Communication method, apparatus, device, chip and medium

By triggering a second authentication process on the terminal to generate a new key, the problem of network parameter update failure when the SIM card is switched between different terminals is solved, and the successful update of terminal network parameters and the improvement of communication performance are achieved.

CN120857111BActive Publication Date: 2026-01-16BEIJING X RING TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511358592.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-22
Publication Date
2026-01-16
Estimated Expiration
2045-09-22

AI Technical Summary

Technical Problem

In existing technologies, failure to update network parameters of a terminal affects communication performance, especially when switching SIM cards between different terminals, as the success of the key negotiation process cannot be guaranteed, leading to failure of network parameter updates.

Method used

By triggering the second authentication process on the terminal, a new first AMF key and a second AUSF key are generated. These keys are then used to update network parameters, ensuring successful integrity verification of the keys across different terminals.

Benefits of technology

It effectively ensures the successful update of terminal network parameters, improves communication performance, ensures the success of the key negotiation process, and is suitable for various communication scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120857111B_ABST
    Figure CN120857111B_ABST
Patent Text Reader

Abstract

The present disclosure provides a communication method, device, equipment, chip and medium, wherein the communication method comprises: determining that a first AUSF key does not support updating a network parameter, wherein the first AUSF key is generated by a first terminal through a first authentication process, and a second authentication process is triggered by the first terminal to generate a first AMF key and a second AUSF key, and the network parameter is updated according to the first AMF key and the second AUSF key. The technical problem that the network parameter of the terminal cannot be ensured to be successfully updated in the prior art, and the communication performance is affected.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and particularly relates to a communication method, device, equipment, chip and medium. BACKGROUND

[0002] The terminal and the network can negotiate the key through the authentication procedure. For example, in the authentication procedure, the terminal derives Kausf (Authentication Server Function (AUSF) key) and Kamf (Access and Mobility management Function (AMF) key) based on the authentication request of the network, and feeds back the authentication response to the network. The network can check the authentication response, and after the check passes, starts the security activation procedure. At this point, the terminal and the network complete the key negotiation procedure, the terminal saves the Kamf and the Kausf, the AUSF saves the Kausf, and the AMF saves the Kamf. Then, the network can initiate the update of the network parameter to the terminal. SUMMARY

[0003] The present disclosure aims to at least solve one of the technical problems in the related art to some extent.

[0004] To this end, the present disclosure provides a communication method, device, equipment, chip, computer readable storage medium and computer program product, which can effectively ensure the successful update of the network parameter of the terminal and improve the communication performance.

[0005] The first aspect embodiment of the present disclosure provides a communication method, comprising: determining that a first AUSF key does not support updating a network parameter, wherein the first AUSF key is generated by a first terminal through a first authentication procedure; triggering a second authentication procedure through the first terminal to generate a first AMF key and a second AUSF key; and updating the network parameter according to the first AMF key and the second AUSF key.

[0006] The second aspect embodiment of the present disclosure provides a communication device, comprising: a determination module configured to determine that a first AUSF key does not support updating a network parameter, wherein the first AUSF key is generated by a first terminal through a first authentication procedure; a generation module configured to trigger a second authentication procedure through the first terminal to generate a first AMF key and a second AUSF key; and an update module configured to update the network parameter according to the first AMF key and the second AUSF key.

[0007] The third aspect of the present disclosure provides a communication device, comprising a processor and a memory connected with the processor; the memory stores computer-executable instructions; and the processor executes the computer-executable instructions stored in the memory to implement the communication method provided in the above aspect of the present disclosure.

[0008] The fourth aspect of the present disclosure provides a chip, comprising a processing circuit and an interface circuit; the interface circuit is configured to read instructions and send the instructions to the processing circuit, so that the processing circuit executes the communication method provided in the first aspect of the present disclosure.

[0009] The fifth aspect of the present disclosure provides a computer-readable storage medium, which stores computer-executable instructions; when the computer-executable instructions are executed by a processor, the computer-executable instructions are configured to implement the communication method provided in the above aspect.

[0010] The communication method, device, communication equipment, chip, computer-readable storage medium and computer program product provided by the present disclosure can effectively ensure the successful update of the network parameters of the terminal and improve the communication performance by determining that the first AUSF key does not support updating the network parameters, wherein the first AUSF key is generated by the first terminal through the first authentication process, and the second authentication process is triggered by the first terminal to generate the first AMF key and the second AUSF key, and the network parameters are updated according to the first AMF key and the second AUSF key.

[0011] The additional aspects and advantages of the present disclosure will be partially given in the following description, partially will become obvious from the following description, or will be understood by practicing the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0012] The above and / or additional aspects and advantages of the present disclosure will become apparent and more readily appreciated from the following description of the embodiments, taken in conjunction with the accompanying drawings, in which:

[0013] Figure 1 is an architecture schematic diagram of a communication system according to an embodiment of the present disclosure;

[0014] Figure 2 is a flow schematic diagram of a communication method provided by an embodiment of the present disclosure;

[0015] Figure 3 is a flow schematic diagram of another communication method provided by an embodiment of the present disclosure;

[0016] Figure 4 is an application flow schematic diagram of an embodiment of the present disclosure;

[0017] Figure 5 is a flow schematic diagram of still another communication method provided by an embodiment of the present disclosure;

[0018] Figure 6 is another application flow diagram according to an embodiment of the present disclosure;

[0019] Figure 7 is a structural diagram of a communication apparatus according to an embodiment of the present disclosure;

[0020] Figure 8 shows a block diagram of an exemplary communication device suitable for implementing embodiments of the present disclosure;

[0021] Figure 9 is a structural diagram of a chip according to an embodiment of the present disclosure;

[0022] Figure 10 is a structural diagram of another chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0023] Embodiments of the present disclosure are described in detail below with reference to the accompanying drawings. Examples of the embodiments are shown in the drawings, in which the same or similar components are denoted by the same or similar reference numerals, and therefore repeated description is omitted. The embodiments described below are examples for explaining the present disclosure, and should not be understood as limiting the present disclosure.

[0024] In embodiments of the present disclosure, the communication device can be, for example, a terminal or a chip, and no limitation is made thereto.

[0025] Figure 1 is a structural diagram of a communication system according to an embodiment of the present disclosure. As shown in Figure 1 , the communication system 100 can include a terminal 101 and a network device 102. The network device 102 can include at least one of an access network device and a core network device.

[0026] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a tablet (Pad), a wireless transceiver-equipped computer, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, and the like, but is not limited thereto.

[0027] In some embodiments, the access network device is at least one of a node or a device that accesses a terminal to a wireless network, and can include an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a WiFi system, and the like, but is not limited thereto.

[0028] In some embodiments, the technical solutions of the present disclosure can be applied to an Open RAN architecture, in which case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0029] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit (control unit). The CU-DU structure can split the protocol layers of the access network device, with some protocol layers being controlled by the CU and the remaining protocol layers being distributed in the DUs. However, the present application is not limited thereto.

[0030] In some embodiments, the core network device can be one device including one or more network elements, or can be multiple devices or device groups including all or part of the one or more network elements. The network element can be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).

[0031] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the present disclosure, and does not constitute a limitation on the technical solutions proposed in the present disclosure. Those skilled in the art can know that, as the system architecture evolves and new business scenarios appear, the technical solutions proposed in the present disclosure are also applicable to similar technical problems.

[0032] The following embodiments of the present disclosure can be applied to Figure 1 The communication system 100 shown is an example, and the present application is not limited thereto. Figure 1 The communication system can include all or part of the subjects shown in Figure 1 The communication system can also include other subjects other than Figure 1 The number and form of each subject are arbitrary, and the connection relationship between the subjects is an example. The subjects can be connected or not connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.

