Communication method and device, storage medium and computer program product
By controlling the terminal to perform initial registration and update the AKMA key when the route identifier is updated, the problem of AKMA service interruption caused by A-KID change is solved, and the reliability of AKMA service is improved.
Patent Information
- Application Number
- CN202410483152.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-19
- Publication Date
- 2025-10-24
AI Technical Summary
Since the A-KID on the terminal side changes as the routing identifier is updated, the normal use of the AKMA service is affected, resulting in service interruption or failure.
When the route identifier is updated, an initial registration request is sent from the UDM network element to the AMF network element, triggering the terminal to perform initial registration, thereby updating the AKMA key and maintaining the consistency of the A-KID authentication context.
This avoids interruptions or failures in the AKMA service, thus improving its reliability.
Smart Images

Figure CN120835286A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and particularly relates to a communication method, device, storage medium and computer program product. BACKGROUND
[0002] With the rapid development of communication technology, communication security problems are paid more and more attention by users. At present, a terminal can support an authentication and key management for application (AKMA) service, and through the service, authenticated communication can be established between the terminal and an application function (AF), and the communication security is improved.
[0003] Based on the AKMA process, the terminal side and the network side can each generate AKMA keys and corresponding AKMA key temporary identifiers (A-KIDs). The A-KIDs can also be referred to as authentication and key management-key temporary identifiers. Since the A-KIDs of the terminal side are usually generated based on routing indicators (RIDs), when the RIDs are updated, the A-KIDs of the terminal side will change, thereby affecting the normal use of the AKMA service. SUMMARY
[0004] Embodiments of the present disclosure provide a communication method, device, storage medium and computer program product for improving the reliability of the AKMA service.
[0005] To achieve the above object, the present disclosure adopts the following technical solutions:
[0006] In a first aspect, the present disclosure provides a communication method applied to a UDM network element, and the method comprises the following steps:
[0007] In the case of parameter update of the terminal, obtaining authentication and key management for application (AKMA) service data and a parameter update reason of the terminal;
[0008] In the case that the AKMA service data indicates that the terminal subscribes to the AKMA service and the parameter update reason of the terminal is routing indicator update, sending initial registration request information of the terminal to an access and mobility management function (AMF) network element, the initial registration request information being used to request the terminal to perform initial registration.
[0009] In a second aspect, the present disclosure provides another communication method applied to a terminal, and the method comprises the following steps:
[0010] receive initial registration request information sent by an AMF network element, the initial registration request information being sent by a UDM network element in a case where a terminal's parameter update, the terminal subscribing to an AKMA service, and a terminal's parameter update reason being routing identifier update;
[0011] perform initial registration.
[0012] In a third aspect, the present disclosure provides another communication method, applied to an AMF network element, the method comprising:
[0013] receive initial registration request information sent by a UDM network element in a case where a terminal's parameter update, the terminal subscribing to an AKMA service, and a terminal's parameter update reason being routing identifier update;
[0014] send initial registration request information to a terminal.
[0015] In a fourth aspect, the present disclosure provides a communication device, comprising:
[0016] an obtaining module configured to, in a case where a terminal's parameter update, obtain AKMA service data of an application and a terminal's parameter update reason;
[0017] a sending module configured to, in a case where the AKMA service data indicates that the terminal subscribes to an AKMA service and a terminal's parameter update reason is routing identifier update, send initial registration request information of the terminal to an AMF network element, the initial registration request information being used to request the terminal to perform initial registration.
[0018] In a fifth aspect, the present disclosure provides another communication device, comprising:
[0019] a receiving module configured to receive initial registration request information sent by an AMF network element, the initial registration request information being sent by a UDM network element in a case where a terminal's parameter update, the terminal subscribing to an AKMA service, and a terminal's parameter update reason being routing identifier update;
[0020] a processing module configured to perform initial registration.
[0021] In a sixth aspect, the present disclosure provides another communication device, comprising:
[0022] a receiving module configured to, in a case where a terminal's parameter update, the terminal subscribing to an AKMA service, and a terminal's parameter update reason being routing identifier update, receive initial registration request information sent by a UDM network element;
[0023] a sending module configured to send initial registration request information to a terminal.
[0024] In a seventh aspect, the present disclosure provides a communication device, comprising: a memory and a processor; the memory and the processor are coupled; the memory is configured to store instructions executable by the processor; and the processor executes the instructions to perform the communication method provided in the first aspect, the second aspect, or the third aspect.
[0025] In an eighth aspect, the present disclosure provides a computer-readable storage medium, which stores a computer program, and when the computer program is executed by a processor, the computer program implements a method for performing the communication method provided in the first aspect, the second aspect, or the third aspect.
[0026] In a ninth aspect, the present disclosure provides a computer program product comprising computer instructions, and when the computer instructions are executed by a processor, the computer instructions implement a method for performing the communication method provided in the first aspect, the second aspect, or the third aspect.
[0027] Based on the technical solutions provided by the present disclosure, in the case where it is determined that the cause of the parameter update of the terminal is the routing identifier update and the terminal subscribes to AKMA, the terminal performs initial registration, thereby triggering the update of the AKMA key. Since the A-KID on the terminal side also changes due to the routing identifier update, the AKMA service is affected. Based on the technical solutions provided by the present disclosure, the terminal performs initial registration when it is determined that the routing identifier is updated, thereby triggering the update of the AKMA key. In this way, the authentication context after the change of the A-KID can remain consistent, thereby enabling the authentication and key management according to the A-KID, avoiding the interruption or failure of the AKMA service, and improving the reliability of the AKMA service. BRIEF DESCRIPTION OF DRAWINGS
[0028] The accompanying drawings are included to provide a further understanding of the technical solutions of the present disclosure, and constitute a part of the specification, and are used together with the embodiments of the present disclosure to explain the technical solutions of the present disclosure, and do not constitute a limitation on the technical solutions of the present disclosure.
