Method and device for determining security key

CN121264080APending Publication Date: 2026-01-02HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380099111.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-06-14
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

In the existing network architecture, control plane messages between the terminal and other network functions in the core network, excluding access and mobility management functions, need to be forwarded through access and mobility management functions. This results in the security protection between the terminal and these network functions relying on the security protection between the terminal and access and mobility management functions, which cannot meet future communication needs.

Method used

The terminal communicates directly with the first network function in the network, and establishes a secure connection by determining a security key to ensure secure communication between the terminal and each network function.

Benefits of technology

It achieves security protection between the terminal and various network functions, meets future communication needs, reduces the processing and communication overhead of network functions, and improves the security and uniqueness of keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121264080A_ABST
    Figure CN121264080A_ABST
Patent Text Reader

Abstract

The invention provides a method and a device for determining a security key, belongs to the technical field of communication, and is used for solving the problem that the future communication requirement cannot be met by only guaranteeing the communication security between a terminal and an AMF (Advanced Media Function). In the method, a terminal can directly communicate with a first network function in a network, and after receiving a first request initiated by the terminal, the first network function can establish secure connection with the terminal by determining a security key, i.e., a message between the first network function and the terminal can be protected through the security key. Therefore, when direct communication is carried out between the terminal and each network function, security protection can be realized between the terminal and each network function, so that communication security can be ensured, and future communication requirements can be met.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for determining a security key Technical Field

[0001] The present application relates to the field of communications, and in particular to a method and device for determining a security key. Background Art

[0002] In the existing network architecture, all control plane messages between a terminal and network functions (NFs) in the core network (CN), except the access and mobility management function (AMF), are forwarded by the AMF. This means that security protection between the terminal and these other NFs is handled by the AMF. In other words, security protection between the terminal and each NF in the CN relies solely on security protection between the terminal and the AMF. For example, non-access stratum (NAS) messages between the terminal and the AMF can be encrypted and protected by a key.

[0003] However, only ensuring the security of communication between the terminal and AMF may not meet future communication needs.

[0004] Summary of the Invention

[0005] The embodiments of the present application provide a method and device for determining a security key to solve the above technical problems.

[0006] To achieve the above objectives, this application adopts the following technical solutions:

[0007] In a first aspect, a method for determining a security key is provided, performed by a first network function. The method comprises: the first network function receiving a first request; obtaining a first key of the first network function based on the first request; and determining a security key based on the first key. The first request is used by a terminal to request service establishment with the first network function, or the first request is used by a terminal to request network access. The first network function is a network function other than a second network function in the network. The second network function is used for terminal access management. The security key is used to establish a secure connection between the terminal and the first network function.

[0008] Based on the method of the first aspect, it can be seen that in future communication needs, the communication between the terminal and each network function (including not only the AMF, but also other network functions) also needs to be guaranteed. On this basis, the terminal can communicate directly with the first network function in the network. In this case, after receiving the first request initiated by the terminal, the first network function can establish a secure connection with the terminal by determining the security key. That is, the messages between the first network function and the terminal can be protected by the security key. In this way, when the terminal communicates directly with each network function, security protection can be achieved between the terminal and each network function, thereby ensuring communication security and meeting future communication needs.

[0009] In one possible design, a first network function obtains its first key based on a first request, including: the first network function sends a second request to a third network function based on the first request; and receives a first response from the third network function; the third network function determines the first network function's key; the second request requests the third network function to derive the first network function's key; the first response carries the first key, and the first response is a response message to the second request. In this way, the first network function can obtain the first key from the third network function, eliminating the need for the first network function to derive the first key itself, thereby reducing processing overhead for the first network function.

[0010] In one possible design, a first network function obtains a first key of the first network function based on a first request, including: obtaining a second key based on the first request; and determining the first key based on the second key; the second key being the key of a third network function, and the key of the third network function being used to determine the key of the first network function. In this way, the first network function can derive the first key independently without requesting the first key from other network functions, thereby reducing the communication overhead of the first network function, reducing the transmission of the first key within the network, and improving the security of the first key.

[0011] Optionally, the third network function is any one of the following: access and mobility management function (AMF), access management function (AM), and security anchor function (SEAF). In this way, key derivation can be performed using existing network functions, such as SEAF; alternatively, the first key can be derived from an access management function (such as AMF or AM), thereby simplifying the processing flow and unifying access management and key derivation to reduce system complexity.

[0012] Optionally, the first network function determines the first key based on the second key, including: the first network function determines the first key based on the second key and first information, where the first information is at least one of the following: terminal information, first request information, first network function information, network identifier, and network security parameters. In this way, the first information can enhance the security of the first key, further ensuring communication security between the terminal and the first network function. Furthermore, the addition of the first information can ensure the uniqueness of the derived first key.

[0013] Furthermore, the second key is included in the first request, or the second key is pre-configured locally on the first network function. That is, when the third network function and the second network function are the same network function, the second network function can send the first request carrying the second key to the first network function, allowing the first network function to obtain the second key from the first request simultaneously with receipt of the first request. This means that the first network function does not need to request the second key from other network functions, thereby reducing the communication overhead of the first network function. Furthermore, pre-configuring the second key locally on the first network function facilitates the first network function's acquisition of the second key, meaning that the first network function does not need to request the second key from other network functions, thereby reducing the communication overhead of the first network function.

[0014] In one possible design, the first network function determines a security key based on the first key, including: the first network function determines the security key based on the first key and second information; the second information is at least one of the following: terminal information, first request information, first network function information, network identifier, and network security parameters. This second information improves the security of the security key and further ensures communication security between the terminal and the first network function. Furthermore, the addition of the second information ensures the uniqueness of the derived security key.

[0015] In one possible design, the first network function determines the security key based on the first key, including: determining the first network function's third key based on the first key and information from the first request; and determining the security key based on the third key. Specifically, the first network function can determine the third key corresponding to the current service status of the terminal based on information from the first request. In other words, for each service between the first network function and the terminal, the first network function can derive a security key corresponding to that service, thereby ensuring communication security for each service between the first network function and the terminal, and further ensuring communication security between the terminal and the first network function.

[0016] Optionally, the first network function determines the security key based on the third key, including: the first network function determines the security key based on the third key and second information, where the second information is at least one of the following: terminal information, information about the first request, information about the first network function, a network identifier, and network security parameters. In this way, the second information can enhance the security of the security key and further ensure communication security between the terminal and the first network function. Furthermore, the addition of the second information can ensure the uniqueness of the derived security key.

[0017] In one possible design, the method described in the first aspect further includes: the first network function sending a first message to the terminal, where the first message includes information indicating a key of the first network function. In this way, the terminal can be instructed to begin deriving a key, so that the terminal begins obtaining a security key for establishing a secure connection with the first network function, thereby ensuring that the secure connection between the terminal and the first network function is successfully established.

[0018] Optionally, the first message further includes information indicating an encryption algorithm, where the encryption algorithm is an encryption algorithm used by the terminal. In this way, after obtaining the key of the first network function, the terminal can determine, based on the encryption algorithm, a security key corresponding to the security key of the first network function, thereby ensuring a successful secure connection between the terminal and the first network function.

[0019] Optionally, the method of the first aspect further includes: the first network function receiving a second message from the terminal, the second message being used to indicate whether the terminal has determined the security key. In this way, after receiving the second message, the first network function can determine a subsequent operation based on the content indicated in the second message.

[0020] In one possible design, the second network function is an AMF or AM. That is, the existing AMF can be upgraded and used to manage terminal access. Alternatively, the AM can be set up for access management to manage multiple entities in a distributed network.

[0021] Optionally, when the second network function is an AMF, the first network function is at least one of the following: a session management function (SMF), a policy control function (PCF), a location management function (LMF), a network data analysis function (NWDAF), and a short message service function (SMSF). In other words, the existing SMF, PCF, LMF, NWDAF, and SMSF can be upgraded so that the upgraded network functions can communicate directly with the terminal, avoiding forwarding messages between the network functions and the terminal through the AMF, thereby improving the communication rate.

[0022] Optionally, when the second network function is AM, the first network function is at least one of the following: mobility management (MM), proxy, or load balancing (LB). That is, in a distributed network, the MM, proxy, or LB can be configured to forward messages between the terminal and each network function in the network corresponding to the first network function.

[0023] According to a second aspect, a method for determining a security key is provided, which is performed by a second network function. The method includes: the second network function receiving a first request; obtaining a first key of the first network function based on the first request; and sending the first key to the first network function. The second network function is used for terminal access management, the first request is used by the terminal to request service establishment with the first network function, or the first request is used by the terminal to request network access, the first network function is a network function other than the second network function in the network, and the first key is used to determine the security key used by the terminal to establish a secure connection with the first network function.