[0033] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based on them, and the like. In addition, a plurality of systems can be combined (for example, combination of LTE or LTE-A and 5G, and the like).

[0034] Optionally, the core network device can include one or more network functions (or referred to as: network elements). The network function is, for example:

[0035] 1. Access and Mobility management Function (AMF).

[0036] The AMF is a logical node function on the core network side, which is the core network control plane access point of the terminal and wireless, receives all connection and session related information from the user equipment, and performs registration, connection, reachability, and mobility management. In addition, the AMF provides a session management message transmission channel for the terminal device and the Session Management Function (SMF) device, and provides authentication and authorization functions when the user accesses.

[0037] 2. Authentication Server Function (AUSF), which is used to receive the request of the AMF for identity verification of the terminal device (user equipment, UE), request a key from the unified data management function (unified data management, UDM), and then forward the key issued by the UDM to the AMF for authentication processing.

[0038] 3. Unified Data Management (UDM). The UDM is responsible for the management of terminal device identification, subscription data, authentication data, and the registration management of service network elements of the terminal device (such as the current AMF providing services for the terminal device, etc., such as when the terminal device switches the accessed AMF, the UDM will also initiate a de-registration message to the old AMF, requiring the old AMF to delete the user related information).

[0039] Optionally, the terminal and the network can negotiate the keys through an authentication procedure (or referred to as: authentication and security activation procedure, authentication procedure). The description for the authentication procedure is as follows: in the case that the terminal locally exists a valid Kamf (AMF key), the terminal uses the Kamf to perform integrity protection on the initial registration message, in the case that the terminal locally does not exist a valid Kamf, the terminal does not perform integrity protection on the initial registration message, and then the terminal can send the initial registration message to the AMF. The AMF can receive the initial registration message, if it is determined that the initial registration message is not integrity protected or the integrity check fails, the AMF notifies the AUSF to start the authentication related procedure. If it is determined that the initial registration message is integrity protected and the integrity check succeeds, the AMF skips the authentication procedure. If the AMF notifies the AUSF to start the authentication related procedure, the AUSF can receive the authentication request sent by the AMF, obtain key calculation related parameters from the UDM, generate a Kausf (AUSF key), derive authentication related parameters, and notify the terminal to start the authentication procedure. After receiving the authentication request sent by the AUSF, the terminal performs authentication on the Subscriber Identity Module (SIM) card, if the authentication is passed, the terminal generates an Integrity Key (IK) and / or a Cipher Key (CK), and an authentication response. In the above authentication procedure, the terminal derives the Kausf (AUSF key) and the Kamf (AMF key) based on the authentication request of the network, and feeds back the authentication response to the network. The network can check the authentication response, and after the check is passed, the network starts the security activation procedure. At this point, the terminal and the network complete the key negotiation procedure, the terminal saves the Kamf and the Kausf, the AUSF saves the Kausf, and the AMF saves the Kamf.

[0040] Optionally, the SIM card exists a "card file for storing the AMF key", but can not exist a "card file for storing the AUSF key". If the SIM card does not exist the "card file for storing the AUSF key", the AUSF key can be stored in a Non-Volatile (NV) memory in the terminal.

[0041] Optionally, the network can initiate an update of the network parameters to the terminal. The network parameters can for example include parameters updated through a UE Parameters Update (UPU) procedure, and / or parameters updated through a Steering Of Roaming (SOR) procedure.

[0042] In the related art, the network initiates the UPU process as an example. When the SIM card is inserted into the terminal 1 to initiate the initial registration, the network can start the authentication and security activation process, negotiate the key K amf 1 and K ausf 1 with the terminal, at this time, the K amf 1 is stored in the SIM card, and the K ausf 1 is stored in the NV memory of the terminal 1. The SIM card is inserted into the terminal 2, at this time, the SIM card stores the K amf 1, but does not store the K ausf 1, and the NV memory of the terminal 2 also does not store the K ausf. According to the agreement, the K amf 1 can be deleted, and the initial registration request is sent in plaintext, the network receives the initial registration request, the initial registration request is in plaintext, and then the network starts the authentication and security activation process, negotiates the key K amf 2 and K ausf 2 with the terminal, at this time, the K amf 2 is stored in the SIM card, and the K ausf 2 is stored in the NV memory of the terminal 2. The SIM card is pulled out again and inserted into the terminal 1, at this time, the terminal 1 reads the K amf 2 from the SIM card and the K ausf 1 from the NV memory, and the K ausf 1 exists, so that the K amf 2 in the SIM card does not need to be deleted, the initial registration request is integrity protected by using the K amf 2, the network performs integrity check on the initial registration request, and passes, and does not need to negotiate the key again. When the network initiates the UPU process, the UPU message authentication code (UPU MAC) is calculated by using the K ausf 2 and sent to the terminal 1, and the terminal 1 calculates the UPU MAC by using the K ausf 1, which fails to match the UPU MAC carried by the network, the terminal 1 considers that the integrity check fails, discards the UPU content, and the UPU process fails. The SOR process also has the above problems. Therefore, in the related art, the network parameter of the terminal cannot be ensured to be successfully updated, and the communication performance is affected.

[0043] The communication method, the apparatus, the communication device, the communication system, the chip and the storage medium provided in the embodiments of the present disclosure are described below with reference to the drawings.

[0044] Optionally, the communication method provided in the embodiments of the present disclosure can be applied in the following scenario: there are a first terminal (for example, UE1), a second terminal (for example, UE2), an AMF network element, an AUSF network element, and a UDM network element. The SIM card can be registered in the first terminal (for example, UE1) first, and a first authentication process is triggered by the first terminal (for example, UE1), then the SIM card is registered in the second terminal (for example, UE2), and a third authentication process is triggered by the second terminal (for example, UE2), and then the SIM card is registered back to the first terminal (for example, UE1), and the authentication process triggered by the first terminal (for example, UE1) again can be referred to as a second authentication process, and this is not limited.

[0045] Optionally, the communication method provided in the embodiments of the present disclosure can exist "card file for storing AMF key" in the SIM card, and does not exist "card file for storing AUSF key". Therefore, the first terminal can store the generated AMF key in the "card file for storing AMF key" in the SIM card, and store the generated AUSF key in the NV memory of the terminal, and the second terminal can store the generated AMF key in the "card file for storing AMF key" in the SIM card, and store the generated AUSF key in the NV memory of the terminal, and this is not limited.

[0046] Figure 2 A flowchart of a communication method provided in the embodiments of the present disclosure.

[0047] The communication method provided in the embodiments can be applied in a terminal. Optionally, the execution subject of the communication method in the embodiments can be, for example, a terminal, or a chip, wherein the chip can be deployed in a terminal, or can also be deployed in any other possible device, and this is not limited.

[0048] As Figure 2 shown, the communication method comprises:

[0049] Step S201: determining that the first AUSF key does not support updating the network parameter, wherein the first AUSF key is generated by the first terminal through the first authentication process.

[0050] The first AUSF key is generated by the first terminal through the first authentication process. That is, the SIM can be registered in the first terminal (for example, UE1) first, and trigger the first authentication process through the first terminal. In the first authentication process, the first terminal can interact with the core network device, for example, AMF network element, AUSF network element, UDM network element, through the access network device to negotiate the key, and generate the first AUSF key (for example, Kausf_1).

[0051] Optionally, the network parameter can be a parameter used by the first terminal for network communication.

[0052] Optionally, the network parameter comprises at least one of the following: a first parameter, wherein the first parameter is a parameter updated through a terminal parameter update UPU process; and a second parameter, wherein the second parameter is a parameter updated through a roaming guidance SOR process. In this way, the optimization and update of various network parameters can be effectively applied, the flexibility is improved, and various communication scenarios are applicable.

