory 4002 may also be used to temporarily store data that has been output or will be output.

[0317] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.

[0318] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0319] This application also provides a communication device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor. When the processor executes the computer program, it implements the steps in any of the above method embodiments.

[0320] The communication device can be a user equipment, used to execute the steps performed by the user equipment; the communication device can also be a network device, used to execute the steps performed by the network device.

[0321] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps described in the various method embodiments above.

[0322] This application also provides a chip including a processor, which is used to read and execute a computer program stored in a memory, and when the computer program is executed by the processor, it can implement the steps in the above-described method embodiments.

[0323] Optionally, the chip also includes a memory electrically connected to the processor.

[0324] Optionally, the chip may also include a communication interface.

[0325] This application also provides a computer program product that, when executed by a processor, can implement the steps in the various method embodiments described above.

[0326] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying the computer program code to a photographic device / user equipment, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunication signals.

[0327] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0328] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0329] In the embodiments provided in this application, it should be understood that the disclosed apparatus / communication devices and methods can be implemented in other ways. For example, the apparatus / communication device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0330] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0331] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0332] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0333] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0334] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0335] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0336] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A communication method, characterized in that, The method is applied to a first mobility management device, and the method includes: Receive the i-th first non-access stratum NAS message, where i is a positive integer; If the i-th first NAS message includes the i-th first temporary identifier corresponding to the terminal device, the i-th first counter result is updated based on the i-th first NAS message to obtain the (i+1)-th first counter result. The first counter result is related to the number of first NAS messages received by the first mobility management device. The (i+1)-th first counter result is used to update the i-th second temporary identifier stored by the first mobility management device to obtain the (i+1)-th second temporary identifier. The (i+1)-th second temporary identifier is used to authenticate the terminal device when the (i+1)-th first NAS message sent by the terminal device is received. Send the i-th second NAS message to the terminal device. The i-th second NAS message includes the (i+1)-th first counter result, but does not include the i-th second temporary identifier.

2. The method according to claim 1, characterized in that, The step of updating the i-th first counter result based on the i-th first NAS message includes: Based on the i-th first NAS message, the i-th first counter result is incremented by n to obtain the (i+1)-th first counter result, where n is a positive integer.

3. The method according to claim 1, characterized in that, The terminal device has a corresponding permanent identifier, and the first mobility management device has a corresponding Global Mobility Management Network element identifier; The method further includes: The (i+1)th first counter result, the permanent identifier, and the Global Mobility Management Network element identifier are encrypted to obtain the first encryption result; The (i+1)th second temporary identifier is obtained based on the first encryption result and the Global Mobility Management Network element identifier; Store the (i+1)th second temporary identifier.

4. The method according to claim 3, characterized in that, The (i+1)th first counter result corresponds to a first timestamp, which is used to indicate the valid time corresponding to the (i+1)th first counter result; The method further includes: The first encryption result is obtained by performing encryption operations on the (i+1)th first counter result, the permanent identifier, the Global Mobility Management Network element identifier, and the first timestamp.

5. The method according to claim 4, characterized in that, The i-th second NAS message includes the first timestamp.

6. The method according to claim 3 or 4, characterized in that, The encryption operation includes hash value calculation.

7. The method according to any one of claims 1 to 5, characterized in that, The first NAS message includes at least one of the following: Initial registration request message; Location update request message; Switch request message; Periodic registration request messages; Service request message.

8. The method according to claim 7, characterized in that, When the i-th first NAS message is the initial registration request message, the i-th first temporary identifier is the Subscription Hidden Identifier (SUCI) or User Identifier (IMSI) corresponding to the terminal device; When the i-th first NAS message includes any one of the handover request message, the location update request message, the periodic registration request message, or the service request message, the i-th first temporary identifier is the i-th first globally unique temporary identifier (GUTI), the i-th first GUTI is the GUTI stored by the terminal device, the terminal device stores the i-th second counter result, and the i-th second counter result is related to the i-th first counter result.

9. The method according to any one of claims 1 to 5, characterized in that, The first counter result includes multiple bits, wherein the multiple bits include a first bit; The method further includes: If all bits in the first counter result except the first bit meet the overflow condition, the first bit is set to 1 and the other bits are reset to obtain the reset result corresponding to the first counter result, which is used as the (i+1)th first counter result.

10. The method according to claim 9, characterized in that, After sending the i-th second NAS message to the terminal device, the method further includes: Receive the (i+1)th first NAS message sent by the terminal device, wherein the (i+1)th first NAS message includes the (i+1)th first temporary identifier; The first bit is set to 0 based on the (i+1)th first temporary identifier, and the other bits are updated based on the (i+1)th first temporary identifier to obtain the (i+2)th first counter result.

11. A communication method, characterized in that, The method is applied to a terminal device, and the method includes: Send the i-th first NAS message to the first mobility management device, where i is a positive integer; If the i-th first NAS message includes the i-th second temporary identifier corresponding to the terminal device, the i-th second NAS message sent by the first mobility management device is received. The i-th second NAS message includes the (i+1)-th first counter result. The (i+1)-th first counter result is obtained by the first mobility management device updating the i-th first counter result based on the i-th first NAS message. The first counter result is related to the number of first NAS messages received by the first mobility management device. The first mobility management device updates the first temporary identifier based on the (i+1)th first counter result to obtain the (i+1)th first temporary identifier. The first mobility management device is used to authenticate the terminal device based on the (i+1)th first temporary identifier when it receives the (i+1)th first NAS message sent by the terminal device.