[0024] In one possible design, a second network function obtains the first key of a first network function based on a first request, including: the second network function sends a second request to a third network function based on the first request; and receives a first response from the third network function; the third network function determines the key of the first network function; the second request is used to request the third network function to derive the key of the first network function; the first response carries the first key, and the first response is a response message to the second request. In this way, the second network function can obtain the first key from the third network function, eliminating the need for the second network function to derive the first key itself, thereby reducing processing overhead for the second network function.

[0025] In one possible design, the second network function obtains the first key of the first network function based on the first request, including: the second network function determines the first key based on the second network function's key. That is, the second network function can derive the first key independently without requesting the first key from other network functions. This reduces communication overhead for the second network function, reduces the transmission of the first key across the network, and improves the security of the first key.

[0026] Optionally, the second network function determines the first key based on the second network function's key, including: the second network function determines the first key based on the second network function's key and first information, where the first information is at least one of the following: terminal information, first request information, first network function information, network identifier, and network security parameters. In this way, the first information can enhance the security of the first key, further ensuring communication security between the terminal and the first network function. Furthermore, the addition of the first information can ensure the uniqueness of the derived first key.

[0027] In one possible design, the first request is a service request, and the second network function receives the first request, including: the second network function receives the service request from the terminal, where the service request is for the terminal to request to establish a service with the first network function. Accordingly, the second network function sends the first key to the first network function, including: the second network function sends the service request carrying the first key to the first network function.

[0028] In one possible design, the first request is an access request, and the second network function receives the first request, including: the second network function receives the access request from the terminal, where the access request is for the terminal to request network access. In response, the second network function sends the first key to the first network function, including: the second network function sends the access request carrying the first key to the first network function.

[0029] In one possible design scheme, the second network function is the access and mobility management function AMF or access management AM.

[0030] Optionally, when the second network function is AMF, the first network function is at least one of the following: session management function SMF, policy control function PCF, positioning management function LMF, network data analysis function NWDAF, and short message service function SMSF.

[0031] Optionally, when the second network function is AM, the first network function is at least one of the following: mobility management MM, proxy, and load balancing LB.

[0032] In addition, the technical effects of the method described in the second aspect can refer to the technical effects of the method described in the first aspect, and will not be repeated here.

[0033] According to a third aspect, a method for determining a security key is provided, performed by a third network function. The method includes: the third network function receiving a second request; obtaining a first key of a first network function based on the second request; and sending a first response. The second request is used to request the third network function to derive a key for the first network function; the key of the first network function is used to determine a security key used by a terminal to establish a secure connection with the first network function; the first network function is a network function other than the second network function in the network; the second network function is used for terminal access management; the first response carries the first key, and the first response is a response message to the second request.

[0034] In one possible design, the third network function receiving the second request includes: the third network function receiving the second request from the second network function. Accordingly, the third network function sending the first response includes: the third network function sending the first response to the second network function.

[0035] In one possible design, the third network function receiving the second request includes: the third network function receiving the second request from the first network function. Accordingly, the third network function sending the first response includes: the third network function sending the first response to the first network function.

[0036] In one possible design scheme, the third network function obtains the first key of the first network function based on the second request, including: the third network function determines the first key based on the second key; the second key is the key of the third network function, and the key of the third network function is used to determine the key of the first network function.

[0037] Optionally, the third network function determines the first key based on the second key, including: the third network function determines the first key based on the second key and first information, where the first information is at least one of the following: terminal information, first request information, first network function information, network identifier, and network security parameters. In this way, the first information can enhance the security of the first key, further ensuring communication security between the terminal and the first network function. Furthermore, the addition of the first information can ensure the uniqueness of the derived first key.

[0038] In one possible design scheme, the second network function is the access and mobility management function AMF or access management AM.

[0039] Optionally, when the second network function is AMF, the first network function is at least one of the following: session management function SMF, policy control function PCF, positioning management function LMF, network data analysis function NWDAF, and short message service function SMSF.

[0040] Optionally, when the second network function is AM, the first network function is at least one of the following: mobility management MM, proxy, and load balancing LB.

[0041] In addition, the technical effects of the method described in the third aspect can refer to the technical effects of the method described in the first aspect, and will not be repeated here.

[0042] In a fourth aspect, a method for determining a security key is provided, performed by a terminal, the method comprising: the terminal receiving a first message from a first network function, and sending a second message to the first network function. The first message includes information indicating a key of the first network function, the first network function being a network function other than the second network function in a network, the second network function being used for access management of the terminal, and the second message indicating whether the terminal has determined a security key for establishing a secure connection between the terminal and the first network function.

[0043] In one possible design, the first message further includes information indicating an encryption algorithm, where the encryption algorithm is an encryption algorithm used by the terminal. The method according to the fourth aspect further includes: the terminal determining a security key based on the key information of the first network function and the information indicating the encryption algorithm. In this way, the terminal can accurately determine the security key corresponding to the security key of the first network function, thereby ensuring a successful secure connection between the terminal and the first network function.

[0044] In one possible design, before the terminal receives the first message from the first network function, the method according to the fourth aspect further includes: the terminal sending a first request to the second network function; the first request is used by the terminal to request service establishment with the first network function, or the first request is used by the terminal to request network access. That is, when there is a service demand or a network access demand, the terminal can establish a secure connection with the first network function corresponding to the first request by sending the first request.

[0045] In one possible design scheme, the second network function is the access and mobility management function AMF or access management AM.

[0046] Optionally, when the second network function is AMF, the first network function is at least one of the following: session management function SMF, policy control function PCF, positioning management function LMF, network data analysis function NWDAF, and short message service function SMSF.

[0047] Optionally, when the second network function is AM, the first network function is at least one of the following: mobility management MM, proxy, and load balancing LB.

[0048] In addition, the technical effects of the method described in the fourth aspect can refer to the technical effects of the method described in the first aspect, and will not be repeated here.

[0049] In a fifth aspect, a communication device is provided. The communication device includes: a module for executing the method of the first aspect, such as a processing module and a transceiver module. For example, the transceiver module is configured to receive a first request; the processing module is configured to obtain a first key of a first network function based on the first request; and the processing module is further configured to determine a security key based on the first key. The first request is used by a terminal to request to establish a service with the first network function, or the first request is used by a terminal to request to access a network, the first network function is a network function other than a second network function in the network, the second network function is used for terminal access management, and the security key is used to establish a secure connection between the terminal and the first network function.

[0050] Optionally, the transceiver module may include a sending module and a receiving module, wherein the sending module is used to implement the sending function of the communication device described in the fifth aspect, and the receiving module is used to implement the receiving function of the communication device described in the fifth aspect.

[0051] Optionally, the communication device described in the fifth aspect may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device may execute the method described in the first aspect.

[0052] It can be understood that the communication device described in the fifth aspect can be a terminal, such as a remote device, or a chip (system) or other parts or components that can be set in the terminal, or a device including a terminal. This application does not limit this.

[0053] In addition, the technical effects of the communication device described in the fifth aspect can refer to the technical effects of the method described in the first aspect, and will not be repeated here.

[0054] In a sixth aspect, a communication device is provided. The communication device includes: a module for executing the method of the second aspect, such as a processing module and a transceiver module. For example, the transceiver module is configured to receive a first request; the processing module is configured to obtain a first key of a first network function based on the first request; and the transceiver module is further configured to send the first key to the first network function. The second network function is used for terminal access management, the first request is used by the terminal to request to establish a service with the first network function, or the first request is used by the terminal to request to access the network, the first network function is a network function other than the second network function in the network, and the first key is used to determine the security key used by the terminal to establish a secure connection with the first network function.

[0055] Optionally, the transceiver module may include a sending module and a receiving module, wherein the sending module is used to implement the sending function of the communication device described in the sixth aspect, and the receiving module is used to implement the receiving function of the communication device described in the sixth aspect.

[0056] Optionally, the communication device described in the sixth aspect may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device may execute the method described in the second aspect.

[0057] It can be understood that the communication device described in the sixth aspect can be a terminal, such as a remote device, or a chip (system) or other parts or components that can be set in the terminal, or a device including a terminal. This application does not limit this.

[0058] In addition, the technical effects of the communication device described in the sixth aspect can refer to the technical effects of the method described in the second aspect, and will not be repeated here.

[0059] In a seventh aspect, a communication device is provided. The communication device includes: a module for executing the method of the third aspect, such as a processing module and a transceiver module. For example, the transceiver module is used to receive a second request; the processing module is used to obtain a first key of a first network function based on the second request; and the transceiver module is further used to send a first response. The second request is used to request a third network function to generate a key for the first network function, the key of the first network function is used to determine a security key used by a terminal to establish a secure connection with the first network function, the first network function is a network function other than the second network function in the network, the second network function is used for access management of the terminal, the first response carries the first key, and the first response is a response message to the second request.

[0060] Optionally, the transceiver module may include a sending module and a receiving module, wherein the sending module is used to implement the sending function of the communication device described in the seventh aspect, and the receiving module is used to implement the receiving function of the communication device described in the seventh aspect.