[0053] For example, the first parameter is, for example, Routing Identifier (Routing ID), Default Configuration NSSAI, and the like. The full name of NSSAI is Network Slice Selection Assistance Information, which represents network slice selection assistance information. The second parameter is, for example, authentication data, roaming failure response policy data, and the like.

[0054] Optionally, the SIM card is registered in the first terminal, and triggers the first terminal to generate a first AUSF key through a first authentication process. Then, when it is determined that the network parameter needs to be updated, it can be analyzed whether the first AUSF key supports updating the network parameter.

[0055] Optionally, in some embodiments, the process of updating the network parameter can be performed, and in the process of updating the network parameter, the AUSF network element can integrity protect some update parameters (which can be used to update the network parameter). Then, the AUSF network element interacts with the first terminal through the UDM network element and the AMF network element to transmit the update parameter. The first terminal can use the first AUSF key to integrity check the update parameter. If the integrity check fails, it is determined that the first AUSF key does not support updating the network parameter. If the integrity check is successful, it is determined that the first AUSF key supports updating the network parameter. No limitation is made to this.

[0056] Optionally, in some embodiments, it can be determined whether the first AUSF key supports updating the network parameter before updating the network parameter. For example, it can be determined whether the SIM performs registration switching between the first terminal and the second terminal, such as first registered to the first terminal, then registered to the second terminal, and then registered back to the first terminal, and the authentication procedure is initiated when registered to the first terminal and the second terminal (wherein the authentication procedure initiated by the first terminal can be referred to as the first authentication procedure, and the authentication procedure initiated by the second terminal can be referred to as the third authentication procedure), and the first AUSF key generated by the first authentication procedure initiated on the first terminal is stored in the NV memory of the first terminal, and the AUSF key generated by the third authentication procedure initiated on the second terminal is stored in the NV memory of the second terminal. Therefore, when the first terminal updates the network parameter, the first AUSF key is used for integrity check, and the third AUSF key used by the AUSF network element for integrity protection is generated in the third authentication procedure between the second terminal, so that the first AUSF key used by the first terminal for integrity check and the third AUSF key used by the AUSF network element for integrity protection are generated based on different authentication procedures, which cannot ensure successful integrity check. Therefore, it is determined that the first AUSF key does not support updating the network parameter, and no limitation is made thereon.

[0057] Of course, any other possible way can also be used to determine that the first AUSF key does not support updating the network parameter, such as by comparing the second AMF key generated by the first terminal in the first authentication procedure and the third AMF key generated by the second terminal in the third authentication procedure. If the second AMF key and the third AMF key are different, it is determined that the first AUSF key does not support updating the network parameter, and no limitation is made thereon.

[0058] Step S202: Trigger the second authentication procedure by the first terminal to generate the first AMF key and the second AUSF key.

[0059] Optionally, after determining that the first AUSF key does not support updating the network parameter, the second authentication procedure can be triggered by the first terminal to generate the first AMF key and the second AUSF key. That is, the SIM can be first registered in the first terminal (for example, UE1), and the first authentication procedure can be triggered by the first terminal, in which the first terminal can interact with the core network device through the access network device to negotiate the key to obtain the first AUSF key. If it is determined that the first AUSF key does not support updating the network parameter, the second authentication procedure can be triggered again by the first terminal, in which the first terminal can interact with the core network device through the access network device to negotiate the key to obtain the first AMF key (for example, Kamf_3) and the second AUSF key (for example, Kausf_3), and the re-negotiated key can be used to update the network parameter.

[0060] Step S203: updating the network parameter according to the first AMF key and the second AUSF key.

[0061] Optionally, after generating the first AMF key and the second AUSF key, the first AMF key and the second AUSF key can be used to update the network parameter. That is, if it is determined that the first AUSF key does not support updating the network parameter, the first terminal can re-trigger the second authentication procedure in plaintext form, and use the first AMF key and the second AUSF key generated in the second authentication procedure to update the network parameter.

[0062] In the example, since the first AMF key and the second AUSF key are generated by the second authentication procedure re-initiated by the first terminal, in the second authentication procedure, the AUSF network element generates and saves the fourth AUSF key (Kausf_3). Then, if the UDM network element initiates to update the network parameter, the AUSF network element can use the fourth AUSF key to integrity protect the first update parameter (the first update parameter is used to update the network parameter), and then transmit the first update parameter to the first terminal through the UDM network element and the AMF network element. The first terminal can use the first AMF key to receive the transmitted first update parameter, and use the second AUSF key to integrity check the first update parameter. Since the first AMF key, the second AUSF key, and the fourth AUSF key are all generated in the same second authentication procedure, it can be ensured that the network parameter is successfully updated.

[0063] Optionally, in some embodiments, in the process of updating the network parameter according to the first AMF key and the second AUSF key, the second update parameter and the first message authentication code can be received according to the first AMF key, the first message authentication code is processed by the AUSF network element according to the fourth AUSF key, the fourth AUSF key is generated by the AUSF network element through the second authentication process, and the integrity check of the second update parameter is determined according to the second AUSF key and the first message authentication code. In the case of successful integrity check of the second update parameter, the network parameter is updated according to the second update parameter. Therefore, since the first AMF key (generated by the first terminal), the second AUSF key (generated by the first terminal), and the fourth AUSF key (generated by the AUSF network element) are all generated in the second authentication process initiated by the first terminal, the integrity protection and check of the second update parameter can be ensured, thereby greatly improving the accuracy of network parameter updating.

[0064] Optionally, in some embodiments, in the process of determining whether the integrity check of the second update parameter is successful according to the second AUSF key and the first message authentication code, the second update parameter can be processed according to the second AUSF key to obtain a second message authentication code, and in the case that the first message authentication code and the second message authentication code are the same, it is determined that the integrity check of the second update parameter is successful, and in the case that the first message authentication code and the second message authentication code are different, it is determined that the integrity check of the second update parameter is not successful. Therefore, the efficiency and effect of integrity check are improved, and the integrity protection effect is ensured.

[0065] In this embodiment, it is determined that the first AUSF key does not support updating the network parameter, wherein the first AUSF key is generated by the first terminal through the first authentication process, and the second authentication process is triggered by the first terminal to generate the first AMF key and the second AUSF key, and the network parameter is updated according to the first AMF key and the second AUSF key. Therefore, the network parameter of the terminal can be effectively updated to improve the communication performance.

[0066] Optionally, in some embodiments of the present disclosure, in the process of determining that the first AUSF key does not support updating the network parameter, a third AUSF key can be determined, wherein the third AUSF key is used for the AUSF network element to protect the integrity of the network parameter update, the third AUSF key is generated by the AUSF network element through a third authentication process, the third authentication process is triggered by a second terminal, and in the case that the first AUSF key and the third AUSF key are different, it is determined that the first AUSF key does not support updating the network parameter. Therefore, the case that the first AUSF key does not support updating the network parameter can be accurately identified, and the identification effect is improved.

[0067] Optionally, in some embodiments of the present disclosure, in the process of determining that the first AUSF key and the third AUSF key are different, it can be determined whether the first file and the second file exist in the SIM card, the first file is used to store the AMF key, the second file is used to store the AUSF key, and it is determined whether the SIM card meets the condition, the condition is used to represent that the SIM card is registered in the first terminal and triggers the first authentication process, is registered in the second terminal and triggers the third authentication process, is registered in the first terminal again, and the first file exists in the SIM card and the second file does not exist, and the SIM card meets the condition. In the case of the first file existing in the SIM card and the second file not existing, and the SIM card meeting the condition, it is determined that the first AUSF key and the third AUSF key are different. Therefore, the case that the first AUSF key and the third AUSF key are different can be accurately identified, and the efficiency and effect of detection and identification are improved.