[0029] Figure 1 A network architecture diagram of AKMA provided by an embodiment of the present disclosure;
[0030] Figure 2 A process diagram for updating the parameters of a terminal through a control plane of a UDM provided by an embodiment of the present disclosure;
[0031] Figure 3 A flow diagram of a communication method provided by an embodiment of the present disclosure;
[0032] Figure 4 A flow diagram of another communication method provided by an embodiment of the present disclosure;
[0033] Figure 5An AKMA key architecture diagram provided by an embodiment of the present disclosure;
[0034] Figure 6 A flowchart of another communication method provided by an embodiment of the present disclosure;
[0035] Figure 7 An interaction diagram of a communication method provided by an embodiment of the present disclosure;
[0036] Figure 8 A schematic diagram of another process for updating parameters of a terminal through a control plane of a UDM provided by an embodiment of the present disclosure;
[0037] Figure 9 A composition diagram of a communication device provided by an embodiment of the present disclosure;
[0038] Figure 10 A composition diagram of a communication device provided by an embodiment of the present disclosure;
[0039] Figure 11 A composition diagram of a communication device provided by an embodiment of the present disclosure;
[0040] Figure 12 A structure diagram of a communication device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0041] The technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present disclosure.
[0042] Unless the context clearly requires otherwise, throughout the description and the claims, the words "comprise", "comprising", and the like are to be construed in an open, inclusive sense as "including, but not limited to." As used throughout the description and the claims, the term "one embodiment," "some embodiments," "an exemplary embodiment," "example," "specific example," or "some examples" means that a particular feature, structure, material, or characteristic is included in at least one embodiment or example of the disclosure, but not necessarily all embodiments or examples. The appearance of the phrases "in one embodiment" or "in some embodiments" in various places in the specification are not necessarily all referring to the same embodiment or example. Furthermore, the particular features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0043] The terms "first", "second", etc. are used only to describe the purpose and are not to be construed as indicating or implying relative importance or a specific number of the technical features indicated. Thus, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the disclosure, the meaning of "a plurality of" is two or more, unless otherwise specified.
[0044] In the embodiments of the disclosure, the words "exemplary" or "for example" are used to mean serving as an example, instance, or illustration. Any embodiment or design described herein as "exemplary" or "for example" should not be construed as being more preferred or advantageous than other embodiments or designs. Rather, the exemplary or example embodiments are presented for purposes of illustration.
[0045] In addition, the use of "based on" means open and inclusive, as the process, step, calculation, or other action based on one or more stated conditions or values can be based on additional conditions or values beyond those stated.
[0046] The AKMA service is an important service for ensuring application security and reliability. This service covers various aspects such as user identity verification, access control, and key generation, storage, distribution, update, and destruction. Among them, the AKMA service can ensure that only authorized users can access the application by verifying the identity of the user, and can also be used to generate and manage keys for encrypting and decrypting data. In addition, an AKMA anchor function (AAnF) can be introduced in the network architecture to generate session keys between the UE and the AF, as well as the corresponding security context. Since the A-KID usually needs to be generated based on the Routing Indicator (RID), when the RID is updated, the A-KID on the terminal side will change accordingly, so that the network side cannot correctly locate the AAnF or the unified data management (UDM), and cannot find the AKMA security context of the terminal, thereby affecting the AKMA service.
[0047] Therefore, the present disclosure provides a communication method applied to a UDM network element, which comprises: in the case of parameter update of a terminal, obtaining AKMA service data of an application and a parameter update reason of the terminal; in the case that the AKMA service data indicates that the terminal subscribes to the AKMA service and the parameter update reason of the terminal is routing indicator update, sending initial registration request information of the terminal to an access and mobility management function (AMF) network element, the initial registration request information being used to request the terminal to perform initial registration.
[0048] In this way, the terminal can be controlled to perform initial registration when the routing indicator is updated, thereby triggering the update of the AKMA key, so that the authentication context after the change of the A-KID can remain consistent, thereby enabling authentication and key management according to the A-KID, and avoiding interruption or failure of the AKMA service.
[0049] The technical solution provided by the embodiments of the present disclosure can be applied to various mobile communication networks, such as a 5th generation mobile networks (5G) communication network, a new radio (NR) mobile communication network using 5G, an internet of things (loT), a narrow band internet of things (NB-loT), a long term evolution (LTE) communication network, a future mobile communication network such as 6G, or a variety of communication fusion systems, etc., and the embodiments of the present disclosure are not limited thereto.
[0050] For example,Figure 1 As shown, the present disclosure provides a network architecture diagram of AKMA. The network architecture includes at least a terminal, an access network (AN), a core network and a data service network. Compared with the traditional 5th Generation Mobile Networks (5G) architecture, a new network function (NF) network element, AAnF network element, is added. The AAnF can be used to generate a session key between the terminal and the AF network element, and maintain the corresponding security context. For example, the AAnF network element can be used to support AKMA anchor key (K AKMA ), and generate an application key (K AF ). Moreover, the AAnF network element can be a single NF network element, or can be deployed with other NF network elements. It can be understood that, Figure 1 This is only an illustrative description and does not limit the present disclosure.
[0051] The terminal can also be referred to as a terminal device, a user equipment (UE), etc., and is a device with wireless transceiver function. It can communicate with one or more core networks (CNs) through an access network ((Radio) access network (R)AN) access network device. The terminal can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; it can also be deployed on water (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons and satellites, etc.). The terminal can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical treatment, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc.
