Communication method, communication device and communication system
By receiving the AKMA key identifier and context information from the terminal device, the AF network element is notified to shut down the AKMA service, which resolves the compliance risks when the terminal device is roaming, ensures the accurate shutdown of the service, and reduces resource consumption and storage space.
Patent Information
- Application Number
- CN202410585689.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-11
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2044-05-11
AI Technical Summary
When terminal devices roam and access new networks, how can we ensure that AF network elements correctly shut down AKMA services to avoid compliance risks?
By receiving the AKMA key identifier and context information from the terminal device, the second device is notified to shut down the AKMA service, avoiding the use of a new AKMA key identifier for service interaction. Combined with roaming status information subscription and timer management, the accuracy and timeliness of the information are ensured.
This enabled the AF network element to correctly shut down AKMA services, reducing compliance risks, saving storage space, and reducing the overhead and resource consumption of terminal equipment.
Smart Images

Figure CN120935709A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technology, and in particular to a communication method, communication device and communication system. Background Technology
[0002] To enhance communication security, when terminal devices communicate with application function (AF) network elements, both parties need to use the same application key to protect the application authentication and key management for applications (AKMA) services. The application key used by the terminal device is generated by the terminal device itself, while the application key used by the AF network element can be generated and sent to the AF network element by the AKMA anchor function (AAnF) network element.
[0003] When a terminal device roams and connects to a new network, a re-authentication process is triggered between the terminal device and the core network. This re-authentication process will cause the AAnF network element to obtain and save the new AKMA key identifier. If the terminal device cannot use AKMA services in this new network, the AAnF network element can notify the AF network element to disable the corresponding AKMA services.
[0004] How to help AF network elements properly shut down AKMA services is a question worth considering. Summary of the Invention
[0005] This application provides a communication method, communication device, and communication system that help AF network elements correctly shut down AKMA services.
[0006] In a first aspect, embodiments of this application provide a communication method, which can be executed by a first device. Unless otherwise specified, the "first device" in this application can refer to an AAnF network element, a component within an AAnF network element (e.g., a communication module, processor, circuit, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of an AAnF network element. The method includes: receiving a first key registration request message, the first key registration request message including a first identifier of a terminal device and a first AKMA key identifier, the first AKMA key identifier being generated after the terminal device completes primary authentication in a first network; receiving an application key request message from a second device, the application key request message including the first AKMA key identifier, the application key request message being used to request an application key corresponding to the first AKMA key identifier, the application key being used to protect a first AKMA service between the terminal device and the second device; storing first information, the first information being associated with the first AKMA service; receiving a second key registration request message, the second key registration request message including the first identifier of the terminal device and a second AKMA key identifier, the second AKMA key identifier being generated after the terminal device completes primary authentication in a second network; and when the terminal device cannot use the AKMA service in the second network, sending an AKMA service shutdown notification message to the second device, the AKMA service shutdown notification message including the first information.
[0007] Based on the above scheme, when a terminal device changes its registration from the first network to the second network, or simultaneously to both networks, and the terminal device cannot use the AKMA service on the second network, the first device notifies the second device to disable the terminal device's AKMA service via first information. This first information is associated with the terminal device's AKMA service, thus helping the second device to correctly disable the AKMA service. Furthermore, this avoids the second device continuing to perform the first AKMA service on the second network when the terminal device cannot use it; that is, it prevents the second device from continuing to use the application key corresponding to the first AKMA key identifier to interact with the terminal device regarding the first AKMA service, thereby avoiding compliance risks. Compared to the first device using the second AKMA key identifier (i.e., the AKMA key identifier generated under the new network) to notify the second device to disable the terminal device's AKMA service, where the second device does not have an AKMA service associated with the second AKMA key identifier, thus failing to correctly disable the AKMA service, the scheme provided in this application is more reasonable.
[0008] In one possible implementation, the first information includes one or more of the following: the first AKMA key identifier; the second identifier of the terminal device; or, a context identifier, which is used to indicate the context of the connection between the first device and the second device.
[0009] Based on the above scheme, the AKMA service can be correctly shut down by notifying the second device to close the AKMA service of the terminal device through the first AKMA key identifier, the second identifier of the terminal device, or the context identifier, instead of using the second AKMA key identifier to notify the second device to close the AKMA service of the terminal device.
[0010] In one possible implementation, the method further includes: sending a subscription request to a third device, the subscription request being used to subscribe to roaming status information of the terminal device; receiving first roaming status information of the terminal device from the third device, the first roaming status information including information of the first network; and receiving second roaming status information of the terminal device from the third device, the second roaming status information including information of the second network.
[0011] Based on the above scheme, by subscribing to the roaming status information of terminal devices, network changes of terminal devices can be detected in a timely manner, thereby enabling a quick decision on whether to shut down the AKMA service of the terminal device, which helps to reduce the overhead and resource consumption of terminal devices.
[0012] In one possible implementation, storing the first information includes storing the correspondence between the first information and the identification information of the second device.
[0013] Based on the above scheme and this correspondence, the second device that needs to shut down the AKMA service and / or the first information carried in the AKMA service shutdown notification message can be accurately determined. Specifically, when determining which second devices are instructed to shut down the AKMA service, the corresponding second devices can be identified through this correspondence; when determining what information the AKMA service shutdown notification message carries, the corresponding first information can be identified through this correspondence.
[0014] In one possible implementation, the identification information of the second device includes the identifier of the second device or the Uniform Resource Identifier of the second device.
[0015] In one possible implementation, the step of sending an AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network includes: when the terminal device cannot use the AKMA service on the second network and the second device provides a Uniform Resource Identifier for service shutdown, sending the AKMA service shutdown notification message to the second device.
[0016] Based on the above scheme, when the terminal device cannot use the AKMA service in the second network and the second device provides a Uniform Resource Identifier for service shutdown, it indicates that the AKMA service of the terminal device needs to be shut down. Furthermore, the object to notify the shutdown of the AKMA service (i.e., the second device) can be found through the Uniform Resource Identifier for service shutdown, and then an AKMA service shutdown notification message can be sent to the second device, which helps to achieve accurate sending of the AKMA service shutdown notification message.
[0017] In one possible implementation, the method further includes: starting a timer, the timer being used to indicate the validity period of the first information.
[0018] Based on the above solution, by setting the validity period of the first information through a timer, the first information can be deleted after the timer expires, thus saving storage space.
[0019] In one possible implementation, the step of sending an AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network includes: sending the AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network and the timer has not expired.
[0020] Based on the above scheme, when the terminal device cannot use the AKMA service in the second network and the timer has not expired, it indicates that the AKMA service of the terminal device needs to be shut down. The first information can accurately notify the shutdown of the corresponding AKMA service, and then send an AKMA service shutdown notification message to the second device, which helps to achieve the correct shutdown of the AKMA service.
[0021] In one possible implementation, the method further includes: deleting the first information after the timer expires.
[0022] Based on the above solution, the first piece of information can be deleted after the timer expires, which can save storage space.
[0023] In one possible implementation, storing the first information includes: storing the first information when a triggering condition is met; wherein the triggering condition includes one or more of the following: having subscribed to roaming status information; having obtained a Uniform Resource Identifier (URI) for service shutdown provided by the second device; or having sent the application key corresponding to the first AKMA key identifier to the second device.
[0024] Based on the above scheme, the first information is stored only when the triggering condition is met, and not stored when the triggering condition is not met. This allows the first information to be stored only when necessary, thus saving storage space.
[0025] In one possible implementation, the first information is not deleted after receiving the second key registration request message.
[0026] Secondly, embodiments of this application provide a communication method, which can be executed by a second device. Unless otherwise specified, the "second device" in this application can refer to an AF network element, a component within an AF network element (e.g., a communication module, processor, circuit, chip, or chip system), or a logic module or software capable of implementing all or part of the AF network element's functions. The method includes: sending an application key request message to a first device, the application key request message including a first AKMA key identifier, the application key request message being used to request an application key corresponding to the first AKMA key identifier, the first AKMA key identifier being generated after a terminal device completes primary authentication in a first network, the application key being used to protect a first AKMA service between the terminal device and the second device; receiving an AKMA service closure notification message from the first device, the AKMA service closure notification message including first information; closing the first AKMA service corresponding to the first information, the first information including a context identifier or a second identifier of the terminal device, the context identifier being used to indicate the context of the connection between the first device and the second device.
[0027] Based on the above scheme, when a terminal device changes its registration from the first network to the second network, or simultaneously to both networks, and the terminal device cannot use the AKMA service on the second network, the first device notifies the second device to disable the terminal device's AKMA service via first information. This first information is associated with the terminal device's AKMA service, thus helping the second device to correctly disable the AKMA service. Furthermore, this avoids the second device continuing to perform the first AKMA service on the second network when the terminal device cannot use it; that is, it prevents the second device from continuing to use the application key corresponding to the first AKMA key identifier to interact with the terminal device regarding the first AKMA service, thereby avoiding compliance risks. Compared to the first device using the second AKMA key identifier (i.e., the AKMA key identifier generated under the new network) to notify the second device to disable the terminal device's AKMA service, where the second device does not have an AKMA service associated with the second AKMA key identifier, thus failing to correctly disable the AKMA service, the scheme provided in this application is more reasonable.
[0028] In one possible implementation, the method further includes: storing the correspondence between the first information and the first AKMA key identifier and / or the application key.
[0029] Based on the above scheme, the corresponding AKMA service can be correctly shut down through this correspondence.
[0030] In one possible implementation, shutting down the first AKMA service corresponding to the first information includes: determining the first AKMA key identifier and / or the application key corresponding to the first information based on the correspondence; and shutting down the first AKMA service corresponding to the first AKMA key identifier and / or the application key.
[0031] Based on the above scheme, the corresponding AKMA service can be correctly shut down through this correspondence.
[0032] In one possible implementation, the AKMA service shutdown notification message further includes a second AKMA key identifier, which is generated after the terminal device completes primary authentication in the second network; shutting down the first AKMA service corresponding to the first information includes: shutting down the first AKMA service corresponding to the first information if shutting down the AKMA service according to the second AKMA key identifier fails.
[0033] Thirdly, embodiments of this application provide a communication device that has the function of implementing any of the methods described in the first aspect. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned function.
[0034] Fourthly, embodiments of this application provide a communication device that has the function of implementing any of the methods described in the second aspect above. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned function.
[0035] Fifthly, embodiments of this application provide a communication device, including units or means for performing each step of any of the implementation methods in the first to second aspects described above.
[0036] Sixthly, embodiments of this application provide a communication device, including a processor and an interface circuit. The processor is configured to communicate with other devices via the interface circuit and execute any of the implementation methods described in the first to second aspects. The processor may include one or more devices.
[0037] Optionally, the communication device may further include a memory for storing computer instructions, the memory being coupled to a processor that executes the computer instructions stored in the memory to cause the device to perform any of the implementation methods of the first to second aspects described above.
[0038] In a seventh aspect, embodiments of this application also provide a computer program product, which includes a computer program or instructions that, when executed by a communication device, cause any of the implementation methods in the first to second aspects described above to be executed.
[0039] Eighthly, embodiments of this application also provide a computer-readable storage medium storing instructions that, when executed on a communication device, cause any implementation method in the first aspect to be performed.
[0040] Ninthly, this application provides a chip (or chip system) including a processor coupled to a memory storing a computer program; the processor is configured to invoke part or all of the computer program in the memory, causing any implementation method of the first to second aspects described above to be executed.
[0041] Tenthly, this application provides a communication system, including a first device and a second device. Optionally, the system further includes a third device. The "first device" in this application can refer to an AF network element, a component within an AF network element (e.g., a communication module, processor, circuit, chip, or chip system), or a logic module or software capable of implementing all or part of the AF network element functions. The "second device" in this application can refer to an AF network element, a component within an AF network element (e.g., a communication module, processor, circuit, chip, or chip system), or a logic module or software capable of implementing all or part of the AF network element functions. The "third device" in this application can refer to a unified data management (UDM) network element, a component within a UDM network element (e.g., a communication module, processor, circuit, chip, or chip system), or a logic module or software capable of implementing all or part of the UDM network element functions.
[0042] A first device is configured to receive a first key registration request message, the first key registration request message including a first identifier of a terminal device and an AKMA key identifier for authentication and key management of a first application, the first AKMA key identifier being generated after the terminal device completes primary authentication in a first network; receive an application key request message from a second device, the application key request message including the first AKMA key identifier, the application key request message being used to request an application key corresponding to the first AKMA key identifier, the application key being used to protect a first AKMA service between the terminal device and the second device; store first information, the first information being associated with the first AKMA service; receive a second key registration request message, the second key registration request message including the first identifier of the terminal device and a second AKMA key identifier, the second AKMA key identifier being generated after the terminal device completes primary authentication in a second network; and when the terminal device cannot use the AKMA service in the second network, send an AKMA service shutdown notification message to the second device, the AKMA service shutdown notification message including the first information. A second device is configured to send the application key request message to the first device; and receive the AKMA service shutdown notification message from the first device.
