Security algorithm capability arrangement method and device and computer readable storage medium
By introducing a secure orchestration and management network element into the 6G distributed network, the problem of inconsistent security algorithm capabilities between different networks was solved, and secure access for UEs was achieved.
Patent Information
- Application Number
- CN202410578091.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-10
- Publication Date
- 2025-11-11
AI Technical Summary
In a 6G distributed network architecture, different distributed networks may have different security algorithm capabilities, which may prevent UEs that support specific security algorithm capabilities from effectively accessing the corresponding network.
By introducing a security orchestration and management network element, the security algorithm capabilities of different distributed networks are uniformly managed and orchestrated through a central network, ensuring that UEs that support specific security algorithm capabilities can access the corresponding networks.
It enables unified management of security algorithm capabilities across different distributed networks, ensuring that UEs can successfully access networks that support their security algorithm capabilities.
Smart Images

Figure CN120935703A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to an arrangement method, apparatus and computer-readable storage medium for secure algorithm capabilities. Background Technology
[0002] Currently, in the 6G (6th generation mobile networks) distributed network architecture, different distributed networks may have different security algorithm capabilities and support different security algorithms. UEs (User Equipment) that support specific security algorithm capabilities require security orchestration from the distributed network to access the corresponding distributed network. Summary of the Invention
[0003] Therefore, it is necessary to provide a method, apparatus, and computer-readable storage medium for orchestrating secure algorithm capabilities to address the aforementioned technical problems.
[0004] Firstly, a method for orchestrating security algorithm capabilities is provided, the method being applied to a first Access and Mobility Management Function (AMF) network element in a first distributed network, the method comprising:
[0005] Receive a registration request sent by a user equipment (UE) through a radio access network (RAN) node, wherein the registration request carries the security parameters of the UE;
[0006] A security algorithm capability scheduling request is sent to the security orchestration management network element in the first distributed network. The security algorithm capability scheduling request carries the security parameters and the identification information of the first AMF network element.
[0007] When the security algorithm capabilities supported by the first AMF network element match the security parameters, the security algorithm capability scheduling response sent by the security orchestration management network element is received, and the non-access stratum security mode command (NAS SMC) procedure is initiated to the UE through the RAN node.
[0008] If the security algorithm capabilities supported by the first AMF network element do not match the security parameters, the registration flow request sent by the security orchestration management network element is received and forwarded to the RAN node. The registration flow request carries the identification information of the second AMF network element in the second distributed network.
[0009] As an optional implementation, the method further includes:
[0010] Receive a security algorithm capability collaboration request sent by the security algorithm capability pool in the first distributed network;
[0011] A security algorithm capability collaboration response is sent to the security algorithm capability pool, and the security algorithm capability collaboration response carries the identification information of the first AMF network element.
[0012] Secondly, a method for orchestrating security algorithm capabilities is provided, the method being applied to a security orchestration management network element in a first distributed network, the method comprising:
[0013] The system receives a security algorithm capability scheduling request sent by the first access and mobility management function (AMF) network element in the first distributed network. The security algorithm capability scheduling request carries the security parameters of the user equipment (UE) and the identification information of the first AMF network element.
[0014] Based on the security parameters and the identification information of the first AMF network element, the system determines whether the security algorithm capabilities supported by the first AMF network element match the security parameters in the locally stored list of security algorithm capabilities.
[0015] If the security algorithm capabilities supported by the first AMF network element match the security parameters, a security algorithm capability scheduling response is sent to the first AMF network element.
[0016] If the security algorithm capabilities supported by the first AMF network element do not match the security parameters, a security algorithm capability discovery request is sent to the security orchestration management network element in the central network. After receiving the security algorithm capability discovery response sent by the security orchestration management network element in the central network, a registration transfer request is sent to the first AMF network element. The security algorithm capability discovery request carries the location information and security parameters of the UE. The security algorithm capability discovery response and the registration transfer request carry the identification information of the second AMF network element in the second distributed network.
[0017] As an optional implementation, the method further includes:
[0018] The system receives a security algorithm capability registration message sent by the security algorithm capability pool in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) of the security algorithm capability pool.
[0019] The mapping relationship between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool is stored in the local security algorithm capability list.
[0020] As an optional implementation, the method further includes:
[0021] A security algorithm capability synchronization request is sent to the security orchestration management network element in the central network. The security algorithm capability synchronization request carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
[0022] Thirdly, a method for orchestrating security algorithm capabilities is provided, the method being applied to a security algorithm capability pool in a first distributed network, the method comprising:
[0023] Send a security algorithm capability cooperation request to the first access and mobility management function (AMF) network element in the first distributed network;
[0024] Receive a security algorithm capability cooperation response sent by the first AMF network element, wherein the security algorithm capability cooperation response carries the identification information of the first AMF network element;
[0025] A security algorithm capability registration message is sent to the security orchestration management network element in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) of the security algorithm capability pool.
[0026] Fourthly, a method for orchestrating security algorithm capabilities is provided, which is applied to a security orchestration management network element in a central network. The method includes:
[0027] The system receives a security algorithm capability discovery request sent by a security orchestration management network element in the first distributed network. The security algorithm capability discovery request carries the location information and security parameters of the user equipment (UE).
[0028] Based on the location information and the security parameters, the identification information of the second access and mobility management function (AMF) network element in the second distributed network is determined from the locally stored list of security algorithm capabilities. The security algorithm capabilities supported by the second AMF network element match the security parameters.
[0029] A security algorithm capability discovery response is sent to the security orchestration management network element in the first distributed network, and the security algorithm capability discovery response carries the identification information of the second AMF network element.
[0030] As an optional implementation, the method further includes:
[0031] The system receives a security algorithm capability synchronization request sent by a security orchestration management network element in the first distributed network. The security algorithm capability synchronization request carries the identification information of the first AMF network element in the first distributed network, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) corresponding to the security algorithm capability pool.
[0032] The mapping relationship between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool is stored in the local security algorithm capability list.
[0033] Fifthly, a first access and mobility management function (AMF) network element is provided, which is set in a first distributed network and includes a memory, a transceiver, and a processor;
[0034] The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations:
[0035] Receive a registration request sent by a user equipment (UE) through a radio access network (RAN) node, wherein the registration request carries the security parameters of the UE;
[0036] A security algorithm capability scheduling request is sent to the security orchestration management network element in the first distributed network. The security algorithm capability scheduling request carries the security parameters and the identification information of the first AMF network element.
[0037] When the security algorithm capabilities supported by the first AMF network element match the security parameters, the security algorithm capability scheduling response sent by the security orchestration management network element is received, and the non-access stratum security mode command (NAS SMC) procedure is initiated to the UE through the RAN node.
[0038] If the security algorithm capabilities supported by the first AMF network element do not match the security parameters, the registration flow request sent by the security orchestration management network element is received and forwarded to the RAN node. The registration flow request carries the identification information of the second AMF network element in the second distributed network.
[0039] As an optional implementation, the processor is further configured to read the computer program in the memory and perform the following operations:
[0040] Receive a security algorithm capability collaboration request sent by the security algorithm capability pool in the first distributed network;
[0041] A security algorithm capability collaboration response is sent to the security algorithm capability pool, and the security algorithm capability collaboration response carries the identification information of the first AMF network element.
[0042] In a sixth aspect, a secure orchestration management network element is provided, which is set in a first distributed network and includes a memory, a transceiver, and a processor;
[0043] The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations:
[0044] The system receives a security algorithm capability scheduling request sent by the first access and mobility management function (AMF) network element in the first distributed network. The security algorithm capability scheduling request carries the security parameters of the user equipment (UE) and the identification information of the first AMF network element.
[0045] Based on the security parameters and the identification information of the first AMF network element, the system determines whether the security algorithm capabilities supported by the first AMF network element match the security parameters in the locally stored list of security algorithm capabilities.
[0046] If the security algorithm capabilities supported by the first AMF network element match the security parameters, a security algorithm capability scheduling response is sent to the first AMF network element.
[0047] If the security algorithm capabilities supported by the first AMF network element do not match the security parameters, a security algorithm capability discovery request is sent to the security orchestration management network element in the central network. After receiving the security algorithm capability discovery response sent by the security orchestration management network element in the central network, a registration transfer request is sent to the first AMF network element. The security algorithm capability discovery request carries the location information and security parameters of the UE. The security algorithm capability discovery response and the registration transfer request carry the identification information of the second AMF network element in the second distributed network.
[0048] As an optional implementation, the processor is further configured to read the computer program in the memory and perform the following operations:
[0049] The system receives a security algorithm capability registration message sent by the security algorithm capability pool in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) of the security algorithm capability pool.
[0050] The mapping relationship between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool is stored in the local security algorithm capability list.