[0052] A (radio) access network ((R)AN) is used to manage radio resources and provide access services for terminals. The access network device (for example, a RAN device or an AN device) provided by the present disclosure is a device that provides wireless communication functions for terminal devices, and can also be referred to as a network device. For example, the access network device can include a next generation node base station (gNB) in a 5G system, an evolved node B (eNB) in a long term evolution (LTE), a radio network controller (RNC), a node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (for example, a home evolved node B, or a home node B, HNB), a base band unit (BBU), a transmitting and receiving point (TRP), a transmitting point (TP), a pico base station device, a mobile switching center, or a network device in a future network, and the like. In systems using different wireless access technologies, the names of devices with access network device functions can be different. The present disclosure does not limit the specific type of access network device.
[0053] An access and mobility management function (AMF) can also be referred to as an AMF network element, an AMF network function, or an AMF network function entity, and is used to manage user access to the network, and is responsible for non-access stratum (NAS) signaling management, access control, and mobility management of terminals to the network, for example, including mobile state management, allocation of user temporary identity, authentication and authorization of users, and the like.
[0054] An authentication server function (AUSF) can also be referred to as an AUSF network element, an AUSF network function, or an AUSF network function entity, and is used for authentication services, key generation, and implementation of two-way authentication of user equipment, and supports a unified authentication framework. In the embodiments of the present application, it is mainly used for mutual authentication between the UE and the network, and generates a security key for use in subsequent processes.
[0055] An application function (AF), which can also be referred to as an AF network element, an AF network function, or an AF network function entity, is configured to perform data routing for application influence, access network exposure functions, interact with a policy framework for policy control, and the like.
[0056] A network exposure function (NEF), which can also be referred to as an NEF network element, an NEF network function, or an NEF network function entity, is configured to perform data routing for application influence, access network exposure functions, interact with a policy framework for policy control, and the like.
[0057] A unified data management (UDM), which can also be referred to as a UDM network element, a UDM network function, or a UDM network function entity, can be configured to perform unified management of user data such as user subscription information and security information, as well as related functions such as user identification, access authorization, and mobility management.
[0058] An example of a process for updating parameters of a terminal via a control plane of a UDM is shown in FIG. 1. As shown in FIG. 1, the process includes the following steps Sa1-Sa7: Figure 2 Figure 2 As shown in FIG. 1, the process includes the following steps Sa1-Sa7:
[0059] Sa1, the UDM network element determines to perform parameter update of the terminal.
[0060] Sa2, the UDM network element sends an Nudm_SDM_Notification message to an AMF network element.
[0061] The AMF network element is an AMF network element configured to manage the terminal to be updated. The Nudm_SDM_Notification message can be understood as a unified data management service data management notification message, i.e., the UDM network element can notify the AMF network element of the update of the terminal-related parameters by invoking the Nudm_SDM_Notification service operation.
[0062] In some embodiments, the Nudm_SDM_Notification message can include UDM update data.
[0063] The UDM update data can include UDM update data related to the parameter update of the terminal, indication information of whether the terminal needs to send confirmation information, and indication information of whether the terminal needs to perform re-registration.
[0064] In an example, in the case that the parameter update of the terminal is performed due to the "routing indicator update data", and the updated routing indicator value is not supported by the UDM network element currently registered by the AMF network element, the UDM network element should require the terminal to re-register after the update data. That is, at this time, the UDM update data can include indication information that the terminal needs to re-register.
[0065] Sa3, in the case that the AMF network element determines that the terminal is unreachable, the Nudm_SDM_Info message is sent to the UDM network element.
[0066] The Nudm_SDM_Info message is a unified data management service data management information request message, that is, the AMF can call the Nudm_SDM_Info service operation to notify the UDM that the transmission of the parameter update data of the terminal is unsuccessful. Further, the UDM can consider this process as a suspension of the UE parameter update process, and skip the subsequent steps S4-S7.
[0067] Sa4, the AMF network element sends the DL NAS TRANSPORT message to the terminal.
[0068] The terminal is the terminal determined by the UDM network element to need parameter update, and the AMF network element can be used to manage the terminal. The DL NAS TRANSPORT message is a kind of downlink non-access layer transmission message, and the network side can realize the downlink transmission of information by sending the DL NAS TRANSPORT message. The DL NAS TRANSPORT message sent by the AMF network element to the terminal contains the transparent container received from the UDM.
[0069] The transparent container is a data structure for encapsulating user subscription data or other related information received from the UDM network element. These data are transparent to the AMF network element, that is, the AMF network element does not analyze or modify the content in the container, but only transmits it as a whole. In an example, the above-mentioned UDM update data can be contained in the transparent container. The AMF network element receives the transparent container from the UDM network element, constructs the DL NAS TRANSPORT message, and sends the transparent container as part of the message to the terminal.
[0070] Thus, the terminal can receive the DL NAS TRANSPORT message. The terminal can verify whether the UDM update data is provided by the HPLMN (home public land mobile network), SNPN (specific network public land mobile network) or CH (trusted third party) based on a preset mechanism. In an example, the preset mechanism can be determined based on the mechanism described in TS 33.501
[15] .
[0071] If the security check of the terminal on the UDM update data is successful, the terminal can choose to store the information and use the parameters from then on, or forward the information to the universal subscriber identity module (USIM).
[0072] If the security check of the terminal on the UDM update data fails, the terminal can discard the content of the UDM update data.