[0068] Figure 3 Another flowchart of a communication method provided by an embodiment of the present disclosure.

[0069] The communication method provided in the embodiment can be applied in a terminal. Alternatively, the execution subject of the communication method in the embodiment can be, for example, a terminal, or a chip, wherein the chip can be deployed in a terminal, or can also be deployed in any other possible device, and no limitation is made in this regard.

[0070] As shown in the Figure 3 communication method comprises the following steps.

[0071] Step S301: determining a third AUSF key, wherein the third AUSF key is used for integrity protection of AUSF network element update of network parameters, and the third AUSF key is generated by the AUSF network element through a third authentication process, and the third authentication process is triggered by a second terminal.

[0072] Optionally, as known from the above description, the SIM card can be switched from being registered in a first terminal to being registered in a second terminal, and the second terminal initiates a third authentication process, and in the third authentication process, the AUSF network element generates a third AUSF key.

[0073] Step S302: determining that the first AUSF key is stored in the NV memory of the first terminal.

[0074] Optionally, as can be known from the above description, the SIM card can be first registered in the first terminal, and the first terminal initiates the first authentication process. In the first authentication process, the first terminal can generate the first AUSF key, and since there is no "card file for storing the AUSF key" in the SIM card, the first AUSF key can be stored in the NV memory of the first terminal. In addition, in the first authentication process, the first terminal can also generate the second AMF key, and since there is a "card file for storing the AMF key" in the SIM card, the first terminal can store the second AMF key in the "card file for storing the AMF key" and the NV memory at the same time.

[0075] Step S303: reading the second AMF key from the NV memory, wherein the second AMF key is generated by the first terminal through the first authentication process.

[0076] Optionally, since the second AMF key is stored in the "card file for storing the AMF key" and the NV memory at the same time, the second AMF key can be read from the NV memory, and the read second AMF key can be used for subsequent matching with the third AMF key read from the SIM card, so as to determine whether the SIM card initiates the authentication process on different terminals.

[0077] Step S304: reading the third AMF key from the first file of the SIM card, wherein the third AMF key is generated by the second terminal through the third authentication process.

[0078] The first file is used for storing the AMF key. For example, the first file is the "card file for storing the AMF key".

[0079] Optionally, the first terminal can store the second AMF key in the "card file for storing the AMF key" and the NV memory at the same time. If the SIM card triggers different authentication processes on different terminals, the AMF key stored in the first file of the SIM card will be refreshed. Therefore, the third AMF key can be read from the first file of the SIM card, and the second AMF key read from the NV memory and the third AMF key in the SIM card can be compared, and according to the comparison result, it is detected whether the SIM card triggers different authentication processes on different terminals.

[0080] Step S305: in the case that the second AMF key and the third AMF key are different, determining that the first AUSF key and the third AUSF key are different.

[0081] Step S306: determining that the first AUSF key does not support updating the network parameter.

[0082] Optionally, in the case that the second AMF key and the third AMF key are different, it is determined that the SIM card triggers different authentication processes on different terminals respectively, and based on the above description, the second AMF key and the first AUSF key are generated in the first authentication process, and the third AMF key and the third AUSF key are generated in the third authentication process, so that it is determined that the first AUSF key and the third AUSF key are different, and then it can be determined that the first AUSF key does not support updating the network parameter.

[0083] Step S307: Triggering a second authentication process by the first terminal to generate a first AMF key and a second AUSF key.

[0084] Optionally, the first AMF key can be stored in a first file of the SIM card and an NV memory of the first terminal, and the second AUSF key can be stored in the NV memory. The first AMF key stored in the NV memory of the first terminal can be used to check the subsequent update of the network parameter.

[0085] Step S308: Updating the network parameter according to the first AMF key and the second AUSF key.

[0086] The description of S307-S308 can be specifically referred to the above embodiments, which will not be repeated here.

[0087] In this embodiment, it is determined that the first AUSF key does not support updating the network parameter, wherein the first AUSF key is generated by the first terminal through the first authentication process, the first AMF key and the second AUSF key are generated by triggering a second authentication process by the first terminal, and the network parameter is updated according to the first AMF key and the second AUSF key. Therefore, the network parameter of the terminal can be effectively ensured to be successfully updated, and the communication performance is improved. By determining the third AUSF key, wherein the third AUSF key is used for the AUSF network element to protect the integrity of the update of the network parameter, the third AUSF key is generated by the AUSF network element through the third authentication process, the third authentication process is triggered by the second terminal, and in the case that the first AUSF key and the third AUSF key are different, it is determined that the first AUSF key does not support updating the network parameter. Therefore, the case that the first AUSF key does not support updating the network parameter can be accurately identified, the identification effect is improved, and the flexibility of detection and identification is also improved, which is suitable for various communication scenarios.

[0088] As shown in Figure 4 , the first AUSF key is determined to be different from the third AUSF key, and the first AUSF key is determined to not support updating the network parameter. Figure 4Figure 1 is a flowchart of an application process according to an embodiment of the present disclosure. The first terminal is UE1, the second terminal is UE2, and the core network device includes an AMF network element, an AUSF network element, and a UDM network element. The network initiates a UPU process (also applicable to a SOR process) for example.

[0089] 1. The card is inserted into UE1.

[0090] 2. UE1 interacts with AMF, AUSF, and UDM to initiate an initial registration process, and the network initiates an authentication and security process to negotiate a key with UE1.

[0091] Optionally, the authentication and security process is an optional example of a first authentication process.

[0092] 3a. UE1 generates Kamf_1 and Kausf_1, stores Kamf_1 in the card, and stores Kamf_1 and Kausf_1 in the NV memory.

[0093] Optionally, Kamf_1 generated by UE1 is an optional example of the second AMF key described above. Kausf_1 generated by UE1 is an optional example of the first AUSF key described above.

[0094] 3b. AMF generates and stores Kamf_1.

[0095] 3c. AUSF generates and stores Kausf_1.

[0096] 4. UE1 is powered off and the card is inserted into UE2.

[0097] 5. The card only has Kamf_1 and does not have Kausf_1, the NV memory in UE2 also does not have Kausf, Kamf_1 is deleted, and plaintext is used to initiate registration.

[0098] 6. UE2 interacts with AMF, AUSF, and UDM to initiate an initial registration process, and the network initiates an authentication and security process to negotiate a key with UE2.

[0099] Optionally, the authentication and security process is an optional example of a third authentication process.

[0100] 7a. UE2 generates Kamf_2 and Kausf_2, stores Kamf_2 in the card, and stores Kamf_2 and Kausf_2 in the NV memory.

[0101] Optionally, Kamf_2 generated by UE2 is an optional example of the third AMF key described above.

[0102] 7b. AMF generates and stores Kamf_2.

[0103] 7c. The AUSF generates and stores Kausf_2.

[0104] Optionally, the Kausf_2 generated by the AUSF is an optional example of the third AUSF key.

[0105] 8. The UE2 is powered off and the card is inserted into the UE1.

[0106] 9. The UE1 reads the Kamf_2 from the card, which is inconsistent with the Kamf_1 read from the NV memory, and then deletes the Kamf_1, Kamf_2 and Kausf_1, and initiates the initial registration using plaintext.

[0107] Optionally, the UE1 reads the Kamf_2 from the card, which is inconsistent with the Kamf_1 read from the NV memory, which can be an optional example of the step of determining that the second AMF key and the third AMF key are different.