[0051] As an optional implementation, the processor is further configured to read the computer program in the memory and perform the following operations:
[0052] A security algorithm capability synchronization request is sent to the security orchestration management network element in the central network. The security algorithm capability synchronization request carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
[0053] In a seventh aspect, a security algorithm capability pool is provided, which is set in a first distributed network and includes a memory, a transceiver, and a processor;
[0054] The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations:
[0055] Send a security algorithm capability cooperation request to the first access and mobility management function (AMF) network element in the first distributed network;
[0056] Receive a security algorithm capability cooperation response sent by the first AMF network element, wherein the security algorithm capability cooperation response carries the identification information of the first AMF network element;
[0057] A security algorithm capability registration message is sent to the security orchestration management network element in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) of the security algorithm capability pool.
[0058] Eighthly, a secure orchestration management network element is provided, which is located in a central network and includes a memory, a transceiver, and a processor;
[0059] The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations:
[0060] The system receives a security algorithm capability discovery request sent by a security orchestration management network element in the first distributed network. The security algorithm capability discovery request carries the location information and security parameters of the user equipment (UE).
[0061] Based on the location information and the security parameters, the identification information of the second access and mobility management function (AMF) network element in the second distributed network is determined from the locally stored list of security algorithm capabilities. The security algorithm capabilities supported by the second AMF network element match the security parameters.
[0062] A security algorithm capability discovery response is sent to the security orchestration management network element in the first distributed network, and the security algorithm capability discovery response carries the identification information of the second AMF network element.
[0063] As an optional implementation, the processor is further configured to read the computer program in the memory and perform the following operations:
[0064] The system receives a security algorithm capability synchronization request sent by a security orchestration management network element in the first distributed network. The security algorithm capability synchronization request carries the identification information of the first AMF network element in the first distributed network, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) corresponding to the security algorithm capability pool.
[0065] The mapping relationship between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool is stored in the local security algorithm capability list.
[0066] Ninthly, a security algorithm capability orchestration apparatus is provided, the apparatus being applied to a first Access and Mobility Management Function (AMF) network element in a first distributed network, the apparatus comprising:
[0067] The first receiving unit is configured to receive a registration request sent by a user equipment (UE) through a radio access network (RAN) node, wherein the registration request carries the security parameters of the UE.
[0068] The first sending unit is configured to send a security algorithm capability scheduling request to the security orchestration management network element in the first distributed network. The security algorithm capability scheduling request carries the security parameters and the identification information of the first AMF network element.
[0069] The second receiving unit is configured to receive the security algorithm capability scheduling response sent by the security orchestration management network element when the security algorithm capability supported by the first AMF network element matches the security parameters, and initiate the Non-Access Stratum Security Mode Command (NAS SMC) procedure to the UE through the RAN node.
[0070] The second sending unit is configured to receive a registration flow request sent by the security orchestration management network element when the security algorithm capabilities supported by the first AMF network element do not match the security parameters, and forward the registration flow request to the RAN node. The registration flow request carries the identification information of the second AMF network element in the second distributed network.
[0071] As an optional implementation, the device further includes:
[0072] The third receiving unit is used to receive a security algorithm capability collaboration request sent by the security algorithm capability pool in the first distributed network.
[0073] The third sending unit is used to send a security algorithm capability cooperation response to the security algorithm capability pool, wherein the security algorithm capability cooperation response carries the identification information of the first AMF network element.
[0074] Tenthly, a secure algorithm capability orchestration apparatus is provided, the apparatus being applied to a secure orchestration management network element in a first distributed network, the apparatus comprising:
[0075] The first receiving unit is configured to receive a security algorithm capability scheduling request sent by the first access and mobility management function (AMF) network element in the first distributed network. The security algorithm capability scheduling request carries security parameters of the user equipment (UE) and identification information of the first AMF network element.
[0076] The judgment unit is used to determine, based on the security parameters and the identification information of the first AMF network element, whether the security algorithm capabilities supported by the first AMF network element match the security parameters in the locally stored list of security algorithm capabilities.
[0077] The first sending unit is configured to send a security algorithm capability scheduling response to the first AMF network element if the security algorithm capability supported by the first AMF network element matches the security parameters.
[0078] The second sending unit is configured to send a security algorithm capability discovery request to the security orchestration management network element in the central network if the security algorithm capability supported by the first AMF network element does not match the security parameters, and after receiving the security algorithm capability discovery response sent by the security orchestration management network element in the central network, send a registration transfer request to the first AMF network element. The security algorithm capability discovery request carries the location information and security parameters of the UE, and the security algorithm capability discovery response and the registration transfer request carry the identification information of the second AMF network element in the second distributed network.
[0079] As an optional implementation, the device further includes:
[0080] The second receiving unit is used to receive a security algorithm capability registration message sent by the security algorithm capability pool in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) of the security algorithm capability pool.
[0081] The storage unit is used to store the correspondence between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool into a local security algorithm capability list.
[0082] As an optional implementation, the device further includes:
[0083] The third sending unit is used to send a security algorithm capability synchronization request to the security orchestration management network element in the central network. The security algorithm capability synchronization request carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
[0084] Eleventhly, a security algorithm capability orchestration device is provided, the device being applied to a security algorithm capability pool in a first distributed network, the device comprising:
[0085] The first sending unit is used to send a security algorithm capability cooperation request to the first access and mobility management function (AMF) network element in the first distributed network.
[0086] The receiving unit is configured to receive a security algorithm capability cooperation response sent by the first AMF network element, wherein the security algorithm capability cooperation response carries the identification information of the first AMF network element.
[0087] The second sending unit is used to send a security algorithm capability registration message to the security orchestration management network element in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) of the security algorithm capability pool.
[0088] In a twelfth aspect, a security algorithm capability orchestration device is provided, the device being applied to a security orchestration management network element in a central network, the device comprising:
[0089] The first receiving unit is configured to receive a security algorithm capability discovery request sent by a security orchestration management network element in the first distributed network, wherein the security algorithm capability discovery request carries the location information and security parameters of the user equipment (UE).
[0090] The determining unit is configured to determine the identification information of the second Access and Mobility Management Function (AMF) network element in the second distributed network based on the location information and the security parameters, from the locally stored list of security algorithm capabilities, wherein the security algorithm capabilities supported by the second AMF network element match the security parameters;
[0091] The sending unit is used to send a security algorithm capability discovery response to the security orchestration management network element in the first distributed network, wherein the security algorithm capability discovery response carries the identification information of the second AMF network element.
[0092] As an optional implementation, the device further includes:
[0093] The second receiving unit is used to receive a security algorithm capability synchronization request sent by a security orchestration management network element in the first distributed network. The security algorithm capability synchronization request carries the identification information of the first AMF network element in the first distributed network, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) corresponding to the security algorithm capability pool.
[0094] The storage unit is used to store the correspondence between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool into a local security algorithm capability list.
[0095] In a thirteenth aspect, a communication system is provided, the communication system comprising a central network and multiple distributed networks, each of the distributed networks comprising an Access and Mobility Management Function (AMF) network element, a security algorithm capability pool, and a security orchestration management network element, the central network comprising a security orchestration management network element; wherein, the AMF network element in each of the distributed networks performs the method steps as described in any of the first aspects above, the security algorithm capability pool in each of the distributed networks performs the method steps as described in any of the third aspects above, the security orchestration management network element in each of the distributed networks performs the method steps as described in any of the second aspects above, and the security orchestration management network element in the central network performs the method steps as described in any of the fourth aspects above.
[0096] In a fourteenth aspect, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the method as described in any one of the first, second, third, or fourth aspects.
[0097] This application provides a method, apparatus, and computer-readable storage medium for orchestrating security algorithm capabilities. The technical solutions provided by the embodiments of this application offer at least the following advantages: They introduce security orchestration and management network elements into distributed networks and central networks. Given that different distributed networks support different security algorithm capabilities, the unified management and orchestration of these capabilities by the central network ensures that UEs supporting specific security algorithm capabilities can access the corresponding distributed network.
[0098] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0099] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0100] Figure 1 This application provides a schematic diagram of the structure of a communication system according to an embodiment of the present application.
[0101] Figure 2 A flowchart illustrating an orchestration method for security algorithm capabilities provided in an embodiment of this application;
[0102] Figure 3 A flowchart illustrating another method for orchestrating security algorithm capabilities provided in an embodiment of this application;
[0103] Figure 4 A flowchart illustrating another method for orchestrating security algorithm capabilities provided in an embodiment of this application;
[0104] Figure 5 A flowchart illustrating another method for orchestrating security algorithm capabilities provided in an embodiment of this application;
[0105] Figure 6 Signaling interaction diagram of an embodiment of a method for orchestrating security algorithm capabilities provided in this application;
[0106] Figure 7 Signaling interaction diagram of a second embodiment of an orchestration method for security algorithm capabilities provided in this application;
[0107] Figure 8 Signaling interaction diagram of Embodiment 3 of a method for orchestrating security algorithm capabilities provided in this application;
[0108] Figure 9 Signaling interaction diagram of Embodiment 4 of a method for orchestrating security algorithm capabilities provided in this application;
[0109] Figure 10 A schematic diagram of the structure of a first AMF network element provided in an embodiment of this application;
[0110] Figure 11 A schematic diagram of the structure of a security orchestration management network element provided in an embodiment of this application;
[0111] Figure 12 This is a schematic diagram of the structure of a security algorithm capability pool provided in an embodiment of this application;
[0112] Figure 13 A schematic diagram of the structure of a security orchestration management network element provided in an embodiment of this application;
[0113] Figure 14 A schematic diagram of the structure of an orchestration device for secure algorithm capabilities provided in an embodiment of this application;
[0114] Figure 15 A schematic diagram of the structure of an orchestration device for secure algorithm capabilities provided in an embodiment of this application;
[0115] Figure 16 A schematic diagram of the structure of an orchestration device for secure algorithm capabilities provided in an embodiment of this application;
[0116] Figure 17 This is a schematic diagram of the structure of an orchestration device for secure algorithm capabilities provided in an embodiment of this application. Detailed Implementation
[0117] In this embodiment of the invention, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.