12. The method according to claim 11, characterized in that, The first mobility management device is used to increment the first counter result by one based on the first NAS message to obtain the (i+1)th first counter result.

13. The method according to claim 11, characterized in that, The terminal device has a corresponding permanent identifier, and the first mobility management device has a corresponding Global Mobility Management Network element identifier; The first mobility management device is used to perform encryption operations on the (i+1)th first counter result, the permanent identifier, and the global mobility management network element identifier to obtain a first encryption result; obtain an (i+1)th second temporary identifier based on the first encryption result and the global mobility management network element identifier; and store the (i+1)th second temporary identifier.

14. The method according to claim 13, characterized in that, The (i+1)th first counter result corresponds to a first timestamp, which is used to indicate the valid time corresponding to the (i+1)th first counter result; The first mobility management device is used to perform encryption operations on the (i+1)th first counter result, the permanent identifier, the global mobility management network element identifier, and the first timestamp to obtain the first encryption result.

15. The method according to claim 14, characterized in that, The i-th second NAS message includes the first timestamp.

16. The method according to claim 15, characterized in that, The method further includes: Get the current timestamp; If the current timestamp fails to match the first timestamp, the i-th second NAS message is discarded.

17. The method according to claim 13 or 14, characterized in that, The encryption operation includes hash value calculation.

18. The method according to any one of claims 11 to 16, characterized in that, The terminal device stores the i-th second counter result, which is related to the number of first NAS messages received by the terminal device. The step of updating the i-th first temporary identifier based on the (i+1)-th first counter result to obtain the (i+1)-th first temporary identifier includes: If the (i+1)th first counter result is greater than the ith second counter result, and the difference between the (i+1)th first counter result and the ith second counter result meets a preset difference condition, the ith second counter result is updated based on the (i+1)th first counter result to obtain the (i+1)th second counter result. The first temporary identifier is updated based on the (i+1)th second counter result to obtain the (i+1)th first temporary identifier.

19. The method according to any one of claims 11 to 16, characterized in that, The first NAS message includes at least one of the following: Initial registration request message; Periodic registration request messages; Location update request message; Service request message.

20. The method according to claim 19, characterized in that, When the i-th first NAS message is the initial registration request message, the i-th first temporary identifier is the SUCI or IMSI corresponding to the terminal device; When the i-th first NAS message includes any one of the location update request message, the periodic registration request message, or the service request message, the i-th first temporary identifier is the i-th first GUTI, the i-th first GUTI is the GUTI stored by the terminal device, the terminal device stores the i-th second counter result, and the i-th second counter result is related to the i-th first counter result.

21. The method according to any one of claims 11 to 16, characterized in that, The first counter result includes multiple bits, wherein the multiple bits include a first bit; The first mobility management device is further configured to, when the other bits in the first counter result, excluding the first bit, meet the overflow condition, set the first bit to 1 and reset the other bits to obtain the reset result corresponding to the first counter result, which is used as the (i+1)th first counter result.

22. The method according to claim 21, characterized in that, After receiving the i-th second NAS message sent by the first mobility management device, the method further includes: The first mobility management device sends the (i+1)th first NAS message, which includes the (i+1)th first temporary identifier. The first mobility management device sets the first bit to 0 based on the (i+1)th first temporary identifier and updates the other bits based on the (i+1)th first temporary identifier to obtain the (i+2)th first counter result.

23. A communication method, characterized in that, The method is applied to a second mobility management device, and the method includes: Send the i-th first NAS message to the first mobility management device, wherein the i-th first NAS message includes the i-th first temporary identifier corresponding to the terminal device, where i is a positive integer; Wherein, the first mobility management device is used to send an i-th second NAS message to the terminal device when the i-th first NAS message includes an i-th first temporary identifier corresponding to the terminal device. The i-th second NAS message includes an (i+1)-th first counter result. The (i+1)-th first counter result is obtained by the first mobility management device updating the i-th first counter result based on the i-th first NAS message. The first counter result is related to the number of first NAS messages received by the first mobility management device. The terminal device is used to update the i-th first temporary identifier based on the (i+1)-th first counter result to obtain the (i+1)-th first temporary identifier. The first mobility management device is used to authenticate the terminal device based on the (i+1)-th first temporary identifier when it receives the (i+1)-th first NAS message sent by the terminal device.

24. The method according to claim 23, characterized in that, The first NAS message is a switchover request message.

25. A communication device, characterized in that, The device includes: The receiving unit is used to receive the i-th first non-access stratum (NAS) message, where i is a positive integer; An update unit is configured to update the i-th first counter result based on the i-th first NAS message when the i-th first NAS message includes the i-th first temporary identifier corresponding to the terminal device, to obtain the (i+1)-th first counter result. The first counter result is related to the number of first NAS messages received by the first mobility management device. The (i+1)-th first counter result is used to update the i-th first temporary identifier to obtain the (i+1)-th first temporary identifier. The (i+1)-th first temporary identifier is used to authenticate the terminal device when the (i+1)-th first NAS message sent by the terminal device is received. The sending unit is configured to send the i-th second NAS message to the terminal device, wherein the i-th second NAS message includes the (i+1)-th first counter result.

26. A communication device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1 to 10, or any one of claims 11 to 22, or any one of claims 23 to 24.

27. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 10, or any one of claims 11 to 22, or any one of claims 23 to 24.

Citation Information

Patent Citations

  • Key refresh for small-data traffic

    CN113273234A

  • Method and device for processing non-access stratum context

    CN114258096A