[0043] In one possible implementation, the first information includes one or more of the following: the first AKMA key identifier; the second identifier of the terminal device; or, a context identifier, which is used to indicate the context of the connection between the first device and the second device.
[0044] In one possible implementation, the first device is further configured to send a subscription request to the third device, the subscription request being used to subscribe to the roaming status information of the terminal device; receive first roaming status information of the terminal device from the third device, the first roaming status information including information of the first network; and receive second roaming status information of the terminal device from the third device, the second roaming status information including information of the second network.
[0045] In one possible implementation, the first device is used to store first information, including: storing the correspondence between the first information and the identification information of the second device.
[0046] In one possible implementation, the identification information of the second device includes the identifier of the second device or the Uniform Resource Identifier of the second device.
[0047] In one possible implementation, the first device is configured to send an AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network, including: sending the AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network and the second device provides a Uniform Resource Identifier for service shutdown.
[0048] In one possible implementation, the first device is further configured to activate a timer, the timer being used to indicate the validity period of the first information.
[0049] In one possible implementation, the first device is configured to send an AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network, including: sending the AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network and the timer has not expired.
[0050] In one possible implementation, the first device is further configured to delete the first information after the timer expires.
[0051] In one possible implementation, the first device is configured to store first information, including: storing the first information when a triggering condition is met; wherein the triggering condition includes one or more of the following: having subscribed to roaming status information; having obtained a Uniform Resource Identifier (URI) for service shutdown provided by the second device; or having sent the application key corresponding to the first AKMA key identifier to the second device.
[0052] In one possible implementation, the first device is further configured to not delete the first information after receiving the second key registration request message.
[0053] In one possible implementation, the second device is further configured to disable the first AKMA service corresponding to the first information.
[0054] In one possible implementation, the second device is further configured to store the correspondence between the first information and the first AKMA key identifier and / or the application key.
[0055] In one possible implementation, the second device is configured to shut down the first AKMA service corresponding to the first information, comprising: determining, based on the correspondence, the first AKMA key identifier and / or the application key corresponding to the first information; and shutting down the first AKMA service corresponding to the first AKMA key identifier and / or the application key.
[0056] In one possible implementation, the AKMA service shutdown notification message further includes a second AKMA key identifier, which is generated after the terminal device completes primary authentication in the second network; the second device is used to shut down the first AKMA service corresponding to the first information, including: shutting down the first AKMA service corresponding to the first information if shutting down the AKMA service according to the second AKMA key identifier fails.
[0057] In one possible implementation, the third device is configured to receive a subscription request from the first device, the subscription request being for subscribing to roaming status information of the terminal device; send first roaming status information of the terminal device to the first device, the first roaming status information including information of the first network; and send second roaming status information of the terminal device to the first device, the second roaming status information including information of the second network. Attached Figure Description
[0058] Figure 1 This is a schematic diagram of a 5G network architecture based on a service-oriented architecture.
[0059] Figure 2 This is a schematic diagram of a 5G network architecture based on a point-to-point interface.
[0060] Figure 3 A schematic diagram of the architecture for adding AKMA-related functions to a 5G network;
[0061] Figure 4 A K provided for embodiments of this application AKMA A schematic diagram of the generation method;
[0062] Figure 5 A K provided for embodiments of this application AKMA A diagram illustrating how to use it;
[0063] Figures 6-7 A schematic diagram of the AKMA service shutdown method provided in the embodiments of this application;
[0064] Figures 8 to 13 A flowchart illustrating the communication method provided in an embodiment of this application;
[0065] Figures 14-15 This is a schematic diagram of a communication device provided in an embodiment of this application. Detailed Implementation
[0066] To address the challenges of wireless broadband technology and maintain the leading edge of the 3rd Generation Partnership Project (3GPP) network, the 3GPP standards group developed the Next Generation System architecture, known as the 5th generation (5G) network architecture. This architecture not only supports radio access technologies defined by the 3GPP standards group (such as Long Term Evolution (LTE) and 5G Radio Access Network (RAN)) to access the 5G core network (CN), but also supports access to the core network using non-3GPP access technologies through non-3GPP interworking functions (N3IWF) or next-generation packet data gateways (ngPDG).
[0067] Figure 1 This is a schematic diagram of a 5G network architecture based on a service-oriented architecture. Figure 1The 5G network architecture shown may include access network equipment and core network equipment. Terminal equipment (taking user equipment (UE) as an example in the diagram) accesses the data network (DN) through access network equipment and core network equipment. The core network equipment includes, but is not limited to, some or all of the following network elements: authentication server function (AUSF) network element (not shown in the diagram), unified data management (UDM) network element, unified data repository (UDR) network element, network repository function (NRF) network element (not shown in the diagram), network exposure function (NEF) network element (not shown in the diagram), application function (AF) network element, policy control function (PCF) network element, access and mobility management function (AMF) network element, session management function (SMF) network element, and user plane function (UPF) network element.
[0068] Terminal devices can be UEs, mobile stations, mobile terminal devices, etc. They can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), the Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, and smart cities. Terminal devices can be mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicles, urban air mobility vehicles (such as drones and helicopters), ships, robots, robotic arms, smart home devices, etc. Terminal devices store long-term keys and related functions. When performing two-way authentication with core network elements (such as AMF and AUSF elements), the terminal device uses the long-term key and related functions to verify the authenticity of the network.
[0069] Access network equipment can be either radio access network (RAN) equipment or wired access network equipment. RAN equipment includes 3GPP access network equipment, untrusted non-3GPP access network equipment, and trusted non-3GPP access network equipment. 3GPP access network equipment includes, but is not limited to: evolved NodeBs (eNodeBs) in LTE, next-generation NodeBs (gNBs) in 5G mobile communication systems, base stations in future mobile communication systems, or modules or units that perform some base station functions, such as central units (CUs) and distributed units (DUs). Untrusted non-3GPP access network equipment includes, but is not limited to: untrusted non-3GPP access gateways or N3IWF devices, untrusted wireless local area network (WLAN) access points (APs), switches, and routers. Trusted non-3GPP access network equipment includes, but is not limited to: trusted non-3GPP access gateways, trusted WLAN APs, switches, and routers. Wired access network equipment includes, but is not limited to: wireline access gateways, fixed-line telephone network equipment, switches, and routers.
[0070] Access network equipment and terminal equipment can be fixed or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; and they can be deployed in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of the access network equipment and terminal equipment.
[0071] The AMF (Agency Flow Management) network element includes functions such as mobility management and access authentication / authorization. In addition, it is responsible for transmitting user policies between terminal devices and the PCF (Programmable Flow Management) network element.
[0072] SMF network elements include functions such as performing session management, executing control policies issued by PCF network elements, selecting UPF network elements, or allocating Internet Protocol (IP) addresses to terminal devices.
[0073] UPF network elements include functions such as user plane data forwarding, session / flow-level billing statistics, and bandwidth limiting.
[0074] UDM network elements include functions such as managing contracted data or authorizing user access.
[0075] UDR includes functions for storing and retrieving data of various types, such as contract data, policy data, or application data.
[0076] NEF network elements are used to support the opening of capabilities and events.
[0077] AF (Application Provider) network elements convey application-side requests to the network side, such as QoS requirements or user state event subscriptions. AFs can be third-party functional entities or application services deployed by operators, such as IP Multimedia Subsystem (IMS) voice call services. AF network elements include those within the core network (i.e., the operator's AFs) and third-party AFs (such as an enterprise's application server).
[0078] PCF (Portable Component Function) network elements include policy control functions responsible for billing, QoS bandwidth guarantees, mobility management, and terminal device policy decisions at the session and service flow levels. PCF network elements include access and mobility management policy control function (AM PCF) network elements and session management policy control function (SM PCF) network elements. AM PCF network elements are used to formulate AM policies and user policies for terminal devices; AM PCF network elements can also be referred to as policy control network elements providing services to terminal devices (PCF for aUE). SM PCF network elements are used to formulate session management policies (SM policies) for sessions; SMPCF network elements can also be referred to as policy control network elements providing services to a PDU session (PCF for a PDU session).
[0079] NRF network elements can be used to provide network element discovery functionality, providing network element information corresponding to the network element type based on requests from other network elements. NRF network elements also provide network element management services, such as network element registration, updates, deregistration, and network element status subscription and push.
[0080] The AUSF network element is responsible for authenticating users to determine whether a user or device is allowed to access the network.
[0081] A Domain Provider (DN) is a network located outside of the carrier's network. A carrier's network can connect to multiple DNs, and various services can be deployed on a DN, providing data and / or voice services to terminal devices. For example, a DN might be the private network of a smart factory. Sensors installed in the workshop can act as terminal devices, and a control server for these sensors is deployed within the DN. The control server provides services to the sensors. Sensors can communicate with the control server, receive instructions from it, and transmit the collected sensor data back to the control server accordingly. Another example is a DN serving as an internal office network for a company. Employees' mobile phones or computers can act as terminal devices, accessing information and data resources on the company's internal office network.
[0082] Figure 1 Npcf, Nudr, Nudm, Naf, Namf, and Nsmf are the service interfaces provided by the aforementioned PCF, UDR, UDM, AF, AMF, and SMF network elements, respectively, used to invoke the corresponding service operations. N1, N2, N3, N4, and N6 are interface sequence numbers, with the following meanings:
[0083] 1) N1: The interface between the AMF network element and the terminal device, which can be used to transmit non-access stratum (NAS) signaling (such as QoS rules from the AMF network element) to the terminal device.
[0084] 2) N2: The interface between the AMF network element and the access network equipment, which can be used to transmit radio bearer control information from the core network side to the access network equipment.
[0085] 3) N3: The interface between the access network equipment and the UPF network element, mainly used to transmit uplink and downlink user plane data between the access network equipment and the UPF network element.
[0086] 4) N4: The interface between SMF network elements and UPF network elements. It can be used to transmit information between the control plane and the user plane, including the distribution of forwarding rules, QoS rules, traffic statistics rules, etc. from the control plane to the user plane, as well as the reporting of information from the user plane.
[0087] 5) N6: The interface between the UPF network element and the DN, used to transmit uplink and downlink user data streams between the UPF network element and the DN.
[0088] Figure 2 This is a schematic diagram of a 5G network architecture based on a point-to-point interface. For a description of the functions of the network elements, please refer to [reference needed]. Figure 1 The functions of the corresponding network elements will not be described in detail here. Figure 2 and Figure 1 The main difference is: Figure 1The interfaces between the various control plane network elements are service-oriented interfaces. Figure 2 The interfaces between the various control plane network elements are point-to-point interfaces.
[0089] exist Figure 2 In the architecture shown, the interface names and functions between the various network elements are as follows:
[0090] 1) The meanings of interfaces N1, N2, N3, N4 and N6 can be found in the previous description.
[0091] 2) N5: The interface between the AF network element and the PCF network element, which can be used for application service request distribution and network event reporting.
[0092] 3) N7: The interface between PCF network elements and SMF network elements, which can be used to issue PDU session granularity and service data flow granularity control policies.
[0093] 4) N8: The interface between the AMF network element and the UDM network element. It can be used by the AMF network element to obtain access and mobility management related subscription data and authentication data from the UDM network element, as well as by the AMF network element to register terminal device mobility management related information with the UDM network element.
[0094] 5) N9: User plane interface between UPF network elements, used to transmit uplink and downlink user data streams between UPF network elements.
[0095] 6) N10: The interface between SMF network elements and UDM network elements. It can be used for SMF network elements to obtain session management-related subscription data from UDM network elements, and for SMF network elements to register terminal device session-related information with UDM.
[0096] 7) N11: The interface between SMF network elements and AMF network elements. It can be used to transmit PDU session tunnel information between access network devices and UPF network elements, transmit control messages sent to terminal devices, and transmit radio resource control information sent to access network devices.
[0097] 8) N15: The interface between PCF network elements and AMF network elements, which can be used to issue terminal equipment policies and access control related policies.
[0098] 9) N35: The interface between UDM network elements and UDR network elements, which can be used by UDM network elements to obtain user subscription data information from UDR network elements.
[0099] 10) N36: The interface between PCF network elements and UDR network elements, which can be used by PCF network elements to obtain policy-related contract data and application data related information from UDR network elements.
[0100] Figure 3This is a schematic diagram illustrating the architecture for adding AKMA-related functions to a 5G network. Figure 3 Is Figure 1 The 5G architecture shown can be enhanced with AKMA-related functions, and of course, it can also be used in... Figure 2 The AKMA-related functions added to the 5G architecture shown are based on a similar principle and will not be elaborated further.