[0108] 10. The UE1 interacts with the AMF, AUSF and UDM to initiate the initial registration process, and the network starts the authentication and security process and negotiates the key with the UE1.

[0109] Optionally, the authentication and security process is an optional example of the second authentication process.

[0110] 11a. The UE1 generates Kamf_3 and Kausf_3, stores the Kamf_3 in the card, and stores the Kamf_3 and Kausf_3 in the NV memory.

[0111] Optionally, the Kamf_3 generated by the UE1 is an optional example of the first AMF key. The Kausf_3 generated by the UE1 is an optional example of the second AUSF key.

[0112] 11b. The AMF generates and stores Kamf_3.

[0113] 11c. The AUSF generates and stores Kausf_3.

[0114] Optionally, the Kausf_3 generated by the AUSF is an optional example of the fourth AUSF key.

[0115] 12. The UDM initiates the UPU process.

[0116] 13. The UDM requests the UPU integrity protection from the AUSF.

[0117] 14. The AUSF calculates the UPU MAC using the Kausf_3, the UPU count value and the UPU data.

[0118] Optionally, the UPU count value and the UPU data can be an optional example of the second update parameter described above. The UPU MAC calculated by the AUSF can be an optional example of the first message authentication code described above.

[0119] 15. The AUSF feeds back the UPU integrity protection response (UPU count value, UPU MAC) to the UDM.

[0120] 16. The UDM triggers the AMF to start the UPU procedure (UPU count value, UPU data, UPU MAC).

[0121] 17. The AMF assembles the UPU container (UPU count value, UPU data, UPU MAC).

[0122] 18. The AMF sends the downlink NAS transmission message (UPU container) to the UE1.

[0123] 19. The UE1 parses the UPU count value, UPU data, and UPU MAC, calculates the UPU MAC using Kausf_3, the UPU count value, and the UPU data, and if the UPU MAC is consistent with the received UPU MAC, the integrity check is successful, and the UE parameter is updated.

[0124] In the above process, the UE1 can use the local Kamf_3 to decrypt the downlink NAS transmission message.

[0125] Optionally, the UPU MAC calculated by the UE1 can be an optional example of the second message authentication code described above.

[0126] Optionally, the UE parameter can be an optional example of the network parameter described above.

[0127] In the above Figure 4 , only a file for storing the AMF key exists in the card, and no file for storing the AUSF key exists. After the network negotiates the key through the authentication and security activation procedure, Kausf_1 and Kamf_1 can be saved in the NV memory of the UE1. When it is found that Kamf_1 in the NV memory and Kamf_2 in the card are different, it is considered that the card can be registered on other equipment (UE2) and the key is re-negotiated with the network. At this time, Kamf_1 and Kamf_2 can be deleted, and the registration procedure is initiated using plaintext to trigger the network to restart the authentication and security activation procedure to re-negotiate the key.

[0128] Optionally, in the following embodiments, an implementation of determining that the first AUSF key does not support updating the network parameter by initiating the network parameter update procedure is shown, which is not limited.

[0129] Figure 5A flowchart of another communication method provided by embodiments of the present disclosure is shown.

[0130] The communication method provided in this embodiment can be applied in a terminal. Alternatively, the execution subject of the communication method in this embodiment can be, for example, a terminal, or a chip, wherein the chip can be deployed in a terminal, or can also be deployed in any other possible device, without any limitation.

[0131] As shown in the figure, the communication method comprises the following steps. Figure 5

[0132] Step S501: determining a third AMF key, wherein the third AMF key is generated by the second terminal through a third authentication process.

[0133] Optionally, the third AMF key is generated by the second terminal through the third authentication process. That is to say, the SIM can first register with the first terminal (UE1) and trigger the first authentication process, then register with the second terminal (UE2) and trigger the third authentication process, and return to the first terminal (UE1). At this time, the SIM card will contain the third AMF key generated by the second terminal (UE2) in the third authentication process.

[0134] Optionally, after the SIM card returns to the first terminal (UE1), the third AMF key can be read from the first file of the SIM card, wherein the third AMF key is generated by the second terminal through the third authentication process.

[0135] Step S502: determining whether the first update parameter is successfully integrity-verified according to the third AMF key and a first AUSF key, wherein the first update parameter is used to update a network parameter, and the first AUSF key is generated by the first terminal through the first authentication process.

[0136] Optionally, since the first AUSF key is generated when the SIM card first registers with the first terminal (UE1), and the first AUSF key is stored in the NV memory of the first terminal, after the SIM card returns to the first terminal (UE1), the third AMF key can be read from the first file of the SIM card. The UDM can initiate a network parameter update process, and the first terminal (UE1) can determine whether the first update parameter is successfully integrity-verified based on the third AMF key and the first AUSF key, and the first update parameter is used to update the network parameter.

[0137] Step S503: determining that the first AUSF key does not support updating the network parameter in the case that the first update parameter is not successfully integrity-verified.

[0138] ​Optionally, if the first terminal (UE1) determines that the integrity verification of the first update parameter has failed, it determines that the first AUSF key does not support updating network parameters, and then triggers subsequent steps.

[0139] Step S504: Trigger the second authentication process through the first terminal to generate the first AMF key and the second AUSF key.

[0140] Optionally, the first AMF key can be stored in the first file of the SIM card and the NV memory of the first terminal, and the second AMF key can be stored in the NV memory. The first AMF key stored in the NV memory of the first terminal can be used to detect whether subsequent network parameter updates are supported.

[0141] Step S505: Update the network parameters based on the first AMF key and the second AUSF key.

[0142] For a detailed description of S504-S505, please refer to the above embodiments, which will not be repeated here.

[0143] In this embodiment, by determining that the first AMF key does not support updating network parameters, where the first AMF key is generated by the first terminal through a first authentication process, and the first terminal triggers a second authentication process to generate a first AMF key and a second AMF key, and updates the network parameters based on the first AMF key and the second AMF key, the system effectively ensures successful updating of the terminal's network parameters, improving communication performance. By determining a third AMF key, where the third AMF key is generated by the second terminal through a third authentication process, and based on the third AMF key and the first AMF key, the system determines whether the integrity verification of the first update parameter (used to update network parameters) was successful. If the integrity verification of the first update parameter is unsuccessful, it is determined that the first AMF key does not support updating network parameters. Therefore, the system greatly improves the flexibility of detecting whether the first AMF key supports updating network parameters and is effectively applicable to various communication scenarios, thus improving applicability.

[0144] like Figure 6 As shown, Figure 6 This is another application flow diagram of an embodiment of this disclosure. Taking the first terminal as UE1, the second terminal as UE2, and the core network equipment as: AMF network element, AUSF network element, UDM network element, the network initiates the UPU process (which can also be applied to the SOR process) as an example.

[0145] 1. Insert the card into UE1.

[0146] 2. UE1 interacts with AMF, AUSF, UDM, initiates initial registration procedure, network starts authentication and security procedure and negotiates keys with UE1.

[0147] Optionally, the authentication and security procedure is one optional example of the first authentication procedure.

[0148] 3a. UE1 generates Kamf_1 and Kausf_1, stores Kamf_1 in the card, and stores Kausf_1 in the NV memory.

[0149] Optionally, the Kamf_1 generated by UE1 is one optional example of the second AMF key described above. The Kausf_1 generated by UE1 is one optional example of the first AUSF key described above.

[0150] 3b. AMF generates and stores Kamf_1.

[0151] 3c. AUSF generates and stores Kausf_1.

[0152] 4. UE1 powers off and removes the card, the card is inserted into UE2.

[0153] 5. There is only Kamf_1 in the card, and there is no Kausf in the NV memory in UE2, delete Kamf_1, and initiate registration using plaintext.

