Security context generation method and device and computer readable storage medium

By generating independent security contexts for different communication services in terminal devices, the problem of reduced security caused by public network services and private network services sharing the same security context is solved, achieving security isolation between services and improving overall communication security.

CN120935569APending Publication Date: 2025-11-11HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511182268.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2020-12-25
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

In PNI-NPN, the sharing of the same security context between public network services and private network services leads to a decrease in the security of communication services. If an attacker breaks the security context of one service, it will affect the security of the other service.

Method used

After obtaining the first security context, the terminal device obtains the second security context by generating additional instructions. It then uses different derived parameters and authentication keys to generate different security keys and algorithms, ensuring that different communication services use different security contexts and achieving isolation.

Benefits of technology

By isolating the security contexts of different communication services, attackers are prevented from cracking one service and affecting another, thus improving the security and isolation effectiveness of communication services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120935569A_ABST
    Figure CN120935569A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a security context generation method and device and a computer readable storage medium, and the method comprises the steps: receiving a session request message from a terminal device, the session request message being used for requesting the establishment of a session of a second communication service; an additional security context indication is sent to the data transmission network element, the additional security context indication is used for indicating generation of a second security context, and the second security context is used for protecting the second communication service; and sending a session acceptance message to the terminal device, wherein the session acceptance message is used for completing establishment of the session of the second communication service. The second security context is different from the first security context, the first security context is used for protecting a first communication service of the terminal device, and the first communication service is different from the second communication service. According to the embodiment of the invention, different communication services are protected through different security contexts, so that the security of the communication services can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application. The original application has the application number 202080107902.9 and the original application date is December 25, 2020. The entire contents of the original application are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communication technology, and in particular to a method, apparatus and computer-readable storage medium for generating a security context. Background Technology

[0003] Public networks are communication networks built by network service providers for public use. To meet the network resource needs of certain individuals, businesses, and companies, operators allocate portions of network resources to these users, forming private networks. These private networks are called public network integrated non-public networks (PNI-NPN). In PNI-NPN, user equipment (UE) can connect to the public land mobile network (PLMN) for public network services, or connect to the non-public network (NPN) for private network services. Currently, UEs can connect to the same radio access network (RAN) to simultaneously perform public and private network services, using the same security context for communication. When an attacker cracks the security context used for public network services, they gain access to the corresponding private network service's security context. Conversely, when an attacker obtains the algorithm used for private network services, they also gain access to the corresponding public network service's security context. Therefore, security attacks targeting public or private network services may affect the corresponding private or public network services, thereby reducing the security of communication services. Summary of the Invention

[0004] This invention discloses a security context generation method, apparatus, and computer-readable storage medium for improving the security of communication services.

[0005] The first aspect discloses a security context generation method, which can be applied to a terminal device or a module (e.g., a chip) within the terminal device. The following description uses a terminal device as an example. The security context generation method may include: the terminal device acquiring a first security context, which is used to protect a first communication service of the terminal device; the terminal device sending a session request message to a session management function network element, which is used to request the establishment of a session for a second communication service, which is different from the first communication service; the terminal device receiving a session acceptance message from the session management function network element, which is used to complete the establishment of the second communication service session; the terminal device acquiring an additional generation instruction; and the terminal device acquiring a second security context based on the additional generation instruction, which is used to protect the second communication service.

[0006] In this embodiment, the terminal device can obtain a second security context in addition to obtaining a first security context. The first and second security contexts can protect different communication services respectively. This isolates the protection of different services, preventing an attack on one communication service from affecting another, thereby improving the security of communication services.

[0007] As one possible implementation, the session request message includes first indication information, which is used to indicate that the terminal device supports generating the second security context.

[0008] In this embodiment of the application, when the session request message includes first indication information, the session management function network element can directly determine the second security context based on this indication information, which can reduce the processing steps of the session management function network element and thus improve the generation efficiency of the second security context.

[0009] As one possible implementation, the terminal device obtains a second security context according to the additional generation instruction, including: the terminal device obtains a security key based on a first key according to the additional generation instruction; and / or the terminal device obtains a security algorithm according to the additional generation instruction.

[0010] In this embodiment, the security context may include a security key and / or a security algorithm. The security context can provide encryption and integrity protection for data, thereby ensuring the security and reliability of data in communication services.

[0011] As one possible implementation, the terminal device obtains a security key based on the first key according to the additional generation instruction, including: the terminal device obtaining the first key based on the access stratum (AS) root key of the first security context according to the additional generation instruction; and the terminal device generating the security key based on the first key.

[0012] In this embodiment, when the terminal device generates a security key, it can generate the first key by generating the AS root key of the first security context. Since the AS root key is known and does not need to be generated, the process of generating the second security context can be reduced, thereby improving the efficiency of generating the second security context.

[0013] As one possible implementation, the additional generation instruction includes an indication of the first derived parameter, and the terminal device obtains the first key based on the AS root key of the first security context according to the additional generation instruction, including: the terminal device generating the first key according to the AS root key of the first security context and the first derived parameter.

[0014] In this embodiment of the application, since the first key is generated based on the first derived parameters, and different first derived parameters result in different generated keys, it can prevent the security key included in the second security context from being the same as the security key included in the first security context. This ensures that different communication services use different security contexts, thereby guaranteeing the effectiveness of security isolation and improving the security of communication services.

[0015] In one possible implementation, the first derived parameter is the downlink packet data convergence protocol (PDCP) number COUNT, and the indication of the first derived parameter is a portion of the bits of the downlink PDCP COUNT.

[0016] In this embodiment, when the first derived parameter is the downlink PDCP COUNT, the corresponding COUNT value can change as the number of security contexts generated changes. This change in COUNT value prevents the generation of identical first keys, thus preventing identical security keys and ensuring that the generated security contexts are different. Different security contexts are used to protect different communication services, ensuring the effectiveness of security isolation for communication services and thereby improving the security of communication services.

[0017] As one possible implementation, after the terminal device sends the session request message to the session management function network element and before the terminal device receives the additional generation instruction, the security context generation method further includes: the terminal device performing secondary authentication; the terminal device generating a secondary authentication key during the secondary authentication process; and the terminal device obtaining a security key based on a first key according to the additional generation instruction, including: the terminal device obtaining the first key based on the secondary authentication key according to the additional generation instruction; and the terminal device generating a security key based on the first key.

[0018] In this embodiment, the terminal device can perform two-factor authentication, and then generate a first key using the authentication key obtained from the two-factor authentication. Since different authentication keys result in different first keys, the security key included in the second security context generated using the first key is also different from the security key included in the first security context, thus ensuring that the generated security contexts are different. Different security contexts are used to protect different communication services, ensuring the effectiveness of security isolation of communication services and thereby improving the security of communication services.

[0019] In one possible implementation, the additional generation instruction includes an instruction for a second derived parameter, and the terminal device obtains the first key based on the secondary authentication key according to the additional generation instruction, including: the terminal device generates the first key based on the secondary authentication key and the second derived parameter according to the instruction for the second derived parameter.

[0020] In this embodiment, the terminal device can generate a first key based on the second derived parameters. Since different second derived parameters result in different first keys, this prevents the security key in the generated second security context from being the same as the security key in the first security context. It ensures that different communication services use different security contexts, guaranteeing the effectiveness of security isolation and thus improving the security of communication services.

[0021] As one possible implementation, the second derived parameter is one or more of the following parameters: downlink non-access stratum (NAS) number COUNT, protocol data unit (PDU) session identity document (ID), network slice selection assistance information (NSSAI), and data network name (DNN).

[0022] In this embodiment, when NAS COUNT is used as a parameter for deriving the first key, the derived first key is always different because the COUNT value changes each time. Similarly, when PDU session ID, NSSAI, or DNN is used as a parameter for deriving the first key, the derived first key is also different due to differences in the terminal device's PDU session, the accessed slice, and the data network. Different first keys can generate different security keys, and different security keys ensure different security contexts are generated. Different security contexts can be used to protect different communication services, ensuring the effectiveness of security isolation for communication services and thus improving the security of communication services.

[0023] As one possible implementation, the terminal device generates the security key based on the first key, including: the terminal device generates the security key based on the first key and a third derived parameter.

[0024] In this embodiment, the terminal device can generate a security key based on a first key and a third derived parameter. Since different third derived parameters result in different generated security keys, it avoids the generated security key being the same as an existing security key, thus ensuring that the generated security contexts are different. Protecting different communication services with different security contexts ensures the effectiveness of security isolation for communication services, thereby improving the security of communication services.

[0025] As one possible implementation, the additional generation instruction includes the identifier of the security algorithm, and the terminal device generates the security key based on the first key and the third derived parameters, including: the terminal device generates the security key based on the first key and the identifier and type of the security algorithm.

[0026] In this embodiment of the application, since the type and length of the security key in the second security context are both determined, the security key can be determined by the identifier and type of the corresponding security algorithm, thereby ensuring the validity of the generated security key.

[0027] As one possible implementation, the additional generation instruction includes an identifier of the security algorithm.

[0028] In this embodiment, after the terminal device obtains the identifier of the security algorithm, it can directly determine the security algorithm based on the identifier, thereby ensuring the consistency of the security algorithms generated by the terminal device and the data transmission network element, reducing the process of the terminal device determining the security algorithm, and improving the efficiency of security context generation.

[0029] As one possible implementation, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.

[0030] In this embodiment of the application, the first communication service and the second communication service are different communication services. When one communication service is a private network service and the other communication service is a public network service, it can be ensured that different communication services are protected using different security contexts, and the security isolation between public network services and private network services can be guaranteed, thereby improving the security of public network services and private network services.

[0031] The second aspect discloses a security context generation method, which can be applied to a session management function network element or a module (e.g., a chip) within the session management function network element. The following description uses a session management function network element as an example. The security context generation method may include: the session management function network element receiving a session request message from a terminal device, the session request message being used to request the establishment of a session for a second communication service; the session management function network element sending an additional security context indication to a data transmission network element, the additional security context indication being used to instruct the generation of a second security context, the second security context being used to protect the second communication service; and the session management function network element sending a session acceptance message to the terminal device, the session acceptance message being used to complete the establishment of the second communication service session.

[0032] In this embodiment, after receiving a session request message, the session management function network element can respond to a request to generate a second security context. The session management function network element sends an additional security context indication, and the data transmission network element can generate a second security context based on the additional security context. The session management function network element can coordinate with the terminal device and the data transmission network element to generate the second security context, thereby ensuring the generation of the second security context.

[0033] As one possible implementation, the session request message includes first indication information, which is used to indicate that the terminal device supports the generation of a second security context. The session management function network element sends an additional security context indication to the data transmission network element, including: when the first indication information indicates that the terminal device supports the generation of the second security context, the session management function network element sends the additional security context indication to the data transmission network element.

[0034] In this embodiment of the application, when the session request message includes first indication information, the session management function network element can directly determine the generation of the second security context based on this indication information, which can reduce the processing of the session management function network element and thus improve the generation efficiency of the second security context.

[0035] As one possible implementation, the session management function network element sends an additional security context indication to the data transmission network element, including: the session management function network element obtaining the subscription information of the terminal device according to the session request message; when the subscription information of the terminal device indicates that the second security context needs to be generated, the session management function network element sends the additional security context indication to the data transmission network element.

[0036] In this embodiment of the application, the session management function network element can also determine whether to send an additional security context indication based on the subscription information. The session request message may not carry indication information for determining whether to generate a second security context, thereby reducing information transmission and saving communication resources.

[0037] As one possible implementation, the session management function network element sends an additional security context indication to the data transmission network element, including: when the local policy configured by the session management function network element indicates that the second security context needs to be generated, the session management function network element sends the additional security context indication to the data transmission network element.

[0038] In this embodiment of the application, the session management function network element can determine whether to send an additional security context indication based on local policies. In this case, the session request message may not carry indication information for determining whether to generate a second security context, thereby reducing information transmission and saving communication resources.

[0039] As one possible implementation, the additional security context indication includes an identifier of the security algorithm, and the method further includes: the session management function network element acquiring the security algorithm.

[0040] In this embodiment, after the session management function network element determines the security algorithm, the terminal device and the data transmission network element can receive the identifier of the security algorithm determined by the session management function network element. The terminal device and the data transmission network element can directly determine the security algorithm based on the identifier, so as to reduce the process of the terminal device and the data transmission network element determining the security algorithm and save processing resources, thereby improving the efficiency of security context generation.

[0041] In one possible implementation, the additional security context indication includes a first key, and the method further includes: the session management function network element triggering secondary authentication; after the secondary authentication is successful, the session management function network element receives a secondary authentication key from the authentication, authorization, and accounting network element; and the session management function network element obtaining the first key based on the secondary authentication key.

[0042] In this embodiment, the session management function network element can trigger secondary authentication to obtain an authentication key, which can then be used to generate a first key. Since different authentication keys result in different first keys, the security key included in the second security context generated from the first key is also different from the security key included in the first security context, thus ensuring that the generated security contexts are different. Different security contexts are used to protect different communication services, ensuring the effectiveness of communication service security isolation and thereby improving the security of communication services.

[0043] As one possible implementation, the session management function network element obtaining the first key based on the secondary authentication key includes: the session management function network element obtaining the first key based on the secondary authentication key and the second derived parameter.

[0044] In this embodiment, the session management network element can generate a first key based on the second derived parameters. Different second derived parameters result in different first keys. Therefore, it prevents the security key included in the generated second security context from being the same as the security key included in the first security context, ensuring that different communication services use different security contexts. This guarantees the effectiveness of security isolation, thereby improving the security of communication services.

[0045] As one possible implementation, the second derived parameter is one or more of the following parameters: downlink NASCOUNT, PDU session ID, NSSAI, and DNN.

[0046] In this embodiment, when NAS COUNT is used as a parameter for deriving the first key, the derived first key is always different because the COUNT value changes each time. Similarly, when one or more of PDU session ID, NSSAI, and DNN are used as parameters for deriving the first key, the derived first key is also different due to variations in the terminal device's PDU session, the accessed slice, and the data network. Different first keys can generate different security keys, and different security keys ensure different security contexts are generated. Different security contexts can be used to protect different communication services, ensuring the effectiveness of security isolation for communication services and thus improving the security of communication services.

[0047] In one possible implementation, the session acceptance message includes an indication of a second derived parameter, which is used to indicate how to obtain a security key based on the secondary authentication key.