[0061] Optionally, the communication device described in the seventh aspect may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device may execute the method described in the third aspect.

[0062] It can be understood that the communication device described in the seventh aspect can be a terminal, such as a remote device, or a chip (system) or other parts or components that can be set in the terminal, or a device including a terminal. This application does not limit this.

[0063] In addition, the technical effects of the communication device described in the seventh aspect can refer to the technical effects of the method described in the third aspect, and will not be repeated here.

[0064] In an eighth aspect, a communication device is provided. The communication device includes: a module for executing the method of the fourth aspect, such as a processing module and a transceiver module. For example, the transceiver module is configured to receive a first message from a first network function; the processing module is configured to generate a second message; and the transceiver module is further configured to send the second message to the first network function. The first message includes information indicating a key of the first network function, where the first network function is a network function other than the second network function in the network, and the second network function is configured to manage terminal access. The second message indicates whether the terminal has determined a security key for establishing a secure connection between the terminal and the first network function.

[0065] Optionally, the transceiver module may include a sending module and a receiving module, wherein the sending module is used to implement the sending function of the communication device described in the eighth aspect, and the receiving module is used to implement the receiving function of the communication device described in the eighth aspect.

[0066] Optionally, the communication device described in the eighth aspect may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device may execute the method described in the fourth aspect.

[0067] It can be understood that the communication device described in the eighth aspect can be a terminal, such as a remote device, or a chip (system) or other parts or components that can be set in the terminal, or a device including a terminal. This application does not limit this.

[0068] In addition, the technical effects of the communication device described in the eighth aspect can refer to the technical effects of the method described in the fourth aspect, and will not be repeated here.

[0069] In a ninth aspect, a communication device is provided. The device includes: a processor and a communication interface, wherein the processor is configured to execute computer instructions and the communication interface is configured to communicate, so that the method described in any possible implementation of the first, second, third, or fourth aspects is implemented.

[0070] In a tenth aspect, a communication device is provided, comprising: a processor configured to execute the method described in any possible implementation of the first aspect, the second aspect, the third aspect, or the fourth aspect.

[0071] In one possible design solution, the communication device described in the tenth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the tenth aspect to communicate with other communication devices.

[0072] In one possible design, the communication device described in aspect 10 may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store the computer program and / or data involved in the method described in any one of aspects 1, 2, 3, or 4.

[0073] In an embodiment of the present application, the communication device described in the tenth aspect may be the terminal described in any one of the first aspect, the second aspect, the third aspect or the fourth aspect, or a chip (system) or other parts or components that can be set in the terminal, or a device that includes the terminal.

[0074] In addition, the technical effects of the communication device described in the tenth aspect can refer to the technical effects of the method described in any one of the implementation methods of the first aspect, the second aspect, the third aspect or the fourth aspect, and will not be repeated here.

[0075] In an eleventh aspect, a communication device is provided. The communication device includes: a processor coupled to a memory, the processor being configured to execute a computer program stored in the memory, so that the communication device performs the method described in any possible implementation of the first, second, third, or fourth aspects.

[0076] In one possible design solution, the communication device described in the eleventh aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the eleventh aspect to communicate with other communication devices.

[0077] In an embodiment of the present application, the communication device described in the eleventh aspect may be the terminal described in any one of the first aspect, the second aspect, the third aspect or the fourth aspect, or a chip (system) or other parts or components that can be set in the terminal, or a device that includes the terminal.

[0078] In addition, the technical effects of the communication device described in the eleventh aspect can refer to the technical effects of the method described in any one of the implementation methods of the first aspect, the second aspect, the third aspect or the fourth aspect, and will not be repeated here.

[0079] In the twelfth aspect, a communication device is provided, comprising: a processor and a memory; the memory is used to store a computer program, and when the processor executes the computer program, the communication device executes the method described in any one of the implementation methods of the first aspect, the second aspect, the third aspect or the fourth aspect.

[0080] In one possible design solution, the communication device described in aspect 12 may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in aspect 12 to communicate with other communication devices.

[0081] In an embodiment of the present application, the communication device described in aspect 12 may be the terminal described in any one of aspect 1, aspect 2, aspect 3 or aspect 4, or a chip (system) or other parts or components that may be set in the terminal, or a device that includes the terminal.

[0082] In addition, the technical effects of the communication device described in the twelfth aspect can refer to the technical effects of the method described in any one of the implementation methods of the first aspect, the second aspect, the third aspect or the fourth aspect, and will not be repeated here.

[0083] In a thirteenth aspect, a communication system is provided. The communication system includes at least one of the following: a terminal configured to execute the first network function of the method described in the first aspect, a terminal configured to execute the second network function of the method described in the second aspect, a terminal configured to execute the third network function of the method described in the third aspect, and a terminal configured to execute the method described in the fourth aspect.

[0084] In a fourteenth aspect, a communication chip is provided, in which instructions are stored. When the chip runs on a communication device, the method described in any one of the implementation methods of the first aspect, the second aspect, the third aspect or the fourth aspect is implemented.

[0085] In the fifteenth aspect, a computer-readable storage medium is provided, comprising: a computer program or instructions; when the computer program or instructions are run on a computer, the computer executes the method described in any possible implementation method of the first aspect, the second aspect, the third aspect or the fourth aspect.

[0086] In the sixteenth aspect, a computer program product is provided, comprising a computer program or instructions, which, when the computer program or instructions are run on a computer, enables the computer to execute the method described in any possible implementation of the first aspect, the second aspect, the third aspect or the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0087] FIG1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present application;

[0088] FIG2 is a schematic diagram of a key derivation process according to an embodiment of the present application;

[0089] FIG3 is a second schematic diagram of a key derivation process provided in an embodiment of the present application;

[0090] FIG4 is a second schematic diagram of the architecture of the communication system provided in an embodiment of the present application;

[0091] FIG5 is a third schematic diagram of the architecture of the communication system provided in an embodiment of the present application;

[0092] FIG6 is a flowchart of a method for determining a security key according to an embodiment of the present application;

[0093] FIG7 is a second flow chart of a method for determining a security key provided in an embodiment of the present application;

[0094] FIG8 is a third flow chart of a method for determining a security key according to an embodiment of the present application;

[0095] FIG9 is a fourth flow chart of a method for determining a security key according to an embodiment of the present application;

[0096] FIG10 is a fifth flow chart of a method for determining a security key according to an embodiment of the present application;

[0097] FIG11 is a sixth flow chart of a method for determining a security key according to an embodiment of the present application;

[0098] FIG12 is a seventh flow chart of a method for determining a security key according to an embodiment of the present application;

[0099] FIG13 is a flowchart of a method for determining a security key according to an embodiment of the present application;

[0100] FIG14 is a first structural diagram of a communication device provided in an embodiment of the present application;

[0101] FIG15 is a second structural diagram of the communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0102] For ease of understanding, the technical terms involved in the embodiments of this application are first introduced below.

[0103] 1. Fifth generation (5G) mobile communication system

[0104] As shown in Figure 1, the 5G system includes: terminals, access networks (AN) and CNs.

[0105] The above-mentioned terminal may be one or more, such as a first terminal, a second terminal, a third terminal, etc. A terminal may be a terminal with transceiver functions, or may be a chip or chip system provided in the terminal. The terminal may also be referred to as user equipment (UE), access terminal, subscriber unit (subscriber unit), user station, mobile station (MS), mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device. The terminal in the embodiments of the present application can be a mobile phone, a cellular phone, a smart phone, a tablet computer, a wireless data card, a personal digital assistant (PDA), a wireless modem, a handheld device (handset), a laptop computer, a machine type communication (MTC) terminal, a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a smart home device (for example, a refrigerator, a television, an air conditioner, an electric meter, etc.), an intelligent robot, a robotic arm, a workshop equipment, a wireless terminal in unmanned driving, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, a vehicle-mounted terminal, a roadside unit with terminal function ... The terminal device of the present application may also be an onboard module, onboard module, onboard component, onboard chip or onboard unit built into a vehicle as one or more components or units. The terminal device may also be other devices with terminal functions, for example, the terminal device may also be a device that functions as a terminal in D2D communication.

[0106] The AN implements access-related functions, providing network access for authorized users in a specific area and determining transmission links of varying quality for user data based on user level and service requirements. The AN forwards control signals and user data between terminals and the CN. The AN may include access network equipment, also known as radio access network (RAN) equipment.