[0154] 6. UE2 interacts with AMF, AUSF, UDM, initiates initial registration procedure, network starts authentication and security procedure and negotiates keys with UE2.

[0155] Optionally, the authentication and security procedure is one optional example of the third authentication procedure.

[0156] 7a. UE2 generates Kamf_2 and Kausf_2, stores Kamf_2 in the card, and stores Kausf_2 in the NV memory.

[0157] Optionally, the Kamf_2 generated by UE2 is one optional example of the third AMF key described above.

[0158] 7b. AMF generates and stores Kamf_2.

[0159] 7c. AUSF generates and stores Kausf_2.

[0160] Optionally, the Kausf_2 generated by AUSF is one optional example of the third AUSF key described above.

[0161] 8. UE2 powers off and removes the card, the card is inserted into UE1.

[0162] 9. UE1 reads Kamf_2 from the card, Kausf_1 from the NV memory.

[0163] 10. UE1 interacts with AMF to initiate the initial registration procedure, network integrity check succeeds, no authentication procedure is started.

[0164] 11. UDM initiates the UPU procedure.

[0165] 12. UDM requests UPU integrity protection from AUSF.

[0166] 13. AUSF calculates UPU MAC using Kausf_2, UPU count value and UPU data.

[0167] Optionally, the UPU count value and UPU data can be an optional example of the first update parameter.

[0168] 14. AUSF feeds back UPU integrity protection response (UPU count value, UPU MAC) to UDM.

[0169] 15. UDM triggers AMF to start the UPU procedure (UPU count value, UPU data, UPU MAC).

[0170] 16. AMF assembles the UPU container (UPU count value, UPU data, UPU MAC).

[0171] 17. AMF sends the downlink NAS transport message (UPU container) to UE1.

[0172] 18. UE1 parses the UPU count value, UPU data and UPU MAC, calculates the UPU MAC using Kausf_1, UPU count value and UPU data, the calculated UPU MAC is inconsistent with the received UPU MAC, the integrity check fails, deletes Kamf_2 and Kausf_1, and initiates the initial registration using plaintext.

[0173] In the above process, UE1 can use local Kamf_2 to decrypt the downlink NAS transport message.

[0174] 19. UE1 interacts with AMF, AUSF and UDM to initiate the registration procedure, and the network starts the authentication and security procedure and negotiates the key with UE1.

[0175] Optionally, the authentication and security procedure is an optional example of the second authentication procedure.

[0176] 20a. UE1 generates Kamf_3 and Kausf_3.

[0177] Optionally, the Kamf_3 generated by the UE1 is an optional example of the first AMF key described above. The Kausf_3 generated by the UE1 is an optional example of the second AUSF key described above.

[0178] 20b. The AMF generates and stores the Kamf_3.

[0179] 20c. The AUSF generates and stores the Kausf_3.

[0180] Optionally, the Kausf_3 generated by the AUSF is an optional example of the fourth AUSF key described above.

[0181] 21. The UE1 interacts with the AMF, the AUSF, and the UDM to perform a UPU procedure, the Kausf_3 used by the UE1 is consistent with the Kausf_3 used by the network, and the integrity check is successful.

[0182] In the above Figure 6 , when the UE1 receives the SOR message or the UPU message, if the integrity check of the current SOR data or UPU data fails, the Kamf_2 and the Kausf_1 can be deleted, the registration procedure is initiated using plaintext, and the network is triggered to re-initiate the authentication and security activation procedure to re-negotiate the key with the UE1.

[0183] Figure 7 A structural schematic diagram of a communication apparatus provided by an embodiment of the present disclosure.

[0184] As Figure 7 shown, the communication apparatus 70 includes:

[0185] A determination module 701 is configured to determine that a first AUSF key does not support updating a network parameter, wherein the first AUSF key is generated by a first terminal through a first authentication procedure.

[0186] A generation module 702 is configured to trigger a second authentication procedure through the first terminal to generate a first AMF key and a second AUSF key.

[0187] An updating module 703 is configured to update the network parameter according to the first AMF key and the second AUSF key.

[0188] Optionally, in some embodiments of the present disclosure, the determination module 701 is configured to:

[0189] determine a third AUSF key, wherein the third AUSF key is used for integrity protection of the update of the network parameter by an AUSF network element, and the third AUSF key is generated by the AUSF network element through a third authentication procedure triggered by a second terminal.

[0190] In a case where the first AUSF key and the third AUSF key are determined to be different, it is determined that the first AUSF key does not support updating the network parameter.

[0191] Optionally, in some embodiments of the present disclosure, the determining module 701 is configured to:

[0192] determine whether the first file and the second file exist in the SIM card, wherein the first file is used to store an AMF key, and the second file is used to store an AUSF key;

[0193] determine whether the SIM card meets a condition, wherein the condition is used to indicate that the SIM card is registered in the first terminal and triggers the first authentication process, is registered in the second terminal and triggers the third authentication process, and is registered in the first terminal again;

[0194] In a case where the first file exists in the SIM card, the second file does not exist, and the SIM card meets the condition, it is determined that the first AUSF key and the third AUSF key are different.

[0195] Optionally, in some embodiments of the present disclosure, the determining module 701 is configured to:

[0196] determine that the first AUSF key is stored in the NV memory of the first terminal;

[0197] read a second AMF key from the NV memory, wherein the second AMF key is generated by the first terminal through the first authentication process;

[0198] read a third AMF key from the first file of the SIM card, wherein the third AMF key is generated by the second terminal through the third authentication process;

[0199] In a case where the second AMF key and the third AMF key are determined to be different, it is determined that the first AUSF key and the third AUSF key are different.

[0200] Optionally, in some embodiments of the present disclosure, the determining module 701 is configured to:

[0201] determine the third AMF key, wherein the third AMF key is generated by the second terminal through the third authentication process;

[0202] determine whether the first update parameter is successfully subjected to integrity verification according to the third AMF key and the first AUSF key, wherein the first update parameter is used to update the network parameter;

[0203] In a case where the first update parameter is not successfully subjected to integrity verification, it is determined that the first AUSF key does not support updating the network parameter.

[0204] Optionally, in some embodiments of the present disclosure, the generating module 702 is further configured to:

[0205] The first AMF key is stored in a first file of the SIM card and an NV memory of the first terminal, and the second AUSF key is stored in the NV memory.

[0206] Optionally, in some embodiments of the present disclosure, the updating module 703 is configured to:

[0207] receive the second update parameter and the first message authentication code according to the first AMF key, wherein the first message authentication code is obtained by processing the second update parameter according to a fourth AUSF key by an AUSF network element, and the fourth AUSF key is generated by the AUSF network element through a second authentication process;

[0208] determine whether the integrity check on the second update parameter is successful according to the second AUSF key and the first message authentication code;

[0209] update the network parameter according to the second update parameter in a case where it is determined that the integrity check on the second update parameter is successful.

[0210] Optionally, in some embodiments of the present disclosure, the updating module 703 is configured to:

[0211] process the second update parameter according to the second AUSF key to obtain a second message authentication code;

[0212] determine that the integrity check on the second update parameter is successful in a case where the first message authentication code is the same as the second message authentication code;

[0213] determine that the integrity check on the second update parameter is not successful in a case where the first message authentication code is different from the second message authentication code.

[0214] Optionally, in some embodiments of the present disclosure, the network parameter comprises at least one of:

[0215] a first parameter, wherein the first parameter is a parameter updated through a terminal parameter updating (UPU) process;

[0216] a second parameter, wherein the second parameter is a parameter updated through a steering of roaming (SOR) process.