[0118] In the embodiments of this application, the term "multiple" refers to two or more, and other quantifiers are similar.
[0119] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0120] This application provides an embodiment of a method for orchestrating security algorithm capabilities, which can be applied to communication systems. For example... Figure 1As shown, the communication system mainly includes a UE, RAN (Radio Access Network) nodes, multiple distributed networks, and a central network. Each distributed network is connected to the RAN node, other distributed networks, and the central network. The central network is connected only to each distributed network. Each distributed network and the central network consists of three parts: the user plane, the control plane, and the management platform. The user plane mainly includes UPF (User Plane Function) network elements. The control plane mainly includes PCF (Policy Control Function) network elements, UDM (Unified Data Management) network elements, AMF (Access and Mobility Management Function) network elements, and SMF (Session Management Function) network elements, and a newly added security algorithm capability pool. The security algorithm capability pool in the distributed network stores the security algorithm capabilities supported by the AMF network elements. The management platform adds a security orchestration management network element. This security orchestration management network element is used to orchestrate and manage security algorithms.
[0121] This application provides a method for orchestrating security algorithm capabilities, which is applied to a first AMF network element in a first distributed network, such as... Figure 2 As shown, the specific processing procedure is as follows:
[0122] Step 201: Receive the registration request sent by the UE through the RAN node. The registration request carries the UE's security parameters.
[0123] In implementation, when a UE initiates a registration process with the first distributed network, the UE can send a registration request to the first AMF network element in the first distributed network through the RAN node. This registration request carries the UE's security parameters, which are related to the security algorithms supported by the UE. For example, if the UE supports AES, the security parameter carried in the registration request is 5G-128-EA2. Or, if the UE supports ZUC, the security parameter carried in the registration request is 5G-128-EA3. Correspondingly, the first AMF network element can receive the registration request sent by the UE through the RAN node.
[0124] Step 202: Send a security algorithm capability scheduling request to the security orchestration management network element in the first distributed network. The security algorithm capability scheduling request carries security parameters and the identification information of the first AMF network element.
[0125] In implementation, after receiving the registration request sent by the UE through the RAN node, the first AMF network element can further send a security algorithm capability scheduling request to the security orchestration management network element in the first distributed network. This security algorithm capability scheduling request carries the UE's security parameters and the identification information of the first AMF network element. The identification information may include a GUAMI (Globally Unique AMF Identifier) and / or an AMF set ID. This security algorithm capability scheduling request is used to request the security orchestration management network element to determine, based on a locally stored list of security algorithm capabilities, whether the security algorithm capabilities supported by the first AMF network element match the UE's security parameters.
[0126] The list of security algorithm capabilities stored locally by the security orchestration management network element includes the identification information of the AMF network element in the first distributed network, the supported security algorithm capabilities, and the URI (Uniform Resource Identifier) of the security algorithm capability pool. The list of security algorithm capabilities stored locally by the security orchestration management network element is synchronized through a security algorithm capability registration process initiated by the security algorithm capability pool in the first distributed network, which will be described in detail later and will not be repeated here.
[0127] Step 203: If the security algorithm capabilities supported by the first AMF network element match the security parameters, receive the security algorithm capability scheduling response sent by the security orchestration management network element, and initiate the NAS SMC procedure to the UE through the RAN node.
[0128] In implementation, if the security orchestration management network element in the first distributed network determines, based on its locally stored list of security algorithm capabilities, that the security algorithm capabilities supported by the first AMF network element match the security parameters of the UE, then the security orchestration management network element can send a security algorithm capability scheduling response to the first AMF network element. Correspondingly, the first AMF network element can receive the security algorithm capability scheduling response sent by the security orchestration management network element, confirming that the UE can register with the first AMF network element. Then, the first AMF network element can initiate a NAS SMC (Non-Access Stratum Security Mode Command) procedure to the UE through the RAN node.
[0129] Step 204: If the security algorithm capabilities and security parameters supported by the first AMF network element do not match, a registration flow request sent by the security orchestration management network element is received, and the registration flow request is forwarded to the RAN node. The registration flow request carries the identification information of the second AMF network element in the second distributed network.
[0130] In implementation, if the security orchestration management network element in the first distributed network determines, based on its locally stored list of security algorithm capabilities, that the security algorithm capabilities supported by the first AMF network element do not match the UE's security parameters, then the security orchestration management network element in the first distributed network can request the security orchestration management network element in the central network (hereinafter referred to as the central security orchestration management network element for ease of distinction) to allow the UE to register with other AMF network elements in the distributed network whose supported security algorithm capabilities match the UE's security parameters. Subsequently, after receiving the identification information of the second AMF network element in the second distributed network sent by the central security orchestration management network element, the security orchestration management network element in the first distributed network can send a registration transfer request to the first AMF network element. This registration transfer request carries the identification information of the second AMF network element in the second distributed network. Correspondingly, after receiving the registration transfer request sent by the security orchestration management network element, the first AMF network element in the first distributed network can forward the registration transfer request to the RAN node. This registration transfer request also carries the identification information of the second AMF network element in the second distributed network. This registration flow request is used to instruct the RAN node to initiate a registration process with the second AMF network element in the second distributed network.
[0131] In this way, a security orchestration and management network element is introduced into both the distributed network and the central network. Given that different distributed networks support varying security algorithm capabilities, the central network can uniformly manage and orchestrate these capabilities, ensuring that UEs supporting specific security algorithms can access the corresponding distributed network.
[0132] As an optional implementation, in the security algorithm capability registration process initiated by the security algorithm capability pool in the first distributed network, the first AMF network element also performs the following steps:
[0133] Step 1: Receive a security algorithm capability collaboration request sent by the security algorithm capability pool in the first distributed network.
[0134] In implementation, the security algorithm capability pool in the first distributed network stores the security algorithm capabilities supported by the first AMF network element. When the security algorithm capability pool initiates a security algorithm capability registration process to synchronize the security algorithm capabilities supported by the first AMF network element to the security orchestration management network element, the security algorithm capability pool can first send a security algorithm capability cooperation request to the first AMF network element. This cooperation request instructs the first AMF network element to provide its identification information. Correspondingly, the first AMF network element can receive the security algorithm capability cooperation request sent by the security algorithm capability pool.
[0135] Step two: Send a security algorithm capability collaboration response to the security algorithm capability pool. This response carries the identification information of the first AMF network element.
[0136] In implementation, after receiving a security algorithm capability cooperation request from the security algorithm capability pool, the first AMF network element can send a security algorithm capability cooperation response to the security algorithm capability pool. This response carries the identification information of the first AMF network element.
[0137] This application provides an orchestration method for security algorithm capabilities, which is applied to a security orchestration management network element in a first distributed network. For example... Figure 3 As shown, the specific processing procedure is as follows:
[0138] Step 301: Receive a security algorithm capability scheduling request sent by the first AMF network element in the first distributed network. The security algorithm capability scheduling request carries the UE's security parameters and the identification information of the first AMF network element.
[0139] In implementation, when a UE initiates a registration process with the first distributed network, the UE can send a registration request to the first AMF network element in the first distributed network through the RAN node. This registration request carries the UE's security parameters. After receiving the registration request sent by the UE through the RAN node, the first AMF network element can further send a security algorithm capability scheduling request to the security orchestration management network element in the first distributed network. This security algorithm capability scheduling request carries the UE's security parameters and the identification information of the first AMF network element. The identification information may include GUAMI and / or AMF set ID. This security algorithm capability scheduling request is used to request the security orchestration management network element to determine whether the security algorithm capabilities supported by the first AMF network element match the UE's security parameters based on a locally stored list of security algorithm capabilities. Correspondingly, the security orchestration management network element can receive the security algorithm capability scheduling request sent by the first AMF network element.
[0140] Step 302: Based on the security parameters and the identification information of the first AMF network element, determine whether the security algorithm capabilities supported by the first AMF network element match the security parameters in the locally stored list of security algorithm capabilities.
[0141] In implementation, the list of security algorithm capabilities stored locally by the security orchestration management network element in the first distributed network includes the identification information of the AMF network element in the first distributed network, the supported security algorithm capabilities, and the URI of the security algorithm capability pool. The list of security algorithm capabilities stored locally by the security orchestration management network element is synchronized through a security algorithm capability registration process initiated by the security algorithm capability pool in the first distributed network, which will be described in detail later and will not be repeated here.