[0101] Figure 3 A new AAnF network element has been added, which can request the AKMA root key (i.e., K) from the AUSF network element. AKMA Then, the AAnF network element is based on K AKMA Determine the application key (i.e., K) used by the AF network element. AF ) and K AF The effective time.
[0102] exist Figure 3 In the AKMA scenario shown, the AF network element obtains K from the AAnF network element through interaction with the AAnF network element. AF and K AF The effective time. AF network elements can be located inside or outside the 5G core network. If the AF network element is inside the 5G core network, it can directly interact with the PCF network element. If the AF network element is outside the 5G core network, it can interact with the PCF network element via the NEF network element; that is, the NEF network element acts as an intermediate network element between the AF network element and the PCF network element.
[0103] exist Figure 3 In the AKMA scenario shown, the AUSF network element supports authentication (also known as authorization) for both 3GPP and non-3GPP access, and can generate K for the AAnF network element. AKMA .
[0104] exist Figure 3 In the AKMA scenario shown, the AF network element can obtain services from the AAnF network element. For example, the AF network element can interact with the AAnF network element to obtain K... AF and K AF The effective time.
[0105] exist Figure 3 In the AKMA scenario shown, Ua* is a reference point between the UE and the AF network element, used for message interaction between the UE and the AF network element, and can support key generation in the AKMA process.
[0106] It is understood that the aforementioned network element or function can be a network component in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the aforementioned network element or function can be implemented by one device, multiple devices working together, or a functional module within a single device; this application embodiment does not specifically limit this.
[0107] For ease of explanation, this application uses a UE as an example of a terminal device in its embodiments. The UE described below can be replaced with any terminal device. Furthermore, in this application, the AUSF network element, UDM network element, AAnF network element, AF network element, NEF network element, and NRF network element are abbreviated as AUSF, UDM, AAnF, AF, NEF, and NRF, respectively.
[0108] Figure 4 A K provided for embodiments of this application AKMA A schematic diagram of the generation method. The method includes the following steps:
[0109] In step 401, during the primary authentication process, AUSF sends an authentication request message to UDM. Accordingly, UDM receives the authentication request message.
[0110] The authentication request message includes a Subscription Permanent Identifier (SUPI) or a Subscription Concealed Identifier (SUCI). This authentication request message is used to request an authentication vector from the UDM, which is used to trigger primary authentication between the core network and the UE.
[0111] For example, the authentication request message can be a Numd_UEAuthentication GetRequest message.
[0112] In this embodiment of the application, the main authentication process is also called the main authorization process, which will be explained here and will not be repeated hereafter.
[0113] In step 402, the UDM sends an authentication response message to the AUSF. The AUSF then receives this authentication response message.
[0114] The authentication response message includes an authentication vector.
[0115] If the UDM determines that the UE supports AKMA services based on the UE's subscription information, the authentication response message will also include AKMA indication information. Here, UE support for AKMA services means that the UE has AKMA capability and that the UE's services can use AKMA. The AKMA indication information is used to trigger AUSF to generate K... AKMA .
[0116] In this embodiment, AKMA service refers to a service or business that provides security protection between the UE and AF based on a key generated by AKMA. Specifically, it can be an application session or application service between the UE and AF. AKMA service can be implemented through an application session / connection / link established between the UE and AF. The AKMA service in this embodiment can also be called AKMA service, which will be used consistently here and will not be elaborated further.
[0117] Optionally, the authentication response message may also include a routing identifier (RID), which is used to select AAnF, meaning that AAnF can be selected based on the RID.
[0118] For example, the authentication response message can be a Num_UEAuthentication_GetResponse message.
[0119] Step 403: If AUSF receives AKMA instruction information from UDM, then after the main authentication process is successfully completed, AUSF will use the AUSF root key (K... AUSF Generate K AKMA And AKMA key identifier (A-KID).
[0120] A-KID is used to identify K. AKMA .
[0121] A-KID is the Network Access Identifier (NAI) format, i.e., username@example. The username portion includes the RID and the AKMA temporary UE Identifier (AKMATemporary UE Identifier, A-TID). The RID is part of SUCI and is represented by 1 to 4 decimal digits. A-TID is based on K... AUSFA temporary identifier is generated. The example part includes the Home Network Identifier, which can specifically be the identification information of the Home Public Land Mobile Network (HPLMN ID). The Home Public Land Mobile Network is also called the Home Public Land Mobile Network or the Home Location Public Land Mobile Network.
[0122] Accordingly, after the main authentication process, the UE also follows the same method as AUSF, based on K. AUSF Generate K AKMA And A-KID.
[0123] In step 404, the AUSF selects an AAnF and sends a key registration request message to the selected AAnF. The AAnF then receives the key registration request message.
[0124] The key registration request message includes SUPI, A-KID, and K. AKMA .
[0125] For example, AUSF selects AAnF based on RID.
[0126] The key registration request message can be a Naanf_AKMA_AnchorKey_RegisterRequest message.
[0127] In step 405, AAnF sends a key registration response message to AUSF. AUSF then receives this key registration response message.
[0128] For example, the key registration response message can be a Naanf_AKMA_AnchorKey_RegisterResponse message.
[0129] It should be noted that AAnF only stores the latest information sent by AUSF. When re-authentication occurs, AUSF sends a new A-KID and a new K to AAnF. AKMA Afterwards, AAnF will delete the old A-KID and the old K. AKMA And save the new A-KID and the new K AKMA .
[0130] Through the above scheme, UE and AAnF store the same K. AKMA This facilitates the subsequent use of K by UE and AAnF. AKMA Other keys can be derived from this.
[0131] Figure 5 A K provided for embodiments of this applicationAKMA This is a schematic diagram illustrating the usage method. In this method, AF belongs to a network element in the 3GPP core network or a network element outside the 3GPP core network. When AF belongs to a network element outside the 3GPP core network, the following interactions between AF and AAnF can all be relayed through NEF. Specifically, before step 501, the following steps are completed... Figure 4 The main authentication process and K shown in the embodiment AKMA Generation process.
[0132] The method includes the following steps:
[0133] Step 501: The UE sends an Application Session Establishment Request message to the AF. Correspondingly, the AF receives the Application Session Establishment Request message.
[0134] The application session establishment request message includes an A-KID, which is used by AF to find the KAMA key corresponding to the A-KID.
[0135] The A-KID is established before step 501, in the main authentication process and the K... AKMA It is generated by the UE in the generation process.
[0136] Step 502: If there is no A-KID related context on the AF, the AF selects an AAnF and sends an application key request message to the AAnF. Accordingly, the AAnF receives the application key request message.
[0137] The application key request message includes an A-KID and an AF ID. The A-KID comes from step 501. The AFID is used to identify the AF. The AF ID can be used to calculate K. AF The input parameters at that time are used to achieve key isolation between different AFs.
[0138] Among them, AF can select AAnF based on RID.
[0139] For example, the application key request message can be a Naanf_AKMA_ApplicationKey_Get_Request message or a Naanf_AKMA_ApplicationKey_AnonUser_Getservice message.
[0140] Step 503, optionally, when AAnF determines that AF requires a Generic Public Subscription Identity (GPSI) based on local rules, AAnF sends a request message to UDM. Accordingly, UDM receives the request message.
[0141] This request message is used to request the UE's GPSI. For example, the request message may carry the UE's SUPI to request the GPSI corresponding to that SUPI.
[0142] For example, the request message could be a Nudm_SDM_GetRequest message.
[0143] Step 504, optionally, UDM sends a response message to AAnF. AAnF then receives the response message.
[0144] The response message includes the UE's GPSI. AAnF stores the GPSI as the UE's AKMA context.
[0145] It should be noted that if AAnF determines that AF does not need GPSI based on local rules, then steps 503 to 504 do not need to be executed.
[0146] For example, the response message could be a Nudm_SDM_GetResponse message.
[0147] Step 505, optionally, AAnF sends a subscription request message to UDM. Accordingly, UDM receives the subscription request message.
[0148] The subscription request message contains the UE's SUPI or GPSI, and is used to request the UE's roaming status report or roaming status information.
[0149] For example, the subscription request message can be a Nudm_EventExposure_Subscribe Request message.
[0150] Step 506, optionally, UDM sends a subscription response message to AAnF. AAnF then receives the subscription response message.
[0151] The subscription response message contains the UE's roaming status information.
[0152] The roaming status information includes the public land mobile network (PLMN) information registered by the UE. Optionally, the roaming status information also includes indication information indicating whether the PLMN is the home network. The PLMN information registered by the UE can be referred to as the information of the first network.
[0153] In a dual-registration scenario, the PLMN information includes the identifiers of two PLMNs. These two PLMN identifiers can also be referred to as the information of the first network and the information of the second network, respectively.
[0154] Subsequently, if the UE's roaming information changes, the UDM sends a notification message to the AAnF, which carries the changed roaming status information.
[0155] For example, the subscription response message can be a Nudm_EventExposure_Subscribe Response message.
[0156] Step 507, AAnF obtains K based on A-KID. AKMA And according to K AKMA and AF ID generation K AF And determine K AF The effective time.
[0157] Among them, AAnF is in the main authentication process and K AKMA The generation process obtains the A-KID and the corresponding K. AKMA and A-KID and K AKMA Stored locally.
[0158] In step 508, AAnF sends an application key response message to AF. Correspondingly, AF receives the application key response message.
[0159] The application key response message includes K. AF and K AF The effective time.
[0160] For example, the application key response message can be a Naanf_AKMA_ApplicationKey_GetResponse message.
[0161] In one implementation, when the application key request message in step 502 is Naanf_AKMA_ApplicationKey_Get_Request, the application key response message may carry SUPI or GPSI. When the application key request message in step 502 is Naanf_AKMA_ApplicationKey_AnonUser_Getservice, the application key response message does not carry SUPI or GPSI.
[0162] Step 509: The AF sends an Application Session Establishment Response message to the UE. Correspondingly, the UE receives the Application Session Establishment Response message.
[0163] It should be noted that the UE in the main authentication process and K AKMAIn any subsequent step of the generation process, K is generated using the same method as AAnF. AF And determine K AF The effective time.
[0164] In the above scheme, UE and AAnF are based on K AKMA Determine the same K AF and K AF The effective time, and the K sent by AAnF to AF. AF and K AF The validity period of K allows subsequent communication between the UE and AF. AF Protecting the content transmitted between the UE and AF helps improve communication security.
[0165] In roaming scenarios, there may be situations where AKMA services are not permitted. AAnF can determine whether AKMA services are allowed based on local configuration and the UE's roaming status information.
[0166] Figure 6 This diagram illustrates a method for disabling AKMA services according to an embodiment of this application. This embodiment addresses a scenario where no re-authentication (or re-authorization) occurs between the UE and the core network. The method includes the following steps:
[0167] Step 601: The UE registers with the first network.
[0168] For example, the first network may be a home public land mobile network (HPLMN).
[0169] Step 602, UE accesses AF, AF obtains K AF , and AF provides AAnF with a Uniform Resource Identifier (URI) for service shutdown.
[0170] Among them, AF obtains K AF For details, please refer to Figure 5 The method implementation is as follows, namely steps 501 to 509.
[0171] This URI is used by ANF to locate the AF that needs to shut down AKMA services. For example, this URI could be the IP address of the AF.
[0172] Step 603: AAnF receives a notification message from UDM, which includes the UE's roaming status information. Based on the UE's roaming status information, AAnF detects that the network the UE is registered with has changed.
[0173] For example, the network registered by the UE changes from registering to the first network to registering to the second network, or changes from registering to the first network to registering to both the first and second networks simultaneously.
[0174] The first network can be a network that the UE connects to via 3GPP access or a network that connects via non-3GPP access.
[0175] The second network can be a network connected via 3GPP access or a network connected via non-3GPP access.
[0176] Step 604, AAnF determines that AF provided a URI for service shutdown, and local rules indicate that the UE cannot use AKMA services on the second network.
[0177] Step 605: AAnF sends an AKMA service shutdown notification message to AF. Correspondingly, AF receives the AKMA service shutdown notification message.
[0178] The AKMA service shutdown notification message carries an A-KID, which is used to identify AKMA keys that can no longer be used (e.g., K). AF ).
[0179] For example, the AKMA service shutdown notification message can be a Naanf_AKMA_ServiceDisableNotification message.
[0180] Based on the A-KID, the AF stops or shuts down the AKMA service of the UE corresponding to that A-KID.
[0181] Step 606: AF sends an AKMA service shutdown response message to AAnF. Correspondingly, AAnF receives the AKMA service shutdown response message.
[0182] For example, the AKMA service shutdown response message can be a Naanf_AKMA_ServiceDisableNotification response message.
[0183] In the above scheme, when a UE changes its registration from the first network to the second network, and the UE cannot use the AKMA service in the second network, the AAnF notifies the AF to shut down the AKMA service associated with the A-KID for that UE, thus achieving the correct shutdown of the AKMA service.