[0217] It should be noted that the foregoing explanation and description of the communication method embodiments are also applicable to the communication device of the embodiments, which will not be described herein again.

[0218] In this embodiment, it is determined that the first AUSF key does not support updating the network parameter, wherein the first AUSF key is generated by the first terminal through the first authentication process, and the second authentication process is triggered by the first terminal to generate the first AMF key and the second AUSF key, and the network parameter is updated according to the first AMF key and the second AUSF key. Therefore, the network parameter of the terminal can be effectively ensured to be successfully updated, and the communication performance is improved.

[0219] To implement the above-mentioned embodiments, the present disclosure further provides a communication device, comprising: a processor, and a memory connected with the processor in communication; the memory stores computer execution instructions; and the processor executes the computer execution instructions stored in the memory to implement the method provided by the above-mentioned embodiments.

[0220] Optionally, in some embodiments, the communication device may, for example, be a terminal or a chip, and no limitation is made thereto.

[0221] Figure 8 A block diagram of an exemplary communication device suitable for use in implementing embodiments of the present disclosure is shown. Figure 8 The communication device 12 shown is merely one example and should not be taken as limiting the scope of the functionality or use of the embodiments of the present disclosure. The communication device may, for example, be a terminal, and no limitation is made thereto.

[0222] As shown in Figure 8 The communication device 12 is in the form of a general computing device. Components of the communication device 12 can include, but are not limited to, one or more processors or processing units 16, memory 28, and a bus 18 that connects different system components, including the memory 28 and the processing unit 16.

[0223] The bus 18 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration bus, a processor or local bus using any of a variety of bus architectures including, for example, an Industry Standard Architecture (ISA), Micro Channel Architecture (MCA), Enhanced ISA (EISA), Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus.

[0224] The communication device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the communication device 12, including volatile and non-volatile media, and removable and non-removable media.

[0225] Memory 28 may include computer system readable media in the form of volatile memory, such as Random Access Memory (RAM) 30 and / or cache 32. Communication device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be used to read and write non-removable, non-volatile magnetic media (… Figure 8 Not shown; usually referred to as a "hard drive".

[0226] although Figure 8 As not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disc drive for reading and writing to a removable non-volatile optical disc (e.g., a compact disc read-only memory (CD-ROM), a digital video disc read-only memory (DVD-ROM), or other optical media) may be provided. In these cases, each drive may be connected to bus 18 via one or more data media interfaces. Memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of this disclosure.

[0227] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 42 typically perform the functions and / or methods described in the embodiments of this disclosure.

[0228] The communication device 12 can also communicate with one or more external devices 14 such as a keyboard, a pointing device, a display 24, etc.; one or more devices that enable a human user to interact with the communication device 12; and / or one or more devices (such as network cards, modems, etc.) that enable the communication device 12 to communicate with one or more other computing devices. Such communication can occur via an input / output (I / O) interface 22. Still yet, the communication device 12 can communicate with one or more networks such as a local area network (LAN), a wide area network (WAN), and / or the public switched telephone network (PSTN) and / or an internet which can be utilized to communicate with other computer systems through a network adapter 20. As shown, the network adapter 20 communicates with the other components of the communication device 12 via the bus 18. It should be appreciated that although not shown, other hardware and / or software modules could be used in connection with the communication device 12. Such modules include, but are not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.

[0229] The processing unit 16 performs various function applications and data processing by running programs stored in the memory 28, such as implementing the method mentioned in the foregoing embodiments.

[0230] To implement the foregoing embodiments, the present disclosure further provides a chip, comprising: the chip comprises a processing circuit, the processing circuit is configured to perform the method provided in the foregoing embodiments.

[0231] Figure 9 FIG. 9 is a structural schematic diagram of a chip according to an embodiment of the present disclosure. As shown in FIG. 9, but the chip 900 is not limited to this. Figure 9

[0232] The chip 900 comprises a processing circuit 901 and an interface circuit 902. The interface circuit 902 is configured to read instructions, and the interface circuit 902 sends the instructions to the processing circuit 901, so that the processing circuit 901 performs the method in the foregoing embodiments.

[0233] Optionally, as shown in FIG. 10, the chip 900 further comprises a memory 903 configured to store the instructions. The interface circuit 902 can be configured to read the instructions stored in the memory 903. Figure 10 Figure 10 FIG. 11 is another structural schematic diagram of a chip according to an embodiment of the present disclosure. The chip 900 can further comprise a memory 903 configured to store the instructions. The interface circuit 902 can be configured to read the instructions stored in the memory 903.

[0234] ​​Optionally, the interface circuit 902 is connected with the memory 903, and the interface circuit 902 can be used to receive signals from the memory 903 or other devices, and the interface circuit 902 can be used to send signals to the memory 903 or other devices. For example, the interface circuit 902 can read the instructions stored in the memory 903 and send the instructions to the processing circuit 901.

[0235] Optionally, the number of memories 903 can be one or more. The number of interface circuits 902 can also be one or more.

[0236] In some embodiments, the interface circuit 902 performs at least one of the communication steps such as sending and / or receiving in the above-mentioned methods, and the processing circuit 901 performs other steps.

[0237] In some embodiments, the interface circuit, interface, transceiver pin, transceiver, and the like can be replaced with each other.

[0238] Optionally, all or part of the memory 903 can also be outside the chip 900.

[0239] In order to achieve the above-mentioned embodiments, the present disclosure further proposes a non-transitory computer-readable storage medium, which stores a computer program, and the program is executed by a processor to implement the method proposed in the above-mentioned embodiments of the present disclosure.

[0240] In order to achieve the above-mentioned embodiments, the present disclosure further proposes a computer program product, when the instructions in the computer program product are executed by a processor, the method proposed in the above-mentioned embodiments of the present disclosure is executed.

[0241] The collection, storage, use, processing, transmission, provision, and disclosure of user personal information involved in the present disclosure comply with relevant laws and regulations and do not violate public order and good customs.

[0242] It should be noted that the personal information from the user should be collected for legal and reasonable purposes, and should not be shared or sold outside these legal uses. In addition, such collection / sharing should be carried out after the user's informed consent is received, including but not limited to informing the user to read the user agreement / user notice before the user uses the function, and signing the agreement / authorization including authorization of relevant user information. In addition, any necessary steps should be taken to protect and ensure access to such personal information data, and to ensure that other people with access to personal information data comply with their privacy policies and processes.

[0243] The present disclosure contemplates that the systems and methods described herein can be deployed in various environments in which privacy of personal information is of concern. For example, the systems and methods described herein can be used in applications in which the user has specifically provided consent to the collection of personal information, such as in a social network environment. In this regard, the present disclosure contemplates providing user control over what information is collected, how that information is collected, and how it is used and shared.

[0244] In the preceding embodiments descriptions, reference has been made to descriptive terms such as "one embodiment", "some embodiments", "an example", "a specific example" or "some examples" etc. It is emphasized that these terms are intended to convey that any particular feature, structure, material or characteristic described in connection with the embodiment or example is included in at least one embodiment or example of the present disclosure. Descriptive terms such as these are not necessarily used in reference to the same embodiment or example throughout the specification. Furthermore, the particular features, structures, materials, or characteristics being described can be combined in any suitable manner in one or more embodiments or examples. Moreover, different embodiments or examples described in this specification and different features, structures, materials or characteristics of different embodiments or examples can be combined and combined in any suitable manner, without departing from the scope of the present disclosure, provided that the combination results in a coherent implementation and does not contradict the description.

[0245] Furthermore, the terms "first", "second", etc. are used herein only to describe all possible different arrangements, and do not connote relative importance or a number of the specified technical features. Therefore, a feature defined with "first", "second", etc. can explicitly or implicitly include at least one of the feature. In the description of the present disclosure, the meaning of "a plurality" is at least two, for example, two, three, etc., unless otherwise specifically defined.