[0073] Sa5, the terminal sends an UL NAS TRANSPORT message containing acknowledgment (Ack) information to the AMF network element.
[0074] The UL NAS TRANSPORT message is an uplink non-access layer transmission message, and the terminal can realize uplink transmission of information by sending the UL NAS TRANSPORT message when uplink information transmission is needed. If the security check of the terminal on the UDM update data is successful, and the UDM network element requests the terminal to send determination information to the UDM network element. The terminal can transmit the UL NAS TRANSPORT message containing the Ack information to the AMF network element to realize the uplink transmission of the Ack information.
[0075] Sa61, the AMF network element sends an Nudm_SDM_Info request message to the UDM network element.
[0076] The Nudm_SDM_Info request message can contain the Ack information of the terminal.
[0077] In the case that the AMF receives an UL NAS TRANSPORT message carrying a transparent container from the terminal, and the transparent container carries the Ack information of the terminal, the AMF sends an Nudm_SDM_Info request message to the UDM, and includes the transparent container.
[0078] Sa62, the UDM network element sends an Nudm_SDM_Notification message to the AMF network element.
[0079] If the terminal's parameter update is due to the "routing identifier update data" and the UDM registered by the current AMF also supports the updated routing identifier, the UDM network element can require the terminal to send confirmation information, but does not require the terminal to re-register. After the UDM network element receives the transparent container indicating successful reception, the UDM network element should trigger the Nudm_SDM_Notification service operation to update the terminal context in the AMF using the updated routing indicator data.
[0080] In some embodiments, the UDM network element can also inform other NFs (such as the session management function (SMF), short message service function (SMSF)) about the update of the routing indication value allocated to the SUPI by invoking the Nudm_SDM_Notification service operation.
[0081] Sa7, if the UDM network element requests the terminal to re-register, the terminal initiates re-registration.
[0082] If the UDM requests the UE to re-register, the terminal can wait until it returns to the radio resource control idle (RRC_IDLE) state, and then initiates the registration procedure. The registration procedure can be the registration procedure described in the relevant standard, such as TS 24.501.
[0083] Figure 1 Nausf, Nudm, Namf, Nnef, Naanf, Nl, N2 and Ua* are interface sequence numbers, the meanings of which can be found in the meanings defined in the relevant standard protocol, which will not be described one by one here. And, Figure 1 In the above description, only the terminal as the UE is exemplarily described, Figure 1 The interface names between the various network functions in the above description are also only an example, and in specific implementation, the interface names of the system architecture can also be other names, which are not specifically limited by the present disclosure.
[0084] It should be noted that, Figure 1 The above description is only an exemplary framework, Figure 1 The number of devices or network elements included in the above description, and the names of various devices or network elements are not limited, and in addition to Figure 1 The devices or network elements shown in the above description, other devices or network elements can also be included.
[0085] The application scenarios of the embodiments of the present disclosure are not limited. The system architecture and business scenarios described in the embodiments of the present disclosure are used to more clearly illustrate the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art can know that, with the evolution of network architecture and the appearance of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.
[0086] The method provided by the present disclosure will be described in detail below with reference to the accompanying drawings.
[0087] As shown in the method provided by the present disclosure, the method comprises the following steps. Figure 3
[0088] S101, in the case of parameter update of the terminal, AKMA service data and a parameter update reason of the terminal are acquired.
[0089] In some embodiments, the AKMA service data can include data for indicating whether the UDM network element corresponds to a terminal that subscribes to the AKMA service, such as subscription status data, subscriber identifier data, and the like.
[0090] For example, the AKMA service data can also include one or more of service configuration data, security context, service status data, authentication key data, and the like. The service configuration data can include parameter configurations of the AKMA service, such as the validity period of the authentication key, the update policy, the encryption algorithm used, and the like. The security context refers to information that can be used to implement security protection (such as encryption / decryption and / or integrity protection / verification) of data. For example, the security context can include an encryption key, an integrity protection password, and the like. The service status data can include the current state of the AKMA service, such as whether it is activated, whether it is suspended, and the like. The authentication key data can be the key itself and its related attributes for terminal authentication, such as the version number of the key, the generation time, the usage restrictions, and the like. It should be understood that the above is only an exemplary description of the AKMA service data, and in actual application, the AKMA service data can differ according to the actual business needs of the network architecture, for example, the AKMA service data can also include key update records, service usage records, and the like.
[0091] In one possible implementation, the UDM network element can retrieve the AKMA service data from a data storage.
[0092] For example, the UDM network element will generally maintain a database or data storage system for storing various information related to subscribers, which can include AKMA service data. Thus, when the UDM network element needs to acquire AKMA service data, the UDM can retrieve the corresponding data from its internal database.
[0093] In another possible implementation, the UDM network element can obtain the AKMA service data from other network function network elements, such as AMF, SMF, and the like.
[0094] For example, the other network function network elements, such as AMF, SMF, and the like, can collect authentication and key information related to the terminal, that is, AKMA service data, in the process of interacting with the terminal, and thus can forward the collected AKMA service data to the UDM network element.
[0095] In yet another possible implementation, the UDM network element can also obtain the AKMA service data from an authentication server, a key management system, and the like, which are data sources for generating, distributing, and managing authentication keys.
[0096] It should be noted that the process of obtaining AKMA service data by the UDM network element can be different due to different network architectures and standards. In actual applications, the UDM network element can select a suitable implementation to obtain AKMA service data according to the actual network architecture.
[0097] In some embodiments, the UDM can determine whether the terminal needs to perform parameter update by evaluating data such as network status, device performance, and security requirements of the terminal. That is, the parameter update reason of the terminal can include reasons such as network status, device performance, and security requirements.