[0107] RAN equipment can be devices that provide access to terminals and is primarily responsible for air interface functions such as radio resource management, quality of service (QoS) management, data compression, and encryption. RAN equipment can include gNBs in 5G (such as new radio (NR) systems), or one or a group of antenna panels (including multiple antenna panels) in a 5G base station. Alternatively, RAN equipment can include network nodes that constitute a gNB, a transmission and reception point (TRP or TP), or a transmission measurement function (TMF), such as a baseband unit (BBU), a central unit (CU) or distributed unit (DU), an RSU with base station functionality, a wired access gateway, or a 5G core network element. RAN equipment can also include access points (APs) in wireless fidelity (WiFi) systems, wireless relay nodes, wireless backhaul nodes, various types of macro base stations, micro base stations (also known as small cells), relay stations, access points, wearable devices, and in-vehicle devices. Alternatively, the RAN device may also include a next-generation mobile communication system, such as a 6G access network device, such as a 6G base station, or in the next-generation mobile communication system, the network device may also have other naming methods, which are all covered within the protection scope of the embodiments of this application, and this application does not impose any limitations on this.

[0108] CN is mainly responsible for maintaining the subscription data of the mobile network and providing functions such as session management, mobility management, policy management and security authentication for terminals. CN mainly includes the following network functions: user plane function (UPF), authentication server function (AUSF), access and mobility management function (AMF), session management function (SMF), network slice selection function (NSSF), network exposure function (NEF), network function repository function (NRF), policy control function (PCF), unified data management (UDM), application function (AF), as well as network slice-specific and SNPN authentication and authorization function (NSSAAF), location management function (LMF), network data analytics function (NWDAF), short message service function (SMSF), and security anchor functionality (SEAF).

[0109] Among them, UPF is mainly responsible for user data processing (forwarding, receiving, billing, etc.). For example, UPF can receive user data from the data network (DN) and forward the user data to the terminal through the access network equipment. UPF can also receive user data from the terminal through the access network equipment and forward the user data to the DN. DN refers to the operator network that provides data transmission services to users. For example, the Internet Protocol (IP) Multimedia Service (IMS), the Internet, etc. DN can be an operator's external network or a network controlled by the operator, which is used to provide business services to terminal devices.

[0110] AUSF can be used to perform security authentication for terminal access to the network.

[0111] The AMF is mainly responsible for access and mobility management in mobile networks, such as user location updates, user network registration, and user handover.

[0112] The SMF is primarily responsible for session management in mobile networks, such as session establishment, modification, and release. Specific functions include allocating Internet Protocol (IP) addresses to users and selecting the UPF that provides packet forwarding capabilities.

[0113] PCF primarily supports providing a unified policy framework to control network behavior, providing policy rules to the control layer network functions, and is responsible for obtaining user subscription information related to policy decisions. PCF can provide policies to AMF and SMF, such as quality of service (QoS) policies and slice selection policies.

[0114] NSSF can be used to select network slices for terminals.

[0115] NEF can be used to support the exposure of capabilities and events.

[0116] UDM can be used to manage user data, such as subscription data, authentication / authorization data, etc.

[0117] AF mainly supports interaction with CN to provide services, such as influencing data routing decisions, policy control functions, or providing some third-party services to the network side.

[0118] NSSAAF can be used to support slice authentication and authorization, as well as support access to independent non-public networks using the credentials of the credential holder. NSSAAF can interact with the authentication, authorization, and accounting server (AAA-S) through the authentication, authorization, and accounting proxy (AAA-P).

[0119] LMF can be used to manage the location information of terminals and provide location services for terminals.

[0120] NWDAF can be used to collect data within the network and perform analysis and prediction, providing data analysis services for other network functions.

[0121] SMSF can be used to manage the short message subscription data of the terminal, forward short messages to the terminal, and charge for the short message service.

[0122] SEAF can be used to derive NAS keys and AS keys based on the keys passed by AUSF to protect data in the communication process. It initiates the authentication process and calls the AUSF authentication service.

[0123] 2. Key derivation process

[0124] As shown in Figures 2 and 3, after the terminal connects to the RAN through random access and RRC connection establishment processes, it initiates initial access and uses the user hidden identifier (SUCI) in the registration request. After passing 5G authentication and key agreement (AKA) authentication, the terminal and UDM derive the AUSF key K based on the authentication vector. AUSF The authentication vector includes the encryption key (cipher key, CK) and the consistency key (integrity key, IK). The terminal and AUSF use K AUSF Derive the security anchor key K SEAF . Terminal and SEAF according to K SEAF Derived K AMFIt can be understood that when the Extensible Authentication Protocol-AKA (EAP-AKA') authentication method is used, the AUSF receives the authentication vectors CK' and IK' from the authentication credential repository and processing function (ARPF), and the terminal and AUSF derive K from CK' and IK'. AUSF .

[0125] In the NAS security mode command (SMC) phase, the terminal uses K AUSF Derived K gNB ;AMF according to K AMF Derived K gNB , and the derived K is gNB The AMF does not send the NH (next hop) value to the gNB during initial connection establishment. Upon receiving the Next Generation Application Protocol (NGAP) Initial Context Setup Request message from the AMF, the gNB initializes the NH chaining counter (NCC) to 0. The NCC is used for subsequent key updates.

[0126] At the access stratum (AS) SMC stage, the gNB derives the signaling plane encryption key K RRCenc and integrity protection key K RRCint The terminal receives the SMC message, determines the encryption and integrity protection algorithm, and derives K RRCint , K RRCenc The gNB sends the security algorithm selection result to the terminal via the AS SMC message. The AS SMC and AS SMC Complete messages are sent over SRB1 and are integrity-protected by the gNB and the terminal, respectively, without encryption.

[0127] The AMF sends the security policy result to the gNB through the protocol data unit (PDU) session request feedback message. The security policy includes the effectiveness indication of encryption and integrity protection. After the PDU session is established, the user plane security policy is activated. The gNB and the terminal will check the security policy according to the K gNBDerive the user plane encryption key K UPint and integrity protection key K UPenc .

[0128] It can be understood that the "derivation" mentioned in the embodiments of the present application is only an exemplary expression, and "derivation" can also be replaced by any possible expression, such as "determination", "generation" or "deduction", etc., without limitation.

[0129] 3. Key derivation method

[0130] All key derivations in the 5G system are performed using the key derivation function (KDF) specified in Appendix B.2.0 of TS 33.220v17.4 of the 3rd Generation Partnership Project (3GPP). The input of the KDF function includes: a key Key and an input parameter, and the output parameter is a string S; the Key is the key used to derive the key. For example, if key #1 is derived from key #2, then key #2 is the key of key #1. In other words, the key derivation can be HMAC-SHA-256(Key, S), where HMAC-SHA-256 is a specific function in the KDF function. The specific principle of HMAC-SHA-256 can refer to the principles in the prior art and will not be repeated here.

[0131] The string S is constructed from n+1 input parameters, and its expression is as follows: S=FC||P0||L0||P1||L1||P2||L2||P3||L3||...||Pn||Ln

[0132] Where FC is used to distinguish different instances of the algorithm. P0, ..., Pn are the n+1 input parameter codes, and L0, ..., Ln are the lengths of the corresponding input parameter codes P0, ..., Pn.

[0133] For example, in K AMF In the derivation of , Key is K SEAF The input parameters of the string S are: FC = 0x6D, P0 = IMSI or NAI or GCI or GLI, L0 = P0 length-number of octets in P0, P1 = ABBA parameter, and L1 = P1 length-number of octets in P1, where P0 is the terminal identifier and P1 is a custom parameter sent by SEAF to the terminal.

[0134] In existing network architectures, such as 5G communication systems, message transmission between terminals and the network is centralized. Control plane messages between terminals and network functions other than the AMF must be forwarded through the AMF. In other words, terminals only need to provide security protection with the AMF and do not require security protection with other network functions.

[0135] However, in future communication needs, terminals may communicate directly with various network functions in the network, meaning that there is no need for the AMF to forward messages between the terminal and the network functions. In this case, communication between the terminal and the network functions in the network also requires security protection. In other words, simply ensuring the security of communication between the terminal and the AMF will not meet future communication needs. It should be understood that the above-mentioned direct communication means that the information exchange between the terminal and the network functions does not need to be forwarded by the AMF. However, the corresponding information exchange still needs to be carried out through the air interface via the RAN.

[0136] In response to the above technical problems, the embodiments of the present application propose that when the terminal communicates directly with each network function, a secure connection can be established between the terminal and each network function based on a key to achieve security protection between the two, thereby ensuring communication security and meeting future communication needs.

[0137] The technical solution in this application will be described below with reference to the accompanying drawings.

[0138] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless fidelity (WiFi) systems, vehicle-to-everything (V2X) communication systems, device-to-device (D2D) communication systems, Internet of Vehicles communication systems, 4th generation (4G) mobile communication systems, such as long term evolution (LTE) systems, world-wide interoperability for microwave access (WiMAX) communication systems, 5th generation (5G) mobile communication systems, such as new radio (NR) systems, and future communication systems, such as 6th generation (6G) mobile communication systems.

[0139] This application will present various aspects, embodiments, or features in the context of systems that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. Furthermore, combinations of these aspects may also be used.

[0140] Additionally, in the embodiments of this application, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as an "exemplary" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner.