[0142] After receiving the security algorithm capability scheduling request sent by the first AMF network element, the security orchestration management network element can further query the security algorithm capabilities supported by the first AMF network element in the locally stored security algorithm capability list based on the identification information of the first AMF network element, and determine whether the security algorithm capabilities supported by the first AMF network element match the security parameters of the UE.
[0143] Step 303: If the security algorithm capabilities supported by the first AMF network element match the security parameters, then send a security algorithm capability scheduling response to the first AMF network element.
[0144] In implementation, if the security algorithm capabilities supported by the first AMF network element match the security parameters, it indicates that the UE can register with the first AMF network element. Correspondingly, the security orchestration management network element can send a security algorithm capability scheduling response to the first AMF network element. This response instructs the first AMF network element that the UE can register with it, enabling the first AMF network element to initiate a NAS SMC procedure to the UE through the RAN node.
[0145] Step 304: If the security algorithm capability and security parameters of the first AMF network element do not match, a security algorithm capability discovery request is sent to the security orchestration management network element in the central network. After receiving the security algorithm capability discovery response from the security orchestration management network element in the central network, a registration transfer request is sent to the first AMF network element. The security algorithm capability discovery request carries the UE's location information and security parameters, while the security algorithm capability discovery response and the registration transfer request carry the identification information of the second AMF network element in the second distributed network.
[0146] In implementation, if the security algorithm capabilities and security parameters of the first AMF network element do not match, it means that the UE cannot register to the first AMF network element. Correspondingly, the security orchestration management network element can send a security algorithm capability discovery request to the central security orchestration management network element in the central network. This security algorithm capability discovery request carries the UE's location information and security parameters. The request is used to request the central security orchestration management network element to determine, based on its locally stored list of security algorithm capabilities, which other distributed network AMF network elements whose supported security algorithm capabilities match the UE's security parameters can be registered with by the UE.
[0147] The list of security algorithm capabilities stored locally by the central security orchestration and management network element includes the identification information of the AMF network elements in each distributed network, the supported security algorithm capabilities, and the URI of the security algorithm capability pool. The list of security algorithm capabilities stored locally by the central security orchestration and management network element is synchronized through a security algorithm capability synchronization process initiated by the security orchestration and management network elements in each distributed network, which will be described in detail later and will not be repeated here.
[0148] Based on its locally stored list of security algorithm capabilities, the central security orchestration management network element determines which AMF network elements in other distributed networks (i.e., the second AMF network element in the second distributed network) can be registered and transferred by the UE, and whose supported security algorithm capabilities match the UE's security parameters. It then sends a security algorithm capability discovery response to the security orchestration management network element in the first distributed network. This response carries the identification information of the second AMF network element in the second distributed network. Upon receiving the security algorithm capability discovery response from the central security orchestration management network element, the security orchestration management network element further sends a registration transfer request to the first AMF network element. This request also carries the identification information of the second AMF network element in the second distributed network. Upon receiving the registration transfer request from the security orchestration management network element, the first AMF network element forwards it to the RAN node, enabling the RAN node to initiate a registration process with the second AMF network element in the second distributed network.
[0149] In this way, a security orchestration and management network element is introduced into both the distributed network and the central network. Given that different distributed networks support varying security algorithm capabilities, the central network can uniformly manage and orchestrate these capabilities, ensuring that UEs supporting specific security algorithms can access the corresponding distributed network.
[0150] As an optional implementation, in the security algorithm capability registration process initiated by the security algorithm capability pool in the first distributed network, the security orchestration management network element in the first distributed network also performs the following steps:
[0151] Step 1: Receive a security algorithm capability registration message sent by the security algorithm capability pool in the first distributed network. This message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
[0152] In implementation, the security algorithm capability pool in the first distributed network stores the security algorithm capabilities supported by the first AMF network element. When the security algorithm capability pool initiates a security algorithm capability registration process to synchronize the security algorithm capabilities supported by the first AMF network element to the security orchestration management network element, the security algorithm capability pool first obtains the identification information of the first AMF network element from the first AMF network element. Then, the security algorithm capability pool sends a security algorithm capability registration message to the security orchestration management network element. This registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool. Correspondingly, the security orchestration management network element can receive the security algorithm capability registration message sent by the security algorithm capability pool.
[0153] Step 2: Store the correspondence between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool in the local security algorithm capability list.
[0154] In implementation, after receiving a security algorithm capability registration message from the security algorithm capability pool, the security orchestration management network element can store the correspondence between the identification information of the first AMF network element, its supported security algorithm capabilities, and the URI of the security algorithm capability pool in its local security algorithm capability list. Thus, when the security orchestration management network element subsequently receives a security algorithm capability scheduling request from the first AMF network element, it can determine whether the security algorithm capabilities supported by the first AMF network element match the UE's security parameters based on the locally stored security algorithm capability list.
[0155] As an optional implementation, in the security algorithm capability synchronization process initiated by the security orchestration management network element in the first distributed network, the security orchestration management network element further performs the following steps: sending a security algorithm capability synchronization request to the security orchestration management network element in the central network. The security algorithm capability synchronization request carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
[0156] In implementation, when a security orchestration management network element in the first distributed network initiates a security algorithm capability synchronization process to synchronize the security algorithm capabilities supported by the first AMF network element in the first distributed network to the central security orchestration management network element, the security orchestration management network element can send a security algorithm capability synchronization request to the central orchestration management network element. This request carries the identification information of the first AMF network element, its supported security algorithm capabilities, and the URI of its security algorithm capability pool. Upon receiving this request, the central orchestration management network element can store the identification information, supported security algorithm capabilities, and the URI of its security algorithm capability pool in its local security algorithm capability list. Based on this, the security orchestration management network elements in the distributed networks report and synchronize their supported security algorithm capabilities to the security orchestration management network element in the central network, enabling the central network's security orchestration management network element to understand the security algorithms supported by each distributed network.
[0157] This application provides an embodiment of a method for orchestrating security algorithm capabilities, which is applied to a security algorithm capability pool in a first distributed network. For example... Figure 4 As shown, the specific processing procedure is as follows:
[0158] Step 401: Send a security algorithm capability cooperation request to the first AMF network element in the first distributed network.
[0159] In implementation, the security algorithm capability pool in the first distributed network stores the security algorithm capabilities supported by the first AMF network element. When the security algorithm capability pool initiates a security algorithm capability registration process to synchronize the security algorithm capabilities supported by the first AMF network element to the security orchestration management network element, the security algorithm capability pool can send a security algorithm capability cooperation request to the first AMF network element in the first distributed network. This security algorithm capability cooperation request instructs the first AMF network element to provide its identification information. This identification information may include GUAMI and / or AMF set ID.
[0160] Step 402: Receive the security algorithm capability cooperation response sent by the first AMF network element. The security algorithm capability cooperation response carries the identification information of the first AMF network element.
[0161] In implementation, after receiving a security algorithm capability cooperation request from the security algorithm capability pool, the first AMF network element can send a security algorithm capability cooperation response to the security algorithm capability pool. This response carries the identification information of the first AMF network element. Correspondingly, the security algorithm capability pool can receive the security algorithm capability cooperation response sent by the first AMF network element.
[0162] Step 403: Send a security algorithm capability registration message to the security orchestration management network element in the first distributed network. The security algorithm capability registration message carries the GUAMI of the first AMF network element, the AMF set identifier, the security algorithm capability, and the URI of the security algorithm capability pool.
[0163] In implementation, after receiving the security algorithm capability cooperation response from the first AMF network element, the security algorithm capability pool can further send a security algorithm capability registration message to the security orchestration management network element in the first distributed network. This registration message carries the identification information of the first AMF network element, its supported security algorithm capabilities, and the URI of the security algorithm capability pool. Upon receiving this registration message, the security orchestration management network element can store the correspondence between the first AMF network element's identification information, supported security algorithm capabilities, and the URI of the security algorithm capability pool in its local security algorithm capability list. This facilitates the security orchestration management network element's subsequent determination, based on the locally stored security algorithm capability list, whether the security algorithm capabilities supported by the first AMF network element match the UE's security parameters when receiving a security algorithm capability scheduling request from the first AMF network element.
[0164] so,
[0165] This application provides an orchestration method for security algorithm capabilities, which is applied to a security orchestration management network element in a central network. For example... Figure 5 As shown, the specific processing procedure is as follows:
[0166] Step 501: Receive a security algorithm capability discovery request sent by the security orchestration management network element in the first distributed network. The security algorithm capability discovery request carries the UE's location information and security parameters.
[0167] In implementation, after receiving a security algorithm capability scheduling request from the first AMF network element, the security orchestration management network element in the first distributed network can further query the security algorithm capabilities supported by the first AMF network element in its locally stored security algorithm capability list based on the identification information of the first AMF network element, and determine whether the security algorithm capabilities supported by the first AMF network element match the UE's security parameters. If the security algorithm capabilities of the first AMF network element do not match the security parameters, a security algorithm capability discovery request is sent to the security orchestration management network element in the central network. This security algorithm capability discovery request carries the UE's location information and security parameters. Correspondingly, the central security orchestration management network element can receive the security algorithm capability discovery request sent by the security orchestration management network element in the first distributed network.