[0098] For example, taking the network status as the parameter update reason of the terminal as an example, for example, route identifier update. In the case of route identifier update, the UDM can determine that the terminal needs to perform corresponding parameter update to ensure that it can correctly communicate with the network. The route identifier is one of the key parameters in the network, which is used to identify and locate the routing path in the network. When the route identifier is updated, the UDM network element can receive the route identifier update notification and determine that the relevant terminal affected by this route identifier update needs to perform parameter update.
[0099] In some embodiments, before obtaining the AKMA service data and the parameter update reason of the terminal, the UDM network element can also receive a notification message of an update location unit (UPU) updating the route identifier of the terminal. And according to the notification message, determine to perform parameter update of the terminal.
[0100] Exemplarily, when the routing identifier is updated, a corresponding routing identifier update notification can be generated and sent to a related network entity or network element, such as a UDM network element, through a corresponding signaling protocol or message passing mechanism. Thus, the UDM network element can receive the routing identifier update notification and can parse and process the routing identifier update notification, such as verifying the validity of the notification and determining the related terminal affected by the routing identifier update. Further, the UDM network element can determine that the related terminal needs to perform parameter update.
[0101] S102, in the case that the AKMA service data indicates that the terminal subscribes to the AKMA service and the parameter update cause of the terminal is routing identifier update, the initial registration request information of the terminal is sent to the AMF network element.
[0102] In some embodiments, the UDM network element can determine whether the terminal subscribes to the AKMA service according to the AKMA service data.
[0103] Exemplarily, the UDM network element can determine whether the terminal subscribes to the AKMA service according to data in the AKMA service data, such as subscription state data, subscriber identifier data, and the like, which can indicate whether the terminal subscribes to the AKMA service.
[0104] In some embodiments, the UDM network element can also determine whether the parameter update cause of the terminal is routing identifier update according to the obtained parameter update cause of the terminal.
[0105] Thus, in the case that the AKMA service data indicates that the terminal subscribes to the AKMA service and the parameter update cause of the terminal is routing identifier update, the UDM network element can send the initial registration request information of the terminal to the AMF network element.
[0106] The initial registration request information is used to request the terminal to perform initial registration. Thus, the terminal can perform primary authentication and update the AKMA key.
[0107] In some embodiments, the UDM network element can also send the UDM update data related to the parameter update of the terminal to the AMF network element to trigger the terminal to perform parameter update.
[0108] Based on the technical solution provided in the disclosure, in the case that the terminal subscribes to AKMA and the parameter update of the terminal is caused by routing identifier update, the terminal can perform initial registration, thereby triggering the update of AKMA key. Since the A-KID on the terminal side will also change due to the routing identifier update, the AKMA service will be affected. Based on the technical solution of the disclosure, the terminal can be controlled to perform initial registration when the routing identifier update is determined, thereby triggering the update of AKMA key. In this way, the authentication context after the change of A-KID can remain consistent, thereby enabling authentication and key management according to A-KID, avoiding interruption or failure of AKMA service, and improving the reliability of AKMA service.
[0109] In some embodiments, the disclosure also provides another communication method applied to a terminal, as shown in the following Figure 4 The method comprises:
[0110] S201, receiving an initial registration request information sent by an AMF network element, wherein the initial registration request information is sent by a UDM network element in the case that the parameter update of the terminal, the terminal subscribes to AKMA service and the parameter update of the terminal is caused by routing identifier update.
[0111] S202, performing initial registration.
[0112] In some embodiments, the terminal can first perform deregistration, and then perform initial registration after completing the deregistration process.
[0113] For example, the terminal can perform deregistration and delete its 5G globally unique temporary identifier (5G-GUTI). The 5G-GUTI is a temporary identity of the terminal in the network. It should be understood that the terminal can delete its old 5G-GUTI when performing deregistration, and obtain a new 5G-GUTI when performing initial registration again.
[0114] Further, the terminal can perform initial registration. In the process of initial registration, the terminal side can establish a new registration state with the network side to verify the identity of the terminal, enable the terminal to obtain network access permission, and obtain a new temporary identity, etc. The process includes the primary authentication process of the terminal, which can trigger the update of AKMA key.
[0115] For example, Figure 5 An AKMA key architecture diagram provided by an embodiment of the disclosure is shown in the following Figure 5As shown, the terminal side and the network side complete the main authentication, and a security key can be generated for use in subsequent processes. In some embodiments, the main authentication can also involve network elements such as AMF / SEAF, AUSF and UDM on the network side. During the main authentication process, a security key K AUSF , which is the shared key between the AUSF network element and the terminal. Furthermore, the terminal and the AUSF network element can also generate an AKMA key K AKMA , so that the terminal and AF network element can be connected according to K AKMA Generated K AF Perform traffic protection between the terminal and the AF network element. The terminal and the AUSF network element can obtain K AKMA and KID, KID is K AKMA In this way, the terminal can complete the main authentication between the terminal side and the network side by performing the initial registration, and a new AKMA key can be generated during the main authentication process.
[0116] In some embodiments, the terminal may receive UDM update data related to the terminal parameter update sent by the AMF network element, and then perform parameter update according to the UDM update data.
[0117] Based on the technical solution provided by this disclosure, a terminal can receive an initial registration request message sent by a UDM network element when its parameters are updated, the terminal subscribes to the AKMA service, and the reason for the terminal's parameter update is a routing identifier update, and perform initial registration. In this way, if the A-KID changes due to a routing identifier update, the initial registration can complete primary authentication with the network. During this primary authentication process, a new AKMA key can be generated, thereby avoiding interruptions or failures in the AKMA service and improving the reliability of the AKMA service.