[0141] In the embodiments of the present application, the terms "information," "signal," "message," "channel," and "signaling" may sometimes be used interchangeably. It should be noted that, when the distinction between them is not emphasized, the meanings they intend to convey are the same. The terms "of," "corresponding," and "corresponding" may sometimes be used interchangeably. It should be noted that, when the distinction between them is not emphasized, the meanings they intend to convey are the same.

[0142] In the embodiments of the present application, sometimes a subscript such as W1 may be mistakenly written as a non-subscript form such as W1. When the difference is not emphasized, the meanings to be expressed are the same.

[0143] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0144] To facilitate understanding of the embodiments of the present application, a communication system applicable to the embodiments of the present application is first described in detail using the communication system shown in Figure 4 as an example. For example, Figure 4 is a schematic diagram of the architecture of a communication system applicable to the method for determining a security key provided in the embodiments of the present application.

[0145] As shown in Figure 4, the communication system mainly includes: a first network function, a second network function and a terminal. Optionally, it may also include a third network function.

[0146] This communication system can be applied to the above-mentioned 5G architecture. In this case, the first network function can be a network function other than the second network function in the network, such as SMF, PCF, LMF, NWDAF, or SMSF; the second network function can be used for terminal access management, which can be AMF; and the third network function can derive the key of the first network function, that is, the third network function can be AMF or SEAF. In other words, in some cases, the second network function and the third network function are different network functions, such as the second network function is AMF and the third network function is SEAF; or in other cases, the second network function and the third network function are the same network function, such as the second network function and the third network function are both AMF.

[0147] This communication system can also be applied to the architecture of future communication systems. For example, as shown in Figure 5, this architecture may include an AN, a CN, and possibly a terminal. For descriptions of the AN and terminal, please refer to the aforementioned related introduction. The CN is primarily responsible for maintaining mobile network subscription data and providing terminal functions such as session management, mobility management, policy management, and security authentication. The CN primarily includes access management (AM), SEAF, and at least one subnet. The AM is used for network access management, such as enabling terminal access to different subnets. Each of the at least one subnet primarily includes a network function for terminal mobility management and at least one network function (NF). The network function for terminal mobility management may be a mobility management (MM), proxy, or load balancing (LB). The NF may be any of the following: UPF, AUSF, SMF, NSSF, NEF, NRF, PCF, UDM, AF, or NSSAAF. The NF may also be other network functions, which are not limited here. For descriptions of the aforementioned network functions, please refer to the aforementioned related introduction and will not be repeated here. In this case, the first network function can be any network function other than the second network function in the network. For example, the first network function can be a network function for terminal mobility management, namely, MM, proxy, or LB; the second network function can be used for terminal access management, which can be AM; and the third network function can derive the key of the first network function, namely, the third network function can be AM or SEAF. In other words, in some cases, the second network function and the third network function are different network functions, such as the second network function is AM and the third network function is SEAF; or in other cases, the second network function and the third network function are the same network function, such as the second network function and the third network function are both AM.

[0148] In the communication system, a terminal can communicate directly with a first network function in the network without the need for the AMF to forward messages between the terminal and the first network function. Furthermore, a secure connection can be established between the terminal and the first network function using a security key, thereby ensuring secure communication between the terminal and the first network function, thereby ensuring the security of the communication system and meeting future communication needs.

[0149] It can be understood that the "network function" mentioned in the embodiments of the present application is only an exemplary expression, and "network function" can also be replaced by any possible expression, such as "network element", "entity" or "device", etc., without limitation.

[0150] It should be noted that the solutions in the embodiments of the present application can also be applied to other communication systems, and the corresponding names can also be replaced by the names of corresponding functions in other communication systems.

[0151] It should be understood that FIG4 is only a simplified schematic diagram for ease of understanding, and the communication system may also include other network devices and / or other terminal devices, which are not shown in FIG4 .

[0152] For ease of understanding, the method for determining the security key provided in the embodiment of the present application will be specifically described below with reference to FIG6 .

[0153] 6 is a flow chart of a method for determining a security key according to an embodiment of the present application. The method is mainly applicable to communication between a terminal and a first network function in the above communication system.

[0154] As shown in FIG6 , the process of the above method is as follows:

[0155] S601: A terminal sends a first request to a first network function. Correspondingly, the first network function receives the first request from the terminal.

[0156] It should be understood that the first network function is a network function of the CN, and information exchange between the terminal and the first network function is implemented through the RAN equipment. That is, information sent by the terminal to the first network function and information sent by the first network function to the terminal must be forwarded by the RAN equipment (including direct forwarding or forwarding after processing). The first request is used by the terminal to request to establish a service with the first network function, or the first request is used by the terminal to request access to the network. For example, the first request can be a service request, used by the terminal to request to establish a service with the first network function. For another example, the first request can be an access request, used by the terminal to request access to the network. The following describes different situations.

[0157] Case 1: The terminal has accessed the network and has service requirements with the network. The terminal can then send the above-mentioned service request to the network function within the network, such as directly sending the service request to the network function, or forwarding the service request to the network function through a second network function (such as AMF). The service request may carry at least one of the following: the terminal identifier, such as SUPI, the service identifier, service-related parameters, and information about the network function related to the service, such as the identifier of the first network function, to jointly indicate that the terminal requests to establish a service with the first network function. After receiving the service request, the second network function may forward the service request to the first network function. Accordingly, the first network function may receive the service request from the second network function.

[0158] For example, if the UE needs to transmit service data to the DN or an application server, the UE can first request to establish a PDU session for the service with the SMF (first network function). In this case, the UE can send a session establishment request (service request) to the AMF, and the AMF forwards the session establishment request to the SMF.

[0159] Case 2: If the terminal is not connected to a network and requires access, the terminal can send the aforementioned access request to a network function within the network, such as a second network function (e.g., AM). The access request can include at least one of the following: terminal information and a network identifier, i.e., the identifier of the network the terminal requests access to, indicating that the terminal is requesting access to the network. Upon receiving the access request, the second network function can forward the access request to the first network function, and the first network function can accordingly receive the access request from the second network function.

[0160] For example, if the UE has not yet accessed network #1 and needs to access network #1, the UE can send an access request to the AM, which then forwards the access request to the MM corresponding to network #1.

[0161] It can be understood that the AM can determine the first network function corresponding to the access request based on the network identifier. There are many ways to obtain the network identifier. For example, when the access request carries the network identifier, the AM can obtain the identifier from the access request, or when the network identifier is included in the terminal information, the AM can obtain the identifier from the terminal information. The terminal information can be carried in the access request or pre-configured in the AM. This embodiment of the present application does not limit this.

[0162] In addition, the first request may also carry some security-related information. For details, please refer to the relevant introduction of S602-S603 below, which will not be repeated here.

[0163] S602: The first network function obtains a first key of the first network function according to the first request.

[0164] The first key can be used to determine a security key. The security key can be used to establish a secure connection between the terminal and the first network function, for example, to encrypt and integrity protect information transmitted between the terminal and the first network function, that is, the security key can include an encryption key and an integrity protection key. In one possible implementation, the security key can be a NAS security key, such as K NASenc and K NASint , accordingly, the secure connection can be a NAS secure connection.

[0165] There are multiple ways for the first network function to obtain the first key, such as obtaining it from other network functions or obtaining it locally, which are introduced below.

[0166] Method 1: The first network function obtains the first key from another network function.

[0167] 1) The first network function may send a second request to the third network function based on the first request. Correspondingly, the third network function receives the second request from the first network function.

[0168] The second request may be for requesting the third network function to derive a key for the first network function.

[0169] In one possible approach, the second request may indicate, through the message type, that the third network function needs to derive a key for the first network function. For example, the second request may be a new message, such as a key derivation request. The third network function determines, based on the message type of the second request, that the key is to be derived from the first network function. It is understood that different network functions may reuse second requests of different message types. The third network function can then determine, based on the message type, which network function to derive the key for.

[0170] In another possible approach, the second request can indicate to the third network function that it needs to derive the key of the first network function by multiplexing the message. For example, the second request can be an existing message, the specific message being unrestricted, that is, the existing message is multiplexed by a new network function (the first network function). Accordingly, based on the fact that the second request is multiplexed by the first network function, the third network function is determined to derive the key for the first network function.

[0171] In another possible approach, the second request may carry an indication information element to indicate that the third network function needs to derive the key of the first network function. For example, the indication information element may be an identifier of the first network function or a type of the first network function, indicating that the third network function needs to derive the key of the first network function.

[0172] Of course, the second request may be implemented in other ways, which is not limited in the embodiments of the present application.

[0173] Optionally, the second request may further carry first information, which may be used as a key input parameter for deriving the first network function. For example, the first information may include at least one of the following: terminal information, first request information, first network function information, network identification, and network security parameters.