[0168] Step 502: Based on location information and security parameters, determine the identification information of the second AMF network element in the second distributed network from the locally stored list of security algorithm capabilities. The security algorithm capabilities of the second AMF network element are matched with its security parameters.
[0169] In implementation, the security algorithm capability list stored locally by the central security orchestration management network element includes the identification information of the AMF network elements in each distributed network, the supported security algorithm capabilities, and the URI of the security algorithm capability pool. The security algorithm capability list stored locally by the central security orchestration management network element is synchronized through a security algorithm capability synchronization process initiated by the security orchestration management network elements in each distributed network, which will be described in detail later and will not be repeated here.
[0170] After receiving a security algorithm capability discovery request sent by the security orchestration management network element in the first distributed network, the central security orchestration management network element can further determine, based on location information and security parameters, other AMF network elements in the distributed network (i.e., the second AMF network element in the second distributed network) that the UE can register and transfer and whose supported security algorithm capabilities match the UE's security parameters, from the locally stored list of security algorithm capabilities.
[0171] Step 503: Send a security algorithm capability discovery response to the security orchestration management network element in the first distributed network. The security algorithm capability discovery response carries the identification information of the second AMF network element.
[0172] In implementation, after the central security orchestration management network element determines the second AMF network element in the second distributed network that the UE can register with and that whose supported security algorithm capabilities match the UE's security parameters, it can further send a security algorithm capability discovery response to the security orchestration management network element in the first distributed network. This response carries the identification information of the second AMF network element. Upon receiving the security algorithm capability discovery response from the central security orchestration management network element, the security orchestration management network element in the first distributed network can forward a registration transfer request to the RAN node through the first AMF network element, enabling the RAN node to initiate a registration process with the second AMF network element in the second distributed network.
[0173] In this way, a security orchestration and management network element is introduced into both the distributed network and the central network. Given that different distributed networks support varying security algorithm capabilities, the central network can uniformly manage and orchestrate these capabilities, ensuring that UEs supporting specific security algorithms can access the corresponding distributed network.
[0174] As an optional implementation, in the security algorithm capability synchronization process initiated by the security orchestration management network element in the first distributed network, the security orchestration management network element in the central network also performs the following steps:
[0175] Step 1: Receive a security algorithm capability synchronization request sent by the security orchestration management network element in the first distributed network. This request carries the identification information of the first AMF network element in the first distributed network, its supported security algorithm capabilities, and the URI corresponding to the security algorithm capability pool in the first distributed network.
[0176] In implementation, when a security orchestration management network element in the first distributed network initiates a security algorithm capability synchronization process to synchronize the security algorithm capabilities supported by the first AMF network element in the first distributed network to the central security orchestration management network element, the security orchestration management network element in the first distributed network can send a security algorithm capability synchronization request to the central orchestration management network element. This security algorithm capability synchronization request carries the identification information of the first AMF network element, its supported security algorithm capabilities, and the URI of the security algorithm capability pool. Correspondingly, the central security orchestration management network element can receive the security algorithm capability synchronization request sent by the security orchestration management network element in the first distributed network.
[0177] Step 2: Store the correspondence between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool in the local security algorithm capability list.
[0178] In implementation, after receiving a security algorithm capability synchronization request from the security orchestration management network element in the first distributed network, the central orchestration management network element can store the identification information of the first AMF network element, its supported security algorithm capabilities, and the URI of the security algorithm capability pool in its local security algorithm capability list. In this way, the security orchestration management network elements in the distributed networks report and synchronize their supported security algorithm capabilities to the security orchestration management network element in the central network, enabling the central network's security orchestration management network element to grasp the security algorithms supported by each distributed network.
[0179] This application provides four specific embodiments, as follows:
[0180] Example 1: In this example, the first distributed network includes a first AMF network element, a first security algorithm capability pool, and a first security orchestration management network element. The first AMF network element supports security algorithms including AES and ZUC (i.e., the security algorithms included in the first security algorithm capability pool are AES and ZUC). The security parameter corresponding to AES is 5G-128-EA2, and the security parameter corresponding to ZUC is 5G-128-EA3. For example... Figure 6As shown, the specific processing procedure is as follows:
[0181] Step 601: The first security algorithm capability pool sends a security algorithm capability cooperation request to the first AMF network element.
[0182] Step 602: The first AMF network element sends a security algorithm capability cooperation response to the first security algorithm capability pool. The security algorithm capability cooperation response carries the first AMF network element's GUAMI and AMF set ID.
[0183] Step 603: The first security algorithm capability pool sends a security algorithm capability registration message to the first security orchestration management network element. The security algorithm capability registration message carries the AMF set ID of the first AMF network element, the security algorithm capabilities (5G-128-EA2 and 5G-128-EA3), and the URI of the first security algorithm capability pool.
[0184] Step 604: The first security orchestration management network element stores the AMF set ID of the first AMF network element, the security algorithm capabilities (5G-128-EA2 and 5G-128-EA3), and the URI of the first security algorithm capability pool into the security algorithm capability list.
[0185] Example 2: In this example, the first distributed network includes a first AMF network element, a first security algorithm capability pool, and a first security orchestration management network element. The first AMF network element supports the AES security algorithm. The second distributed network includes a second AMF network element, a second security algorithm capability pool, and a second security orchestration management network element. The second AMF network element supports the ZUC security algorithm. The central network includes a central security orchestration management network element. The security parameter corresponding to AES is 5G-128-EA2, and the security parameter corresponding to ZUC is 5G-128-EA3. For example... Figure 7 As shown, the specific processing procedure is as follows:
[0186] Step 701a: The first security orchestration management network element sends a first security algorithm capability synchronization request to the central security orchestration management network element. The first security algorithm capability synchronization request carries the AMF set ID of the first AMF network element, the security algorithm capability (5G-128-EA2), and the URI of the first security algorithm capability pool.
[0187] Step 701b: The second security orchestration management network element sends a second security algorithm capability synchronization request to the central security orchestration management network element. The second security algorithm capability synchronization request carries the AMF set ID of the second AMF network element, the security algorithm capability (5G-128-EA3), and the URI of the second security algorithm capability pool.
[0188] Step 702a: The central security orchestration management network element sends a first security algorithm capability synchronization response (200 or 201) to the first security orchestration management network element.
[0189] Step 702b: The central security orchestration management network element sends a second security algorithm capability synchronization response (200 or 201) to the second security orchestration management network element.
[0190] Step 703a: The central security orchestration and management network element stores the AMF set ID of the first AMF network element, the security algorithm capability (5G-128-EA2), and the URI of the first security algorithm capability pool into the security algorithm capability list.
[0191] Step 703b: The central security orchestration and management network element stores the AMF set ID of the second AMF network element, the security algorithm capability (5G-128-EA3), and the URI of the second security algorithm capability pool into the security algorithm capability list.
[0192] Example 3: In this example, the security algorithm supported by the UE is ZUC. The first distributed network includes a first AMF network element, a first security algorithm capability pool, and a first security orchestration management network element. The security algorithms supported by the first AMF network element include AES and ZUC. The security parameter corresponding to AES is 5G-128-EA2, and the security parameter corresponding to ZUC is 5G-128-EA3. For example... Figure 8 As shown, the specific processing procedure is as follows:
[0193] Step 801: The UE sends a registration request to the first AMF network element through the RAN node. The registration request carries security parameters (5G-128-EA3).
[0194] Step 802: The first AMF network element sends a security algorithm capability scheduling request to the first security orchestration management network element. The security algorithm capability scheduling request carries a security parameter (5G-128-EA3).
[0195] Step 803: The first security orchestration management network element matches the security parameter (5G-128-EA3) with the security algorithm supported by the first AMF network element.
[0196] Step 804: Since the security algorithm ZUC supported by the first AMF network element matches the security parameter (5G-128-EA3), the first security orchestration management network element sends a security algorithm capability scheduling response to the first AMF network element.
[0197] Step 805: The first AMF network element initiates the NAS SMC procedure to the UE through the RAN node.
[0198] Example 4: In this example, the UE supports the ZUC security algorithm. The first distributed network includes a first AMF network element, a first security algorithm capability pool, and a first security orchestration management network element. The first AMF network element supports the AES security algorithm. The second distributed network includes a second AMF network element, a second security algorithm capability pool, and a second security orchestration management network element. The second AMF network element supports the ZUC security algorithm. The central network includes a central security orchestration management network element. The security parameter corresponding to AES is 5G-128-EA2, and the security parameter corresponding to ZUC is 5G-128-EA3. (The text repeats itself here.) Figure 9 As shown, the specific processing procedure is as follows:
[0199] Step 901: The UE sends a registration request to the first AMF network element through the RAN node. The registration request carries security parameters (5G-128-EA3).
[0200] Step 902: The first AMF network element sends a security algorithm capability scheduling request to the first security orchestration management network element. The security algorithm capability scheduling request carries a security parameter (5G-128-EA3).