[0118] In some embodiments, the present disclosure also provides another communication method, which is applied to an AMF network element, such as Figure 6 As shown, the method includes:
[0119] S301: When a terminal updates its parameters, the terminal subscribes to an AKMA service, and the reason for the terminal's parameter update is a routing identifier update, an initial registration request message sent by a UDM network element is received.
[0120] S302: Send initial registration request information to the terminal.
[0121] It should be understood that the AMF network element sends an initial registration request message to the terminal, which can trigger the terminal to perform initial registration, thereby completing the main authentication on the terminal side and the network side, and a new AKMA key can be generated during the main authentication process.
[0122] In some embodiments, the AMF network element may receive UDM network element update data related to the terminal parameter update sent by the UDM network element, and send UDM update data related to the terminal parameter update to the terminal to trigger the terminal to update the parameters.
[0123] In addition, for the detailed description of steps S301-S302, reference can be made to the relevant description of steps S101-S102 and steps S201-S202, which will not be repeated here.
[0124] Based on the technical solution provided by this disclosure, the AMF network element can receive the initial registration request information sent by the UDM network element and send the initial registration request information to the terminal to trigger the terminal to perform initial registration when the terminal subscribes to the AKMA service and the terminal's parameter update reason is a routing identifier update. As a result, the terminal can complete the main authentication process to generate a new AKMA key, thereby avoiding interruption or failure of the AKMA service and improving the reliability of the AKMA service.
[0125] like Figure 7 The following is a schematic diagram of the interaction of the communication method provided by the present disclosure. Figure 7 To explain:
[0126] S401. When the terminal's parameters are updated, the UDM network element obtains AKMA service data and the reason for the terminal's parameter update.
[0127] S402. The UDM network element sends the initial registration request information of the terminal to the AMF network element.
[0128] Correspondingly, the AMF network element receives the initial registration request information.
[0129] The initial registration request information is sent by the UDM network element when the AKMA service data indicates that the terminal subscribes to the AKMA service and the parameter update reason of the terminal is a routing identifier update.
[0130] S403. The AMF network element sends an initial registration request message to the terminal.
[0131] Correspondingly, the terminal may receive the initial registration request information.
[0132] S404: The terminal performs initial registration.
[0133] In some embodiments, the UDM network element may also send UDM update data related to the terminal parameter update to the AMF network element. Correspondingly, the AMF network element may receive the UDM network element update data related to the terminal parameter update sent by the UDM network element.
[0134] Further, the AMF network element can send terminal parameter update related UDM update data to the terminal. The terminal receives the UDM update data and performs parameter update.
[0135] In some embodiments, in combination with the above embodiments, the present disclosure also provides a process of updating parameters of a terminal through a control plane of a UDM, as shown in the following figure, which includes the following steps Sb1-Sb8: Figure 8
[0136] Sb1, the UDM network element determines to perform parameter update of the terminal.
[0137] Sb2, the UDM network element determines whether the terminal subscribes to the AKMA service.
[0138] For example, the UDM network element can obtain AKMA service data, and determine whether the terminal subscribes to the AKMA service through the AKMA service data.
[0139] Sb3, the UDM network element sends an Nudm_SDM_Notification message to the AMF network element.
[0140] In the case that the parameter update of the terminal is performed due to the "routing indicator update data", and the updated routing indicator value is not supported by the UDM currently registered by the AMF, the UDM should require the terminal to re-register after updating the data. That is, at this time, the UDM update data can include indication information that the terminal needs to re-register.
[0141] In some embodiments, in the case that the parameter update of the terminal is performed due to the "routing indicator update data", and the terminal has subscribed to the AKMA service, the UDM network element can request the terminal to re-register after updating the data. That is, at this time, the UDM update data can include indication information that the terminal needs to re-register.
[0142] Sb4, in the case that the AMF network element determines that the terminal is unreachable, an Nudm_SDM_Info message is sent to the UDM network element.
[0143] Sb5, the AMF network element sends a DL NAS TRANSPORT message to the terminal.
[0144] The terminal is the terminal determined by the UDM to need to perform parameter update, and the AMF can be used to manage the terminal. The DL NAS TRANSPORT message contains a transparent container received from the UDM.
[0145] Sb6, the terminal sends an UL NAS TRANSPORT message containing acknowledgment (acknowledgment, Ack) information to the AMF network element.
[0146] If the security check of the terminal to the UDM succeeds, and the UDM requests the terminal to send the determination information to the UDM. The terminal can transmit an UL NAS TRANSPORT message including Ack information to the AMF.
[0147] Sb71, the AMF network element sends an Nudm_SDM_Info request message to the UDM.
[0148] The Nudm_SDM_Info request message can include the Ack information of the terminal.
[0149] Sb72, the UDM network element sends an Nudm_SDM_Notification message to the AMF network element.
[0150] Sb8, if the UDM requests the terminal to re-register, the terminal initiates re-registration.
[0151] If the UDM requests the UE to re-register, the terminal can wait until it returns to a radio resource control idle (RRC_IDLE) state, and then the terminal can first perform de-registration, delete its 5G-GUTI, and then initiate a registration procedure. The registration procedure can be a registration procedure described in a related standard, such as TS 24.501.
[0152] In addition, the detailed description of steps Sb1-Sb8 can also refer to the related description of steps Sa1-Sa7 described above, which will not be repeated here.
[0153] The above mainly introduces the scheme provided by the disclosure from the perspective of interaction between various devices or network elements. It can be understood that each device or network element contains a hardware structure and / or software module for executing each function in order to achieve the above functions. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiments disclosed herein, the disclosure can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present disclosure.