[0174] The terminal information may include a terminal identifier, such as a SUPI, an international mobile subscriber identity (IMSI), a globally unique temporary identity (GUTI), or terminal address information, such as an Internet Protocol (IP) address or a media access control (MAC) address. The first requested information may include a service type, such as a session service, a policy service, a positioning service, or a data service; or may include a specific identifier of a service, such as a session identifier, a policy service identifier, a positioning service identifier, or a data service identifier. The first network function information may include an identifier of the first network function, such as an SMF identifier or a PCF identifier. The network identifier may include an operator identifier, a slice identifier, a non-public network (NPN) identifier, or a group identifier, such as a closed access group (CAG) identifier. The network security parameters may include the network owner or user, such as a network slice tenant or an NPN network lessee, or operator-defined parameters. It can be understood that for network slicing, the network security parameters can be customized by the tenant of the slice, such as a set of random numbers, or a string associated with the terminal identifier, etc.; for NPN, the network security parameters can be customized by the supporter of the NPN. The network security parameters can be sent by the network owner to the first network function, the second network function, and the third network function through a secure link for use; or can be pre-configured locally in the first network function; or can be stored in the data storage function and obtained from the data storage function by the first network function, the second network function, and the third network function. The embodiments of the present application do not limit the configuration and acquisition methods of the network security parameters.

[0175] The first information may also be pre-configured or predetermined locally in the third network function by a protocol, which is not limited in the embodiment of the present application.

[0176] It is understood that the first information is related to the first request. That is, when the first request is a service request, the first information may include at least one of the following: terminal information, information about the first request, and information about the first network function. When the first request is an access request, the first information may include at least one of the following: terminal information, a network identifier, and network security parameters.

[0177] 2) The third network function may obtain the first key of the first network function according to the second request.

[0178] The third network function may determine the first key based on the second key. The second key may be the key of the third network function, which is used to determine the key of the first network function, that is, the second key may be the key used to derive the key of the first network function. The third network function may be AMF, AM or SEAF, and accordingly, the second key may be K AMF , K AM or K SEAF , where K AM It is the key of AM.

[0179] When the third network function is a different network function, the manner of obtaining the second key may be different, which are described below respectively.

[0180] Situation 1.1:

[0181] When the third network function is SEAF, SEAF obtains K SEAF There are two ways: SEAF can store K SEAF Get the location K SEAF , that is, K SEAF Pre-configured in SEAF. K SEAF It can be obtained according to the aforementioned key derivation process or other methods without limitation. Alternatively, SEAF obtains K from AUSF. SEAF For example, after receiving the second request, SEAF may send a third request to AUSF, such as an authentication request message, to request AUSF to derive K SEAF Accordingly, AUSF can use K AUSF Derived K SEAF and sends a second response to SEAF, which carries K SEAF . AUSF according to K AUSF Derived K SEAF The specific implementation principle can refer to the aforementioned key derivation process and will not be repeated here.

[0182] It is understandable that SEAF obtains K from AUSF SEAF After that, SEAF can use the K SEAFSave it locally for later use; alternatively, SEAF can use K SEAF Then, K SEAF Delete, and use K later SEAF , obtain it from AUSF again.

[0183] Situation 1.2:

[0184] When the third network function is AMF or AM, the second key is K AMF or K AM The second key can be pre-configured or pre-defined by the protocol in the third network function, that is, the AMF or AM can directly obtain it from the local and use K AMF or K AM Or, K AMF or K AM It can be obtained according to the aforementioned key derivation process or by other means without limitation.

[0185] Regarding scenario 1.1 or scenario 1.2 above, after the third network function obtains the second key, it can use the second key as an input parameter to derive the first key, or it can use the second key and the first information as input parameters to derive the first key. For the description of the first information, please refer to the aforementioned related description and will not be repeated here. Of course, the input parameters are not limited to the second key, or the second key and the first information, and other input parameters may also be included. For details, please refer to the aforementioned "3. Key Derivation Method" and will not be repeated here.

[0186] 3) The third network function may send a first response to the first network function. Accordingly, the first network function receives the first response from the third network function. The first response is used to respond to the second request. That is, the first response is a response message to the second request, that is, the first response is a response message carrying the first key. For example, the first response may be a key derivation response, used to respond to the key derivation request.

[0187] Method 2: The first network function obtains the first key locally.

[0188] For example, the first network function may obtain the second key according to the first request, and locally determine the first key according to the second key. There are multiple ways for the first network function to obtain the second key, which are described below in different situations.

[0189] Case 2.1: The first network function obtains the second key locally. That is, the second key may be preconfigured or pre-determined locally on the first network function. After receiving the first request, the first network function may be triggered by the first request to directly obtain the second key locally. Conversely, if the first network function does not receive the first request, it does not obtain the second key.

[0190] Case 2.2: The first network function obtains the second key from the first request, that is, the second key can be carried in the first request. For example, the second network function is the same as the third network function, that is, the second network function and the third network function are AMF or AM. In this case, when the second network function forwards the first request to the first network function, it can carry its own second key (such as K AMF or K AM ) is also carried into the first request.

[0191] Scenario 2.3: The first network function obtains the second key from the third network function. The first network function is triggered to obtain the second key from the third network function based on the first request. For example, based on the first request, the first network function sends a fourth request to the third network function, requesting the third network function to send the second key. Based on the fourth request, the third network function obtains the second key and sends a third response containing the second key to the first network function. Accordingly, the first network function receives the third response from the third network function and obtains the second key from the third response.

[0192] The fourth request can instruct the third network function to send the second key to the first network function by using a message type. For example, the fourth request can be a new message. The third network function obtains the second key through this new message type and sends the second key to the first network function. The fourth request can also instruct the third network function to send the second key to the first network function by using message multiplexing. For example, the fourth request can be an existing message, which is not limited to this. The fourth request can also carry an indication information element to instruct the third network function to send the second key to the first network function. For example, the indication information element can be the identifier of the first network function, which is used to instruct the third network function to send the second key to the first network function.

[0193] It is understood that in each of the above situations, the third network function may be pre-configured with the second key; alternatively, the third network function may obtain the second key when the second key is needed, without limitation. For instructions on how the third network function obtains the second key, please refer to the aforementioned related description and will not be repeated here.

[0194] Regarding Cases 2.1-2.3 above, after the first network function obtains the second key, it can use the second key as an input parameter to determine the first key, or it can use the second key and the first information as input parameters to determine the first key. For the description of the first information, please refer to the aforementioned related description and will not be repeated here. Of course, the input parameters are not limited to the second key, or the second key and the first information, and other input parameters may also be included. For details, please refer to the aforementioned "3. Key Derivation Method" related description and will not be repeated here.

[0195] Furthermore, after the first network function obtains the first key, it can also send the first key to the second network function, so that the second network function can subsequently include the first key in a new first request sent to the first network function. Alternatively, the second network function can subsequently provide the first key to the first network function upon request from the first network function. Alternatively, the first network function can also send the first key to the key management function, so that the key management function can subsequently provide the first key to the first network function upon request from the first network function. Specifically, the key management function can be a function responsible for key management, or it can be a data storage function. Alternatively, the first network function can store the first key locally.

[0196] It can also be understood that if there are multiple first network functions with the same function in the network, such as multiple SMFs, the first key of one first network function can be reused by these multiple first network functions, or each first network function can have its own first key.

[0197] S603: The first network function determines a security key according to the first key.

[0198] For instructions on security keys, please refer to the aforementioned introduction.

[0199] After the first network function obtains the first key, it can use the first key as an input parameter to determine the security key, or it can use the first key and the second information as input parameters to determine the security key. Of course, the input parameters may not be limited to the first key, or the first key and the second information, and there may be other input parameters. For details, please refer to the relevant introduction of the aforementioned "3. Key derivation method", which will not be repeated here.

[0200] The second information may include at least one of the following: terminal information, information about the first request, information about the first network function, a network identifier, and network security parameters. For details about the terminal information, the first request information, the first network function information, and the network security parameters, refer to the description in S601 above and are not repeated here. The second information may be included in the first request, meaning the first network function can obtain the second information based on the received first request. Alternatively, the second information may be preconfigured or locally stored in the first network function by a protocol, meaning the first network function can obtain the second information locally. This is not a limitation in this embodiment of the present application. It is understood that the second information is related to the first request. Specifically, when the first request is a service request, the first information may include at least one of the following: terminal information, information about the first request, and information about the first network function. When the first request is an access request, the first information may include at least one of the following: terminal information, a network identifier, and network security parameters. While the second information and the first information are typically different, they may also be the same information, for example, where both the first and second information are network security parameters.

[0201] In one possible implementation, the first network function may determine a third key of the first network function based on the first key and information in the first request; and determine the security key based on the third key. It should be understood that the third key is used to obtain the security key, and the third key is a key derived from the first key and information in the first request.

[0202] The first request may be a service request, and the information of the first request may be specific identification information of the service request. For example, when the service request is a session establishment request, the specific identification information of the session establishment request may be a session identifier. The first network function may determine various services of the terminal based on the information of the service request.