[0184] Figure 7This diagram illustrates another method for disabling AKMA services provided in this application embodiment. This method addresses scenarios where the UE's registered network changes and the UE undergoes at least two authentications, i.e., re-authentication (or re-authorization) occurs between the UE and the core network. The method includes the following steps:
[0185] Step 701, Master Authentication Process and Key AKMA Generation process.
[0186] For the specific implementation process of step 701, please refer to [link / reference]. Figure 4 Steps 401 to 405 of the embodiment.
[0187] During this process, the UE registers with the first network, and after passing the primary authentication, completes the registration process on the first network. In this embodiment of the application, the K generated by AUSF is used... AKMA A-KID is called K AKMA #1 and A-KID#1.
[0188] Step 702: The UE sends an application session establishment request message to the AF, triggering the AF to obtain the K corresponding to A-KID#1 from the AAnF. AF and K AF The effective time.
[0189] For the specific implementation process of step 702, please refer to [link / reference]. Figure 5 Steps 501 to 509 of the embodiment.
[0190] In step 703, the UE and the core network perform primary authentication again, and the AUSF sends a key registration request message to the AAnF. Correspondingly, the AAnF receives this key registration request message.
[0191] The key registration request message includes SUPI, A-KID#2, and K. AKMA #2. Among them, A-KID#2 and K AKMA #2 is generated by AUSF, and the UE also generates the same A-KID#2 and K. AKMA #2.
[0192] The key registration request message can be a Naanf_AKMA_Key_Register Request message.
[0193] The scenarios in which the UE and the core network perform primary authentication again include any of the following:
[0194] In scenario one, the UE moves from the first network to the second network for access (such as when N2 handover occurs), meaning the UE still maintains single registration.
[0195] Scenario 2: The UE registers to the first network through a first access method (such as 3GPP access) and also registers to the second network through a second access method (such as non-3GPP access), i.e., the UE performs dual registration.
[0196] In step 704, AAnF sends a key registration response message to AUSF. AUSF then receives this key registration response message.
[0197] For example, the key registration response message can be a Naanf_AKMA_AnchorKey_RegisterResponse message.
[0198] It should be noted that AAnF only stores the latest information sent by AUSF. Therefore, when primary authentication (also known as secondary primary authentication, re-authentication, or re-authorization) occurs again, AUSF sends A-KID#2 and K to AAnF. AKMA After #2, AAnF deleted the old A-KID and K. AKMA That is, A-KID#1 and K AKMA #1, and save the new A-KID and K AKMA That is, A-KID#2 and K AKMA #2.
[0199] Step 705: UDM sends a notification message to AAnF. AAnF then receives this notification message.
[0200] The notification message carries the UE ID and roaming status information. The UE ID can be SUPI or SUCI, etc.
[0201] In a single registration scenario, roaming status information includes information from the second network. In a dual registration scenario, roaming status information includes information from both the first and second networks.
[0202] For example, the notification information could be a Nudm_EventExposure_Notification message.
[0203] Step 706, AAnF determines that AF provided a URI for service shutdown, and local rules indicate that the UE cannot use AKMA services on the second network.
[0204] Step 707: AAnF sends an AKMA service shutdown notification message to AF. Correspondingly, AF receives the AKMA service shutdown notification message.
[0205] The AKMA service shutdown notification message carries A-KID#2, which is used to identify AKMA keys that can no longer be used (e.g., K). AF ).
[0206] For example, the AKMA service shutdown notification message can be a Naanf_AKMA_ServiceDisableNotification message.
[0207] Step 708: AF sends an AKMA service shutdown response message to AAnF. Correspondingly, AAnF receives the AKMA service shutdown response message.
[0208] For example, the AKMA service shutdown response message can be a Naanf_AKMA_ServiceDisableNotification response message.
[0209] The AF receives A-KID#2 and attempts to stop or disable the AKMA service of the UE corresponding to A-KID#2. However, the AF is actually running the AKMA service of the UE corresponding to A-KID#1. The AKMA service that should be disabled is the AKMA service of the UE corresponding to A-KID#1, but the AF receives A-KID#2 instead. This causes the AF to be unable to recognize the AKMA key (e.g., K) corresponding to A-KID#2. AF Consequently, the AKMA business shutdown failed.
[0210] In the above scheme, when a UE changes its registration from the first network to the second network, or simultaneously to both networks, if the UE cannot use the AKMA service on the second network, the AAnF notifies the AF to disable the AKMA service. Because a secondary primary authentication occurs between the UE and the core network, the AAnF is triggered to delete the old A-KID and the old KID. AKMA And save the new A-KID and the new K AKMA Therefore, when AAnF notifies AF to close the AKMA service, it sends a new A-KID to AF. However, AF stores and uses the old A-KID instead of the new one. Consequently, AF cannot recognize the new A-KID, causing the AKMA service closure to fail. AF can still utilize the K corresponding to the old A-KID (i.e., A-KID#1). AF Continuing to interact with the UE on the second network leads to compliance risks.
[0211] To address the aforementioned issues, this application provides corresponding solutions.
[0212] Figure 8This is a flowchart illustrating a communication method provided in an embodiment of this application. In this application, "first device" can refer to an ANF network element, a component within an ANF network element (e.g., a communication module, processor, circuit, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of an ANF network element. Similarly, "second device" can refer to an AF network element, a component within an AF network element (e.g., a communication module, processor, circuit, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of an AF network element. Likewise, "third device" can refer to a UDM network element, a component within a UDM network element (e.g., a communication module, processor, circuit, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of a UDM network element.
[0213] The method includes the following steps:
[0214] Step 801: The first device receives the first key registration request message.
[0215] For example, the first key registration request message comes from an AUSF network element.
[0216] The first key registration request message includes the UE's first identifier and the first AKMA key identifier (also known as the first A-KID or A-KID#1), which is generated after the UE completes primary authentication in the first network.
[0217] The UE's first identifier can be either SUPI or GPSI.
[0218] The first network can be a network that the UE connects to via 3GPP access or a network that connects via a non-3GPP access method.
[0219] In step 802, the second device sends an application key request message to the first device. Correspondingly, the first device receives the application key request message.
[0220] The application key request message includes a first AKMA key identifier, and is used to request the application key (also known as K) corresponding to the first AKMA key identifier. AF This application key is used to protect the first AKMA service between the UE and the second device. More specifically, when the UE accesses the first network and transmits the first AKMA service with the second device in the first network, the application key is used to protect the AKMA service.
[0221] For example, before step 802, the UE sends an application session establishment request message to the second device. The application session establishment request message carries a first AKMA key identifier. The application session establishment request message triggers the second device to execute step 802. The first AKMA key identifier in the application key request message of step 802 comes from the application session establishment request message.
[0222] Furthermore, in response to the application key request message, the first device sends the application key corresponding to the first AKMA key identifier to the second device. For example, the first device may generate the application key based on the first AKMA key identifier, or based on the identifier of the second device and the first AKMA key identifier, or generate the application key through other methods; this application is not limited in this regard.
[0223] Step 803: The first device stores the first information.
[0224] This first piece of information is associated with the first AKMA business.
[0225] For example, the first information includes one or more of the following:
[0226] (1) First AKMA key identifier.
[0227] (2) The UE's second identifier. The UE's second identifier is different from its first identifier. For example, the UE's first identifier is SUPI, and its second identifier is GPSI. Or, for another example, the UE's first identifier is GSPI, and its second identifier is SUPI.
[0228] (3) Context ID. This context ID is used to indicate the context of the connection between the first device and the second device. This context ID may be generated by the first device.
[0229] As one implementation method, the first device stores first information, specifically, it may store the correspondence between the first information and the identification information of the second device. The identification of the second device may be the identifier of the second device (e.g., AF ID) or the URI of the second device (e.g., the URI of an AF specifically used for service shutdown). It should be understood that the second device may be one or more devices. For example, multiple second devices may have obtained the application key corresponding to the first AKMA key identifier from the first device; specifically, the second device may have sent an application key request message to the first device and / or received the application key from the first device. Therefore, the second device is a device that has interacted with the first device regarding the UE.
[0230] Furthermore, this mapping relationship can also include the first identifier of the associated UE, that is, the mapping relationship contains the correspondence between the first identifier of the UE, the first information, and the identifier of the second device. This mapping relationship can be used to correctly locate the second device that needs to have its AKMA service turned off.
[0231] As one implementation method, the first device stores first information when a triggering condition is met. The triggering condition includes one or more of the following:
[0232] (1) The first device has subscribed to roaming status information.
[0233] When the first device subscribes to roaming status information, indicating a change in the network registered by the subsequent UE, the first device can detect the network change. Therefore, it can potentially discover that the UE cannot use the AKMA service in the new network, and thus needs to send a first message to the second device to notify it to disable the first AMKA service associated with that first message. Only then does the first device need to store the first message. In other words, if the first device does not subscribe to roaming status information, it cannot detect the network change and therefore cannot discover that the UE cannot use the AKMA service in the new network. Consequently, it does not need to send the first message to the second device to notify it to disable the first AMKA service associated with that first message, and therefore does not need to store the first message.
[0234] (2) The first device has obtained the URI provided by the second device for service shutdown.
[0235] When the second device provides the first device with a URI for service shutdown, the first device can then use that URI to correctly locate the second device that needs to shut down the AKMA service.
[0236] (3) The first device has sent the application key corresponding to the first AKMA key identifier to the second device.
[0237] Once the first device has sent the application key corresponding to the first AKMA key identifier to the second device, the second device can enable the application key to protect the first AKMA service between the UE and the second device. That is, the application key can only be used to protect the first AKMA service if the second device obtains the application key. It may be necessary to close the first AKMA service later. Therefore, it is necessary for the first device to store the first information associated with the first AKMA service.
[0238] In this embodiment of the application, step 803 can be executed at any time after step 802 and before step 805. Therefore, step 803 can be executed before or after step 804 below, or simultaneously with step 804 below.
[0239] Step 804: The first device receives the second key registration request message.
[0240] For example, the second key registration request message comes from an AUSF network element.
[0241] The second key registration request message includes the UE's first identifier and second AKMA key identifier (also known as the second A-KID or A-KID#2), which is generated after the UE completes primary authentication in the second network.
[0242] In one scenario, when a UE moves from the first network to the second network for access (such as during N2 handover), the UE still maintains single registration, and the UE can initiate primary authentication on the second network.
[0243] In another scenario, the UE registers to the first network through a first access method (such as 3GPP access) and also registers to the second network through a second access method (such as non-3GPP access), that is, the UE performs dual registration, and the UE can initiate primary authentication on the second network.
[0244] The second network can be a network connected via 3GPP access or a network connected via non-3GPP access.
[0245] After receiving the UE's first identifier and second AKMA key identifier, the first device stores the correspondence between the UE's first identifier and the second AKMA key identifier.
[0246] It should be noted that in the prior art, after step 804, the first device needs to delete the old AKMA key identifier (i.e., the first AKMA key identifier) and only save the new AKMA key identifier (i.e., the second AKMA key identifier). However, in this embodiment, after step 804, the UE does not delete the first information stored in step 803.
[0247] Step 805: When the UE cannot use the AKMA service in the second network, the first device sends an AKMA service shutdown notification message to the second device. Correspondingly, the second device receives the AKMA service shutdown notification message.
[0248] The AKMA service shutdown notification message includes first information. This AKMA service shutdown notification message is used to instruct the second device to shut down the first AKMA service corresponding to the first information. Optionally, the AKMA service shutdown notification message also includes a second AKMA key identifier.
[0249] In one possible design, the first device locally pre-configures a list of allowed networks and / or a list of disallowed networks for the UE. The list of allowed networks contains networks where the UE is permitted to use AKMA services while roaming; that is, if the UE's roaming network is included in the list of allowed networks, the UE is permitted to use AKMA services on that roaming network. The list of disallowed networks contains networks where the UE is not permitted to use AKMA services while roaming; that is, if the UE's roaming network is included in the list of disallowed networks, the UE is not permitted to use AKMA services on that roaming network. Based on this list of allowed and / or disallowed networks, the first device can determine whether the UE can use AKMA services on a second network. For example, if the second network is included in the list of allowed networks, the first device determines that the UE can use AKMA services. Conversely, if the second network is included in the list of disallowed networks, the first device determines that the UE cannot use AKMA services.
[0250] In one possible design, the first device can determine the recipients of the AKMA service shutdown notification message according to any one or more of the following methods A to C, that is, determine which second devices to send the AKMA service shutdown notification message to:
[0251] Method A: If a second device has sent an application key request message to a first device, then the first device sends an AKMA service shutdown notification message to the second device.
[0252] Method B: If the first device has sent an application key to a second device, then the first device sends an AKMA service shutdown notification message to the second device. The first device may send the application key to the second device in response to a received application key request message.
[0253] Method C: If a second device has sent a URI for service shutdown to the first device, then the first device sends an AKMA service shutdown notification message to the second device. The URI for service shutdown can be the IP address of the second device.