[0048] In this embodiment, when the session management function network element receives an indication of the second derived parameter, the session management network element can generate a first key based on the secondary authentication key and the second derived parameter. Different second derived parameters result in different generated security keys, which in turn result in different generated security contexts. These different security contexts ensure the effectiveness of secure isolation for communication services, thereby improving the security of communication services.

[0049] The third aspect discloses a security context generation method, which can be applied to data transmission network elements or modules (e.g., chips) within a data transmission network element. The following description uses a data transmission network element as an example. The security context generation method may include: the data transmission network element receiving an additional security context indication from a session management function network element; the data transmission network element obtaining a second security context based on the additional security context indication, the second security context being used to protect a second communication service; and the data transmission network element sending an additional generation indication to a terminal device, the additional generation indication being used to instruct the generation of the second security context.

[0050] In this embodiment of the application, the data transmission network element can obtain a second security context, which can protect the second communication service and thereby improve the security of the second communication service.

[0051] As one possible implementation, the data transmission network element obtains a second security context according to the additional security context indication, including: the data transmission network element obtains a security key based on a first key according to the additional security context indication; and / or the data transmission network element obtains a security algorithm according to the additional security context indication.

[0052] In this embodiment, the security context may include a security key and / or a security algorithm. The security context can provide encryption and integrity protection for data, thereby ensuring the security and reliability of data in communication services.

[0053] As one possible implementation, before the data transmission network element receives an additional security context indication from the session management function network element, the security context generation further includes: the data transmission network element obtaining a first security context, the first security context being used to protect a first communication service, the first communication service being different from the second communication service.

[0054] In this embodiment, the data transmission network element can acquire a second security context in addition to the first security context. The first and second security contexts can protect different communication services respectively. This isolates the protection of different services, preventing an attack on one communication service from affecting another, thereby improving the security of communication services.

[0055] As one possible implementation, the data transmission network element generates the security key based on the first key according to the additional security context indication, including: the data transmission network element obtaining the first key based on the AS root key of the first security context according to the additional security context indication; and the data transmission network element generating the security key according to the first key.

[0056] In this embodiment, when the data transmission network element generates a security key, it can generate the first key by generating the AS root key of the first security context. Since the AS root key is known and does not need to be generated, the process of generating the second security context can be reduced, thereby improving the efficiency of generating the second security context.

[0057] As one possible implementation, the additional generation indication includes an indication of the first derived parameter, and the data transmission network element obtains the first key based on the AS root key of the first security context according to the additional security context indication, including: the data transmission network element generates the first key according to the AS root key of the first security context and the first derived parameter.

[0058] In this embodiment, since the first key is generated based on the first derived parameters, and different first derived parameters result in different first keys, it can prevent the security key included in the generated second security context from being the same as the security key included in the first security context. This ensures that different communication services use different security contexts, thereby guaranteeing the effectiveness of security isolation and improving the security of communication services.

[0059] As one possible implementation, the first derived parameter is a downlink PDCP COUNT, and the indication of the first derived parameter is a portion of the bits of the downlink PDCP COUNT.

[0060] In this embodiment, when the first derived parameter is the downlink PDCP COUNT, the corresponding COUNT value can change as the number of security contexts generated changes. The change in the COUNT value prevents the generated first keys from being identical, thus preventing the generation of identical security keys and ensuring that the generated security contexts are different. Different security contexts are used to protect different communication services, ensuring the effectiveness of security isolation for communication services and thereby improving the security of communication services.

[0061] In one possible implementation, the additional security context indication includes the first key, and the data transmission network element obtains the security key based on the first key according to the additional security context indication, including: the data transmission network element generating the security key according to the first key.

[0062] In this embodiment, the data transmission network element can generate a security key based on the received first key. The first key can be a key generated by the session management function network element based on the authentication key obtained through secondary authentication. Since different authentication keys result in different first keys, the security key included in the second security context generated using the first key is also different from the security key included in the first security context, thus ensuring that the generated security contexts are different. Different security contexts are used to protect different communication services, ensuring the effectiveness of security isolation for communication services and thereby improving the security of communication services.

[0063] As one possible implementation, the data transmission network element generates the security key based on the first key, including: the data transmission network element generates the security key based on the first key and a third derived parameter.

[0064] In this embodiment, the data transmission network element can generate a security key based on a first key and a third derived parameter. Since different third derived parameters result in different generated security keys, different communication services are protected through different security contexts. This ensures the effectiveness of secure isolation of communication services, thereby improving the security of communication services.

[0065] As one possible implementation, the additional security context indication includes the identifier of the security algorithm, and the data transmission network element generates the security key based on the first key and the third derived parameters, including: the data transmission network element generates the security key based on the first key and the identifier and type of the security algorithm.

[0066] In this embodiment of the application, since the type and length of the security key in the second security context are both determined, the security key can be determined by the identifier and type of the corresponding security algorithm, thereby ensuring the validity of the generated security key.

[0067] As one possible implementation, the additional generation instruction includes an identifier of the security algorithm.

[0068] In this embodiment, after the terminal device obtains the identifier of the security algorithm, it can directly determine the security algorithm based on the identifier. This ensures the consistency of the security algorithms generated by the terminal device and the data transmission network element, reduces the process of the data transmission network element determining the security algorithm, and improves the efficiency of security context generation. Furthermore, the data transmission network element can determine the security algorithm and share the identifier of the security algorithm.

[0069] As one possible implementation, the additional security context indication includes an identifier of the security algorithm.

[0070] In this embodiment, after the data transmission network element obtains the identifier of the security algorithm, it can directly determine the security algorithm based on the identifier. This ensures the consistency of the security algorithms generated by the terminal device and the data transmission network element, reduces the process of the data transmission network element determining the security algorithm, and improves the efficiency of security context generation.

[0071] As one possible implementation, the data transmission network element obtains the security algorithm according to the additional security context indication, including: the data transmission network element obtains the security algorithm based on the security capabilities of the terminal device and a pre-configured algorithm priority list according to the additional security context indication, wherein the security capabilities of the terminal device are used to indicate all security algorithms supported by the terminal device.

[0072] In this embodiment, the data transmission network element can obtain a security algorithm based on the security capabilities of the corresponding terminal device and a pre-configured algorithm priority list. The algorithm priority list is pre-configured by the data transmission network element, and each terminal device can pre-configure its own corresponding security algorithm. The data transmission network element can determine the security algorithms of all corresponding terminal devices through the algorithm priority list. When a terminal device suffers a security attack, the security algorithm of that specific terminal device may be leaked, but the security algorithms of all terminal devices will not be leaked, thereby improving the security of communication services between different terminal devices.

[0073] As one possible implementation, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.

[0074] In this embodiment of the application, the first communication service and the second communication service are different communication services. When one communication service is a private network service and the other communication service is a public network service, it can be ensured that different communication services are protected using different security contexts, and the security isolation between public network services and private network services can be guaranteed, thereby improving the security of public network services and private network services.

[0075] The fourth aspect discloses a security context generation apparatus, which can be a terminal device or a module (e.g., a chip) within the terminal device. The apparatus may include:

[0076] An acquisition unit is configured to acquire a first security context, wherein the first security context is used to protect the first communication service of the terminal device.

[0077] The sending unit is used to send a session request message to the session management function network element. The session request message is used to request the establishment of a session for a second communication service, which is different from the first communication service.

[0078] The receiving unit is configured to receive a session acceptance message from the session management function network element, wherein the session acceptance message is used to complete the establishment of a session for the second communication service;

[0079] The acquisition unit is also used to acquire additional generation instructions;

[0080] The acquisition unit is further configured to acquire a second security context according to the additional generation instruction, the second security context being used to protect the second communication service.

[0081] As one possible implementation, the session request message includes first indication information, which is used to indicate that the terminal device supports generating the second security context.

[0082] As one possible implementation, the acquisition unit acquires a second security context according to the additional generation instruction, the second security context being used to protect the second communication service including:

[0083] According to the additional generation instruction, obtain a security key based on the first key; and / or

[0084] The security algorithm is obtained based on the additional generation instructions.

[0085] As one possible implementation, the acquisition unit acquires the security key based on the first key according to the additional generation instruction, including:

[0086] According to the additional generation instruction, the first key is obtained based on the AS root key of the first security context;

[0087] The security key is generated based on the first key.

[0088] As one possible implementation, the additional generation indication includes an indication of the first derived parameter, and the acquisition unit acquires the first key based on the AS root key of the first security context according to the additional generation indication, including:

[0089] The first key is generated based on the AS root key of the first security context and the first derived parameters.

[0090] As one possible implementation, the first derived parameter is a downlink PDCP COUNT, and the indication of the first derived parameter is a portion of the bits of the downlink PDCP COUNT.

[0091] As one possible implementation, the device may further include:

[0092] The execution unit is used to perform secondary authentication;

[0093] A generation unit is used to generate a secondary authentication key during the secondary authentication process;

[0094] The acquisition unit acquires the security key based on the first key according to the additional generation instruction, including:

[0095] Based on the additional generation instruction, the first key is obtained using the secondary authentication key;

[0096] Generate a security key based on the first key.

[0097] As one possible implementation, the additional generation indication includes an indication of the second derived parameter, and the acquisition unit acquires the first key based on the secondary authentication key according to the additional generation indication, including:

[0098] The first key is generated based on the secondary authentication key and the second derived parameter, according to the indication of the second derived parameter.

[0099] As one possible implementation, the second derived parameter is one or more of the following parameters: downlink NASCOUNT, PDU session ID, NSSAI, and DNN.

[0100] As one possible implementation, the acquisition unit generates a security key based on the first key, including:

[0101] The security key is generated based on the first key and the third derived parameter.

[0102] As one possible implementation, the additional generation indication includes an identifier of the security algorithm, and the acquisition unit generates the security key based on the first key and the third derived parameters, including:

[0103] The security key is generated based on the first key and the identifier and type of the security algorithm.

[0104] As one possible implementation, the additional generation instruction includes an identifier of the security algorithm.

[0105] As one possible implementation, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.

[0106] The fifth aspect discloses a security context generation apparatus, which can be a session management function network element or a module (e.g., a chip) within the session management function network element. The apparatus may include:

[0107] A receiving unit is configured to receive a session request message from a terminal device, wherein the session request message is used to request the establishment of a session for a second communication service;

[0108] A sending unit is configured to send an additional security context indication to a data transmission network element, wherein the additional security context indication is used to indicate the generation of a second security context, and the second security context is used to protect the second communication service.

[0109] The sending unit is further configured to send a session acceptance message to the terminal device, the session acceptance message being used to complete the establishment of a session for the second communication service.

[0110] As one possible implementation, the session request message includes first indication information, which is used to indicate that the terminal device supports generating a second security context. The sending unit sending the additional security context indication to the data transmission network element includes:

[0111] When the first indication information indicates that the terminal device supports generating the second security context, the additional security context indication is sent to the data transmission network element.

[0112] As one possible implementation, the sending unit sending additional security context indications to the data transmission network element includes:

[0113] Obtain the subscription information of the terminal device according to the session request message;

[0114] When the subscription information of the terminal device indicates that the second security context needs to be generated, the additional security context indication is sent to the data transmission network element.

[0115] As one possible implementation, the sending unit sending additional security context indications to the data transmission network element includes:

[0116] When the local policy configuration of the session management function network element indicates that the second security context needs to be generated, the additional security context indication is sent to the data transmission network element.

[0117] As one possible implementation, the additional security context indication includes an identifier of the security algorithm, and the apparatus may further include an acquisition unit, wherein:

[0118] The acquisition unit is used to acquire the security algorithm.

[0119] As one possible implementation, the additional security context indication includes a first key, and the device may further include:

[0120] The triggering unit is used to trigger secondary authentication;

[0121] The receiving unit is also used to receive the secondary authentication key from the authentication, authorization, and billing network element after the secondary authentication is successful;

[0122] The acquisition unit is further configured to acquire the first key based on the secondary authentication key.

[0123] As one possible implementation, the acquisition unit acquires the first key based on the secondary authentication key, including:

[0124] The first key is obtained based on the secondary authentication key and the second derived parameter.

[0125] As one possible implementation, the second derived parameter is one or more of the following parameters: downlink NASCOUNT, PDU session ID, NSSAI, and DNN.

[0126] In one possible implementation, the session acceptance message includes an indication of a second derived parameter, which is used to indicate how to obtain a security key based on the secondary authentication key.

[0127] The sixth aspect discloses a security context generation apparatus, which can be a data transmission network element or a module (e.g., a chip) within the data transmission network element. The apparatus may include:

[0128] The receiving unit is used to receive additional security context indications from the session management function network element;

[0129] The acquisition unit is configured to acquire a second security context based on the additional security context indication, wherein the second security context is used to protect the second communication service;

[0130] A sending unit is configured to send an additional generation instruction to a terminal device, the additional generation instruction being used to instruct the generation of the second security context.

[0131] As one possible implementation, the acquisition unit is specifically used for:

[0132] Based on the additional security context indication, obtain the security key based on the first key; and / or

[0133] The security algorithm is obtained based on the additional security context indication.

[0134] As one possible implementation, the acquisition unit is further configured to acquire a first security context before receiving an additional security context indication from the session management function network element. The first security context is used to protect a first communication service, which is different from the second communication service.

[0135] As one possible implementation, the acquisition unit generates the security key based on the first key according to the additional security context indication, including:

[0136] Based on the additional security context indication, the first key is obtained using the AS root key of the first security context;

[0137] The security key is generated based on the first key.

[0138] As one possible implementation, the additional generation indication includes an indication of the first derived parameter, and the acquisition unit acquires the first key based on the AS root key of the first security context according to the additional security context indication, including:

[0139] The first key is generated based on the AS root key of the first security context and the first derived parameters.

[0140] As one possible implementation, the first derived parameter is a downlink PDCP COUNT, and the indication of the first derived parameter is a portion of the bits of the downlink PDCP COUNT.

[0141] As one possible implementation, the additional security context indication includes the first key, and the acquisition unit acquires the security key based on the first key according to the additional security context indication, including:

[0142] The security key is generated based on the first key.

[0143] As one possible implementation, the acquisition unit generates the security key based on the first key, including:

[0144] The security key is generated based on the first key and the third derived parameter.

[0145] As one possible implementation, the additional security context indicator includes an identifier of the security algorithm, and the acquisition unit generates the security key based on the first key and the third derived parameters, including:

[0146] The security key is generated based on the first key and the identifier and type of the security algorithm.