[0246] Any process or method descriptions or blocks in flow charts or otherwise described herein represent embodiments which can be managed as one or more modules, segments, or portions of code which include one or more steps for implementing specific logic functions, and preferred embodiments of the present disclosure also contemplate the combination of other steps, functions, and / or structures with these one or more steps, functions, and / or structures. Unless otherwise specifically noted, the order or arrangement of steps, or sequence or order of functions and / or structures does not generally limit the implementation of the embodiments of the disclosure, except where specified.

[0247] The logic and / or steps represented in flow diagrams or otherwise described herein, for example, can be considered as a sequence of executable instructions, and can be embodied in any computer-readable medium for use by or in connection with an instruction execution system, apparatus, or device, such as a computer-based system, processor-containing system, or other system that can fetch the instructions from the instruction execution system, apparatus, or device and execute the instructions. For purposes of this specification, a "computer-readable medium" can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device. The computer-readable medium can be a product of the manufacturing and / or processing. The computer-readable medium can include, but is not limited to, the following: an electronic connection (an electronic device having one or more wires), a portable computer diskette (a magnetic device), a RAM (random access memory), a ROM (read-only memory), an EPROM (erasable programmable ROM) or Flash memory, an optical fiber device, and a portable CD ROM. Additionally, the computer-readable medium can be paper or another suitable medium upon which the program is printed, as the program can be electronically captured, via, for example, an optical scanner, then compiled, interpreted, or otherwise processed, and stored in a computer memory in order to be executed.

[0248] It should be understood that portions of the present disclosure can be implemented in hardware, software, firmware, or combinations thereof. In the above embodiments, the various steps or methods can be implemented in software or firmware stored in a memory and executed by a suitable instruction execution system. As such, if implemented in hardware and in another embodiment, any of the following technologies, or combinations thereof, can be used: discrete logic circuitry having logic gates for implementing logic functions upon data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), and the like.

[0249] Those of ordinary skill in the art can understand that all or part of the steps involved in the above-mentioned embodiment methods can be completed by programs instructing relevant hardware, and the programs can be stored in a computer-readable storage medium. When the programs are executed, one or a combination of the steps of the method embodiments is included.

[0250] In addition, each functional unit in each embodiment of the present disclosure can be integrated in one processing module, or each unit can exist physically separately, or two or more units can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of a software functional module. When the integrated module is realized in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer readable storage medium.

[0251] The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present disclosure have been shown and described above, it should be understood that the above embodiments are exemplary and should not be construed as limiting the present disclosure, and those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present disclosure.

Claims

1. A communication method characterized by comprising: The method comprises: determining that a first AUSF key does not support updating a network parameter, wherein the first AUSF key is generated by a first terminal through a first authentication process; triggering, by the first terminal, a second authentication process to generate a first AMF key and a second AUSF key; updating the network parameter according to the first AMF key and the second AUSF key; The determination that the first AUSF key does not support updating the network parameter comprises: determining a third AUSF key, wherein the third AUSF key is used for integrity protection of the AUSF network element on updating the network parameter, and the third AUSF key is generated by the AUSF network element through a third authentication process triggered by a second terminal; in a case where the first AUSF key and the third AUSF key are determined to be different, determining that the first AUSF key does not support updating the network parameter.

2. The method of claim 1, wherein, The determination that the first AUSF key and the third AUSF key are different comprises: determining whether a first file and a second file exist in a SIM card, wherein the first file is used to store an AMF key, and the second file is used to store an AUSF key; determining whether the SIM card meets a condition, wherein the condition is used to indicate that the SIM card is registered to the first terminal and triggers the first authentication process first, is registered to the second terminal and triggers the third authentication process, and is registered to the first terminal again; in a case where the first file exists in the SIM card, the second file does not exist, and the SIM card meets the condition, determining that the first AUSF key and the third AUSF key are different.

3. The method of claim 1, wherein, The determination that the first AUSF key and the third AUSF key are different comprises: determining that the first AUSF key is stored in an NV memory of the first terminal; reading a second AMF key from the NV memory, wherein the second AMF key is generated by the first terminal through the first authentication process; reading a third AMF key from a first file of a SIM card, wherein the third AMF key is generated by the second terminal through the third authentication process; in a case where the second AMF key and the third AMF key are different, determining that the first AUSF key and the third AUSF key are different.

4. The method of claim 1, wherein, The determination that the first AUSF key does not support updating the network parameter comprises: determining a third AMF key, wherein the third AMF key is generated by a second terminal through a third authentication process; determining whether integrity verification of a first update parameter is successful according to the third AMF key and the first AUSF key, wherein the first update parameter is used to update the network parameter; in a case where the integrity verification of the first update parameter is not successful, determining that the first AUSF key does not support updating the network parameter.

5. The method of claim 1, wherein, The method further comprises: store the first AMF key to a first file of a SIM card and an NV memory of the first terminal, and store the second AUSF key to the NV memory.

6. The method of claim 1, wherein, The updating the network parameter according to the first AMF key and the second AUSF key comprises: receiving a second update parameter and a first message authentication code according to the first AMF key, wherein the first message authentication code is processed by an AUSF network element according to a fourth AUSF key, and the fourth AUSF key is generated by the AUSF network element through the second authentication process; determining whether the second update parameter is successfully integrity-verified according to the second AUSF key and the first message authentication code; updating the network parameter according to the second update parameter in a case that the second update parameter is successfully integrity-verified.

7. The method of claim 6, wherein, The determining whether the second update parameter is successfully integrity-verified according to the second AUSF key and the first message authentication code comprises: processing the second update parameter according to the second AUSF key to obtain a second message authentication code; determining that the second update parameter is successfully integrity-verified in a case that the first message authentication code and the second message authentication code are the same; determining that the second update parameter is not successfully integrity-verified in a case that the first message authentication code and the second message authentication code are different.

8. The method according to any one of claims 1 to 7, characterized in that, The network parameter comprises at least one of: a first parameter, wherein the first parameter is a parameter updated through a terminal parameter update (UPU) process; a second parameter, wherein the second parameter is a parameter updated through a steering of roaming (SOR) process.

9. A communications device, characterized by comprise: a determining module configured to determine that a first AUSF key does not support updating a network parameter, wherein the first AUSF key is generated by a first terminal through a first authentication process; a generating module configured to trigger a second authentication process through the first terminal to generate a first AMF key and a second AUSF key; an updating module configured to update the network parameter according to the first AMF key and the second AUSF key. The determining that the first AUSF key does not support updating the network parameter comprises: determining a third AUSF key, wherein the third AUSF key is used for integrity protection of updating the network parameter by an AUSF network element, and the third AUSF key is generated by the AUSF network element through a third authentication process triggered by a second terminal; determining that the first AUSF key does not support updating the network parameter in a case that the first AUSF key and the third AUSF key are different.

10. A communication device, characterized by comprise: a processor, and a memory connected with the processor in communication; the memory stores computer-executed instructions; the processor executes the computer-executed instructions stored in the memory to implement the method according to any one of claims 1-8.

11. A computer readable storage medium, characterized in that, The computer readable storage medium stores computer-executable instructions that, when executed by the processor, implement the method of any of claims 1-8.

12. A chip comprising processing circuitry, interface circuitry; wherein, The interface circuit is configured to read the instructions and to transmit the instructions to the processing circuitry to cause the processing circuitry to perform the method of any of claims 1-8.

Citation Information

Patent Citations

  • Communication method and apparatus

    WO2022067803A1