[0254] Alternatively, the second device in step 805 can be understood as a device that has interacted with the first device regarding the UE and / or a device with service shutdown functionality. Specifically, the first device can determine the second device based on the identifier of the second device stored in step 803.
[0255] In one possible design, the first device can determine whether to include the first information in the AKMA service closure notification message using the following method: The first device determines to include the first information in the AKMA service closure notification message based on the correspondence between the first information and the identification information of the second device. That is, if the first device determines that the AKMA service between the second device and the UE is associated with the first information, then the AKMA service closure notification message includes the first information to close the corresponding AKMA service. Conversely, if the first device determines that the AKMA service between the second device and the UE is unrelated to the second AKMA key identifier, that is, the first device has not sent the application key corresponding to the second AKMA key identifier to the second device, then the first device may not include the second AKMA key identifier in the AKMA service closure notification message. It should be understood that the first device may also include the first information and the second AKMA key identifier in the AKMA service closure notification message, so that the second device can further determine to close the first AKMA service corresponding to the first information, because the second device does not have the information corresponding to the second AKMA key identifier, and the second device may not need to perform further processing based on the second AKMA key identifier.
[0256] As a specific example, the first device maintains a set of AKMA-related contexts for the UE. These contexts may include first information and a second AKMA key identifier; or the AKMA-related service context may include a correspondence between the first information and the identification information of the second device, as well as the second AKMA key identifier; or the AKMA-related context may include a correspondence between the first information, the UE's first identifier, and the identification information of the second device, as well as the second AKMA key identifier. If the first device determines that the second AKMA key identifier does not have an AKMA service but the first information is associated with a first AKMA service, then the first device includes the first information in the AKMA service shutdown notification message.
[0257] As another specific example, the first device maintains two sets of AKMA-related contexts for the UE. The first set of AKMA-related contexts is generated after the first device sends an application key to the second device, and is related to the AKMA service. For example, the content of this AKMA-related context includes the corresponding information of the application key sent by the first device, namely, the first information associated with the first AKMA service, the identification information of the second device, and / or the first identifier of the UE, etc. Exemplarily, the first set of AKMA-related contexts includes the first information, or the correspondence between the first information and the identification information of the second device, or the correspondence between the first information, the first identifier of the UE, and the identification information of the second device. The second set of AKMA-related contexts is generated before the first device sends an application key to the second device, and is related to the second AKMA key identifier. Exemplarily, the second set of AKMA-related contexts includes the second AKMA key identifier. Optionally, the second set of AKMA-related contexts also includes the first identifier of the UE and the K corresponding to the second AKMA key identifier. AKMA Furthermore, the first device obtains first information from the first set of AKMA-related context and carries the first information in the AKMA service shutdown notification message. For example, if the first device determines that the UE cannot use AKMA service in the second network, it obtains the first information from the first set of AKMA-related context by default, or the first device determines to obtain the first information from the first set of AKMA-related context based on any of the following information recorded in the first set of AKMA-related context: a) the identifier of the second device that sent the application key request message to the first device; b) which second devices the first device sent the application key to; c) which second devices the first device received the URI for service shutdown from.
[0258] As one implementation method, the first device can send a subscription request to the third device, the subscription request being used to subscribe to the UE's roaming status information. This subscription request can be executed in any step after step 802 and before step 805. Accordingly, the first device can receive the UE's first roaming status information from the third device, which includes information about the first network. When the UE roams and registers with a second network, or simultaneously registers with both the first and second networks, the first device receives the UE's second roaming status information from the third device. This second roaming status information includes information about the second network, or includes information about both the first and second networks. Therefore, the first device determines that the UE is roaming based on either the first or second roaming status information. The first device then determines whether the UE can use the AKMA service on the second network. If the AKMA service cannot be used, the first device sends an AKMA service shutdown notification message to the second device.
[0259] Step 806: The second device shuts down the first AKMA service corresponding to the first information.
[0260] Specifically, “closing the first AKMA service” can be one or more of the following operations: the second device deletes the connection, link or session related to the first AKMA service; the second device deletes the context related to the first AKMA service; the second device deletes the cached data or signaling related to the first AKMA service; and the second device sends a connection, link or session release message to the UE to disconnect the connection, link or session with the UE.
[0261] Optionally, after closing the first AKMA service corresponding to the first information, the second device sends an AKMA service closure notification response message to the first device, indicating that the first AKMA service associated with the first information has been closed, and then the first device deletes the first information. Alternatively, the first device deletes the first information after sending the AKMA service closure notification message to the second device. The first device deletes the first information for example, if it stores two sets of AKMA-related contexts, it deletes the aforementioned first set of AKMA-related contexts; or if it stores one set of AKMA-related contexts, it deletes the first information in the AKMA-related context; or it deletes the correspondence between the first information in the AKMA-related context and the identification information of the second device; or it deletes the correspondence between the first information in the AKMA-related context, the first identifier of the UE, and the identification information of the second device. This application does not limit the specific implementation method of deleting the first information; how the first information is deleted depends on the storage format of the first information.
[0262] The following describes the specific implementation method for the second device to shut down the first AKMA service.
[0263] In scenario one, the first information includes the first AKMA key identifier.
[0264] In response to this situation, the second device can pre-store the correspondence between the first AKMA key identifier and the first AKMA service. The second device can use this correspondence to determine the first AKMA service corresponding to the first AKMA key identifier.
[0265] In response to this situation, the second device can also pre-store the correspondence between the first AKMA key identifier and the application key, as well as the correspondence between the application key and the first AKMA service. The second device can determine the application key corresponding to the first AKMA key identifier based on the correspondence between the first AKMA key identifier and the application key, and then determine the first AKMA service corresponding to the application key based on the correspondence between the application key and the first AKMA service.
[0266] In scenario two, the first information includes the UE's second identifier.
[0267] In this situation, the second device can pre-store the correspondence between the UE's second identifier and the first AKMA service. The second device can use this correspondence to determine the first AKMA service corresponding to the UE's second identifier.
[0268] In response to this situation, the second device may also pre-store the correspondence between the UE's second identifier and the first AKMA key identifier and / or application key, as well as the correspondence between the first AKMA key identifier and / or application key and the first AKMA service. The second device can determine the first AKMA key identifier and / or application key corresponding to the UE's second identifier based on the correspondence between the UE's second identifier and the first AKMA key identifier and / or application key, and then determine the first AKMA service corresponding to the first AKMA key identifier and / or application key based on the correspondence between the first AKMA key identifier and / or application key and the first AKMA service.
[0269] In scenario three, the first piece of information includes a context identifier.
[0270] In response to this situation, the second device can pre-store the correspondence between the context identifier and the first AKMA service. The second device can use this correspondence to determine the first AKMA service corresponding to the context identifier.
[0271] In response to this situation, the second device may also pre-store the correspondence between the context identifier and the first AKMA key identifier and / or application key, as well as the correspondence between the first AKMA key identifier and / or application key and the first AKMA service. The second device can determine the first AKMA key identifier and / or application key corresponding to the context identifier based on the correspondence between the context identifier and the first AKMA key identifier and / or application key, and then determine the first AKMA service corresponding to the first AKMA key identifier and / or application key based on the correspondence between the first AKMA key identifier and / or application key and the first AKMA service.
[0272] As one implementation method, in this application, a timer can also be set to indicate the validity period of the first information. That is, the timer is started first, and when the timer expires, the first information becomes invalid and is then deleted. For example, the timing of starting the timer can be any of the following: when the first information is generated, within a set period after the first information is generated, when the first device receives the second key registration request message, within a set period after the first device receives the second key registration request message, when the first device stores the second AKMA key identifier, or within a set period after the first device stores the second AKMA key identifier.
[0273] If a timer is set, step 805 above can specifically be: when the UE cannot use the AKMA service in the second network and the timer has not expired, the first device sends an AKMA service shutdown notification message to the second device.
[0274] As one implementation method, the AKMA service shutdown notification message sent by the first device to the second device may carry not only the first information but also the second AKMA key identifier. Accordingly, the second device determines the AKMA service to be shut down based on the second AKMA key identifier and / or the first information. For example, the second device first attempts to determine the AKMA service corresponding to the second AKMA key identifier. If no corresponding AKMA service is found, it then determines the AKMA service corresponding to the first information. If a AKMA service corresponding to the first information is found, the AKMA service is shut down. Alternatively, the second device first attempts to determine the AKMA service corresponding to the first information. If a AKMA service corresponding to the first information is found, the AKMA service is shut down; in this case, the second AKMA key identifier is not needed.
[0275] Based on the above scheme, when a UE changes its registration from the first network to the second network, or simultaneously to both networks, and the UE cannot use the AKMA service on the second network, the first device notifies the second device to disable the UE's AKMA service via first information. This first information is associated with the UE's AKMA service, thus helping the second device to correctly disable the AKMA service. Furthermore, this avoids the second device continuing to perform the first AKMA service on the second network when the UE cannot use it, i.e., it prevents the second device from continuing to use the application key corresponding to the first AKMA key identifier to interact with the UE regarding the first AKMA service, thereby avoiding compliance risks. Compared to the first device using the second AKMA key identifier (i.e., the AKMA key identifier generated under the new network) to notify the second device to disable the terminal device's AKMA service, if the second device does not have an AKMA service associated with the second AKMA key identifier, then correctly disabling the AKMA service is not possible. Figure 8 The proposed solution is more reasonable.
[0276] To facilitate understanding of this invention, the following description is provided. Figures 9-12 Specific embodiments of the above Figure 8 The embodiments will be described below. In the following embodiments, A-KID#1 and A-KID#2 are respectively... Figure 8 Specific examples of the first AKMA key identifier and the second AKMA key identifier in the embodiments.
[0277] Figure 9 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 9 In the embodiment, it is Figure 8 The first information in this embodiment is illustrated using the first AKMA key identifier (i.e., A-KID#1) as an example. The method includes the following steps:
[0278] Step 901, Master Authentication Process and Key AKMA Generation process.
[0279] For the specific implementation process of step 901, please refer to [link / reference]. Figure 4 Steps 401 to 405 of the embodiment.
[0280] During this process, the UE registers with the first network, and after passing the primary authentication, completes the registration process on the first network. In this embodiment of the application, the K generated by AUSF is used... AKMA A-KID and K are respectively called K AKMA #1 and A-KID#1.
[0281] In step 901, AAnF obtains the UE's SUPI and K from AUSF.AKMA #1 and A-KID#1, and store SUPI, K AKMA The correspondence between #1 and A-KID#1.
[0282] In step 902, the UE sends an application session establishment request message to the AF. Correspondingly, the AF receives the application session establishment request message.
[0283] The application session establishment request message includes A-KID#1, which is used by AF to find the KAMA key corresponding to A-KID#1.
[0284] The A-KID#1 is located before step 902, in the main authentication process and K AKMA It is generated by the UE in the generation process.
[0285] Step 903: If there is no context associated with A-KID#1 on the AF, the AF selects an AAnF and sends an application key request message to the AAnF. The AAnF then receives the application key request message.
[0286] The application key request message includes A-KID#1 and AF ID. A-KID#1 comes from step 902. AFID is used to identify the AF. The AF ID can be used to calculate K. AF The input parameters at that time are used to achieve key isolation between different AFs.
[0287] Among them, AF can select AAnF based on RID.
[0288] For example, the application key request message can be a Naanf_AKMA_ApplicationKey_Get_Request message or a Naanf_AKMA_ApplicationKey_AnonUser_Getservice message.
[0289] In step 904, when AAnF determines that AF requires GPSI based on local rules, AAnF sends a request message to UDM. Accordingly, UDM receives the request message.
[0290] This request message is used to request the UE's GPSI. For example, the request message may carry the UE's SUPI to request the GPSI corresponding to that SUPI.
[0291] For example, the request message could be a Nudm_SDM_GetRequest message.
[0292] In step 905, UDM sends a response message to AAnF. AAnF then receives the response message.
[0293] The response message includes the UE's GPSI. AAnF stores the GPSI as the UE's AKMA context.
[0294] It should be noted that if AAnF determines that AF does not need GPSI based on local rules, then steps 904 to 905 do not need to be executed.
[0295] For example, the response message could be a Nudm_SDM_GetResponse message.
[0296] In step 906, AAnF sends a subscription request message to UDM. Accordingly, UDM receives the subscription request message.
[0297] The subscription request message contains the UE's SUPI or GPSI, and is used to request the UE's roaming status report or roaming status information.
[0298] For example, the subscription request message can be a Nudm_EventExposure_Subscribe Request message.
[0299] In step 907, UDM sends a subscription response message to AAnF. AAnF then receives the subscription response message.
[0300] The subscription response message contains the UE's roaming status information.
[0301] The roaming status information includes the PLMN information registered by the UE. Optionally, the roaming status information also includes indication information indicating whether the PLMN is the home network. Here, the PLMN information registered by the UE can also be referred to as the information of the first network.