[0147] As one possible implementation, the additional generation instruction includes an identifier of the security algorithm.

[0148] As one possible implementation, the additional security context indication includes an identifier of the security algorithm.

[0149] As one possible implementation, the acquisition unit acquires the security algorithm based on the additional security context indication, including:

[0150] Based on the additional security context indication, the security algorithm is obtained according to the security capabilities of the terminal device and a pre-configured list of algorithm priorities, wherein the security capabilities of the terminal device are used to indicate all security algorithms supported by the terminal device.

[0151] As one possible implementation, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.

[0152] A seventh aspect discloses a security context generation apparatus, which may be a terminal device or a module (e.g., a chip) within a terminal device. The security context generation apparatus may include: a processor, a memory, an input interface, and an output interface. The input interface is used to receive information from other devices outside the device, and the output interface is used to output information to other devices outside the device. When the processor executes a computer program stored in the memory, the processor performs the security context generation method disclosed in the first aspect or any embodiment of the first aspect.

[0153] The eighth aspect discloses a security context generation apparatus, which can be a session management function network element or a module (e.g., a chip) within a session management function network element. The security context generation apparatus may include: a processor, a memory, an input interface, and an output interface. The input interface is used to receive information from other devices outside the apparatus, and the output interface is used to output information to other devices outside the apparatus. When the processor executes a computer program stored in the memory, the processor performs the security context generation method disclosed in the second aspect or any embodiment of the second aspect.

[0154] A ninth aspect discloses a security context generation apparatus, which can be a data transmission network element or a module (e.g., a chip) within a data transmission network element. The security context generation apparatus may include a processor, a memory, an input interface, and an output interface. The input interface is used to receive information from other devices outside the apparatus, and the output interface is used to output information to other devices outside the apparatus. When the processor executes a computer program stored in the memory, the processor performs the security context generation method disclosed in the third aspect or any embodiment of the third aspect.

[0155] The tenth aspect discloses a communication system, which includes a security context generation apparatus of the seventh aspect, a security context generation apparatus of the eighth aspect, and a security context generation apparatus of the ninth aspect.

[0156] The eleventh aspect discloses a computer-readable storage medium storing a computer program or computer instructions, which, when executed, implements the security context generation method disclosed in the above aspects.

[0157] The twelfth aspect discloses a chip including a processor for executing a program stored in a memory, which, when executed, causes the chip to perform the above-described method.

[0158] As one possible implementation, the memory is located outside the chip.

[0159] The thirteenth aspect discloses a computer program product comprising computer program code, which, when run, causes the above-described methods to be performed. Attached Figure Description

[0160] Figure 1 This is a schematic diagram of a network architecture disclosed in an embodiment of this application;

[0161] Figure 2 This is a schematic diagram of a security context generation process disclosed in an embodiment of this application;

[0162] Figure 3 This is a schematic diagram of another security context generation process disclosed in an embodiment of this application;

[0163] Figure 4 This is a schematic diagram of another security context generation process disclosed in the embodiments of this application;

[0164] Figure 5 This is a schematic diagram of another security context generation process disclosed in the embodiments of this application;

[0165] Figure 6 This is a schematic diagram of another security context generation process disclosed in the embodiments of this application;

[0166] Figure 7 This is a schematic diagram of the structure of a communication device disclosed in an embodiment of this application;

[0167] Figure 8 This is a schematic diagram of another communication device disclosed in an embodiment of the present invention;

[0168] Figure 9 This is a schematic diagram of the structure of another communication device disclosed in an embodiment of the present invention;

[0169] Figure 10 This is a schematic diagram of the structure of another communication device disclosed in an embodiment of the present invention;

[0170] Figure 11 This is a schematic diagram of the structure of another communication device disclosed in an embodiment of the present invention. Detailed Implementation

[0171] This application discloses a security context generation method, apparatus, and computer-readable storage medium to improve the security of communication services. These will be described in detail below.

[0172] To better understand the security context generation method, apparatus, and computer-readable storage medium disclosed in the embodiments of the present invention, the network architecture used in the embodiments of the present invention is described below. Please refer to... Figure 1 , Figure 1 This is a schematic diagram of a network architecture disclosed in an embodiment of the present invention. Figure 1As shown, the network architecture may include user equipment (UE), radio access network ((R)AN) equipment, user plane function (UPF) network elements, data network (DN), session management function (SMF) network elements, access and mobility management function (AMF) network elements, unified data management (UDM) network elements, authentication server function (AUSF) network elements, network slice selection function (NSSF) network elements, policy control function (PCF) network elements, application function (AF) network elements, network slice selection assistance information (NSSAI) network elements, network data analytics function (NWDAF) network elements, network exposure function (NEF) network elements, and network repository function (NRF) network elements.

[0173] UE, also known as terminal equipment, mobile station (MS), mobile terminal (MT), etc., is a device that provides voice and / or data connectivity to users. Terminal devices can include handheld terminals, laptops, subscriber units, cellular phones, smartphones, wireless data cards, personal digital assistant (PDA) computers, tablet computers, wireless modems, handheld devices, laptop computers, cordless phones, wireless local loop (WLL) stations, machine-type communication (MTC) terminals, wearable devices (such as smartwatches, smart bracelets, pedometers, etc.), in-vehicle equipment (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, smart home devices (such as refrigerators, televisions, air conditioners, electricity meters, etc.), intelligent robots, workshop equipment, wireless terminals in self-driving vehicles, wireless terminals in remote medical surgery, and smart grids. Wireless terminals in a grid, wireless terminals in transportation safety, wireless terminals in a smart city, or wireless terminals in a smart home, flying equipment (e.g., intelligent robots, hot air balloons, drones, airplanes), or other devices that can access the network. Figure 1 The terminal device shown is a UE, which is only an example and does not limit the terminal device. The UE can access the DN by establishing a session between the UE-(R)AN device-UPF-DN, that is, a protocol data unit (PDU) session.

[0174] (R)AN equipment is a device that provides radio access for UEs, primarily responsible for functions such as air interface-side radio resource management, Quality of Service (QoS) flow management, data compression, and encryption. (R)AN can communicate directly with UEs via AS. (R)AN equipment can include various types of base stations, such as macro base stations, micro base stations (also known as small cells), relay stations, and access points. (R)AN equipment can also include wireless fidelity (WiFi) access points (APs). (R)AN equipment can also include worldwide interoperability for microwave access (WiMax) base stations (BSs). (R)AN can be network-side equipment in 5G networks or later networks, or network equipment in PLMN networks, such as next-generation NodeBs (gNBs), next-generation evolved NodeBs (ng-eNBs), and long-term evolution NodeBs (eNBs).

[0175] AMF network elements can access the UE's non-access stratum (NAS) signaling (including mobility management (MM) signaling and session management (SM) signaling) through the N1 interface and access the RAN signaling through the N2 interface to complete the forwarding of the UE's SM signaling and mobility management.

[0176] The SMF (Service Management Function) network element is primarily responsible for session management in mobile networks, including processes such as session establishment, modification, release, and update. Specific functions include assigning IP addresses to users and selecting the UPF (User Member Filter) network element to provide packet forwarding capabilities. Messages between the SMF and the UE can be encapsulated within a NAS (Service Attached Message) session management (SM) container. The AMF (Application Management Filter) can extract the SM container content from the NAS message and then send it to the SMF.

[0177] PCF network elements can be responsible for terminal device policy management, including mobility-related policies as well as PDU session-related policies, such as QoS policies and charging policies. PCF can also manage user session policies.

[0178] The AF network element mainly supports interaction with the 3rd generation partnership project (3GPP) core network to provide services, and to influence service flow routing, access network capability opening, policy control, etc.

[0179] UDM network elements are responsible for user key management, user identifier processing, access authorization for subscription data, UE network function entity management, session and service continuity management, SMS push, legal monitoring (observation), subscription management, SMS management, and management of user data such as subscription information.

[0180] The UPF network element is primarily responsible for processing user packets, such as forwarding and accounting. It can receive user packets from the DN and transmit them to the UE through the RAN equipment; it can also receive user packets from the UE through the RAN equipment and forward them to the DN. The transmission resources and scheduling functions provided by the UPF network element to the UE are managed and controlled by the SMF network element.

[0181] A DN can be an internet, an IP multi-media service (IMS) network, a local area network (LAN), or a multi-access edge computing (MEC) network. The DN is the destination for the UE's PDU session access. The DN includes or deploys an application server, which can transmit data with the UE and provide service to the UE.

[0182] The AUSF network element can be responsible for authenticating and authorizing UE access.

[0183] The data transmission network element is mainly responsible for processing user packets. It can be a RAN device or a UPF network element.

[0184] The network elements mentioned above in the core network can also be called functional entities. These can be network components implemented on dedicated hardware, software instances running on dedicated hardware, or instances of virtualized functions on appropriate platforms. For example, the virtualization platform mentioned above can be a cloud platform.

[0185] It should be noted that, Figure 1 The system architecture shown is not limited to the network elements shown in the figure, but may also include other devices or network elements not shown in the figure. These will not be listed here.

[0186] It should be noted that the embodiments of this application do not limit the distribution of each network element in the core network. Figure 1 The distribution shown is merely exemplary and is not intended to limit the scope of this application.

[0187] It should be understood that all network element names in this application are merely examples. In future communications, such as 6G, they may be referred to by other names, or in future communications, such as 6G, the network elements involved in this application may be replaced by other entities or devices with the same function. This application does not limit these possibilities. This is a general explanation and will not be elaborated further here.

[0188] It should be noted that, Figure 1 The 5G network architecture shown is not intended to limit the scope of 5G networks. Optionally, the method described in this application embodiment is also applicable to various future communication systems, such as 6G or other communication networks.

[0189] In addition, the above network structure may also include an authentication, authorization and accounting (AAA) network element, which can complete the authentication of access terminal devices.

[0190] To better understand the embodiments of this application, the application scenarios of the embodiments of this application will be described below.

[0191] In a PNI-NPN scenario, three roles can exist: the terminal device (e.g., a company computer used by Volkswagen employees), the PLMN (e.g., China Mobile), and the NPN (e.g., Volkswagen). The terminal device can simultaneously perform public and private network services through the PLMN. For example, the terminal device can use instant messaging applications and email simultaneously. Considering 5G network security, the terminal device can be securely protected with the access network. That is, a security context can be used for communication protection between the UE and the (R)AN device, thereby ensuring the security of user plane data streams between the user and the network.

[0192] To facilitate understanding of this application, relevant technical knowledge involved in the embodiments of this application will be introduced first.

[0193] A security context is a context in which communication content can be securely protected. Security protection can include confidentiality protection and / or integrity protection. The context must at least contain a security key and a security algorithm. Optionally, the context may also contain security policies, security activation indicators, freshness parameters, etc. When the communication content is a communication service, the security key for confidentiality protection can be Kup-enc, and the security algorithm for confidentiality protection can be the 5G encryption algorithm (NEA) or the EPS encryption algorithm (EEA). The security key for integrity protection can be Kup-int, and the security algorithm for integrity protection can be the 5G integrity algorithm (NIA) or the EPS integrity algorithm (EIA). The communicating parties can configure the security key and security algorithm at the PDCP layer. The sender can use the security key and security algorithm to encrypt and / or protect the integrity of the sent communication content, and the receiver can use the same security key and security algorithm to decrypt and / or verify the integrity of the received communication content.

[0194] Communication services refer to user plane traffic that allows terminal devices to communicate with services provided by servers via mobile networks. This can include public network services and / or private network services. Public network services represent services provided by servers that are publicly accessible, such as applications provided by service providers. Private network services represent services provided by servers that have restricted access, such as proprietary enterprise applications. Terminal devices may need to establish different sessions with the mobile network for different services.

[0195] The UE and (R)AN equipment can use the encryption key kup-enc and encryption algorithm to encrypt user plane traffic, and the integrity protection key kup-int and integrity protection algorithm to protect user plane traffic. The security key can include the encryption key and the integrity protection key, and the security algorithm can include the encryption algorithm and the integrity protection algorithm. The security context can include the security key and / or the security algorithm. User plane traffic can be transmitted through different data radio bearers (DRBs), and different DRBs may have encryption protection or integrity protection enabled or disabled. When DRB protection is enabled, all DRBs with enabled protection use the same key and algorithm, meaning that all terminal devices and access network equipment can use the same security context for communication protection. In this case, when an attacker obtains the security key used for public network services, they also obtain the security key for private network services, thus gaining access to private network service traffic, and vice versa. For example, an attacker can obtain the security key used for public network services by cracking the security algorithm used for public network services, thereby gaining access to the security context of public network services. When an attacker obtains the security context of the public network, they can also obtain the security context of the private network, and then use the private network's security context to access private network traffic. The above protection methods do not achieve secure isolation between public and private network service protection. Therefore, how to achieve secure isolation between public and private network services in PNI-NPN is a pressing technical problem that needs to be solved.

[0196] Based on the above network architecture, please refer to Figure 2 , Figure 2 This is a flowchart illustrating a security context generation method disclosed in an embodiment of the present invention. Figure 2 As shown, the security context generation method may include the following steps.

[0197] 201. The terminal device obtains the first security context.

[0198] When a terminal device needs to protect data, it can generate a first security context to protect the data. The first security context may include a first security key and / or a first security algorithm. The first security key may include a first encryption key and / or a first integrity protection key. The first security algorithm may include a first encryption algorithm and / or a first integrity protection algorithm. The first security context can protect the terminal device's first communication service. The first communication service can be a public network service or a private network service. It should be understood that the aforementioned data can be user plane data.

[0199] After registering with the PLMN and requesting to establish a session for the first communication service, the terminal device and the access network device can obtain a first security context to protect the first communication service, and can use the first security context to protect the first communication service. The process for the terminal device to obtain the first security context can be found in the relevant description in 3GPP TS 33.501.

[0200] 202. The terminal device sends a session request message to the session management function network element.