[0201] Step 903: The first security orchestration management network element matches the security parameter (5G-128-EA3) with the security algorithm supported by the first AMF network element.
[0202] Step 904: Because the security algorithm AES supported by the first AMF network element does not match the security parameter (5G-128-EA3), the first security orchestration management network element sends a security algorithm capability discovery message to the central security orchestration management network element. The security algorithm capability discovery message carries the UE's location information and the security parameter (5G-128-EA3).
[0203] Step 905: The central security orchestration and management network element selects the second AMF network element in the second distributed network from the security algorithm capability list based on the UE's location information and security parameters (5G-128-EA3).
[0204] Step 906: The central security orchestration management network element sends a security algorithm capability discovery response to the first security orchestration management network element. This response carries the GUAMI of the second AMF network element.
[0205] Step 907: The first security orchestration management network element sends a registration flow request to the RAN node through the first AMF network element. The registration flow request carries the GUAMI of the second AMF network element.
[0206] Step 908: The RAN node sends a registration request to the second AMF network element. The registration request includes security parameters (5G-128-EA3).
[0207] Step 909: The second AMF network element sends a security algorithm capability scheduling request to the second security orchestration management network element. The security algorithm capability scheduling request carries a security parameter (5G-128-EA3).
[0208] Step 910: The second security orchestration management network element matches the security parameter (5G-128-EA3) with the security algorithm supported by the second AMF network element.
[0209] Step 911: Since the security algorithm ZUC supported by the second AMF network element matches the security parameter (5G-128-EA3), the second security orchestration management network element sends a security algorithm capability scheduling response to the second AMF network element.
[0210] Step 912: The second AMF network element initiates the NAS SMC procedure to the UE through the RAN node.
[0211] This application provides a security algorithm orchestration method that introduces a security orchestration management network element into a distributed network and a central network. Given that different distributed networks support varying security algorithm capabilities, the central network provides unified management and orchestration of these capabilities, ensuring that UEs supporting specific security algorithm capabilities can access the corresponding distributed network.
[0212] It is understood that the same / similar parts between the various embodiments of the methods described above in this specification can be referred to each other. Each embodiment focuses on the differences from other embodiments, and relevant parts can be referred to the description of other method embodiments.
[0213] The technical solutions provided in this application can be applied to a variety of systems. For example, applicable systems may include Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) systems, 5G New Radio (NR) systems, and their evolved communication systems. These systems may include terminal equipment and network equipment. The systems may also include a core network component, such as Evolved Packet System (EPS) or 5G systems (5GS).
[0214] This application embodiment also provides a first AMF network element, which is configured in a first distributed network, such as... Figure 10 As shown, it includes a memory 1010, a transceiver 1020, and a processor 1030;
[0215] The memory 1010 is used to store computer programs; the transceiver 1020 is used to send and receive data under the control of the processor 1030; the processor 1030 is used to read the computer program in the memory 1010 and perform the following operations:
[0216] Receive the registration request sent by the UE through the RAN node. The registration request carries the UE's security parameters.
[0217] A security algorithm capability scheduling request is sent to the security orchestration management network element in the first distributed network. The security algorithm capability scheduling request carries security parameters and the identification information of the first AMF network element.
[0218] When the security algorithm capabilities supported by the first AMF network element match the security parameters, it receives the security algorithm capability scheduling response sent by the security orchestration management network element and initiates the NAS SMC procedure to the UE through the RAN node.
[0219] In the event that the security algorithm capabilities and security parameters supported by the first AMF network element do not match, the registration flow request sent by the security orchestration management network element is received and forwarded to the RAN node. The registration flow request carries the identification information of the second AMF network element in the second distributed network.
[0220] As an optional implementation, the processor 1030 is also configured to read a computer program from memory and perform the following operations:
[0221] Receive security algorithm capability collaboration requests sent by the security algorithm capability pool in the first distributed network;
[0222] Send a security algorithm capability collaboration response to the security algorithm capability pool. The security algorithm capability collaboration response carries the identification information of the first AMF network element.
[0223] This application embodiment also provides a secure orchestration management network element, which is configured in a first distributed network, such as... Figure 11 As shown, it includes a memory 1110, a transceiver 1120, and a processor 1130;
[0224] The memory 1110 is used to store computer programs; the transceiver 1120 is used to send and receive data under the control of the processor 1130; the processor 1130 is used to read the computer program in the memory 1110 and perform the following operations:
[0225] The system receives a security algorithm capability scheduling request sent by the first AMF network element in the first distributed network. The security algorithm capability scheduling request carries the UE's security parameters and the identification information of the first AMF network element.
[0226] Based on security parameters and the identification information of the first AMF network element, the system determines whether the security algorithm capabilities supported by the first AMF network element match the security parameters in the locally stored list of security algorithm capabilities.
[0227] If the security algorithm capabilities supported by the first AMF network element match the security parameters, a security algorithm capability scheduling response is sent to the first AMF network element.
[0228] If the security algorithm capabilities supported by the first AMF network element do not match the security parameters, a security algorithm capability discovery request is sent to the security orchestration management network element in the central network. After receiving the security algorithm capability discovery response sent by the security orchestration management network element in the central network, a registration transfer request is sent to the first AMF network element. The security algorithm capability discovery request carries the UE's location information and security parameters. The security algorithm capability discovery response and the registration transfer request carry the identification information of the second AMF network element in the second distributed network.
[0229] As an optional implementation, the processor 1130 is also configured to read a computer program from memory and perform the following operations:
[0230] Receive a security algorithm capability registration message sent by the security algorithm capability pool in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
[0231] Store the mapping between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool in the local security algorithm capability list.
[0232] As an optional implementation, the processor 1130 is also configured to read a computer program from memory and perform the following operations:
[0233] Send a security algorithm capability synchronization request to the security orchestration and management network element in the central network. The security algorithm capability synchronization request carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
[0234] This application embodiment also provides a security algorithm capability pool, which is set in a first distributed network, such as... Figure 12 As shown, it includes a memory 1210, a transceiver 1220, and a processor 1230;
[0235] The memory 1210 is used to store computer programs; the transceiver 1220 is used to send and receive data under the control of the processor 1230; the processor 1230 is used to read the computer program in the memory 1210 and perform the following operations:
[0236] Send a security algorithm capability cooperation request to the first AMF network element in the first distributed network;
[0237] Receive the security algorithm capability cooperation response sent by the first AMF network element, the security algorithm capability cooperation response carrying the identification information of the first AMF network element;
[0238] A security algorithm capability registration message is sent to the security orchestration management network element in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
[0239] This application embodiment also provides a security algorithm capability pool, which is set in a first distributed network, such as... Figure 13 As shown, it includes a memory 1310, a transceiver 1320, and a processor 1330;
[0240] The memory 1310 is used to store computer programs; the transceiver 1320 is used to send and receive data under the control of the processor 1330; the processor 1330 is used to read the computer program in the memory 1310 and perform the following operations:
[0241] The system receives a security algorithm capability discovery request sent by the security orchestration management network element in the first distributed network. The security algorithm capability discovery request carries the UE's location information and security parameters.
[0242] Based on location information and security parameters, the identification information of the second AMF network element in the second distributed network is determined from the list of security algorithm capabilities stored locally. The security algorithm capabilities supported by the second AMF network element are matched with the security parameters.
[0243] A security algorithm capability discovery response is sent to the security orchestration management network element in the first distributed network. The security algorithm capability discovery response carries the identification information of the second AMF network element.
[0244] As an optional implementation, the processor 1330 is also configured to read a computer program from memory and perform the following operations:
[0245] Receive a security algorithm capability synchronization request sent by a security orchestration management network element in the first distributed network. The security algorithm capability synchronization request carries the identification information of the first AMF network element in the first distributed network, the supported security algorithm capabilities, and the URI corresponding to the security algorithm capability pool.
[0246] Store the mapping between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool in the local security algorithm capability list.
[0247] The bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors (represented by the processor) and memory (represented by the memory). The bus architecture can also link various other circuits such as peripherals, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides the interface. A transceiver is used to receive and send data under the control of the processor. A transceiver can be multiple components, including transmitters and receivers, providing a unit for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. The processor is responsible for managing the bus architecture and general processing, and the memory can store the data used by the processor during operation. The processor can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD), and can also employ a multi-core architecture.
[0248] It should be noted that the base station provided in this embodiment of the invention can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0249] This application provides an orchestration device for security algorithm capabilities, which is applied to a first AMF network element in a first distributed network, such as... Figure 14 As shown, the device includes:
[0250] The first receiving unit 1410 is used to receive a registration request sent by the UE through the RAN node, the registration request carrying the UE's security parameters;
[0251] The first sending unit 1420 is used to send a security algorithm capability scheduling request to the security orchestration management network element in the first distributed network. The security algorithm capability scheduling request carries security parameters and the identification information of the first AMF network element.
[0252] The second receiving unit 1430 is used to receive the security algorithm capability scheduling response sent by the security orchestration management network element when the security algorithm capability supported by the first AMF network element matches the security parameters, and to initiate the NAS SMC procedure to the UE through the RAN node.