[0154] Figure 9 As shown, the communication device 900 can be applied to a UDM network element, and includes an obtaining module 901 and a sending module 902. In some embodiments, the communication device 900 can further include a determining module 903. Figure 9 As shown, the communication device 900 can be applied to a UDM network element, and includes an obtaining module 901 and a sending module 902. In some embodiments, the communication device 900 can further include a determining module 903.
[0155] The obtaining module 901 is configured to obtain AKMA service data of an application and a parameter update reason of the terminal in a case where the terminal is subjected to parameter update.
[0156] The sending module 902 is configured to send initial registration request information of the terminal to an AMF network element in a case where the AKMA service data indicates that the terminal subscribes to an AKMA service and the parameter update reason of the terminal is a routing identifier update.
[0157] In some embodiments, the sending module 902 is further configured to send UDM update data related to the parameter update of the terminal to the AMF network element, so as to trigger the terminal to perform the parameter update.
[0158] In some embodiments, the obtaining module 901 is further configured to receive a notification message in which a UPU updates the routing identifier of the terminal. The determining module 903 is configured to determine to perform the parameter update of the terminal according to the notification message.
[0159] For more details of the obtaining module 901, the sending module 902, and the determining module 903, and more details of the technical features and beneficial effects thereof, please refer to the corresponding method embodiments described above, which will not be repeated here.
[0160] Figure 10 As shown in the figure, the communication device 1000 can be applied to a terminal and includes a receiving module 1001 and a processing module 1002. Figure 10 As shown in the figure, the communication device 1000 can be applied to a terminal and includes a receiving module 1001 and a processing module 1002.
[0161] The receiving module 1001 is configured to receive initial registration request information sent by an AMF network element, wherein the initial registration request information is sent by a UDM network element in a case where the terminal is subjected to parameter update, the terminal subscribes to an AKMA service, and the parameter update reason of the terminal is a routing identifier update.
[0162] The processing module 1002 is configured to perform initial registration.
[0163] In some embodiments, the receiving module 1001 is further configured to receive UDM update data related to the parameter update of the terminal sent by the AMF network element. The processing module 1002 is further configured to perform parameter update according to the UDM update data.
[0164] In some embodiments, the processing module 1002 is further configured to perform deregistration before performing the initial registration.
[0165] For more details of the receiving module 1101 and the sending module 1102, and the descriptions of the technical features and the beneficial effects, please refer to the corresponding method embodiments above, and details are not described here.
[0166] Figure 11 As shown in the embodiment of the present disclosure, a schematic diagram of a communication device is provided. As shown in the embodiment of the present disclosure, the communication device 1100 can be applied to an AMF network element, and includes a receiving module 1101 and a sending module 1102. Figure 11
[0167] The receiving module 1101 is configured to receive initial registration request information sent by a UDM network element in the case that a terminal performs parameter update, the terminal subscribes to an AKMA service, and the parameter update of the terminal is caused by route identifier update.
[0168] The sending module 1102 is configured to send the initial registration request information to the terminal.
[0169] In some embodiments, the receiving module 1101 is further configured to receive UDM network element update data related to parameter update of the terminal sent by the UDM network element. The sending module 1102 is further configured to send the UDM update data related to the parameter update of the terminal to the terminal, so as to trigger the terminal to perform parameter update.
[0170] For more details of the receiving module 1101 and the sending module 1102, and the descriptions of the technical features and the beneficial effects, please refer to the corresponding method embodiments above, and details are not described here.
[0171] It should be noted that, Figure 9 , Figure 10 or Figure 11 The modules in the above embodiments can also be called units, for example, the sending module can be called a sending unit. In addition, in the embodiments shown in Figure 9 , Figure 10 or Figure 11 The names of the modules can not be the names shown in the figures, for example, the sending module can also be called a communication module, and the receiving module can also be called a communication module.
[0172] Figure 9 , Figure 10 or Figure 11 Each unit or module in the above description, if implemented in the form of a software function module and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present disclosure, in essence or the part that contributes to the prior art, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the embodiments of the present disclosure. The storage medium storing the computer software product includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0173] In the case of implementing the functions of the above integrated modules in the form of hardware, the embodiments of the present disclosure provide a structural diagram of a communication device, which can include the above communication apparatus 900, the communication apparatus 1000 or the communication apparatus 1100. As shown in the figure, the communication device 1200 includes a processor 1202, a communication interface 1203 and a bus 1204. Optionally, the communication device 1200 can also include a memory 1201. Figure 12
[0174] The processor 1202 can be various exemplary logical blocks, modules and circuits described in combination with the content of the present disclosure. The processor 1202 can be a central processing unit, a general purpose processor, a digital signal processor, an application specific integrated circuit, a field programmable gate array or other programmable logic device, transistor logic device, hardware component or any combination thereof. It can implement or execute various exemplary logical blocks, modules and circuits described in combination with the content of the present disclosure. The processor 1202 can also be a combination of computing functions, such as one or more microprocessor combinations, combinations of DSP and microprocessor, etc.
[0175] The communication interface 1203 is used to connect with other devices through a communication network. The communication network can be an Ethernet, a wireless access network, a wireless local area network (WLAN) and the like.
[0176] The memory 1201 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited to this.
[0177] As a possible implementation, the memory 1201 can exist independently of the processor 1202, and the memory 1201 can be connected to the processor 1202 through the bus 1204, for storing instructions or program codes. When the processor 1202 invokes and executes the instructions or program codes stored in the memory 1201, the method provided by the embodiments of the present disclosure can be implemented.