[0201] Terminal devices can send session request messages to session management function (SM) network elements, and correspondingly, SM network elements can receive session request messages from terminal devices. Specifically, terminal devices can first send NAS messages to access and mobility management (AM) network elements, where NAS messages may include SM messages. After receiving the NAS message from the terminal device, AM can extract the SM message from the NAS message and then send the SM message to the session management function (SM) network element. The session request message can be an SM message. The SM message can be a PDU session suggestion request message or a PDU session modification request message. The session request message can be used to request the establishment of a session for a second communication service. The NAS message may include DNN and / or NSSAI, which AM can extract from the NAS message and send to the session management function (SM) network element. Furthermore, when the data transmission network element is a user plane function network element, the session request message may include the identifier of the terminal device, which can be used to identify the user plane function network element. It should be understood that the session request message refers to the request to establish a session for a second communication service, and the name of this message is not limited.

[0202] The session request message may include first indication information, which may indicate that the terminal device supports the generation of a second security context. That is, the first indication information can be understood as indicating that the terminal device supports the generation of a second security context, requesting the generation of a second security context, and indicating that the session needs to implement secure isolation. The second security context may include a second security algorithm and / or a second security key. The second security algorithm may include a second encryption algorithm and / or a second integrity protection algorithm.

[0203] The second security key may include a second encryption key and / or a second integrity protection key.

[0204] The first communication service and the second communication service are different communication services. The second communication service can be a public network service or a private network service. When the first communication service is a public network service, the second communication service can be a private network service; when the first communication service is a private network service, the second communication service can be a public network service.

[0205] The first security context and the second security context are different security contexts. This can be understood as follows: the second security key is different from the first security key, but the second security algorithm is the same as the first security algorithm; or the second security algorithm is different from the first security algorithm, but the second security key is the same as the first security key; or both the second security key and the second security algorithm are different. The second security context can protect a second communication service, while the first and second security contexts can protect different communication services respectively.

[0206] 203. Session management function network elements send additional security context indications to data transmission network elements.

[0207] After receiving a session request message from the terminal device, the session management function network element can first determine whether a second security context needs to be generated for the terminal device. If it is determined that the terminal device needs to generate a second security context, it can send an additional security context indication to the data transmission network element. Correspondingly, the data transmission network element can receive the additional security context indication from the session management function network element. If it is determined that the terminal device does not need to generate a second security context, steps 203-207 can be skipped.

[0208] In one possible implementation, after receiving a session request message from a terminal device, the session management function network element can determine whether the terminal device supports the generation of a second security context based on first indication information. In one approach, when the first indication information is explicitly indicated, the session management function network element can determine whether the session request message includes the first indication information. If the session request message includes the first indication information, it indicates that the terminal device supports the generation of a second security context. If the session request message does not include the first indication information, it indicates that the terminal device does not support the generation of a second security context. In another approach, the first indication information is implicit. For example, the session request message may include 1 bit. If this bit is a specific value, such as 0 or 1, it indicates that the terminal device supports the generation of a second security context. If this bit is not the specific value or does not include the specific value, it indicates that the terminal device does not support the generation of a second security context.

[0209] Another possible implementation is that after receiving a session request message from a terminal device, the session management function network element can obtain the terminal device's subscription information. It can then determine whether the terminal device needs to generate a second security context based on this subscription information. If the subscription information includes second indication information, it indicates that the terminal device needs to generate a second security context. Otherwise, it indicates that the terminal device does not need to generate a second security context. The second indication information can indicate that the terminal device supports generating a second security context, that is, it indicates that the terminal device supports the generation of a second security context; or it can be used to request the generation of a second security context; or it can be used to indicate that the session needs to implement security isolation. The session management function network element can obtain the terminal device's subscription information from a UDM network element or a PCF network element.

[0210] Another possible implementation is that the session management function network element can be pre-configured or default-configured with local policies. Therefore, after receiving a session request message from the terminal device, it can determine whether the terminal device needs to generate a second security context based on the relevant information of the session and the local policy. For example, if the local policy requires different security contexts to protect specific sessions, then when the session management function network element receives the DNN and / or NSSAI from the terminal device, it can determine whether the service corresponding to the DNN and / or NSSAI needs to be protected with different security contexts based on the local policy. When it is determined that it is necessary, the session management function network element determines that a second security context needs to be generated for the UE.

[0211] It should be understood that the session management function network element can determine whether a second security context needs to be generated through one or more of the methods described above. Specifically, it can determine whether the terminal device supports the generation of a second security context through the first indication information; if the first indication information determines that the terminal device supports the generation of a second security context, then the generation of a second security context is required. Alternatively, it can determine whether a second security context needs to be generated through subscription information; or it can determine whether a second security context needs to be generated through local policies. It can also determine whether a second security context needs to be generated through both the first indication information and subscription information; if the first indication information determines that the terminal device supports the generation of a second security context, and the subscription information also determines that a second security context needs to be generated, then the generation of a second security context is required. Furthermore, it can determine whether a second security context needs to be generated through both the first indication information and local policies; if the first indication information determines that the terminal device supports the generation of a second security context, and the local policies also determine that a second security context needs to be generated, then the generation of a second security context is required.

[0212] Additional security context indicators can be used to instruct the generation of a second security context. These indicators can be explicit. For example, an additional security context indicator might include a 1-bit value, where a value of 1 indicates the generation of a second security context, and a value of 0 indicates that a second security context should not be generated. Additional security context indicators can also be implicit. For example, an additional security context indicator might be information elements required to generate a second security context, such as a key, algorithm, flags, indicators, indexes, or transmission resources, sent to the data transmission network element. For instance, when the data transmission network element receives a key, it indicates that the session management function network element has instructed the data transmission network element to generate a second security context.

[0213] Optionally, after the session management function network element determines that a second security context needs to be generated for the terminal device, it can determine the security algorithm.

[0214] One possible implementation is that the session management function network element can pre-configure the mapping relationship between DNN and security algorithm. When it is determined that the terminal device needs to generate a second security context, the security algorithm used can be found directly based on the DNN reported by the terminal device and the above mapping relationship.

[0215] Another possible implementation is that the session management function network element can pre-configure the mapping relationship between the DNN and the algorithm priority list. When it is determined that the terminal device needs to generate a second security context, the algorithm priority list can be found based on the DNN reported by the terminal device and the above mapping relationship. Then, the security algorithm to be used is obtained based on the security capabilities of the terminal device and the algorithm priority list. The algorithm priority list is a list of algorithms reflecting usage priority, which can be represented as Priority 1: Algorithm B, Priority 2: Algorithm A, Priority 3: Algorithm C, with smaller priority numbers indicating higher priority. The security capabilities of the terminal device are reported by the terminal device and can represent the algorithms that the terminal device can support. For example, if Algorithm A, Algorithm B, and Algorithm C are supported by the terminal device, then since Algorithm B has the highest priority, Algorithm B is ultimately selected as the security algorithm.

[0216] Once the session management function network element determines the security algorithm, the additional security context indication may include the identifier of the security algorithm.

[0217] Optionally, after the session management function network element determines that a second security context needs to be generated for the terminal device, it can determine the first key.

[0218] The first key can also be obtained based on the secondary authentication key, wherein the session management function network element receives the secondary authentication key from the authentication, authorization, and accounting network element.

[0219] The session management function network element can generate a first key based on the secondary authentication key and the second derived parameter. The session management function network element can trigger secondary authentication for the terminal device. For example, when the session management function network element confirms the need to generate a second security context, it can trigger secondary authentication between the terminal device and the authentication, authorization, and accounting network element based on the subscription information of the DNN and the terminal device. After successful secondary authentication of the terminal device, the authentication, authorization, and accounting network element can send the secondary authentication key to the session management function network element. The session management function network element can receive the secondary authentication key from the authentication, authorization, and accounting network element. The second derived parameter can be a freshness parameter, which can include one or more of the following: uplink or downlink NAS COUNT, NSSAI, DNN, and PDU session ID. The NAS COUNT can be stored in the non-access stratum context of the terminal device and updated each time a key is derived, preventing two consecutively generated first keys from being the same. For example, assuming the value of NAS COUNT is 'a', after one derivation using NAS COUNT, NASCOUNT can be updated to a+b; therefore, the updated NAS COUNT value can be used for the second derivation. b can be 1, 2, or any other value; no restriction is placed here. The value of b can be the same each time it is updated, meaning the NAS COUNT value increases or decreases with b as the step size, or it can be different. The session management function network element can obtain the NSSAI, DNN, and PDU session ID from the terminal device through session request messages. Since different terminal devices or session management network elements access different slices (NSSAI identifier), data networks (DNN identifier), and PDU sessions (PDU session ID identifier), the generated first key can be different.

[0220] Once the session management function network element determines the first key, the additional security context indication may include the first key.

[0221] It should be understood that the information required to generate the second security context differs depending on the method used to generate it. Therefore, the additional security context indicator can contain different information depending on how the second security context is generated. For example, the additional security context indicator can be an explicit location indicator, an identifier of the security algorithm, or a first key. Alternatively, the additional security context indicator can include both an explicit location indicator and an identifier of the security algorithm, or it can include both the first key and an identifier of the security algorithm.

[0222] Session management function network elements can send additional security context indications to data transmission network elements through various messages and signaling. For example, when the data transmission network element is an access network device, the session management function network element can encapsulate the additional security context indication in an N2 SM information container and send it to the data transmission network element; when the data transmission network element is a user plane function network element, the session management function network element can encapsulate the additional security context indication in an N4 session establishment request message and send it to the data transmission network element.

[0223] 204. The data transmission network element obtains the second security context based on the additional security context indication.

[0224] After receiving an additional security context indication from the session management function network element, the data transmission network element can obtain a second security context based on the additional security context indication.

[0225] Data transmission network elements can acquire security algorithms based on additional security context indications.

[0226] One possible implementation is that the data transmission network element can pre-configure an algorithm priority list. This list can include the security capabilities of the terminal device and the priority information of the security algorithms. The data transmission network element can determine the security algorithm based on this priority list. Specifically, the data transmission network element can obtain the security capabilities of the terminal device from the stored context of the terminal device. When the data transmission network element has a first security context, since it needs to generate a first security algorithm and a second security algorithm for the same terminal device, their corresponding algorithm priority lists must be different to ensure they are distinct. Using the same algorithm priority list for the same terminal device could potentially lead to the final determined first and second security algorithms being identical, thus failing to achieve security isolation. It should be understood that the security algorithm obtained based on the additional security context indication is the second security algorithm.

[0227] Another possible approach is that when the additional security context indication includes an identifier for the security algorithm, the data transmission network element can identify the security algorithm corresponding to that identifier as the security algorithm.

[0228] Another possible implementation is that when the data transmission network element has a first security context, the data transmission network element can obtain a security algorithm from the first security algorithm of the first security context based on the additional security context indication.

[0229] Data transmission network elements can obtain a security key based on the first key according to an additional security context indication. This can be understood as the additional security context indication triggering the data transmission network element to obtain a security key based on the first key. Alternatively, it can be understood as the data transmission network element responding to the additional security context indication and obtaining a security key based on the first key.

[0230] In one scenario, the data transmission network element can first determine the first key, and then obtain the security key based on the first key.

[0231] When a data transmission network element possesses a first security context, the data transmission device can obtain the first key based on the AS root key of the first security context, according to the additional security context indication. That is, the first key is determined (or generated) based on the AS root key of the first security context. The AS root key can be key K. gNB It can also be K eNB It can also be the next hop (NH).

[0232] In one approach, the data transmission network element can use the AS root key of the first security context as the first key.

[0233] In another approach, the data transmission network element can generate a first key based on the AS root key of the first security context and a first derived parameter. The first derived parameter can be a PDCP COUNT, which can be stored in the access layer context of the terminal device. Each time the data transmission network element uses the PDCP COUNT, it needs to update its value; that is, it updates the PDCP COUNT value every time a key is derived, preventing two consecutive generated keys from being the same. For example, assuming the PDCP COUNT value is 'a', after one derivation using the PDCP COUNT, its value can be updated to 'a+b'. Therefore, the next derivation can use the updated PDCP COUNT value. 'b' can be 1, 2, or other values, without limitation. The value of 'b' can be the same each time it is updated, meaning the PDCP COUNT value increases or decreases with 'b' as the step size, or it can be different. It should be understood that the first derived parameter can be a freshness parameter. By updating the PDCP COUNT value, each generated security key can be different, thereby improving key security and achieving the effect of security isolation.

[0234] When a data transmission network element is configured with a mapping between the identifier of a terminal device and the root key Kn, and the additional security context indicator can carry the identifier of the terminal device, the data transmission network element can obtain the first key based on the identifier of the terminal device, that is, determine (or generate) the first key based on Kn. The root key Kn should be different for each terminal device and can be pre-configured on the data transmission network element. The data transmission network element can determine the root key Kn based on the identifier of this terminal device and the mapping between the terminal device and the root key Kn.

[0235] In one approach, the data transmission network element can use the Kn root key as the first key.

[0236] In another approach, after the data transmission network element determines the Kn root key, it can generate the first key based on the Kn root key and the first derived parameters. A detailed description of generating the first key can be found in the aforementioned description of the data transmission network element generating the first key based on the AS root key and the first derived parameters; it will not be repeated here.

[0237] In another scenario, the additional security context indication may include a first key. The data transmission network element can first extract the first key from the additional security context indication, and then generate a security key based on the first key.

[0238] After the data transmission network element determines the first key, a security key can be generated based on the first key.

[0239] Optionally, the data transmission network element can generate a security key based on the first key and the third derived parameters.

[0240] The third derived parameter can include the identifier and type of the security algorithm. In this case, the data transmission network element can determine the identifier and type of the security algorithm based on the acquired security algorithm.

[0241] Optionally, the data transmission network element can obtain a security algorithm based on additional security context indications, and determine the identifier and type of the security algorithm based on the obtained security algorithm.

[0242] Optionally, when the data transmission network element has a first security context, the data transmission network element can obtain a security algorithm based on the first security algorithm of the first security context, and determine the identifier and type of the security algorithm based on the obtained security algorithm.

[0243] The security algorithm identifier can be used to identify the security algorithm being acquired. For example, the encryption algorithm could be EEA1, NEA1, etc., and the integrity algorithm could be EIA1, NIA1, etc.