[0302] Subsequently, if the UE's roaming information changes, the UDM sends a notification message to the AAnF, which carries the changed roaming status information.
[0303] For example, the subscription response message can be a Nudm_EventExposure_Subscribe Response message.
[0304] Step 908, AAnF obtains K based on A-KID#1 AKMA #1.
[0305] Optionally, AAnF can also be based on K AKMA #1 and AF ID generation K AF And determine K AF The effective time.
[0306] Among them, AAnF is in the main authentication process and KAKMA During the generation process, A-KID#1 and the K corresponding to A-KID#1 are obtained. AKMA #1, and put A-KID#1 and K AKMA #1 is stored locally.
[0307] In step 909, AAnF sends an application key response message to AF. Correspondingly, AF receives the application key response message.
[0308] Generate K in AAnF AF and K AF In the case of a valid time period, the application key response message includes K. AF and K AF The effective time.
[0309] For example, the application key response message can be a Naanf_AKMA_ApplicationKey_GetResponse message.
[0310] In one implementation, when the application key request message in step 903 is Naanf_AKMA_ApplicationKey_Get_Request, the application key response message may carry SUPI or GPSI. When the application key request message in step 903 is Naanf_AKMA_ApplicationKey_AnonUser_Getservice, the application key response message does not carry SUPI or GPSI.
[0311] Step 910, AAnF stores the UE identifier (UE ID), A-KID#1, K AKMA #1 and the correspondence between the identification information of AF and #1.
[0312] The UE ID can be either SUPI or GPSI.
[0313] The identification information of an AF can be an AF ID or an AF URI.
[0314] As described above, in step 901, AAnF has already stored SUPI and K. AKMA The correspondence between #1 and A-KID#1 can be established, so in step 910, the AF identification information can be added to this correspondence. Optionally, SUPI in this correspondence can be replaced with GPSI.
[0315] In another implementation, AAnF may not be SUPI, K in step 901. AKMAInstead of adding the AF identification information to the mapping relationship between #1 and A-KID#1, a new mapping relationship is established, which is the mapping relationship between A-KID#1 and the AF identification information. Therefore, step 910 can also be replaced by: AAnF storing the mapping relationship #1 between A-KID#1 and the AF identification information. Optionally, this mapping relationship #1 may also include the UE's identifier.
[0316] As one implementation method, the conditions that trigger AAnF to execute step 910 include one or more of the following 1) to 3):
[0317] 1) AAnF subscribed to roaming state change events or roaming state information, i.e., it executed step 906.
[0318] 2) AAnF obtained the URI provided by AF for service shutdown.
[0319] 3) AAnF sent the K corresponding to A-KID#1 to AF. AF .
[0320] It should be noted that in the above correspondence #1, the identifier information of the associated AF can be one or more. For example, AF#1 uses the K corresponding to A-KID#1. AF To protect the AKMA service between the UE and AF#1, AF#2 also uses the K corresponding to A-KID#1. AF This protects the AKMA service between the UE and AF#2.
[0321] In step 911, the AF sends an application session establishment response message to the UE. Correspondingly, the UE receives the application session establishment response message.
[0322] It should be noted that the UE in the main authentication process and K AKMA In any subsequent step of the generation process, K is generated using the same method as AAnF. AF And determine K AF The effective time.
[0323] In step 912, the UE and the core network perform primary authentication again, and the AUSF sends a key registration request message to the AAnF. Correspondingly, the AAnF receives this key registration request message.
[0324] The key registration request message includes SUPI, A-KID#2, and K. AKMA #2. Among them, A-KID#2 and K AKMA #2 is generated by AUSF, and the UE also generates the same A-KID#2 and K. AKMA #2.
[0325] The key registration request message can be a Naanf_AKMA_Key_Register Request message.
[0326] The scenarios in which the UE and the core network perform primary authentication again include any of the following:
[0327] In scenario one, the UE moves from the first network to the second network for access (such as when N2 handover occurs), meaning the UE still maintains single registration.
[0328] Scenario 2: The UE registers to the first network through a first access method (such as 3GPP access) and also registers to the second network through a second access method (such as non-3GPP access), i.e., the UE performs dual registration.
[0329] Step 913, AAnF stores the correspondence #2 between the UE identifier (UE ID) and A-KID#2.
[0330] The UE ID can be either SUPI or GPSI.
[0331] Optionally, this correspondence #2 also includes K. AKMA #2.
[0332] After step 913, two correspondences are stored on AAnF, one of which is correspondence #1 and the other is correspondence #2.
[0333] It should be noted that since no AKMA service corresponding to A-KID#2 has been established between the UE and AF, the identification information of AF does not need to be added to the correspondence #2.
[0334] In step 914, AAnF sends a key registration response message to AUSF. AUSF then receives this key registration response message.
[0335] For example, the key registration response message can be a Naanf_AKMA_AnchorKey_RegisterResponse message.
[0336] In step 915, UDM sends a notification message to AAnF. AAnF then receives this notification message.
[0337] The notification message carries the UE ID and roaming status information. The UE ID can be SUPI or SUCI, etc.
[0338] In a single registration scenario, roaming status information includes information from the second network. In a dual registration scenario, roaming status information includes information from both the first and second networks.
[0339] For example, the notification information could be a Nudm_EventExposure_Notification message.
[0340] Step 916: When the UE cannot use the AKMA service in the second network, AAnF determines A-KID#1.
[0341] For example, if AAnF determines that AF provides a URI for service shutdown and local rules indicate that the UE cannot use AKMA services on the second network, then it determines A-KID#1 corresponding to the UE's identifier.
[0342] Specifically, AAnF can determine the A-KID #1 based on the above correspondence #1.
[0343] Step 917: AAnF sends an AKMA service shutdown notification message to AF. Correspondingly, AF receives the AKMA service shutdown notification message.
[0344] The AKMA service shutdown notification message carries A-KID#1, which is used to identify AKMA keys that can no longer be used (e.g., K). AF The A-KID#1 is associated with the first AKMA business.
[0345] For example, the AKMA service shutdown notification message can be a Naanf_AKMA_ServiceDisableNotification message.
[0346] The AF stops or shuts down the first AKMA service of the UE corresponding to A-KID#1 based on A-KID#1.
[0347] In step 918, AF sends an AKMA service shutdown response message to AAnF. Correspondingly, AAnF receives the AKMA service shutdown response message.
[0348] For example, the AKMA service shutdown response message can be a Naanf_AKMA_ServiceDisableNotification response message.
[0349] Optionally, after step 918, AAnF deletes the above correspondence #1.
[0350] It should be noted that the above Figure 9 Not all steps in the embodiments are mandatory. To achieve the purpose of this invention, only some key steps may be retained. For example, steps 904 to 909, 911, 914, and 918 above can all be optional steps to achieve the purpose of this invention.
[0351] Based on the above scheme, when a UE changes its registration from the first network to the second network, or changes to registering to both the first and second networks simultaneously, and the UE cannot use the AKMA service in the second network, the AAnF will notify the AF to shut down the UE's AKMA service through A-KID#1 instead of using A-KID#2 to notify the AF to shut down the UE's AKMA service, thus ensuring the correct shutdown of the AKMA service.
[0352] Figure 10 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 10 In the embodiment, it is Figure 8 The first piece of information in this embodiment is a context identifier, which will be used as an example for illustration. The method includes the following steps:
[0353] Steps 1001 to 1009 are the same. Figure 9 Steps 901 to 909 in the embodiments.
[0354] Step 1010, AAnF stores the correspondence between the context ID and the AF's identification information #1.
[0355] Optionally, the mapping relationship #1 may also include the UE identifier (UE ID).
[0356] The UE ID can be either SUPI or GPSI.
[0357] The identification information of an AF can be an AF ID or an AF URI.
[0358] The context identifier is used to indicate the context of the connection created by AAnF for AF, which is the connection between AAnF and AF in step 1003 above. This context identifier can also be called a session identifier, connection identifier, session identifier, or connection identifier, etc.
[0359] Accordingly, the AF needs to store the context identifier and A-KID#1 and / or K. AF The correspondence between them.
[0360] Step 1010 can be performed in any step after step 1003 and before step 1011.
[0361] As one implementation method, the conditions that trigger AAnF to execute step 1010 include one or more of the following 1) to 3):
[0362] 1) AAnF subscribed to roaming status change events or roaming status information, i.e., it executed step 1006.
[0363] 2) AAnF obtained the URI provided by AF for service shutdown.
[0364] 3) AAnF sent the K corresponding to A-KID#1 to AF. AF .
[0365] Steps 1011 to 1015 are the same. Figure 9 Steps 911 to 915 in the embodiments.
[0366] Step 1016: When the UE cannot use the AKMA service in the second network, then the AAnF context identifier.
[0367] For example, if AAnF determines that AF provides a URI for service shutdown and local rules indicate that the UE cannot use AKMA services on the second network, then it determines the context identifier.
[0368] Specifically, the UE can determine the context identifier based on the above correspondence #1.
[0369] Step 1017: AAnF sends an AKMA service shutdown notification message to AF. Correspondingly, AF receives the AKMA service shutdown notification message.
[0370] The AKMA service shutdown notification message carries a context identifier, which is associated with the first AKMA service.
[0371] For example, the AKMA service shutdown notification message can be a Naanf_AKMA_ServiceDisableNotification message.
[0372] AF finds the A-KID#1 and / or K corresponding to the context identifier based on the context identifier. AF Then close with A-KID#1 and / or K AF The corresponding UE's first AKMA service.
[0373] In step 1018, AF sends an AKMA service shutdown response message to AAnF. Correspondingly, AAnF receives the AKMA service shutdown response message.
[0374] For example, the AKMA service shutdown response message can be a Naanf_AKMA_ServiceDisableNotification response message.
[0375] Optionally, after step 1018, AAnF deletes the above correspondence #1.
[0376] It should be noted that the above Figure 10Not all steps in the embodiments are mandatory. To achieve the purpose of this invention, only some key steps may be retained. For example, steps 1004 to 1009, 1011, 1014, and 1018 above can all be optional steps to achieve the purpose of this invention.
[0377] Based on the above scheme, when a UE changes its registration from the first network to the second network, or changes to registering to both the first and second networks simultaneously, and the UE cannot use the AKMA service in the second network, AAnF will notify the AF to shut down the UE's AKMA service through the context identifier, instead of using A-KID#2 to notify the AF to shut down the UE's AKMA service, thus ensuring the correct shutdown of the AKMA service.
[0378] Figure 11 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 11 In the embodiment, it is Figure 8 In this embodiment, the first information is the UE's second identifier (i.e., GPSI or SUPI), which will be used as an example for illustration. The method includes the following steps:
[0379] Steps 1101 to 1109 are the same. Figure 9 Steps 901 to 909 in the embodiments.
[0380] Step 1110, AAnF stores the correspondence between the UE's second identifier and the AF's identifier information #1.
[0381] Optionally, the mapping #1 may also include the UE's first identifier.
[0382] In this implementation, the UE's second identifier is the UE identifier carried in step 1109 above. The UE's first identifier refers to the UE identifier stored locally in ANF. Specifically, the UE's first identifier is SUPI, and the UE's second identifier is GPSI. In another implementation, the UE's first identifier is GPSI, and the UE's second identifier is SUPI.
[0383] The identification information of an AF can be an AF ID or an AF URI.
[0384] Optionally, AAnF stores a marker that indicates whether AAnF has sent the UE's first identifier to AF.
[0385] Step 1110 can be performed in any step after step 1103 and before step 1111.
[0386] As one implementation method, the conditions that trigger AAnF to execute step 1110 include one or more of the following 1) to 4):
[0387] 1) AAnF subscribed to roaming status change events or roaming status information, i.e., it executed step 1106.
[0388] 2) AAnF obtained the URI provided by AF for service shutdown.
[0389] 3) AAnF sent the K corresponding to A-KID#1 to AF. AF .
[0390] 4) The UE identifier sent by AAnF in step 1109 is GPSI, and AAnF locally stores SUPI; or, the UE identifier sent by AAnF in step 1109 is SUPI, and AAnF locally stores GPSI.
[0391] It should be noted that in the above correspondence #1, the identifier information of the associated AF can be one or more. For example, AF#1 uses the K corresponding to A-KID#1. AF To protect the AKMA service between the UE and AF#1, AF#2 also uses the K corresponding to A-KID#1. AF This protects the AKMA service between the UE and AF#2.
[0392] Steps 1111 to 1115 are the same. Figure 9 Steps 911 to 915 in the embodiments.
[0393] Step 1116: When the UE cannot use the AKMA service in the second network, AAnF determines the UE's second identifier.
[0394] For example, if AAnF determines that AF provides a URI for service shutdown and local rules indicate that the UE cannot use AKMA services on the second network, then it determines the UE's second identifier.