[0178] In another possible implementation, the memory 1201 can also be integrated with the processor 1202.
[0179] The bus 1204 can be an extended industry standard architecture (EISA) bus or the like. The bus 1204 can be divided into an address bus, a data bus, a control bus, and the like. For the sake of brevity and conciseness, Figure 12 In the figure, only one thick line is used to represent the bus, but it does not mean that there is only one bus or only one type of bus.
[0180] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of brevity and conciseness, only the above division of functional modules is taken as an example for illustration, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device or apparatus is divided into different functional modules to complete all or part of the above described functions.
[0181] The embodiments of the present disclosure further provide a computer readable storage medium. All or part of the flow of the above-mentioned method embodiments can be directed by computer instructions to complete the related hardware, and the program can be stored in the above-mentioned computer readable storage medium. When the program is executed, it can include the flow of each method embodiment as described above. The computer readable storage medium can be the memory of any of the preceding embodiments. The above-mentioned computer readable storage medium can also be an external storage device of the above-mentioned device or apparatus, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the above-mentioned device or apparatus. Further, the above-mentioned computer readable storage medium can include both the internal storage unit of the above-mentioned device or apparatus and the external storage device. The above-mentioned computer readable storage medium is used to store the above-mentioned computer program and other programs and data required by the above-mentioned device or apparatus. The above-mentioned computer readable storage medium can also be used to temporarily store data that has been output or will be output.
[0182] The embodiments of the present disclosure further provide a computer program product, which contains a computer program, and when the computer program product runs on a computer, it makes the computer execute any method provided in the above embodiments.
[0183] Although the present disclosure is described herein in conjunction with various embodiments, it will be understood that other variations of the disclosed embodiments can be understood and effected by those skilled in the art in practicing the claimed disclosure, from an inspection of the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps,
[0184] The word "a" or "an" does not exclude a plurality. A single processor or other unit can fulfill the functions of several means recited in the claims. Means recited in different dependent claims mean alternative, not mutually exclusive, implementations.
[0185] Although the present disclosure is described herein in conjunction with specific features and embodiments thereof, it is obvious that various modifications and combinations can be made thereto within the spirit and scope of the disclosure. Accordingly, the description and drawings are to be regarded simply as illustrative of the present disclosure as defined by the appended claims, and are to be construed that any and all modifications, variations, combinations or equivalents that are within the scope of the present disclosure are to be embraced by the present disclosure. Obviously, those skilled in the art can make various modifications and changes to the present disclosure without departing from the spirit and scope of the present disclosure. Thus, if these modifications and changes of the present disclosure fall within the scope of the claims of the present disclosure and their equivalents, they are also intended to be included in the present disclosure.
[0186] The above merely provides the specific implementation of the present disclosure, but the protection scope of the present disclosure is not limited thereto, any change or replacement within the technical scope disclosed by the present disclosure should be covered in the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.
Claims
1. A communication method characterized by comprising: The method is applied to a unified data management function (UDM) network element, and the method comprises the following steps: In the case of parameter update of a terminal, authentication and key management for applications (AKMA) service data of the terminal and a parameter update reason of the terminal are acquired; In the case that the AKMA service data indicates that the terminal subscribes to AKMA service and the parameter update reason of the terminal is route identifier update, initial registration request information of the terminal is sent to an access and mobility management function (AMF) network element, and the initial registration request information is used to request the terminal to perform initial registration.
2. The method of claim 1, wherein, The method further comprises the following steps: UDM update data related to parameter update of the terminal is sent to the AMF network element, so as to trigger the terminal to perform parameter update.
3. The method of claim 1, wherein, Before the step of acquiring the AKMA service data of the terminal and the parameter update reason of the terminal, the method further comprises the following steps: A notification message that a UPU updates a route identifier of the terminal is received; According to the notification message, it is determined to perform parameter update of the terminal.
4. A communication method characterized by comprising: The method is applied to a terminal, and the method comprises the following steps: Initial registration request information sent by an AMF network element is received, wherein the initial registration request information is sent by a UDM network element in the case of parameter update of a terminal, the terminal subscribes to AKMA service, and the parameter update reason of the terminal is route identifier update; Initial registration is performed.
5. The method of claim 4, wherein, The method further comprises the following steps: UDM update data related to parameter update of the terminal is received by an AMF network element; According to the UDM update data, parameter update is performed.
6. The method of claim 4, wherein, Before the step of performing initial registration, the method further comprises the following steps: Deregistration is performed.
7. A communication method characterized by comprising: The method is applied to an AMF network element, and the method comprises the following steps: In the case of parameter update of a terminal, the terminal subscribes to AKMA service, and the parameter update reason of the terminal is route identifier update, initial registration request information sent by a UDM network element is received; The initial registration request information is sent to the terminal.
8. The method of claim 7, wherein, The method further comprises the following steps: UDM network element update data related to parameter update of the terminal sent by the UDM network element is received; UDM update data related to parameter update of the terminal is sent to the terminal, so as to trigger the terminal to perform parameter update.
9. A communication device, characterized by Comprise: A memory and a processor; The memory and the processor are coupled; The memory is used to store instructions executable by the processor; The processor executes the instructions to perform the method in any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, and when the computer instructions run on the processor, the processor executes the method in any one of claims 1 to 8.
11. A computer program product, characterised in that, The computer program product contains a computer program, and when the computer program runs on a computer, the computer executes the method in any one of claims 1 to 8.
Citation Information
Cited By
Communication methods, communication device, storage medium and computer program product
EP4723697A1
Communication methods, communication device, storage medium and computer program product
WO2025218267A1