[0244] The type of the security algorithm can be set to different values ​​depending on the scenario in which the algorithm is used. For example, when the security algorithm is used for user plane confidentiality protection, the type of the security algorithm can be set to the value 0x05 corresponding to N-UP-ENC-ALG; when the security algorithm is used for user plane integrity protection, the type of the security algorithm can be set to the value 0x06 corresponding to N-UP-INT-ALG. Therefore, the type of the security algorithm can be either 0x05 or 0x06. Furthermore, the type of the security algorithm can also be a value different from the existing 0x01-0x06, used to indicate whether the security algorithm is used for user plane confidentiality protection or user plane integrity protection of the second communication service. For example, when the current algorithm is used for user plane confidentiality protection of the second communication service, the type of the security algorithm can be 0x07; when the current algorithm is used for user plane integrity protection of the second communication service, the type of the security algorithm can be 0x08. The data transmission network element can generate a security key based on the first key and the identifier and type of the security algorithm. For details on how to generate the first key, please refer to the relevant description above, which will not be repeated here.

[0245] Optionally, the data transmission network element can also generate a security key based on the first key and a special string. The special string can be a pre-configured specific string, such as "NPN", "Secondary", etc.

[0246] Introducing a special string, distinct from the existing 0x01-0x06 security algorithm types, as a derived parameter for generating a second encryption key and a second integrity protection key ensures that even if the obtained security algorithm is the same as the first security algorithm and the obtained first key is the same as the AS root key of the first security context, the obtained security key will still be different from the first security key. This can be understood as the first encryption key being different from the second encryption key, or the first integrity protection key being different from the second integrity protection key, or even simply the first encryption key being different from the second encryption key, and the first integrity protection key being different from the second integrity protection key. This avoids the first security context and the second security context being the same, ensuring the effectiveness of security isolation and thus guaranteeing the security of communication services.

[0247] It should be understood that the methods for determining the security algorithm and the methods for generating the security key can be related or independent.

[0248] 205. The data transmission network element sends an additional generation instruction to the terminal device.

[0249] Additional generation indicators can be used to instruct the generation of a second security context. These indicators can be explicit. For example, an additional generation indicator might include a 1-bit value, where a value of 1 indicates the generation of a second security context, and a value of 0 indicates that a second security context should not be generated. Additional generation indicators can also be implicit. For example, an additional generation indicator might be information elements required to generate a second security context, such as algorithms, flags, indicators, indexes, or transmission resources, sent to the terminal device. For instance, when the terminal device receives an indicator, it indicates that the data transmission network element has instructed the terminal device to generate a second security context.

[0250] After the data transmission network element determines the security key, the additional generated indication can also be used to instruct the terminal device to obtain the security key. In this case, the additional generated indication may include an indication of the first derived parameter. The indication of the first derived parameter can be the first derived parameter itself, or it can be a value indicating the first derived parameter. For example, if the second derived parameter includes PDCPCOUNT, then the indication of the first derived parameter may include a portion of the bits of PDCP COUNT.

[0251] Once the data transmission network element determines the security algorithm, the additional generated instruction can also be used to instruct the terminal device to acquire the security algorithm. In this case, the additional generated instruction may include the identifier of the security algorithm.

[0252] It should be understood that the determination of the second security context is not unique. Different determination methods may result in different additional security context indications received and additional generation indications sent by the data transmission network element. Therefore, the additional generation indication may contain different information depending on the method of generating the second security context. For example, the additional generation indication may be an explicit location indication, an indication of the first derived parameter, or an identifier of the security algorithm. The additional security context indication may also include an explicit location indication and an identifier of the security algorithm, an indication of the first derived parameter and an identifier of the security algorithm, or an explicit location indication, an indication of the first derived parameter, and an identifier of the security algorithm. It should be understood that the additional generation indication will only correspond to the packet or the indication of the first derived parameter and / or the identifier of the security algorithm when the data transmission network element uses the first derived parameter and / or the third derived parameter to generate the second security context.

[0253] Data transmission network elements can directly send additional generation instructions to terminal devices, which can be done via RRC messages. Optionally, the RRC message can be an RRC reconfiguration message.

[0254] The data transmission network element can indirectly send an additional generation instruction to the terminal device through the session management function network element. In this case, the additional generation instruction can be encapsulated in an N4 Session Establishment Response message and sent to the session management function network element. The session management function network element then encapsulates the additional generation instruction in a session acceptance message and sends it to the terminal device.

[0255] It should be understood that step 205 is an optional step.

[0256] 206. The session management function network element sends a session acceptance message to the terminal device.

[0257] After receiving a session request message from a terminal device, the session management function network element can establish a session for transmitting the second communication service based on the session request message. Once the session is established, it can send a session acceptance message to the terminal device. Correspondingly, the terminal device can receive the session acceptance message from the session management function network element. The session acceptance message can indicate the completion of the session establishment for the second communication service. The session acceptance message can be a PDU session suggestion request message or a PDU session modification request message.

[0258] Optionally, the session accept message may include an additional generation instruction, which is used to instruct the terminal device to generate a second security context.

[0259] After the session management function network element determines the security algorithm, the additional generation instruction can also be used to instruct the terminal device to obtain the security algorithm. In this case, the additional generation instruction may include the identifier of the security algorithm. It should be understood that the identifier of the security algorithm may be carried in one of the additional generation instructions sent to the terminal device by the session receiving message and data transmission network elements, or it may not be carried in either. There is no limitation here regarding which specific information the identifier of the security algorithm is included in.

[0260] After the session management function network element determines the first key, the additional generated indication can also be used to instruct the terminal device to obtain the first key. In this case, the additional generated indication may include an indication of the second derived parameter. The indication of the second derived parameter can be the second derived parameter itself, or it can be a value used to indicate the second derived parameter. For example, if the second derived parameter includes NAS COUNT, then the indication of the second derived parameter may include a portion of the bits of NAS COUNT. If the second derived parameter includes NSSAI, DNN, and PDU session ID, then the indication of the second derived parameter may include NSSAI, DNN, and PDU session ID themselves. Alternatively, since the terminal device already knows NSSAI, DNN, and PDU session ID, the indication of the second derived parameter may include a specific value; when this value is 1, it is used to instruct the terminal device to obtain NSSAI, DNN, and PDU session ID.

[0261] When a session management function network element receives an additional generation instruction from a data transmission network element, it can forward the additional generation instruction to the terminal device. The session management function network element can encapsulate the additional generation instruction in a session accept message and send it to the terminal device.

[0262] It should be understood that steps 205 and 206 can be executed sequentially or in parallel, and the execution order is not restricted.

[0263] 207. The terminal device obtains additional generation instructions.

[0264] The terminal device can obtain additional generation instructions, which can be understood as the terminal device being able to receive additional generation instructions from data transmission network elements and / or session management network elements.

[0265] Terminal equipment can receive additional generation instructions from data transmission network elements.

[0266] In one scenario, the terminal device can directly receive additional generation instructions from the data transmission network element, meaning the terminal device can receive additional generation instructions from the data transmission device.

[0267] In another scenario, the terminal device can indirectly receive additional generation instructions from the data transmission network element. That is, the data transmission network element can forward the additional generation instructions to the terminal device through the session management function network element. For a detailed description, please refer to the description of the additional security instructions sent by the data transmission network element to the terminal device through the session management network element in step 205; further details will not be provided here.

[0268] The terminal device can receive additional generation instructions from the session management function network element, that is, the terminal device can receive additional generation instructions from the session management function.

[0269] Additional generation instructions may include one or more of the following: instructions for the first derived parameter, instructions for the second derived parameter, and identifiers for the security algorithm.

[0270] It should be understood that since the additional generated indication can contain multiple indications, it can be divided into two parts based on the source of the received information: one part obtained from the data transmission network element, and the other part obtained from the session management network element. Therefore, the terminal device can generate additional indications from the data transmission network element and obtain the other part from the session management network element. For example, the terminal device can obtain an indication of the first derived parameter and the identifier of the security algorithm from the data transmission network element, and can also obtain an indication of the second derived parameter from the session management network element.

[0271] 208. The terminal device obtains a second security context based on additional generated instructions.

[0272] After receiving the additional generation instruction, the terminal device can generate a second security context based on the additional generation instruction. It should be understood that the terminal device generates the second security context in the same way that the data transmission network element generates the second security context; for a detailed description, please refer to the relevant description in step 204.

[0273] Terminal devices can obtain security algorithms based on additional generated instructions.

[0274] It should be noted that when the additional generated instruction includes an identifier for the security algorithm, the terminal device can determine the security algorithm based on this identifier. When the additional generated instruction does not include an identifier for the security algorithm, the terminal device can obtain the security algorithm based on the first security algorithm in the first security context.

[0275] The terminal device can obtain the first key based on additional generated instructions.

[0276] When the terminal device has a first security context, it can obtain the first key based on the AS root key of the first security context according to the additional generation instruction, that is, determine the first key based on the AS root key of the first security context.

[0277] In one approach, the terminal device can use the AS root key of the first security context as the first key.

[0278] In another approach, the additional generation instruction includes an instruction for the first derived parameters. The terminal device can generate the first key based on the AS root key of the first security context and the first derived parameters. A detailed description can be found in step 204, where the data transmission network element generates the first key based on the AS root key of the first security context and the first derived parameters; this will not be repeated here.

[0279] The terminal device can be pre-configured with a Kn root key, and the terminal device can generate a first key based on the Kn root key according to an additional generation instruction.

[0280] In one approach, the terminal device can use the Kn root key as the first key.

[0281] In another approach, the additional generation instruction includes an instruction for the first derived parameter, allowing the terminal device to generate the first key based on the Kn root key and the first derived parameter. A detailed description can be found in step 204, where the data transmission network element generates the first key based on the Kn root key and the first derived parameter; this will not be repeated here.

[0282] When the session management function network element triggers two-factor authentication, the terminal device can perform two-factor authentication. The terminal device can generate a two-factor authentication key during the two-factor authentication process. The terminal device can receive additional generation instructions, which may include instructions for the second derived parameters. The terminal device can generate a first key based on the two-factor authentication key and the second derived parameters. A detailed description of the generation method can be found in step 203, where the session management function network element generates the first key based on the two-factor authentication key and the second derived parameters; it will not be repeated here.

[0283] After the terminal device generates the first key, it can further obtain a security key based on the first key according to additional generation instructions. A second security context is then generated based on the first key. The specific generation method can correspond to the same method used for generating the data transmission network element in step 204.

[0284] The additional generation instruction includes an identifier for the security algorithm, allowing the terminal device to generate a security key based on the first key and the third derived parameters. A detailed description can be found in step 204, where the data transmission network element generates the security key based on the first key and the third derived parameters; this will not be repeated here.

[0285] It should be understood that the second security context can be generated by the terminal device and the data transmission network element. The data transmission network element can be an access network device, a user plane function network element, or other network elements with the same function. In other words, a security context can be generated by two devices. When the data transmission network element possesses a first security context, both the first and second security contexts can be generated by the terminal device and the data transmission network element. When the data transmission network element does not possess a first security context, the second security context can be obtained by the terminal device and the data transmission network element. In this case, the two security contexts reside on different devices. Because the two security contexts have different algorithms and / or keys and reside on different network elements, further security isolation can be achieved.

[0286] After receiving a session acceptance message from the session management function network element, the terminal device can determine that the second communication service has been established based on the session acceptance message. Then, it can transmit the corresponding service with the data network, and the transmitted second communication service can be protected using a second security context. Therefore, when public network services are attacked, the impact on private network services can be avoided, and vice versa. This achieves secure isolation between public and private network services, thereby improving their security.

[0287] Based on the above network architecture, please refer to Figure 3 , Figure 3 This is a flowchart illustrating another security context generation method disclosed in an embodiment of the present invention. Figure 3 As shown, the security context generation method may include the following steps.

[0288] 301. The terminal device obtains the first security context.

[0289] For a detailed description of step 301, please refer to the description of step 201, which will not be repeated here.

[0290] 302. Access network devices obtain the first security context.

[0291] The detailed description of step 302 can be found in the description of step 201, and will not be repeated here.

[0292] 303. The terminal device sends a session request message to the session management function network element.

[0293] For a detailed description of step 303, please refer to the description of step 202, which will not be repeated here.

[0294] 304. Session management function network elements send additional security context indications to access network devices.

[0295] For a detailed description of step 304, please refer to the description of step 203, which will not be repeated here.

[0296] It should be understood that when the session management function network element has determined the security algorithm, the additional security context indication may also include the identifier of the security algorithm.

[0297] 305. The access network device obtains a second security context based on the additional security context indication.

[0298] After receiving an additional security context indication from the session management function network element, the access network device can generate a second security context based on the additional security context indication. A detailed description of generating the second security context can be found in the description of step 204.

[0299] Access network devices can obtain security algorithms based on additional security context indications.

[0300] One possible implementation is that, when the additional security context indication supports the generation of a second security context, the access network device can obtain a security algorithm based on an algorithm priority list. A detailed description can be found in the relevant description in step 204, and will not be repeated here.

[0301] Another possible implementation is that the additional security context indication can include an identifier of the security algorithm, which the access network device can use to determine the security algorithm. The security algorithm may already be determined in the session management function network element. For detailed descriptions, please refer to the corresponding descriptions in step 203 (session management function network element determining the security algorithm) and step 204 (determining the security algorithm based on the additional security context indication), which will not be repeated here.

[0302] Another possible implementation is that the access network device can obtain the security algorithm from the first security algorithm in the first security context based on additional security context indications.

[0303] Access network devices can generate a first key based on additional security context indications.

[0304] One possible implementation is that the access network device can obtain the AS root key of the first security context and use this AS root key as the first key. A detailed description can be found in the relevant description in step 204, and will not be repeated here.

[0305] Another possible implementation is that the access network device can generate the first key based on the AS root key of the first security context and the first derived parameters. A detailed description can be found in the relevant description in step 204, and will not be repeated here.

[0306] Furthermore, the access network device can generate a security key based on the first key, according to additional security context indications.

[0307] The access network device can generate a security key based on the first key and the third derived parameters. A detailed description of generating the security key can be found in step 204, which describes generating the security key based on the first key and the third derived parameters; it will not be repeated here.

[0308] 306. The session management function network element sends a session acceptance message to the terminal device.

[0309] For a detailed description of step 306, please refer to the description of step 206, which will not be repeated here.

[0310] It should be understood that when the session management function network element has determined the security algorithm, the session acceptance message may include an additional generation instruction, which may include the identifier of the security algorithm.

[0311] 307. The access network device sends an additional generation instruction to the terminal device.

[0312] The access network device can send additional generation instructions to the terminal device, and correspondingly, the terminal device can receive additional generation instructions from the access network device. For a detailed description of these steps, please refer to steps 205-207, which will not be repeated here.