[0395] Specifically, the UE searches for the second identifier of the UE that corresponds to the first identifier of the UE based on the above correspondence #1.
[0396] Optionally, before determining the second identifier of the UE corresponding to the first identifier of the UE, the AAnF also determines that the identifier stored on the AAnF indicates that the AAnF has sent the second identifier of the UE to the AF. That is, if the AAnF determines that the identifier indicates that the AAnF has sent the second identifier of the UE to the AF, the AF provides a URI for service shutdown, and the local rules show that the UE cannot use AKMA services on the second network, then the second identifier of the UE is determined.
[0397] Step 1117: AAnF sends an AKMA service shutdown notification message to AF. Correspondingly, AF receives the AKMA service shutdown notification message.
[0398] The AKMA service shutdown notification message carries the UE's second identifier, which is associated with the first AKMA service.
[0399] For example, the AKMA service shutdown notification message can be a Naanf_AKMA_ServiceDisableNotification message.
[0400] AF finds the A-KID#1 and / or K corresponding to the UE's second identifier based on the UE's second identifier. AF Then close with A-KID#1 and / or K AF The corresponding UE's first AKMA service. Alternatively, the AF disables the first AKMA service of the UE corresponding to the UE's second identifier.
[0401] In step 1118, AF sends an AKMA service shutdown response message to AAnF. Correspondingly, AAnF receives the AKMA service shutdown response message.
[0402] For example, the AKMA service shutdown response message can be a Naanf_AKMA_ServiceDisableNotification response message.
[0403] Optionally, after step 1118, AAnF deletes the above correspondence #1.
[0404] It should be noted that the above Figure 11 Not all steps in the embodiments are mandatory. To achieve the purpose of this invention, only some key steps may be retained. For example, steps 1104 to 1109, 1111, 1114, and 1118 above can all be optional steps to achieve the purpose of this invention.
[0405] Based on the above scheme, when a UE changes its registration from the first network to the second network, or changes to registering to both the first and second networks simultaneously, and the UE cannot use the AKMA service in the second network, the AAnF notifies the AF to close the UE's AKMA service through the UE's second identifier, instead of using A-KID#2 to notify the AF to close the UE's AKMA service, thus ensuring the correct closure of the AKMA service.
[0406] Figure 12 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 12 In the embodiment, it is Figure 8The first information in this embodiment is illustrated using the first AKMA key identifier (i.e., A-KID#1) as an example. The method includes the following steps:
[0407] Steps 1201 to 1209 are the same. Figure 9 Steps 901 to 909 in the embodiments.
[0408] In step 1210, the AF sends an application session establishment response message to the UE. Correspondingly, the UE receives the application session establishment response message.
[0409] Optionally, the UE in the main authentication process and K AKMA In any step after the generation process, K can also be generated using the same method as AAnF. AF And determine K AF The effective time.
[0410] In step 1211, the UE and the core network perform primary authentication again, and the AUSF sends a key registration request message to the AAnF. Correspondingly, the AAnF receives this key registration request message.
[0411] The key registration request message includes SUPI, A-KID#2, and K. AKMA #2. Among them, A-KID#2 and K AKMA #2 is generated by AUSF, and the UE also generates the same A-KID#2 and K. AKMA #2.
[0412] The key registration request message can be a Naanf_AKMA_Key_Register Request message.
[0413] The scenarios in which the UE and the core network perform primary authentication again include any of the following:
[0414] In scenario one, the UE moves from the first network to the second network for access (such as when N2 handover occurs), meaning the UE still maintains single registration.
[0415] Scenario 2: The UE registers to the first network through a first access method (such as 3GPP access) and also registers to the second network through a second access method (such as non-3GPP access), i.e., the UE performs dual registration.
[0416] Step 1212, AAnF stores the correspondence between the UE identifier (UE ID) and A-KID#2#2.
[0417] Optionally, this correspondence #2 also includes K. AKMA #2.
[0418] The UE ID can be either SUPI or GPSI.
[0419] After step 1212, two correspondences are stored on AAnF, one of which is correspondence #1 and the other is correspondence #2.
[0420] Step 1213, AAnF starts the timer.
[0421] Step 1213 can be executed before, after, or simultaneously with step 1212.
[0422] This timer is used to indicate the validity period of the aforementioned correspondence #1. That is, after the timer expires, the aforementioned correspondence #1 becomes invalid, and AAnF can delete the correspondence #1.
[0423] As one implementation method, the conditions that trigger AAnF to execute step 1213 include one or more of the following 1) to 3):
[0424] 1) AAnF subscribed to roaming state change events or roaming state information, i.e., it executed step 1206.
[0425] 2) AAnF obtained the URI provided by AF for service shutdown.
[0426] 3) AAnF sent the K corresponding to A-KID#1 to AF. AF .
[0427] 4) AAnF received the key registration request message in step 1211.
[0428] 5) AAnF performed step 1212.
[0429] In step 1214, AAnF sends a key registration response message to AUSF. AUSF then receives this key registration response message.
[0430] For example, the key registration response message can be a Naanf_AKMA_AnchorKey_RegisterResponse message.
[0431] Step 1215: UDM sends a notification message to AAnF. AAnF then receives this notification message.
[0432] The notification message carries the UE ID and roaming status information. The UE ID can be SUPI or SUCI, etc.
[0433] In a single registration scenario, roaming status information includes information from the second network. In a dual registration scenario, roaming status information includes information from both the first and second networks.
[0434] For example, the notification information could be a Nudm_EventExposure_Notification message.
[0435] Step 1216: If the UE cannot use the AKMA service in the second network, then determine A-KID#1.
[0436] For example, if AAnF determines that AF provides a URI for service shutdown, local rules show that the UE cannot use AKMA services on the second network, and the timer has not expired, then AAnF determines that A-KID#1.
[0437] Specifically, AAnF can determine the A-KID #1 based on the above correspondence #1.
[0438] Step 1217: AAnF sends an AKMA service shutdown notification message to AF. Correspondingly, AF receives the AKMA service shutdown notification message.
[0439] The AKMA service shutdown notification message carries A-KID#1, which is used to identify AKMA keys that can no longer be used (e.g., K). AF The A-KID#1 is associated with the first AKMA business.
[0440] For example, the AKMA service shutdown notification message can be a Naanf_AKMA_ServiceDisableNotification message.
[0441] The AF stops or shuts down the first AKMA service of the UE corresponding to A-KID#1 based on A-KID#1.
[0442] In step 1218, AF sends an AKMA service shutdown response message to AAnF. Correspondingly, AAnF receives the AKMA service shutdown response message.
[0443] For example, the AKMA service shutdown response message can be a Naanf_AKMA_ServiceDisableNotification response message.
[0444] Optionally, after step 1218, AAnF deletes the above correspondence #1.
[0445] It should be noted that the above Figure 12 Not all steps in the embodiments are mandatory. To achieve the purpose of this invention, only some key steps may be retained. For example, steps 1204 to 1210, 1214, and 1218 above can all be optional steps to achieve the purpose of this invention.
[0446] Based on the above scheme, when a UE changes its registration from the first network to the second network, or changes to registering to both the first and second networks simultaneously, and the UE cannot use the AKMA service in the second network, the AAnF will notify the AF to shut down the UE's AKMA service through A-KID#1 instead of using A-KID#2 to notify the AF to shut down the UE's AKMA service, thus ensuring the correct shutdown of the AKMA service.
[0447] It should be noted that the above Figures 9-12 In various embodiments, the specific implementation methods for AAnF to determine whether the first information (i.e., A-KID#1, context identifier, or the UE's second identifier) should be carried in the AKMA service shutdown notification message, the specific implementation methods for AAnF to determine which AF(s) to send the AKMA service shutdown notification message to, and the specific implementation methods for AAnF to determine that the UE cannot use the AKMA service in the second network can all be found in the following examples. Figure 8 The relevant descriptions in the embodiments will not be repeated here.
[0448] In one implementation method, in the above Figures 9-12 In any embodiment, the AKMA service shutdown notification message sent by AAnF to AF may also additionally carry A-KID#2. In this case, AF can first attempt to shut down the AKMA service corresponding to A-KID#2 based on A-KID#2. If the AKMA service shutdown fails, it can then use A-KID#1, the context identifier, or the UE's second identifier to attempt to shut down the AKMA service corresponding to A-KID#1, the context identifier, or the UE's second identifier. Alternatively, AF can also first attempt to shut down the AKMA service corresponding to A-KID#1, the context identifier, or the UE's second identifier using A-KID#1, the context identifier, or the UE's second identifier. If the AKMA service shutdown fails, it can then attempt to shut down the AKMA service corresponding to A-KID#2 based on A-KID#2.
[0449] This application embodiment does not limit the number of AFs that AAnF notifies to shut down AKMA services. For example, if the UE cannot use AKMA services on the second network, and the UE is currently providing AKMA services with multiple AFs, then AAnF can notify those multiple AFs to shut down the corresponding AKMA services. The following is in conjunction with... Figure 13 Please provide an explanation. Figure 13 This is a flowchart illustrating a communication method provided in an embodiment of this application. The method is illustrated using the example of a UE simultaneously engaging in services with two AFs. The method includes the following steps:
[0450] Step 1301: After the UE performs its first authentication on the first network, both the UE and AF obtain A-KID#1, and the UE communicates with AF#1, whereby AF#1 obtains the K corresponding to A-KID#1. AF #1.
[0451] The K AF #1 is used to protect the AKMA service between the UE and AF#1.
[0452] For the specific implementation process of step 1301, please refer to the aforementioned... Figures 4-5 Description of the embodiments.
[0453] In step 1302, after the UE performs a second authentication on the second network, both the UE and AF obtain A-KID#2, and the UE communicates with AF#2, with AF#2 obtaining the K corresponding to A-KID#2. AF #2.
[0454] The K AF #2 is used to protect the AKMA service between the UE and AF#2.
[0455] For the specific implementation process of step 1302, please refer to the aforementioned... Figures 4-5 Description of the embodiments.
[0456] In step 1303, after the UE performs the third authentication on the third network, both the UE and AAnF obtain A-KID#3, and the UE does not communicate with the AF, that is, A-KID#3 is not used.
[0457] For the specific implementation process of step 1301, please refer to the aforementioned... Figure 4 Description of the embodiments.
[0458] Step 1304: After the UE performs the fourth authentication on the fourth network, both the UE and AAnF obtain A-KID#4. At this time, AAnF discovers that the UE cannot use the AKMA service on the fourth network, so AAnF can notify AF#1 and AF#2 to shut down the corresponding AKMA service.
[0459] For example, AAnF sends A-KID#1 to AF#1, or sends the context identifier #1 between AF#1 and AAnF, or sends the second identifier of the UE, to notify AF#1 to close the corresponding AKMA service, and sends A-KID#2 to AF#2, or sends the context identifier #2 between AF#2 and AAnF, or sends the second identifier of the UE, to notify AF#2 to close the corresponding AKMA service.
[0460] For specific implementation details of step 1304, please refer to [link / reference]. Figure 8The relevant descriptions in the embodiments will not be repeated here.
[0461] It should be noted that after the fourth authentication, AAnF may not save A-KID#3, but it must save A-KID#1 and A-KID#2. For example, the first, second, and third networks mentioned above can be completely identical, partially identical, or completely different, while the fourth network is different from the first, second, and third networks.
[0462] The above example illustrates the scenario of a UE conducting business with two AFs. In practical applications, a UE can also conduct business with three or more AFs simultaneously. In this case, if the AF can simultaneously notify three or more AFs to close the corresponding AKMA service.
[0463] It is understood that, in order to achieve the functions in the above embodiments, the first or second device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, based on the units and method steps of the various examples described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.
[0464] Figure 14 and Figure 15 The diagram illustrates the possible structures of communication devices provided in embodiments of this application. These communication devices can be used to implement the functions of the first or second device in the above method embodiments, and thus also achieve the beneficial effects of the above method embodiments. In the embodiments of this application, the communication device can be either the first or the second device.
[0465] Figure 14 The communication device 1400 shown includes a processing unit 1410 and a transceiver unit 1420. The communication device 1400 is used to implement the functions of the first device or the second device in the above method embodiments.
[0466] When the communication device 1400 is used to implement the function of the first device in the above method embodiment, the transceiver unit 1420 is used to receive a first key registration request message, the first key registration request message including a first identifier of the terminal device and a first AKMA key identifier, the first AKMA key identifier being generated after the terminal device completes primary authentication in the first network; receive an application key request message from a second device, the application key request message including the first AKMA key identifier, the application key request message being used to request an application key corresponding to the first AKMA key identifier, the application key being used to protect the first AKMA service between the terminal device and the second device; the processing unit 1410 is used to store first information, the first information being associated with the first AKMA service; the transceiver unit is also used to receive a second key registration request message, the second key registration request message including the first identifier of the terminal device and a second AKMA key identifier, the second AKMA key identifier being generated after the terminal device completes primary authentication in the second network; the transceiver unit 1420 is also used to send an AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service in the second network, the AKMA service shutdown notification message including the first information.