[0203] For example, if the first network function is an SMF, the service request is a session establishment request, and the specific identification information of the session establishment request is ID#1, the first network function can determine, based on the session establishment request, that the session service provided by the first network function for the terminal is session#1. The SMF also receives a session establishment request carrying specific identification information of ID#2. Based on the session establishment request, the first network function can determine, that the session service provided by the first network function for the terminal is session#2, i.e., session#2 is different from session#1. In other words, the terminal can distinguish different sessions between itself and the terminal based on the specific identification information of the session establishment request.

[0204] The third key is used to obtain the security key and is derived from the first key and the information in the first request. That is, the third key is derived based on service granularity. In other words, when multiple services exist between the first network function and the terminal, the third key corresponding to each of the multiple services is different, that is, the security key corresponding to each of the multiple services is different.

[0205] After the first network function obtains the first key and the first request information, it can use the first key and the first request information as input parameters to determine the third key. Of course, the input parameters are not limited to the first key or the first key and the first request information, and other input parameters may also be included. For details, please refer to the relevant description of "3. Key Derivation Method" above and will not be repeated here.

[0206] After the first network function obtains the third key, it can use the third key as an input parameter to determine the security key. Alternatively, it can use the third key and the second information as input parameters to determine the security key. For a description of the second information, please refer to the aforementioned description and will not be repeated here. Of course, the input parameters are not limited to the first key, or the first key and the first request information. Other input parameters may also be included. For details, please refer to the aforementioned "3. Key Derivation Method" and will not be repeated here.

[0207] In one possible design, after the first network function determines the security key, the method may further include: the first network function may send a first message to the terminal. Accordingly, the terminal receives the first message from the first network function.

[0208] The first message may include information indicating a key for the first network function. This information may indicate that the first network function has determined a security key (referred to as security key #1) for establishing a secure connection between the terminal and the first network function. After receiving the first message, the terminal may initiate key derivation to obtain a security key (security key #2) for establishing a secure connection between the terminal and the first network function. The key derivation principles of the terminal may refer to the aforementioned key derivation process or principles in the prior art and are not further described here.

[0209] It can be understood that security key #1 and security key #2 are a set of key pairs, and the key pair can be used by the receiving end and the sending end. For example: the sending end uses security key #1 to encrypt the plaintext, obtain the ciphertext, and send the ciphertext to the receiving end. When the receiving end receives the ciphertext, it can use security key #2 to decrypt it to obtain the plaintext.

[0210] In one possible implementation, the first message may further include information indicating an encryption algorithm, where the encryption algorithm is an encryption algorithm used by the terminal. For example, after deriving the key of the first network, the terminal may determine security key #2 corresponding to security key #1 based on the key of the first network and the encryption algorithm.

[0211] Furthermore, the method may further include: the terminal determining a security key for establishing a secure connection between the terminal and the first network function based on the key information of the first network function and the information indicating the encryption algorithm. For example, the terminal may first initiate key derivation based on the key information of the first network function. After deriving the key of the first network function, the terminal may determine the security key (security key #2) based on the encryption indicating algorithm and the key of the first network function.

[0212] In one possible implementation, the terminal sends a second message to the first network function. In response, the first network function receives the second message from the terminal. The second message indicates whether the terminal has determined the security key. The first network function may determine its subsequent operations based on the second message.

[0213] In summary, if the terminal can communicate directly with the first network function in the network, after receiving the first request initiated by the terminal, the first network function can establish a secure connection with the terminal by determining the security key. In other words, messages between the first network function and the terminal can be protected by the security key. This ensures secure communication between the first network function and the terminal, thereby meeting future communication needs.

[0214] Scenario 1:

[0215] Figure 7 is a second flow chart of a method for determining a security key provided in an embodiment of the present application. This method is applicable to the above-mentioned communication system, and mainly involves communication between the UE (the above-mentioned terminal), the AMF (the above-mentioned second network function), the NF (the above-mentioned first network function), the SEAF (the above-mentioned third network function), and the AUSF.

[0216] As shown in FIG7 , the above method may include the following steps:

[0217] S701: The UE sends a service request to the AMF. Correspondingly, the AMF receives the service request from the UE.

[0218] S702: AMF sends a service request to NF. Correspondingly, NF receives the service request from AMF.

[0219] S703: NF sends a key derivation request to SEAF. Correspondingly, SEAF receives the key derivation request from NF.

[0220] The key derivation request is the second request in the aforementioned S602.

[0221] S704, SEAF according to K SEAF , get the key K of NF NF .

[0222] Among them, SEAF can obtain K from AUSF by sending an authentication request message SEAF The specific implementation principles of S701-S704 can refer to the relevant introduction of S601-S602 above, which will not be repeated here.

[0223] S705, SEAF sends K to NF NF . Accordingly, NF receives K from SEAF NF .

[0224] NF receives K NF After that, we can use K NF , determine the security key; or, according to K NF The specific implementation principle of the NF determining the security key can be referred to the relevant introduction of S603 above and will not be repeated here.

[0225] It can be understood that NF can be obtained based on K NF After the security key is determined, proceed to S706.

[0226] S706: The NF sends a NAS SMC message to the UE. Correspondingly, the UE receives the NAS SMC message from the NF.

[0227] The NAS SMC message is the first message in the aforementioned S603.

[0228] S707: The UE sends a NAS SMC complete message to the NF. Correspondingly, the NF receives the NAS SMC complete message from the UE.

[0229] The NAS SMC completion message is the second message in the aforementioned S603. The specific implementation principles of S706-S707 can be referred to the relevant introduction of the aforementioned S603 and will not be repeated here.

[0230] Scenario 2:

[0231] Figure 8 is a flow chart of the third method for determining a security key provided in an embodiment of the present application. This method is applicable to the above-mentioned communication system, mainly involving communication between the UE (the above-mentioned terminal), the AMF (the above-mentioned second network function) and the NF (the above-mentioned first network function).

[0232] As shown in FIG8 , the above method may include the following steps:

[0233] S801: The UE sends a service request to the AMF. Correspondingly, the AMF receives the service request from the UE.

[0234] S802: AMF sends a service request to NF. Correspondingly, NF receives the service request from AMF.

[0235] Among them, the business request carries K AMF , that is, in this case, K AMF Preconfigured in AMF.

[0236] S803, NF according to K AMF , get the key K of NF NF .

[0237] NF receives K NF After that, we can use K NF , determine the security key; or, according to K NF and second information, determining a security key.

[0238] It can be understood that NF can be obtained based on K NF After the security key is determined, proceed to S804.

[0239] S804: NF sends a NAS SMC message to UE. Correspondingly, UE receives the NAS SMC message from NF.

[0240] The NAS SMC message is the first message in the aforementioned S603.

[0241] S805: The UE sends a NAS SMC complete message to the NF. Correspondingly, the NF receives the NAS SMC complete message from the UE.

[0242] The NAS SMC completion message is the second message in the aforementioned S603.

[0243] The specific implementation principles of S801-S805 can refer to the relevant introduction of S601-S603 above, which will not be repeated here.

[0244] Scenario 3:

[0245] Figure 9 is a fourth flow chart of a method for determining a security key provided in an embodiment of the present application. This method is applicable to the above-mentioned communication system, and mainly involves communication between the UE (the above-mentioned terminal), the AM (the above-mentioned second network function), the MM (the above-mentioned first network function), the SEAF (the above-mentioned third network function), and the AUSF.

[0246] As shown in FIG9 , the above method may include the following steps:

[0247] S901: UE sends an access request to AM. Correspondingly, AM receives the access request from UE.

[0248] S902: The AMF sends an access request to the MM. Correspondingly, the MM receives the access request from the AMF.

[0249] S903: MM sends a key derivation request to SEAF. Correspondingly, SEAF receives the key derivation request from MM.

[0250] The key derivation request is the second request in the aforementioned S602.

[0251] S904, SEAF according to K SEAF , get the MM key K MM .

[0252] Among them, SEAF can obtain K from AUSF by sending an authentication request message SEAF The specific implementation principles of S901-S904 can refer to the above-mentioned introduction of S601-S602, which will not be repeated here.

[0253] S905, SEAF sends K to MM MM . Accordingly, MM receives K from SEAF MM .

[0254] MM gets K MM After that, we can use K MM , determine the security key; or, according to K MM The specific implementation principle of MM determining the security key can be referred to the relevant introduction of S603 above, which will not be repeated here.

[0255] It is understandable that the MM may proceed to S906 after determining the security key.

[0256] S906: The MM sends a NAS SMC message to the UE. Correspondingly, the UE receives the NAS SMC message from the MM.

[0257] The NAS SMC message is the first message in the aforementioned S603.

[0258] S907: The UE sends a NAS SMC complete message to the MM. Correspondingly, the MM receives the NAS SMC complete message from the UE.