[0313] It should be noted that additional generated instructions may include one or more of the following: explicit instructions, instructions for the first derived parameter, and identifiers of the security algorithm.

[0314] It should be understood that in steps 306 and 307, one of the messages includes the identifier of the security algorithm.

[0315] 308. The terminal device obtains a second security context based on additional generated instructions.

[0316] For a detailed description of step 308, please refer to the descriptions of steps 305 and 208.

[0317] Terminal devices can obtain security algorithms based on additional generated instructions.

[0318] Additional generated instructions may include an identifier for the security algorithm. The terminal device can determine the security algorithm based on this identifier. Alternatively, the terminal device can obtain the security algorithm based on the first security algorithm of the first security context. A detailed description can be found in the relevant description of step 208, and will not be repeated here.

[0319] The terminal device can generate the first key based on additional generation instructions.

[0320] One possible implementation is that the terminal device can obtain the AS root key of the first security context and use this AS root key as the first key. Detailed descriptions can be found in steps 208 and 305, and will not be repeated here.

[0321] Another possible implementation is that, when the additional generation instruction includes an instruction for the first derived parameter, the terminal device can generate the first key based on the AS root key of the first security context and the first derived parameter. A detailed description can be found in steps 204, 208, and 305, which describe the generation of the first key based on the AS root key and the first derived parameter, and will not be repeated here.

[0322] Furthermore, the terminal device can generate a security key based on the first key according to additional generation instructions.

[0323] When the additional generation instruction includes an identifier of the security algorithm, the terminal device can generate a security key based on the first key and the third derived parameter. The third derived parameter may be an identifier of the security algorithm. A detailed description of generating the security key can be found in steps 204, 208, and 305, which describe the generation of the security key based on the first key and the third derived parameter, and will not be repeated here.

[0324] Thus, the terminal device can protect user plane data through a first security context and a second security context. The first and second security contexts can be used to protect private network services (public network data) and public network services (private network data), respectively. When an attacker obtains one set of security contexts, the other security context will not be exposed because the two sets are different. This achieves the goal of protecting public network services and private network services separately, thereby improving the security of communication services.

[0325] It should be understood that the data transmission network element in this embodiment is an access network device.

[0326] Based on the above network architecture, please refer to Figure 4 , Figure 4 This is a flowchart illustrating another security context generation method disclosed in an embodiment of the present invention. Figure 4 As shown, the security context generation method may include the following steps.

[0327] 401. The terminal device obtains the first security context.

[0328] For a detailed description of step 401, please refer to the description of step 201, which will not be repeated here.

[0329] 402. Access network devices obtain the first security context.

[0330] The detailed description of step 402 can be found in the description of step 201, and will not be repeated here.

[0331] 403. The terminal device sends a session request message to the session management function network element.

[0332] For a detailed description of step 403, please refer to the description of step 202, which will not be repeated here.

[0333] 404. The terminal device performs secondary authentication.

[0334] The session management function network element can trigger secondary authentication between the terminal device and the authentication, authorization, and accounting network element based on the DNN and / or the terminal device's subscription information carried in the session request message. The terminal device's subscription information can be obtained by requesting it from the UDM. For example, when the DNN is a specific DNN, or when the terminal device's subscription information indicates that secondary authentication is required, the session management function network element can trigger secondary authentication.

[0335] Terminal devices can obtain a secondary authentication key through two-factor authentication. Secondary authentication can be implemented based on an extended authentication protocol (EAP). The terminal device and the authentication, authorization, and accounting network element can generate a secondary authentication key. The secondary authentication key can be a master session key (MSK) or an extended master session key (EMSK).

[0336] The secondary authentication process can be found in 3GPP TS 33.501 and RFC 3748.

[0337] After the authentication, authorization, and accounting network element completes the secondary authentication, it can send the secondary authentication key to the session management function network element. Correspondingly, the session management function network element can receive the secondary authentication key from the authentication, authorization, and accounting network element.

[0338] 405. The session management function network element generates the first key based on the secondary authentication key.

[0339] The session management function network element can first determine whether a second security context needs to be generated. For a detailed description, please refer to step 203, which describes how the session management function network element determines whether the terminal device needs to generate a second security context; it will not be repeated here.

[0340] When the session management function network element determines that a second security context needs to be generated, it can determine the security algorithm. A detailed description of the process by which the session management function network element determines the security algorithm can be found in step 203, and will not be repeated here.

[0341] When the session management function network element determines that a second security context needs to be generated, it can generate a first key based on the received secondary authentication key. The session management function network element can generate the first key based on the second derived parameters and the secondary authentication key. A detailed description of the generation process can be found in step 203, and will not be repeated here.

[0342] 406. Session management function network elements send additional security context indications to access network devices.

[0343] For a detailed description of step 406, please refer to the description of step 203, which will not be repeated here.

[0344] It should be noted that the additional security context indication includes at least the first key.

[0345] It should be understood that when the session management function network element has determined the security algorithm, the additional security context indication may also include the identifier of the security algorithm.

[0346] 407. The access network device obtains a second security context based on the additional security context indication.

[0347] After receiving an additional security context indication from the session management function network element, the access network device can obtain a second security context based on the additional security context indication. A detailed description of generating the second security context can be found in the description of step 204.

[0348] Access network devices can obtain security algorithms based on additional security context indications.

[0349] One possible implementation is that, when the additional security context indication supports the generation of a second security context, the access network device can obtain a security algorithm based on an algorithm priority list. A detailed description can be found in the relevant description in step 204, and will not be repeated here.

[0350] Another possible implementation is that the additional security context indication may include an identifier of the security algorithm, which the access network device can use to determine the security algorithm. The security algorithm can be determined by the session management function network element. Detailed descriptions can be found in the corresponding descriptions in steps 203 and 204, and will not be repeated here.

[0351] Another possible implementation is that the access network device can obtain the security algorithm from the first security algorithm in the first security context based on additional security context indications.

[0352] Access network devices can generate a first key based on additional security context indications.

[0353] Additional security context indications may include a first key, which access network devices can directly obtain. A detailed description can be found in the relevant description in step 204, and will not be repeated here.

[0354] Furthermore, the access network device can generate a security key based on the first key, according to additional security context indications.

[0355] The access network device can generate a security key based on the first key and the third derived parameters. A detailed description of generating the security key can be found in step 204, and will not be repeated here.

[0356] 408. The session management function network element sends a session acceptance message to the terminal device.

[0357] For a detailed description of step 408, please refer to the description of step 206, which will not be repeated here.

[0358] The session accept message may include additional generation instructions, which may include instructions for a second derived parameter and / or an identifier for a security algorithm.

[0359] 409. The access network device sends an additional generation instruction to the terminal device.

[0360] Correspondingly, the terminal device receives an additional generation instruction from the session management function network element. A detailed description of step 409 can be found in the descriptions of steps 205 and 207.

[0361] It should be noted that additional generated instructions may include one or more of the following: explicit instructions and identifiers of security algorithms.

[0362] It should be understood that in steps 408 and 409, one of the messages includes an identifier for the security algorithm.

[0363] 410. The terminal device obtains a second security context based on additional generated instructions.

[0364] For a detailed description of step 410, please refer to the descriptions of steps 407 and 208.

[0365] The additional generation instruction may include an identifier of the security algorithm, which the terminal device can use to determine the security algorithm. If the additional generation instruction does not include an identifier of the security algorithm, the terminal device can also obtain the security algorithm based on the first security algorithm of the first security context. For a detailed description, please refer to the relevant descriptions in steps 407 and 208, which will not be repeated here.

[0366] The terminal device can generate the first key based on additional generation instructions.

[0367] The additional generation instruction may include an instruction for a second derived parameter, which may instruct the terminal device to obtain the first key based on the second derived parameter. The terminal device can generate the first key based on the secondary authentication key and the second derived parameter. Detailed descriptions can be found in steps 203, 208, and 407, and will not be repeated here.

[0368] Furthermore, the terminal device can generate a security key based on the first key according to additional generation instructions.

[0369] When the additional generation instruction includes an identifier for the security algorithm, the terminal device can generate a security key based on the first key and the third derived parameters. A detailed description of generating the security key can be found in steps 204, 208, and 407, which describe the generation of the security key based on the first key and the third derived parameters; it will not be repeated here.

[0370] Thus, the terminal device can protect user plane data through both the second and first security contexts. The terminal device can obtain both security contexts. When sending data for the corresponding PDU session (e.g., private network data), the terminal device can use the second security context for user plane security protection. When sending data for the corresponding PDU session (e.g., public network data), the terminal device can use the first security context for user plane security protection, thereby achieving secure isolation between public network services and public network services.

[0371] It should be understood that the data transmission network element in this embodiment is an access network device.

[0372] Based on the above network architecture, please refer to Figure 5 , Figure 5 This is a flowchart illustrating another security context generation method disclosed in an embodiment of the present invention. Figure 5 As shown, the security context generation method may include the following steps.

[0373] 501. The terminal device obtains the first security context.

[0374] 502. Access network devices obtain the first security context.

[0375] 503. The terminal device sends a session request message to the session management function network element.

[0376] 504. Terminal devices must perform secondary authentication.

[0377] 505. The session management function network element generates the first key based on the secondary authentication key.

[0378] For a detailed description of steps 501-505, please refer to the description of steps 401-405, which will not be repeated here.

[0379] 506. Session management function network elements send additional security context indications to user plane function network elements.

[0380] For a detailed description of step 506, please refer to the relevant description in step 203, which will not be repeated here.

[0381] It should be noted that the additional security context indication includes at least the first key.

[0382] It should be understood that when the session management function network element has determined the security algorithm, the additional security context indication may also include the identifier of the security algorithm.

[0383] 507. User plane function network elements obtain a second security context based on additional security context instructions.

[0384] After receiving an additional security context indication from the session management function network element, the user plane function network element can generate a second security context based on the additional security context indication. A detailed description of generating the second security context can be found in step 204.

[0385] User plane function network elements can obtain security algorithms based on additional security context indications.

[0386] One possible implementation is that, when the additional security context indication supports the generation of a second security context, the user plane function network element can obtain a security algorithm based on an algorithm priority list. A detailed description can be found in the relevant description in step 204, and will not be repeated here.

[0387] Another possible implementation is that the additional security context indication may include an identifier of the security algorithm, which the user plane function network element can use to determine the security algorithm. The security algorithm can be determined by either the session management function network element or the user plane function network element. For detailed descriptions, please refer to the corresponding descriptions in steps 203 and 204, which will not be repeated here.

[0388] User plane function network elements can generate a first key based on additional security context instructions.

[0389] Additional security context indications may include a first key, which user plane function network elements can directly obtain. For a detailed description, please refer to the relevant description in step 204, which will not be repeated here.

[0390] Furthermore, user plane function network elements can generate security keys based on the first key according to additional security context instructions.

[0391] User plane function network elements can generate a security key based on the first key and the third derived parameters. A detailed description of generating the security key can be found in step 204, and will not be repeated here.

[0392] 508. User plane function network element sends additional generation instruction to session management function network element.

[0393] User plane function network elements can send additional generation instructions to session management function network elements, and correspondingly, session management function network elements can receive additional generation instructions from user plane function network elements. Additional generation instructions may include an identifier of the security algorithm. Additional generation instructions can be encapsulated in an N4Session Establishment Response message.

[0394] For a detailed description of step 508, please refer to the relevant descriptions in steps 205 and 207, which will not be repeated here.

[0395] It should be understood that step 508 is an optional step.

[0396] 509. The session management function network element sends a session acceptance message to the terminal device.

[0397] After receiving an additional generation instruction from the user plane function network element, the session management function network element can encapsulate the received additional generation instruction in a session acceptance message, and then send the session acceptance message to the terminal device. Correspondingly, the terminal device can receive the session acceptance message from the session management function network element.

[0398] It should be noted that the session acceptance message may include additional generation instructions, which may include one or more of the following: instructions for the second derived parameters and identifiers for the security algorithm. The instructions for the second derived parameters may originate from the session management function network element; the identifiers for the security algorithm may originate from either the user plane function network element or the session management function network element.

[0399] For a detailed description of 509, please refer to the relevant descriptions in steps 205-207, which will not be repeated here.

[0400] 510. The terminal device obtains a second security context based on additional generated instructions.

[0401] The terminal device can obtain a second security context based on additional generated instructions. A detailed description of step 510 can be found in the descriptions of steps 507 and 208.

[0402] The terminal device can obtain the security algorithm based on an additional generated instruction. The additional generated instruction may include an identifier of the security algorithm, and the terminal device can determine the security algorithm based on the identifier. If the additional generated instruction does not include an identifier of the security algorithm, the terminal device can also obtain the security algorithm based on the first security algorithm of the first security context. For a detailed description, please refer to the relevant descriptions in steps 508 and 208, which will not be repeated here.

[0403] The terminal device can generate the first key based on additional generation instructions.

[0404] The additional generation instruction may include an instruction for a second derived parameter, which may instruct the terminal device to obtain the first key based on the second derived parameter. The terminal device can generate the first key based on the secondary authentication key and the second derived parameter. Detailed descriptions can be found in steps 203, 208, and 507, and will not be repeated here.

[0405] Furthermore, the terminal device can generate a security key based on the first key according to additional generation instructions.

[0406] When the additional generation instruction includes an identifier for the security algorithm, the terminal device can generate a security key based on the first key and the third derived parameters. A detailed description of generating the security key can be found in steps 204, 208, and 507, which describe the generation of the security key based on the first key and the third derived parameters; it will not be repeated here.

[0407] Thus, the terminal device can protect user plane data through both the second and first security contexts. The terminal device can obtain both security contexts. When sending data for the corresponding PDU session (e.g., private network data), the terminal device can use the first security context for user plane security protection, with the access network device handling the deprotection. When sending data for the corresponding PDU session (e.g., public network data), the terminal device can use the second security context for user plane security protection, with the user plane functional network element handling the deprotection. Therefore, one security context resides on the access network device, and the other on the user plane functional network element. These two security contexts have different algorithms and keys and reside in different entities, thus achieving security isolation. Furthermore, the second security context can be generated from the key produced after the terminal device performs secondary authentication with the authentication, authorization, and accounting network element. The first security context can be generated from the key produced after the terminal device performs initial authentication with the unified data management network element (located on the public network). In this way, even if an attacker obtains the key of the unified data management network element, since the attacker does not obtain the key of the authentication, authorization, and accounting network element, they will also be unable to obtain the first key of the second security context, thus further achieving isolation. Furthermore, assuming that the user plane function network element, session management function network element, and authentication, authorization, and accounting network element are all maintained by the private network, while access network equipment, access and mobility management function network elements, etc., are maintained by the public network, the public network will also be unable to obtain the first security context, thereby resolving the issue of mutual distrust between the private and public networks.