[0467] In one possible implementation, the first information includes one or more of the following: the first AKMA key identifier; the second identifier of the terminal device; or, a context identifier, which is used to indicate the context of the connection between the first device and the second device.
[0468] In one possible implementation, the transceiver unit 1420 is further configured to send a subscription request to a third device, the subscription request being used to subscribe to the roaming status information of the terminal device; receive first roaming status information of the terminal device from the third device, the first roaming status information including information of the first network; and receive second roaming status information of the terminal device from the third device, the second roaming status information including information of the second network.
[0469] In one possible implementation, the processing unit 1410 is used to store first information, including: storing the correspondence between the first information and the identification information of the second device.
[0470] In one possible implementation, the identification information of the second device includes the identifier of the second device or the Uniform Resource Identifier of the second device.
[0471] In one possible implementation, the transceiver unit 1420 is configured to send an AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network, including: sending the AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network and the second device provides a Uniform Resource Identifier for service shutdown.
[0472] In one possible implementation, the processing unit 1410 is further configured to start a timer, the timer being used to indicate the validity period of the first information.
[0473] In one possible implementation, the transceiver unit 1420 is configured to send an AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network, including: sending the AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network and the timer has not expired.
[0474] In one possible implementation, the processing unit 1410 is further configured to delete the first information after the timer expires.
[0475] In one possible implementation, the processing unit 1410 is configured to store first information, including: storing the first information when a triggering condition is met; wherein the triggering condition includes one or more of the following: roaming status information has been subscribed; a Uniform Resource Identifier for service shutdown provided by the second device has been obtained; or the application key corresponding to the first AKMA key identifier has been sent to the second device.
[0476] In one possible implementation, the processing unit 1410 is further configured not to delete the first information after the transceiver unit 1420 receives the second key registration request message.
[0477] When the communication device 1400 is used to implement the function of the second device in the above method embodiment, the transceiver unit 1420 is used to send an application key request message to the first device. The application key request message includes a first AKMA key identifier. The application key request message is used to request an application key corresponding to the first AKMA key identifier. The first AKMA key identifier is generated after the terminal device completes primary authentication in the first network. The application key is used to protect the first AKMA service between the terminal device and the second device. The transceiver unit 1420 receives an AKMA service shutdown notification message from the first device. The AKMA service shutdown notification message includes first information. The processing unit 1410 is used to shut down the first AKMA service corresponding to the first information. The first information includes a context identifier or a second identifier of the terminal device. The context identifier is used to indicate the context of the connection between the first device and the second device.
[0478] In one possible implementation, the processing unit 1410 is further configured to store the correspondence between the first information and the first AKMA key identifier and / or the application key.
[0479] In one possible implementation, the processing unit 1410 is configured to shut down the first AKMA service corresponding to the first information, including: determining the first AKMA key identifier and / or the application key corresponding to the first information based on the correspondence; and shutting down the first AKMA service corresponding to the first AKMA key identifier and / or the application key.
[0480] In one possible implementation, the AKMA service shutdown notification message further includes a second AKMA key identifier, which is generated after the terminal device completes primary authentication in the second network; the processing unit 1410 is used to shut down the first AKMA service corresponding to the first information, including: shutting down the first AKMA service corresponding to the first information if shutting down the AKMA service according to the second AKMA key identifier fails.
[0481] A more detailed description of the processing unit 1410 and the transceiver unit 1420 can be obtained directly from the relevant descriptions in the above method embodiments, and will not be repeated here.
[0482] Figure 15The communication device 1500 shown includes a processor 1510 and an interface circuit 1520. The processor 1510 and the interface circuit 1520 are coupled to each other. It is understood that the interface circuit 1520 can be a transceiver or an input / output interface. Optionally, the communication device 1500 may also include a memory 1530 for storing instructions executed by the processor 1510, or storing input data required by the processor 1510 to execute instructions, or storing data generated after the processor 1510 executes instructions.
[0483] When the communication device 1500 is used in the above method embodiment, the processor 1510 is used to implement the function of the processing unit 1410, and the interface circuit 1520 is used to implement the function of the transceiver unit 1420.
[0484] It is understood that the processor in the embodiments of this application may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor may be a microprocessor or any conventional processor.
[0485] The method steps in the embodiments of this application can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Furthermore, the ASIC can reside in a first device or a second device. Alternatively, the processor and storage medium can exist as discrete components in a base station or terminal device.
[0486] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are performed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a base station, a user equipment, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video optical disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both types of storage media.
[0487] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0488] In this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. In the textual description of this application, the character " / " generally indicates an "or" relationship between the preceding and following related objects; in the formulas of this application, the character " / " indicates a "division" relationship between the preceding and following related objects.
[0489] It is understood that the various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. The order of the process numbers described above does not imply the order of execution; the execution order of each process should be determined by its function and internal logic.
Claims
1. A communication method, characterized in that, Applied to a first device, the method includes: Receive a first key registration request message, the first key registration request message including a first identifier of the terminal device and an Authentication and Key Management AKMA key identifier of the first application, the first AKMA key identifier being generated after the terminal device completes primary authentication in the first network; Receive an application key request message from a second device, the application key request message including the first AKMA key identifier, the application key request message is used to request the application key corresponding to the first AKMA key identifier, the application key is used to protect the first AKMA service between the terminal device and the second device; Store first information, which is associated with the first AKMA service; Receive a second key registration request message, the second key registration request message including a first identifier and a second AKMA key identifier of the terminal device, the second AKMA key identifier being generated after the terminal device completes master authentication in the second network; When the terminal device cannot use the AKMA service on the second network, it sends an AKMA service shutdown notification message to the second device, and the AKMA service shutdown notification message includes the first information.
2. The method as described in claim 1, characterized in that, The first information includes one or more of the following: The first AKMA key identifier; The second identifier of the terminal device; or... A context identifier, which is used to indicate the context of the connection between the first device and the second device.
3. The method as described in claim 1 or 2, characterized in that, The method further includes: Send a subscription request to a third device, the subscription request being used to subscribe to the roaming status information of the terminal device; The terminal device receives first roaming status information from the third device, the first roaming status information including information from the first network; The terminal device receives second roaming status information from the third device, the second roaming status information including information about the second network.
4. The method according to any one of claims 1 to 3, characterized in that, The stored first information includes: The correspondence between the first information and the identification information of the second device is stored.
5. The method as described in claim 4, characterized in that, The identification information of the second device includes the identifier of the second device or the Uniform Resource Identifier of the second device.
6. The method according to any one of claims 1 to 5, characterized in that, When the terminal device cannot use the AKMA service on the second network, sending an AKMA service shutdown notification message to the second device includes: When the terminal device cannot use the AKMA service on the second network and the second device provides a Uniform Resource Identifier for service shutdown, the terminal device sends the AKMA service shutdown notification message to the second device.
7. The method according to any one of claims 1 to 5, characterized in that, The method further includes: Start a timer, which is used to indicate the validity period of the first information.
8. The method as described in claim 7, characterized in that, When the terminal device cannot use the AKMA service on the second network, sending an AKMA service shutdown notification message to the second device includes: When the terminal device cannot use the AKMA service on the second network and the timer has not expired, it sends an AKMA service shutdown notification message to the second device.
9. The method as described in claim 7 or 8, characterized in that, The method further includes: The first information is deleted after the timer expires.
10. The method according to any one of claims 1 to 9, characterized in that, The stored first information includes: If the triggering conditions are met, the first information is stored; wherein the triggering conditions include one or more of the following: I have already subscribed to roaming status information; The Uniform Resource Identifier provided by the second device for service shutdown has been obtained; or, The application key corresponding to the first AKMA key identifier has been sent to the second device.
11. The method according to any one of claims 1 to 10, characterized in that, After receiving the second key registration request message, it also includes: Do not delete the first piece of information.
12. A communication device, characterized in that, It includes a processor and an interface circuit, the processor being used to communicate with other devices through the interface circuit and to implement the method of any one of claims 1 to 11.
13. A communication system, characterized in that, include: A first device is configured to receive a first key registration request message, the first key registration request message including a first identifier of a terminal device and an Authentication and Key Management (AKMA) key identifier of a first application, the first AKMA key identifier being generated after the terminal device completes primary authentication in a first network; Receive an application key request message from a second device, the application key request message including the first AKMA key identifier, the application key request message is used to request the application key corresponding to the first AKMA key identifier, the application key is used to protect the first AKMA service between the terminal device and the second device; Store first information, which is associated with the first AKMA service; receive a second key registration request message, which includes a first identifier and a second AKMA key identifier of the terminal device, wherein the second AKMA key identifier is generated after the terminal device completes master authentication in the second network; When the terminal device cannot use the AKMA service on the second network, it sends an AKMA service shutdown notification message to the second device, and the AKMA service shutdown notification message includes the first information; The second device is used to send the application key request message to the first device; And receive the AKMA service shutdown notification message from the first device.
14. The system as described in claim 13, characterized in that, The first information includes one or more of the following: The first AKMA key identifier; The second identifier of the terminal device; or... A context identifier, which is used to indicate the context of the connection between the first device and the second device.
15. The system as described in claim 13 or 14, characterized in that, The first device is further configured to send a subscription request to the third device, the subscription request being used to subscribe to the roaming status information of the terminal device; receive first roaming status information of the terminal device from the third device, the first roaming status information including information of the first network; and receive second roaming status information of the terminal device from the third device, the second roaming status information including information of the second network.
16. The system as claimed in any one of claims 13 to 15, characterized in that, The first device is used to store first information, including: storing the correspondence between the first information and the identification information of the second device.
17. The system as claimed in claim 16, characterized in that, The identification information of the second device includes the identifier of the second device or the Uniform Resource Identifier of the second device.
18. The system as claimed in any one of claims 13 to 17, characterized in that, The first device is configured to send an AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network, including: sending the AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network and the second device provides a Uniform Resource Identifier for service shutdown.
19. The system as claimed in any one of claims 13 to 17, characterized in that, The first device is also used to activate a timer, which is used to indicate the validity period of the first information.
20. The system as described in claim 19, characterized in that, The first device is configured to send an AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network, including: sending the AKMA service shutdown notification message to the second device when the terminal device cannot use the AKMA service on the second network and the timer has not expired.
21. The system as described in claim 19 or 20, characterized in that, The first device is further configured to delete the first information after the timer expires.
22. The system as claimed in any one of claims 13 to 21, characterized in that, The first device is configured to store first information, including: storing the first information when a triggering condition is met; wherein the triggering condition includes one or more of the following: having subscribed to roaming status information; having obtained a Uniform Resource Identifier (URI) for service shutdown provided by the second device; or having sent the application key corresponding to the first AKMA key identifier to the second device.
23. The system as claimed in any one of claims 13 to 22, characterized in that, The first device is further configured to not delete the first information after receiving the second key registration request message.
24. The system as claimed in any one of claims 13 to 23, characterized in that, The second device is also used to shut down the first AKMA service corresponding to the first information.
25. The system as described in claim 24, characterized in that, The second device is further configured to store the correspondence between the first information and the first AKMA key identifier and / or the application key.
26. The system as described in claim 25, characterized in that, The second device is configured to disable the first AKMA service corresponding to the first information, comprising: determining, based on the correspondence, the first AKMA key identifier and / or the application key corresponding to the first information; and disabling the first AKMA service corresponding to the first AKMA key identifier and / or the application key.
27. The system as described in claim 24 or 25, characterized in that, The AKMA service shutdown notification message also includes a second AKMA key identifier, which is generated after the terminal device completes primary authentication in the second network; The second device is used to shut down the first AKMA service corresponding to the first information, including: shutting down the first AKMA service corresponding to the first information if shutting down the AKMA service according to the second AKMA key identifier fails.
28. The system as claimed in any one of claims 13 to 27, characterized in that, The system further includes a third device, which is configured to receive a subscription request from the first device, the subscription request being used to subscribe to roaming status information of the terminal device; send first roaming status information of the terminal device to the first device, the first roaming status information including information of the first network; and send second roaming status information of the terminal device to the first device, the second roaming status information including information of the second network.
29. A computer program product, characterized in that, The computer program product includes instructions that, when executed on a processor, implement the method of any one of claims 1 to 11.
30. A computer-readable storage medium, characterized in that, The storage medium stores a computer program or instructions, which, when executed, implement the method described in any one of claims 1 to 11.
Citation Information
Patent Citations
Authentication and / or key management method, first device, terminal and communication device
CN116419220A
Communication method, communication device and communication system
CN117336714A
Method and apparatus for user equipment identifier request
CN117528505A
Network information processing method and device
CN117676558A
Communication method, apparatus, and system
US20220174063A1