[0253] The second sending unit 1440 is used to receive a registration transfer request sent by the security orchestration management network element when the security algorithm capabilities and security parameters supported by the first AMF network element do not match, and to forward the registration transfer request to the RAN node. The registration transfer request carries the identification information of the second AMF network element in the second distributed network.
[0254] As an optional implementation, the device further includes:
[0255] The third receiving unit is used to receive security algorithm capability collaboration requests sent by the security algorithm capability pool in the first distributed network.
[0256] The third sending unit is used to send a security algorithm capability collaboration response to the security algorithm capability pool. The security algorithm capability collaboration response carries the identification information of the first AMF network element.
[0257] This application provides an orchestration device for secure algorithm capabilities, which is applied to a secure orchestration management network element in a first distributed network, such as... Figure 15 As shown, the device includes:
[0258] The first receiving unit 1510 is used to receive a security algorithm capability scheduling request sent by the first AMF network element in the first distributed network. The security algorithm capability scheduling request carries the security parameters of the UE and the identification information of the first AMF network element.
[0259] The judgment unit 1520 is used to determine whether the security algorithm capabilities supported by the first AMF network element match the security parameters based on the security parameters and the identification information of the first AMF network element, in the locally stored list of security algorithm capabilities.
[0260] The first sending unit 1530 is used to send a security algorithm capability scheduling response to the first AMF network element if the security algorithm capability supported by the first AMF network element matches the security parameters.
[0261] The second sending unit 1540 is configured to send a security algorithm capability discovery request to the security orchestration management network element in the central network if the security algorithm capability supported by the first AMF network element does not match the security parameters, and after receiving the security algorithm capability discovery response sent by the security orchestration management network element in the central network, send a registration transfer request to the first AMF network element. The security algorithm capability discovery request carries the UE's location information and security parameters, and the security algorithm capability discovery response and the registration transfer request carry the identification information of the second AMF network element in the second distributed network.
[0262] As an optional implementation, the device further includes:
[0263] The second receiving unit is used to receive a security algorithm capability registration message sent by the security algorithm capability pool in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
[0264] The storage unit is used to store the correspondence between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URIs of the security algorithm capability pool into the local security algorithm capability list.
[0265] As an optional implementation, the device further includes:
[0266] The third sending unit is used to send a security algorithm capability synchronization request to the security orchestration management network element in the central network. The security algorithm capability synchronization request carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
[0267] This application provides an orchestration device for security algorithm capabilities, which is applied to a security algorithm capability pool in a first distributed network, such as... Figure 16 As shown, the device includes:
[0268] The first sending unit 1610 is used to send a security algorithm capability cooperation request to the first AMF network element in the first distributed network.
[0269] The receiving unit 1620 is used to receive the security algorithm capability cooperation response sent by the first AMF network element, wherein the security algorithm capability cooperation response carries the identification information of the first AMF network element.
[0270] The second sending unit 1630 is used to send a security algorithm capability registration message to the security orchestration management network element in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
[0271] This application provides an orchestration device for secure algorithm capabilities, which is applied to a secure orchestration management network element in a central network, such as... Figure 17 As shown, the device includes:
[0272] The first receiving unit 1710 is used to receive a security algorithm capability discovery request sent by a security orchestration management network element in the first distributed network. The security algorithm capability discovery request carries the UE's location information and security parameters.
[0273] The determining unit 1720 is used to determine the identification information of the second AMF network element in the second distributed network based on location information and security parameters, in the list of security algorithm capabilities stored locally, and the security algorithm capabilities supported by the second AMF network element are matched with the security parameters.
[0274] The sending unit 1730 is used to send a security algorithm capability discovery response to the security orchestration management network element in the first distributed network. The security algorithm capability discovery response carries the identification information of the second AMF network element.
[0275] As an optional implementation, the device further includes:
[0276] The second receiving unit is used to receive a security algorithm capability synchronization request sent by the security orchestration management network element in the first distributed network. The security algorithm capability synchronization request carries the identification information of the first AMF network element in the first distributed network, the supported security algorithm capabilities, and the URI corresponding to the security algorithm capability pool.
[0277] The storage unit is used to store the correspondence between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URIs of the security algorithm capability pool into the local security algorithm capability list.
[0278] It should be noted that the division of units in the embodiments of this application is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.
[0279] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application.
[0280] It should be noted that the apparatus provided in this embodiment of the invention can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.
[0281] This application provides a communication system comprising a central network and multiple distributed networks. Each distributed network includes an AMF (Advanced Management Function) network element, a security algorithm capability pool, and a security orchestration management network element. The central network includes a security orchestration management network element. Specifically, the AMF network element in each distributed network executes the steps of any security algorithm orchestration method executed by the first AMF network element described above; the security algorithm capability pool in each distributed network executes the steps of any security algorithm orchestration method executed by the security algorithm capability pool described above; the security orchestration management network element in each distributed network executes the steps of any security algorithm orchestration method executed by the security orchestration management network element described above; and the security orchestration management network element in the central network executes the steps of any security algorithm orchestration method executed by the central security orchestration management network element described above.
[0282] This application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of any of the above-described security algorithm orchestration methods.
[0283] This application provides a computer program product, which includes program instructions that, when executed by a computer, cause the computer to perform the steps of any of the downlink antenna selection methods described above.
[0284] The processor-readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic memory (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO)), optical memory (e.g., CD, DVD, BD, HVD), and semiconductor memory (e.g., ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)).
[0285] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0286] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0287] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the processor-readable memory produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0288] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for orchestrating security algorithm capabilities, characterized in that, The method is applied to a first Access and Mobility Management Function (AMF) network element in a first distributed network, and the method includes: Receive a registration request sent by a user equipment (UE) through a radio access network (RAN) node, wherein the registration request carries the security parameters of the UE; A security algorithm capability scheduling request is sent to the security orchestration management network element in the first distributed network. The security algorithm capability scheduling request carries the security parameters and the identification information of the first AMF network element. When the security algorithm capabilities supported by the first AMF network element match the security parameters, the security algorithm capability scheduling response sent by the security orchestration management network element is received, and the non-access stratum security mode command (NAS SMC) procedure is initiated to the UE through the RAN node. If the security algorithm capabilities supported by the first AMF network element do not match the security parameters, the registration flow request sent by the security orchestration management network element is received and forwarded to the RAN node. The registration flow request carries the identification information of the second AMF network element in the second distributed network.
2. The method according to claim 1, characterized in that, The method further includes: Receive a security algorithm capability collaboration request sent by the security algorithm capability pool in the first distributed network; A security algorithm capability collaboration response is sent to the security algorithm capability pool, and the security algorithm capability collaboration response carries the identification information of the first AMF network element.
3. A method for orchestrating security algorithm capabilities, characterized in that, The method is applied to a security orchestration and management network element in a first distributed network, and the method includes: The system receives a security algorithm capability scheduling request sent by the first access and mobility management function (AMF) network element in the first distributed network. The security algorithm capability scheduling request carries the security parameters of the user equipment (UE) and the identification information of the first AMF network element. Based on the security parameters and the identification information of the first AMF network element, the system determines whether the security algorithm capabilities supported by the first AMF network element match the security parameters in the locally stored list of security algorithm capabilities. If the security algorithm capabilities supported by the first AMF network element match the security parameters, a security algorithm capability scheduling response is sent to the first AMF network element. If the security algorithm capabilities supported by the first AMF network element do not match the security parameters, a security algorithm capability discovery request is sent to the security orchestration management network element in the central network. After receiving the security algorithm capability discovery response sent by the security orchestration management network element in the central network, a registration transfer request is sent to the first AMF network element. The security algorithm capability discovery request carries the location information and security parameters of the UE. The security algorithm capability discovery response and the registration transfer request carry the identification information of the second AMF network element in the second distributed network.
4. The method according to claim 3, characterized in that, The method further includes: The system receives a security algorithm capability registration message sent by the security algorithm capability pool in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) of the security algorithm capability pool. The mapping relationship between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool is stored in the local security algorithm capability list.
5. The method according to claim 4, characterized in that, The method further includes: A security algorithm capability synchronization request is sent to the security orchestration management network element in the central network. The security algorithm capability synchronization request carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
6. A method for orchestrating security algorithm capabilities, characterized in that, The method is applied to the security algorithm capability pool in a first distributed network, and the method includes: Send a security algorithm capability cooperation request to the first access and mobility management function (AMF) network element in the first distributed network; Receive a security algorithm capability cooperation response sent by the first AMF network element, wherein the security algorithm capability cooperation response carries the identification information of the first AMF network element; A security algorithm capability registration message is sent to the security orchestration management network element in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) of the security algorithm capability pool.
7. A method for orchestrating security algorithm capabilities, characterized in that, The method is applied to a security orchestration and management network element in a central network, and the method includes: The system receives a security algorithm capability discovery request sent by a security orchestration management network element in the first distributed network. The security algorithm capability discovery request carries the location information and security parameters of the user equipment (UE). Based on the location information and the security parameters, the identification information of the second access and mobility management function (AMF) network element in the second distributed network is determined from the locally stored list of security algorithm capabilities. The security algorithm capabilities supported by the second AMF network element match the security parameters. A security algorithm capability discovery response is sent to the security orchestration management network element in the first distributed network, and the security algorithm capability discovery response carries the identification information of the second AMF network element.