[0408] It should be understood that the data transmission network element in this embodiment is a user plane function network element.

[0409] Based on the above network architecture, please refer to Figure 6 , Figure 6 This is a flowchart illustrating another security context generation method disclosed in an embodiment of the present invention. Figure 6 As shown, the security context generation method may include the following steps.

[0410] 601. The terminal device obtains the first security context.

[0411] For a detailed description of step 601, please refer to the description of step 201, which will not be repeated here.

[0412] 602. The correspondence between the identifier of the pre-configured terminal equipment of the user plane function network element and the Kn root key.

[0413] User plane function network elements can pre-configure the mapping between terminal device identifiers and root keys (Kn). The terminal device identifier can be a generic public subscription identifier (GPSI) or an internet protocol (IP) address. That is, knowing the terminal device's own identifier, the user plane function network element can determine the first key based on the mapping between the terminal device identifier and the root key (Kn). For example, the user plane function network element can pre-configure a mapping table between terminal device identifiers and root keys (Kn), where one identifier corresponds to one root key (Kn). It should be understood that the above example is illustrative of the possibility of user plane function network elements pre-configuring the mapping between terminal device identifiers and root keys (Kn), and does not constitute a limitation.

[0414] After the user plane function network element pre-configures the identifier of the terminal device and the correspondence between the Kn root key and the terminal device, it can issue the Kn root key to the corresponding terminal device.

[0415] For a detailed description of step 602, please refer to the description of step 205, which will not be repeated here.

[0416] 603. Terminal devices are pre-configured with the Kn root key.

[0417] 604. The terminal device sends a session request message to the session management function network element.

[0418] For a detailed description of step 604, please refer to the description of step 202, which will not be repeated here.

[0419] It should be noted that the session request message may include the identifier of the terminal device.

[0420] 605. The session management function network element determines the corresponding user plane function network element.

[0421] The session management function network element can first determine whether a second security context needs to be generated. For a detailed description, please refer to step 203; it will not be repeated here.

[0422] The session management function network element can identify the user plane function network element. Optionally, the user plane function network element has a mapping between the terminal device identifier and the Kn root key.

[0423] One possible implementation is that if there is one user plane function network element corresponding to the DNN of the session request message, then this user plane function network element can be identified as the network element that generates the corresponding second security context.

[0424] Another possible implementation involves multiple user plane function network elements corresponding to the DNN in the session request message. The session management function network element can determine the user plane function network element by pre-configuring the mapping between the terminal device identifier and the user plane function network element. Optionally, the session management function network element can also obtain the context of the corresponding terminal device based on the session request message, determine the identifier of the terminal device based on the context of the terminal device, and then determine the user plane function network element based on the pre-configured mapping between the terminal device identifier and the user plane function network element. It should be understood that the identifier of the terminal device can be carried in the SM message or stored in the context of the session management function network element.

[0425] 606. Session management function network elements send additional security context indications to user plane function network elements.

[0426] For a detailed description of step 606, please refer to the description of step 203, which will not be repeated here.

[0427] It should be noted that additional security context indications may include the identifier of the terminal device.

[0428] 607. User plane function network elements obtain a second security context based on additional security context instructions.

[0429] After receiving an additional security context indication from the session management function network element, the user plane function network element can generate a second security context based on the additional security context indication. For a detailed description, please refer to the description of step 204.

[0430] User plane function network elements can obtain security algorithms based on additional security context indications. A detailed description can be found in step 204, and will not be repeated here.

[0431] User plane function network elements can generate a first key based on additional security context instructions.

[0432] One possible implementation is that the user plane function network element can first determine the Kn root key based on the identifier of the received terminal device and the correspondence between the terminal device and the Kn root key. The user plane function network element can then use the Kn root key as the first key.

[0433] Another possible implementation is that after the user plane function network element determines the root Kn key, it can generate the first key based on the Kn root key and the first derived parameter. The specific generation method can be referred to the relevant description in step 204, which will not be repeated here.

[0434] Furthermore, user plane function network elements can generate security keys based on the first key according to additional security context instructions.

[0435] User plane function network elements can generate security keys based on the first key and the third derived parameters. A detailed description of generating the security key can be found in step 204, which describes generating the security key based on the first key and the third derived parameters; it will not be repeated here.

[0436] 608. User plane function network element sends additional generation instruction to session management function network element.

[0437] User plane function network elements can send additional generation instructions to session management function network elements, and correspondingly, session management function network elements can receive additional generation instructions from user plane function network elements.

[0438] For a detailed description of step 608, please refer to the descriptions of steps 205 and 207, which will not be repeated here.

[0439] 609. The session management function network element sends a session acceptance message to the terminal device.

[0440] After receiving an additional generation instruction from the user plane function network element, the session management function network element can encapsulate the received additional generation instruction in a session acceptance message, and then send the session acceptance message to the terminal device. Correspondingly, the terminal device can receive the session acceptance message from the session management function network element.

[0441] It should be noted that the session acceptance message may include additional generation instructions, which may include one or more of the following: an indication of a first derived parameter, an indication of a second derived parameter, and an identifier of a security algorithm. Specifically, the indication of the first derived parameter may originate from a user plane function network element; the indication of the second derived parameter may originate from a session management function network element; and the identifier of the security algorithm may originate from either a user plane function network element or a session management function network element.

[0442] For a detailed description of step 609, please refer to the descriptions of steps 205-207, which will not be repeated here.

[0443] 610. The terminal device obtains a second security context based on additional generated instructions.

[0444] The terminal device can obtain a second security context based on additional generated instructions. A detailed description of step 610 can be found in the descriptions of steps 607 and 208.

[0445] The terminal device can obtain the security algorithm based on the additional generated instructions. The additional generated instructions may include an identifier for the security algorithm, which the terminal device can use to determine the security algorithm. For a detailed description, please refer to the relevant descriptions in steps 607 and 208, which will not be repeated here.

[0446] The terminal device can generate a first key based on additional generation instructions. Detailed descriptions can be found in steps 607 and 208, and will not be repeated here.

[0447] The terminal device can use the pre-configured Kn root key as the first key. For a detailed description, please refer to the relevant descriptions in steps 607 and 208, which will not be repeated here.

[0448] Additional generation instructions may include instructions for the first derived parameters, and the terminal device may generate the first key based on the Kn root key and the first derived parameters.

[0449] Furthermore, the terminal device can generate a security key based on the first key according to additional generation instructions.

[0450] When the additional generation instruction includes an identifier for the security algorithm, the terminal device can generate a security key based on the first key and the third derived parameters. A detailed description of generating the security key can be found in steps 204, 208, and 607, which describe the generation of the security key based on the first key and the third derived parameters; it will not be repeated here.

[0451] It should be noted that when the terminal device generates the first key during the generation of the second security context, the first key can be determined based on the Kn root key and the first derived parameter configured on the terminal device.

[0452] Thus, the terminal device can protect user plane data through the second security context and the first security context. The second security context is generated by the terminal device and the Kn root key pre-configured on the user plane function network element. Figure 5 In the corresponding method embodiment, the first security context is generated by the key produced after the terminal device performs its initial authentication with the unified data management network element (located on the public network). Thus, even if an attacker obtains the key of the unified data management network element, since the attacker does not obtain the key of the user plane function network element, they cannot obtain the key of the second security context, thereby further achieving security isolation. Furthermore, compared to... Figure 5 The corresponding method embodiment can not only achieve the above-mentioned functions, but also further reduce the cost of private network equipment.

[0453] It should be understood that the data transmission network element in this embodiment is a user plane function network element.

[0454] It should be understood that the functions performed by the terminal device in the above security context generation method can also be performed by modules (e.g., chips) in the terminal device, the functions performed by the session management function network element can also be performed by modules (e.g., chips) in the session management function network element, the functions performed by the data transmission network element can also be performed by modules (e.g., chips) in the data transmission network element, the functions performed by the user plane function network element can also be performed by modules (e.g., chips) in the user plane function network element, and the functions performed by the access network device can also be performed by modules (e.g., chips) in the access network device.

[0455] Based on the above network architecture, please refer to Figure 7 , Figure 7 This is a schematic diagram of the structure of a security context generation device disclosed in an embodiment of this application. Figure 7 As shown, the device may include an acquisition unit 701, a transmission unit 702, and a receiving unit 703, wherein:

[0456] The acquisition unit 701 is used to acquire a first security context, which is used to protect the first communication service of the terminal device.

[0457] Sending unit 702 is used to send a session request message to the session management function network element. The session request message is used to request the establishment of a session for a second communication service, which is different from the first communication service.

[0458] The receiving unit 703 is configured to receive a session acceptance message from the session management function network element, wherein the session acceptance message is used to complete the establishment of a session for the second communication service;

[0459] Acquisition unit 701 is also used to acquire additional generation instructions;

[0460] The acquisition unit 701 is further configured to acquire a second security context according to the additional generation instruction, the second security context being used to protect the second communication service.

[0461] As one possible implementation, the session request message includes first indication information, which is used to indicate that the terminal device supports generating the second security context.

[0462] As one possible implementation, the acquisition unit 701 acquires a second security context according to the additional generation instruction, the second security context being used to protect the second communication service including:

[0463] According to the additional generation instruction, obtain a security key based on the first key; and / or

[0464] The security algorithm is obtained based on the additional generation instructions.

[0465] As one possible implementation, the acquisition unit 701 acquires the security key based on the first key according to the additional generation instruction, including:

[0466] According to the additional generation instruction, the first key is obtained based on the AS root key of the first security context;

[0467] The security key is generated based on the first key.

[0468] As one possible implementation, the additional generation indication includes an indication of the first derived parameter, and the acquisition unit 701 acquires the first key based on the AS root key of the first security context according to the additional generation indication, including:

[0469] The first key is generated based on the AS root key of the first security context and the first derived parameters.

[0470] As one possible implementation, the first derived parameter is a downlink PDCP COUNT, and the indication of the first derived parameter is a portion of the bits of the downlink PDCP COUNT.

[0471] As one possible implementation, the device may further include:

[0472] Execution unit 704 is used to perform secondary authentication;

[0473] The generation unit 705 is used to generate a secondary authentication key during the secondary authentication process;

[0474] The acquisition unit 701 acquires the security key based on the first key according to the additional generation instruction, including:

[0475] Based on the additional generation instruction, the first key is obtained using the secondary authentication key;

[0476] Generate a security key based on the first key.

[0477] As one possible implementation, the additional generation indication includes an indication of the second derived parameter, and the acquisition unit 701 acquires the first key based on the secondary authentication key according to the additional generation indication, including:

[0478] The first key is generated based on the secondary authentication key and the second derived parameter, according to the indication of the second derived parameter.

[0479] As one possible implementation, the second derived parameter is one or more of the following parameters: downlink NASCOUNT, PDU session ID, NSSAI, and DNN.

[0480] As one possible implementation, the acquisition unit 701 generates a security key based on the first key, including:

[0481] The security key is generated based on the first key and the third derived parameter.

[0482] As one possible implementation, the additional generation instruction includes an identifier of the security algorithm, and the acquisition unit 701 generates the security key based on the first key and the third derived parameters, including:

[0483] The security key is generated based on the first key and the identifier and type of the security algorithm.

[0484] As one possible implementation, the additional generation instruction includes an identifier of the security algorithm.

[0485] As one possible implementation, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.

[0486] For a more detailed description of the aforementioned acquisition unit 701, sending unit 702, receiving unit 703, execution unit 704, and generation unit 705, please refer directly to the above description. Figures 2-6 The description of the terminal device in the method embodiment shown is directly obtained and will not be repeated here.

[0487] Based on the above network architecture, please refer to Figure 8 , Figure 8 This is a schematic diagram of another security context generation device disclosed in an embodiment of this application. Figure 8 As shown, the device may include:

[0488] The receiving unit 801 is configured to receive a session request message from a terminal device, wherein the session request message is used to request the establishment of a session for a second communication service;

[0489] The sending unit 802 is configured to send an additional security context indication to the data transmission network element, wherein the additional security context indication is used to indicate the generation of a second security context, and the second security context is used to protect the second communication service.

[0490] The sending unit 802 is further configured to send a session acceptance message to the terminal device, the session acceptance message being used to complete the establishment of a session for the second communication service.

[0491] As one possible implementation, the session request message includes first indication information, which is used to indicate that the terminal device supports generating a second security context. The sending unit 802 sending the additional security context indication to the data transmission network element includes:

[0492] When the first indication information indicates that the terminal device supports generating the second security context, the additional security context indication is sent to the data transmission network element.

[0493] As one possible implementation, the sending unit 802 sending additional security context indications to the data transmission network element includes:

[0494] Obtain the subscription information of the terminal device according to the session request message;

[0495] When the subscription information of the terminal device indicates that the second security context needs to be generated, the additional security context indication is sent to the data transmission network element.

[0496] As one possible implementation, the sending unit 802 sending additional security context indications to the data transmission network element includes:

[0497] When the local policy configuration of the session management function network element indicates that the second security context needs to be generated, the additional security context indication is sent to the data transmission network element.

[0498] As one possible implementation, the additional security context indication includes an identifier of the security algorithm, and the apparatus may further include an acquisition unit 803, wherein:

[0499] The acquisition unit 803 is used to acquire the security algorithm.

[0500] As one possible implementation, the additional security context indication includes a first key, and the device may further include:

[0501] Trigger unit 804 is used to trigger secondary authentication;

[0502] The receiving unit 801 is also used to receive the secondary authentication key from the authentication, authorization, and billing network element after the secondary authentication is successful.

[0503] The acquisition unit 803 is also used to acquire the first key based on the secondary authentication key.

[0504] As one possible implementation, the acquisition unit 803 acquires the first key based on the secondary authentication key, including:

[0505] The first key is obtained based on the secondary authentication key and the second derived parameter.

[0506] As one possible implementation, the second derived parameter is one or more of the following parameters: downlink NASCOUNT, PDU session ID, NSSAI, and DNN.

[0507] In one possible implementation, the session acceptance message includes an indication of a second derived parameter, which is used to indicate how to obtain a security key based on the secondary authentication key.