8. The method according to claim 7, characterized in that, The method further includes: The system receives a security algorithm capability synchronization request sent by a security orchestration management network element in the first distributed network. The security algorithm capability synchronization request carries the identification information of the first AMF network element in the first distributed network, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) corresponding to the security algorithm capability pool. The mapping relationship between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool is stored in the local security algorithm capability list.
9. A first access and mobility management function (AMF) network element, characterized in that, The first AMF network element is configured in the first distributed network and includes a memory, a transceiver, and a processor; The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations: Receive a registration request sent by a user equipment (UE) through a radio access network (RAN) node, wherein the registration request carries the security parameters of the UE; A security algorithm capability scheduling request is sent to the security orchestration management network element in the first distributed network. The security algorithm capability scheduling request carries the security parameters and the identification information of the first AMF network element. When the security algorithm capabilities supported by the first AMF network element match the security parameters, the security algorithm capability scheduling response sent by the security orchestration management network element is received, and the non-access stratum security mode command (NAS SMC) procedure is initiated to the UE through the RAN node. If the security algorithm capabilities supported by the first AMF network element do not match the security parameters, the registration flow request sent by the security orchestration management network element is received and forwarded to the RAN node. The registration flow request carries the identification information of the second AMF network element in the second distributed network.
10. The first AMF network element according to claim 9, characterized in that, The processor is also configured to read the computer program in the memory and perform the following operations: Receive a security algorithm capability collaboration request sent by the security algorithm capability pool in the first distributed network; A security algorithm capability collaboration response is sent to the security algorithm capability pool, and the security algorithm capability collaboration response carries the identification information of the first AMF network element.
11. A security orchestration and management network element, characterized in that, The secure orchestration management network element is located in the first distributed network and includes a memory, a transceiver, and a processor; The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations: The system receives a security algorithm capability scheduling request sent by the first access and mobility management function (AMF) network element in the first distributed network. The security algorithm capability scheduling request carries the security parameters of the user equipment (UE) and the identification information of the first AMF network element. Based on the security parameters and the identification information of the first AMF network element, the system determines whether the security algorithm capabilities supported by the first AMF network element match the security parameters in the locally stored list of security algorithm capabilities. If the security algorithm capabilities supported by the first AMF network element match the security parameters, a security algorithm capability scheduling response is sent to the first AMF network element. If the security algorithm capabilities supported by the first AMF network element do not match the security parameters, a security algorithm capability discovery request is sent to the security orchestration management network element in the central network. After receiving the security algorithm capability discovery response sent by the security orchestration management network element in the central network, a registration transfer request is sent to the first AMF network element. The security algorithm capability discovery request carries the location information and security parameters of the UE. The security algorithm capability discovery response and the registration transfer request carry the identification information of the second AMF network element in the second distributed network.
12. The security orchestration management network element according to claim 11, characterized in that, The processor is also configured to read the computer program in the memory and perform the following operations: The system receives a security algorithm capability registration message sent by the security algorithm capability pool in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) of the security algorithm capability pool. The mapping relationship between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool is stored in the local security algorithm capability list.
13. The security orchestration management network element according to claim 12, characterized in that, The processor is also configured to read the computer program in the memory and perform the following operations: A security algorithm capability synchronization request is sent to the security orchestration management network element in the central network. The security algorithm capability synchronization request carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool.
14. A security algorithm capability pool, characterized in that, The security algorithm capability pool is set in the first distributed network and includes a memory, a transceiver, and a processor; The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations: Send a security algorithm capability cooperation request to the first access and mobility management function (AMF) network element in the first distributed network; Receive a security algorithm capability cooperation response sent by the first AMF network element, wherein the security algorithm capability cooperation response carries the identification information of the first AMF network element; A security algorithm capability registration message is sent to the security orchestration management network element in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) of the security algorithm capability pool.
15. A security orchestration and management network element, characterized in that, The security orchestration management network element is located in the central network and includes a memory, transceiver, and processor; The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs in the memory and perform the following operations: The system receives a security algorithm capability discovery request sent by a security orchestration management network element in the first distributed network. The security algorithm capability discovery request carries the location information and security parameters of the user equipment (UE). Based on the location information and the security parameters, the identification information of the second access and mobility management function (AMF) network element in the second distributed network is determined from the locally stored list of security algorithm capabilities. The security algorithm capabilities supported by the second AMF network element match the security parameters. A security algorithm capability discovery response is sent to the security orchestration management network element in the first distributed network, and the security algorithm capability discovery response carries the identification information of the second AMF network element.
16. The security orchestration management network element according to claim 15, characterized in that, The processor is also configured to read the computer program in the memory and perform the following operations: The system receives a security algorithm capability synchronization request sent by a security orchestration management network element in the first distributed network. The security algorithm capability synchronization request carries the identification information of the first AMF network element in the first distributed network, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) corresponding to the security algorithm capability pool. The mapping relationship between the identification information of the first AMF network element, the supported security algorithm capabilities, and the URI of the security algorithm capability pool is stored in the local security algorithm capability list.
17. An orchestration device for secure algorithm capabilities, characterized in that, The apparatus is applied to a first Access and Mobility Management Function (AMF) network element in a first distributed network, and the apparatus includes: The first receiving unit is configured to receive a registration request sent by a user equipment (UE) through a radio access network (RAN) node, wherein the registration request carries the security parameters of the UE. The first sending unit is configured to send a security algorithm capability scheduling request to the security orchestration management network element in the first distributed network. The security algorithm capability scheduling request carries the security parameters and the identification information of the first AMF network element. The second receiving unit is configured to receive the security algorithm capability scheduling response sent by the security orchestration management network element when the security algorithm capability supported by the first AMF network element matches the security parameters, and initiate the Non-Access Stratum Security Mode Command (NAS SMC) procedure to the UE through the RAN node. The second sending unit is configured to receive a registration flow request sent by the security orchestration management network element when the security algorithm capabilities supported by the first AMF network element do not match the security parameters, and forward the registration flow request to the RAN node. The registration flow request carries the identification information of the second AMF network element in the second distributed network.
18. An orchestration device for secure algorithm capabilities, characterized in that, The device is applied to a security orchestration and management network element in a first distributed network, and the device includes: The first receiving unit is configured to receive a security algorithm capability scheduling request sent by the first access and mobility management function (AMF) network element in the first distributed network. The security algorithm capability scheduling request carries security parameters of the user equipment (UE) and identification information of the first AMF network element. The judgment unit is used to determine, based on the security parameters and the identification information of the first AMF network element, whether the security algorithm capabilities supported by the first AMF network element match the security parameters in the locally stored list of security algorithm capabilities. The first sending unit is configured to send a security algorithm capability scheduling response to the first AMF network element if the security algorithm capability supported by the first AMF network element matches the security parameters. The second sending unit is configured to send a security algorithm capability discovery request to the security orchestration management network element in the central network if the security algorithm capability supported by the first AMF network element does not match the security parameters, and after receiving the security algorithm capability discovery response sent by the security orchestration management network element in the central network, send a registration transfer request to the first AMF network element. The security algorithm capability discovery request carries the location information and security parameters of the UE, and the security algorithm capability discovery response and the registration transfer request carry the identification information of the second AMF network element in the second distributed network.
19. An orchestration device for secure algorithm capabilities, characterized in that, The device is applied to a security algorithm capability pool in a first distributed network, and the device includes: The first sending unit is used to send a security algorithm capability cooperation request to the first access and mobility management function (AMF) network element in the first distributed network. The receiving unit is configured to receive a security algorithm capability cooperation response sent by the first AMF network element, wherein the security algorithm capability cooperation response carries the identification information of the first AMF network element. The second sending unit is used to send a security algorithm capability registration message to the security orchestration management network element in the first distributed network. The security algorithm capability registration message carries the identification information of the first AMF network element, the supported security algorithm capabilities, and the Uniform Resource Identifier (URI) of the security algorithm capability pool.
20. An orchestration device for secure algorithm capabilities, characterized in that, The device is applied to a security orchestration and management network element in a central network, and the device includes: The first receiving unit is configured to receive a security algorithm capability discovery request sent by a security orchestration management network element in the first distributed network, wherein the security algorithm capability discovery request carries the location information and security parameters of the user equipment (UE). The determining unit is configured to determine the identification information of the second Access and Mobility Management Function (AMF) network element in the second distributed network based on the location information and the security parameters, from the locally stored list of security algorithm capabilities, wherein the security algorithm capabilities supported by the second AMF network element match the security parameters; The sending unit is used to send a security algorithm capability discovery response to the security orchestration management network element in the first distributed network, wherein the security algorithm capability discovery response carries the identification information of the second AMF network element.
21. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method steps of any one of claims 1 to 2, or 3 to 5, or 6, or 7 to 8.