[0508] For a more detailed description of the receiving unit 801, transmitting unit 802, acquiring unit 803, and triggering unit 804 mentioned above, please refer directly to the above description. Figures 2-6 The descriptions of the session management function network element in the method embodiment shown are directly obtained and will not be elaborated here.

[0509] Based on the above network architecture, please refer to Figure 9 , Figure 9 This is a schematic diagram of the structure of another security context generation device disclosed in the embodiments of this application. For example... Figure 9 As shown, the device may include:

[0510] The receiving unit 901 is used to receive additional security context indications from the session management function network element;

[0511] The acquisition unit 902 is configured to acquire a second security context according to the additional security context indication, wherein the second security context is used to protect the second communication service;

[0512] The sending unit 903 is configured to send an additional generation instruction to the terminal device, the additional generation instruction being used to instruct the generation of the second security context.

[0513] As one possible implementation, the acquisition unit 902 is specifically used for:

[0514] Based on the additional security context indication, obtain the security key based on the first key; and / or

[0515] The security algorithm is obtained based on the additional security context indication.

[0516] As one possible implementation, the acquisition unit 902 is further configured to acquire a first security context before receiving an additional security context indication from the session management function network element. The first security context is used to protect a first communication service, which is different from the second communication service.

[0517] As one possible implementation, the acquisition unit 902 generates the security key based on the first key according to the additional security context indication, including:

[0518] Based on the additional security context indication, the first key is obtained using the AS root key of the first security context;

[0519] The security key is generated based on the first key.

[0520] As one possible implementation, the additional generation indication includes an indication of the first derived parameter, and the acquisition unit 902 acquires the first key based on the AS root key of the first security context according to the additional security context indication, including:

[0521] The first key is generated based on the AS root key of the first security context and the first derived parameters.

[0522] As one possible implementation, the first derived parameter is a downlink PDCP COUNT, and the indication of the first derived parameter is a portion of the bits of the downlink PDCP COUNT.

[0523] As one possible implementation, the additional security context indication includes the first key, and the acquisition unit 902 acquires the security key based on the first key according to the additional security context indication, including:

[0524] The security key is generated based on the first key.

[0525] As one possible implementation, the acquisition unit 902 generates the security key based on the first key by:

[0526] The security key is generated based on the first key and the third derived parameter.

[0527] As one possible implementation, the additional security context indicator includes an identifier of the security algorithm, and the acquisition unit 902 generates the security key based on the first key and the third derived parameters, including:

[0528] The security key is generated based on the first key and the identifier and type of the security algorithm.

[0529] As one possible implementation, the additional generation instruction includes an identifier of the security algorithm.

[0530] As one possible implementation, the additional security context indication includes an identifier of the security algorithm.

[0531] As one possible implementation, the acquisition unit 902 acquires the security algorithm based on the additional security context indication, including:

[0532] Based on the additional security context indication, the security algorithm is obtained according to the security capabilities of the terminal device and a pre-configured list of algorithm priorities, wherein the security capabilities of the terminal device are used to indicate all security algorithms supported by the terminal device.

[0533] As one possible implementation, when the first communication service is a public network service, the second communication service is a private network service; when the first communication service is a private network service, the second communication service is a public network service.

[0534] For a more detailed description of the receiving unit 901, the acquiring unit 902, and the transmitting unit 903, please refer directly to the above description. Figures 2-6 The relevant descriptions of the data transmission network elements in the method embodiments shown are directly obtained and will not be elaborated here.

[0535] Based on the above network architecture, please refer to Figure 10 , Figure 10 This is a schematic diagram of the structure of another security context generation device disclosed in the embodiments of this application. For example... Figure 10 As shown, the security context generation device may include a processor 1001, a memory 1002, an input interface 1003, an output interface 1004, and a bus 1005. The memory 1002 may be independent and connected to the processor 1001 via the bus 1005. Alternatively, the memory 1002 may be integrated with the processor 1001. The bus 1005 is used to connect these components.

[0536] In one embodiment, the security context generation device can be a terminal device or a module (e.g., a chip) within the terminal device. When the computer program instructions stored in the memory 1002 are executed, the processor 1001 controls the sending unit 702 and the receiving unit 703 to perform the operations performed in the above embodiments. The processor 1001 is also used to execute the operations performed by the acquisition unit 701, the execution unit 704, and the generation unit 705 in the above embodiments. The input interface 1003 is used to execute the operations performed by the receiving unit 703 in the above embodiments, and the output interface 1004 is used to execute the operations performed by the sending unit 702 in the above embodiments. The terminal device or the module within the terminal device can also be used to perform the above... Figures 2-6 The various methods executed by the terminal device in the method embodiments will not be described in detail.

[0537] In one embodiment, the security context generation device can be a session management function network element or a module (e.g., a chip) within the session management function network element. When the computer program instructions stored in the memory 1002 are executed, the processor 1001 is used to control the receiving unit 801 and the sending unit 803 to perform the operations performed in the above embodiment. The processor 1001 is also used to execute the operations performed by the acquisition unit 803 and the triggering unit 804 in the above embodiment. The input interface 1003 is used to execute the operations performed by the receiving unit 801 in the above embodiment, and the output interface 1004 is used to execute the operations performed by the sending unit 802 in the above embodiment. The above-mentioned session management function network element or the module within the session management function network element can also be used to perform the above-mentioned operations. Figures 2-6 The various methods executed by the session management function network element in the method embodiment will not be described in detail.

[0538] In one embodiment, the security context generation device can be a data transmission network element or a module (e.g., a chip) within the data transmission network element. When the computer program instructions stored in the memory 1002 are executed, the processor 1001 controls the receiving unit 901 and the sending unit 903 to perform the operations performed in the above embodiment. The processor 1001 is also used to execute the operations performed by the acquiring unit 902 in the above embodiment. The input interface 1003 is used to execute the operations performed by the receiving unit 901 in the above embodiment, and the output interface 1004 is used to execute the operations performed by the sending unit 903 in the above embodiment. The aforementioned data transmission network element or module within the data transmission network element can also be used to perform the aforementioned operations. Figures 2-6 The various methods executed by the data transmission network element in the method embodiment will not be described in detail.

[0539] Based on the above network architecture, please refer to Figure 11 , Figure 11 This is a schematic diagram of the structure of another security context generation device disclosed in the embodiments of this application. For example... Figure 11As shown, the security context generation device may include an input interface 1101, a logic circuit 1102, and an output interface 1103. The input interface 1101 and the output interface 1103 are connected via the logic circuit 1102. The input interface 1101 is used to receive information from other devices, and the output interface 1103 is used to output, schedule, or send information to other devices. The logic circuit 1102 is used to perform operations other than those of the input interface 1101 and the output interface 1103, such as implementing the functions implemented by the processor 1001 in the above embodiments. The security context generation device may be a terminal device or a module of a terminal device, a session management function network element or a module of a session management function network element, or a data transmission network element or a module of a data transmission network element. More detailed descriptions of the input interface 1101, the logic circuit 1102, and the output interface 1103 can be directly obtained by referring to the relevant descriptions of the terminal device, the session management function network element, and the data transmission network element in the above method embodiments, and will not be repeated here.

[0540] This application also discloses a computer-readable storage medium storing instructions thereon, which, when executed, perform the methods described in the above method embodiments.

[0541] This application also discloses a computer program product including instructions that, when executed, perform the methods described in the above method embodiments.

[0542] This application also discloses a communication system, which includes a terminal device, a session management function network element, and a data transmission network element. For detailed descriptions, please refer to... Figures 2-6 The security context generation method is shown.

[0543] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of this application. It should be understood that the above description is only a specific embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of this application should be included within the scope of protection of this application.

Claims

1. A method for generating a security context, characterized in that, Applications to security context generation apparatus include: Receive a session request message from a terminal device, the session request message being used to request the establishment of a session for a second communication service; Send an additional security context indication to the data transmission network element. The additional security context indication is used to indicate the generation of a second security context, which is used to protect the second communication service. A session acceptance message is sent to the terminal device, which is used to complete the establishment of a session for the second communication service.

2. The method according to claim 1, characterized in that, The second security context is different from the first security context. The first security context is used to protect the first communication service of the terminal device, and the first communication service is different from the second communication service.

3. The method according to claim 2, characterized in that, The first communication service is a public network service, and the second communication service is a private network service; or... The first communication service is a private network service, and the second communication service is a public network service; The public network service and the private network service are services in a non-public network integrated with a public network.

4. The method according to any one of claims 1-3, characterized in that, The session request message includes first indication information, and the step of sending additional security context indication to the data transmission network element includes: When the first indication information indicates that the terminal device supports generating the second security context, the additional security context indication is sent to the data transmission network element.

5. The method according to any one of claims 1-4, characterized in that, Sending additional security context indications to data transmission network elements includes: The subscription information of the terminal device is obtained based on the session request message; When the subscription information of the terminal device indicates that the second security context needs to be generated, the additional security context indication is sent to the data transmission network element.

6. The method according to any one of claims 1-5, characterized in that, Sending additional security context indications to data transmission network elements includes: When the local policy configured by the security context generation device indicates that the second security context needs to be generated, the additional security context indication is sent to the data transmission network element.

7. The method according to any one of claims 1-6, characterized in that, The additional security context indication includes an identifier of the security algorithm, and the method further includes: Obtain the security algorithm.

8. The method according to any one of claims 1-7, characterized in that, The additional security context indication includes a first key, and the method further includes: Trigger two-factor authentication; After successful secondary authentication, the secondary authentication key is received from the authentication, authorization, and billing network element; The first key is obtained based on the secondary authentication key.

9. The method according to claim 8, characterized in that, The step of obtaining the first key based on the secondary authentication key includes: The first key is obtained based on the secondary authentication key and the second derived parameter, wherein the second derived parameter is one or more of the following parameters: downlink non-access layer number (NAS COUNT), the identifier of the second communication service session, the network slice selection support information corresponding to the second communication service session, or the data network name corresponding to the second communication service session.

10. The method according to claim 8 or 9, characterized in that, The session accept message includes an indication of a second derived parameter, which is used to indicate how to obtain a security key based on the secondary authentication key.

11. The method according to any one of claims 1-10, characterized in that, The security context generation device is a session management function network element or a chip within a session management function network element.

12. A method for generating a security context, characterized in that, Applications to security context generation apparatus include: Receive additional security context indications from the session management function network element; A second security context is obtained based on the additional security context indication, and the second security context is used to protect the second communication service; Send an additional generation instruction to the terminal device, the additional generation instruction being used to instruct the generation of the second security context.

13. The method according to claim 12, characterized in that, The second security context is different from the first security context. The first security context is used to protect the first communication service of the terminal device, and the first communication service is different from the second communication service.

14. The method according to claim 13, characterized in that, The first communication service is a public network service, and the second communication service is a private network service; or... The first communication service is a private network service, and the second communication service is a public network service; The public network service and the private network service are services in a non-public network integrated with a public network.

15. The method according to claim 13 or 14, characterized in that, Before receiving additional security context indication from the session management function network element, the method further includes: Obtain the first security context.

16. The method according to any one of claims 12-15, characterized in that, The second security context includes a security key, and obtaining the second security context according to the additional security context indication includes: obtaining the security key based on the first key according to the additional security context indication; and / or, The second security context includes a security algorithm, and obtaining the second security context according to the additional security context indication includes: obtaining the security algorithm according to the additional security context indication.

17. The method according to claim 16, characterized in that, The step of obtaining the security key based on the first key according to the additional security context indication includes: According to the additional security context indication, the first key is obtained based on the access layer root key of the first security context, the first security context being used to protect the first communication service, which is different from the second communication service; The security key is generated based on the first key.

18. The method according to claim 17, characterized in that, The additional generation indication includes an indication of the first derived parameter, and the step of obtaining the first key based on the access layer root key of the first security context according to the additional security context indication includes: The first key is generated based on the access layer root key of the first security context and the first derived parameters.

19. The method according to claim 18, characterized in that, The first derived parameter is the downlink packet data aggregation protocol number (PDCP COUNT), and the indication of the first derived parameter is a portion of the bits of the downlink PDCP COUNT.

20. The method according to claim 16, characterized in that, The additional security context indication includes the first key, and the step of obtaining the security key based on the first key according to the additional security context indication includes: The security key is generated based on the first key.

21. The method according to claim 20, characterized in that, The step of generating the security key based on the first key includes: The security key is generated based on the first key and the third derived parameter, wherein the third derived parameter includes the identifier and type of the security algorithm.

22. The method according to any one of claims 16-21, characterized in that, The additional generation instruction includes an identifier for the security algorithm.

23. The method according to any one of claims 16-22, characterized in that, The additional security context indication includes an identifier of the security algorithm.

24. The method according to any one of claims 16-22, characterized in that, The step of obtaining the security algorithm based on the additional security context indication includes: Based on the additional security context indication, the security algorithm is obtained according to the security capabilities of the terminal device and a pre-configured list of algorithm priorities, wherein the security capabilities of the terminal device are used to indicate all security algorithms supported by the terminal device.

25. The method according to any one of claims 12-24, characterized in that, The security context generation device is a data transmission network element or a chip within a data transmission network element.

26. A security context generation apparatus, characterized in that, Includes modules or units for performing the method as described in any one of claims 1-25.

27. A security context generation apparatus, characterized in that, It includes a processor and a memory, wherein the processor calls a computer program stored in the memory to implement the method as described in any one of claims 1-25.

28. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program or computer instructions that, when executed, implement the method as described in any one of claims 1-25.

29. A method for generating a security context, characterized in that, include: The session management function network element receives a session request message from the terminal device, the session request message being used to request the establishment of a session for the second communication service; The session management function network element sends an additional security context indication to the data transmission network element. The additional security context indication is used to indicate the generation of a second security context, which is used to protect the second communication service. The data transmission network element receives additional security context indications from the session management function network element; The data transmission network element obtains a second security context according to the additional security context indication, and the second security context is used to protect the second communication service; The data transmission network element sends an additional generation instruction to the terminal device, the additional generation instruction being used to instruct the generation of the second security context; The session management function network element sends a session acceptance message to the terminal device, and the session acceptance message is used to complete the establishment of a session for the second communication service.

30. A system, characterized in that, include: Security context generation apparatus for performing the method as described in any one of claims 1-11 and security context generation apparatus for performing the method as described in any one of claims 12-25.