[0259] The NAS SMC completion message is the second message in the aforementioned S603. The specific implementation principles of S906-S907 can refer to the relevant introduction of the aforementioned S603 and will not be repeated here.

[0260] Scenario 4:

[0261] Figure 10 is a flowchart diagram of a method for determining a security key according to an embodiment of the present application. This method is applicable to the above-mentioned communication system, and mainly involves communication between the UE (the above-mentioned terminal), the AM (the above-mentioned second network function), and the MM (the above-mentioned first network function).

[0262] As shown in FIG10 , the above method may include the following steps:

[0263] S1001: UE sends an access request to AM. Correspondingly, AM receives the access request from UE.

[0264] S1002: AM sends an access request to MM. Correspondingly, MM receives the access request from AM.

[0265] The access request carries the AM key K AM , K AM Preconfigured in AMF.

[0266] S1003, MM according to K AM , get the MM key K MM .

[0267] MM gets K MM After that, we can use K MM , determine the security key; or, according to K MM and second information, determining a security key.

[0268] It is understandable that the MM may proceed to S1004 after determining the security key.

[0269] S1004: The MM sends a NAS SMC message to the UE. Correspondingly, the UE receives the NAS SMC message from the MM.

[0270] The NAS SMC message is the first message in the aforementioned S603.

[0271] S1005: The UE sends a NAS SMC complete message to the MM. Correspondingly, the MM receives the NAS SMC complete message from the UE.

[0272] The NAS SMC completion message is the second message in the aforementioned S603.

[0273] The specific implementation principles of S1001-S1005 can refer to the relevant introduction of S601-S603 above, which will not be repeated here.

[0274] Figure 11 is a sixth flow chart of a method for determining a security key according to an embodiment of the present application. This method is mainly applicable to communication between a terminal and a first network function in the above communication system.

[0275] As shown in FIG11 , the process of the above method is as follows:

[0276] S1101: A terminal sends a first request to a second network function. Correspondingly, the second network function receives the first request from the terminal.

[0277] For the description of the first request, please refer to the relevant introduction in the aforementioned S601, which will not be repeated here.

[0278] Among them, the terminal can send a first request corresponding to the demand to the second network function according to its current demand. For example, when the terminal has a service demand, the terminal can send a service request to the second network function, and accordingly, the second network function receives the service request from the terminal; for example, when the terminal has a need to access the network, the terminal can send an access request to the second network function, and accordingly, the second network function receives the access request from the terminal. For relevant instructions, please refer to the relevant introduction in the aforementioned S601, which will not be repeated here.

[0279] S1102: The second network function obtains the first key of the first network function according to the first request.

[0280] The first key can be used to determine the security key. The description of the security key can refer to the relevant introduction in the above S602, which will not be repeated here.

[0281] There are multiple ways for the second network function to obtain the first key, such as obtaining it from other network functions or obtaining it locally, which are introduced below.

[0282] Method 1: The second network function obtains the first key from another network function.

[0283] 1) The second network function may send a second request to the third network function based on the first request. Correspondingly, the third network function receives the second request from the second network function.

[0284] The above-mentioned second request is similar to the second request in the aforementioned S602. The difference is that the second request in S602 is a request sent by the first network function to the third network function, and the second request in S1102 is a request sent by the second network function to the third network function. For the similarities, please refer to the relevant introduction of the aforementioned S602, which will not be repeated here.

[0285] Optionally, the second request may also carry the first information. For the description of the first information, please refer to the relevant introduction of S602 above, which will not be repeated here.

[0286] 2) The third network function may obtain the first key of the first network function according to the second request. For the specific implementation principle, reference may be made to the related introduction of S602 above, which will not be repeated here.

[0287] 3) The third network function may send a first response to the second network function. Correspondingly, the second network function receives the first response from the third network function. The description of the first response can refer to the relevant introduction of S602 above and will not be repeated here.

[0288] Method 2: The second network function obtains the first key locally.

[0289] For example, the second network function may obtain the key of the second network function through the first request, so as to obtain the first key according to the key of the second network function.

[0290] The key of the second network function may be K AMF or K AM .K AMF or K AM The method for obtaining can refer to the relevant introduction in the aforementioned S602 and will not be repeated here.

[0291] After the second network function obtains the second network function key, it may use the second network function key as an input parameter to determine the first key, or it may use the second network function key and the first information as input parameters to determine the first key. For a description of the first information, refer to the aforementioned description of S602 and will not be repeated here. Of course, the input parameters are not limited to the second network function key, or the second network function key and the first information, and may include other input parameters. For details, refer to the aforementioned description of "3. Key Derivation Method" and will not be repeated here.

[0292] S1103: The second network function sends a first key to the first network function. Correspondingly, the first network function receives the first key from the second network function.

[0293] The first key may be included in the first request. That is, the second network function may include the first key in the first request when forwarding the first request to the first network function, so that the first network function can provide the corresponding service to the terminal based on the first request and determine the security key based on the first key. For example, the second network function may send a service request including the first key to the first network function, or the second network function may send an access request including the first key to the first network function.

[0294] After receiving the first key, the first network function can determine the security key based on the first key; and establish a secure connection with the terminal based on the security key. The specific implementation principle can be referred to the relevant introduction of the aforementioned S603 and will not be repeated here.

[0295] As can be seen, the difference between the embodiment of the present application and the method described in FIG. 6 is that in the embodiment of the present application, the second network function triggers the acquisition of the first key, while the method described in FIG. 6 (S601-S603) triggers the acquisition of the first key by the first network function. The actions for triggering the acquisition of the first key in both embodiments are similar, and the similarities can be referenced in each other.

[0296] In summary, if a terminal can communicate directly with a first network function in the network, when the terminal initiates a first request corresponding to the network function, the second network function can, based on the first request, obtain a security key used to establish a secure connection between the first network function and the terminal. This allows the first network function to establish a secure connection with the terminal based on the security key. In other words, messages between the first network function and the terminal can be protected by the security key. This ensures secure communication between the first network function and the terminal, thereby meeting future communication needs.

[0297] Scenario 5:

[0298] Figure 12 is a flow chart of the seventh method for determining a security key provided in an embodiment of the present application. This method is applicable to the above-mentioned communication system, and mainly involves communication between the UE (the above-mentioned terminal), the AMF (the above-mentioned second network function), the NF (the above-mentioned first network function), the SEAF (the above-mentioned third network function) and the AUSF.

[0299] As shown in FIG12 , the above method may include the following steps:

[0300] S1201: The UE sends a service request to the AMF. Correspondingly, the AMF receives the service request from the UE.

[0301] S1202: AMF sends a key derivation request to SEAF. In response, SEAF receives the key derivation request from AMF.

[0302] The key derivation request is the second request in the aforementioned S1102, and the key derivation request may also be an authentication request of the terminal.

[0303] S1203, SEAF according to K SEAF , get the key K of NF NF .

[0304] S1204, SEAF sends K to AMF NF . Accordingly, AMF receives K from SEAF NF.

[0305] Among them, the specific implementation principles of S1201-S1204 can refer to the relevant introduction of the above S1101-S1102, and will not be repeated here.

[0306] S1205: AMF sends a service request to NF. Correspondingly, NF receives the service request from AMF.

[0307] Among them, the business request carries K NF NF gets K NF After that, we can use K NF , determine the security key; or, according to K NF The specific implementation principle of the NF determining the security key can be referred to the relevant introduction of S1103 above and will not be repeated here.

[0308] It can be understood that NF can be obtained based on K NF After the security key is determined, proceed to S1206.

[0309] S1206: The NF sends a NAS SMC message to the UE. Correspondingly, the UE receives the NAS SMC message from the NF.

[0310] The NAS SMC message is the first message in the aforementioned S603.

[0311] S1207: The UE sends a NAS SMC complete message (the second message described above) to the NF. Correspondingly, the NF receives the NAS SMC complete message from the UE.

[0312] The NAS SMC completion message is the second message in the aforementioned S603. The specific implementation principles of S1206-S1207 can be referred to the relevant introduction of the aforementioned S1103 and will not be repeated here.

[0313] Scenario 6:

[0314] Figure 13 is a flowchart of the eighth method for determining a security key provided in an embodiment of the present application. This method is applicable to the above-mentioned communication system, and mainly involves communication between the UE (the above-mentioned terminal), the AM (the above-mentioned second network function), the MM (the above-mentioned first network function), the SEAF (the above-mentioned third network function), and the AUSF.

[0315] S1301: The UE sends an access request to the AM. Correspondingly, the AM receives the access request from the UE.

[0316] S1302: AM sends a key derivation request to SEAF. Correspondingly, SEAF receives the key derivation request from AM.

[0317] S1303, SEAF according to K SEAF , get the MM key K MM .

[0318] S1304, SEAF sends K to AM MM . Accordingly, AM receives K from SEAF MM .

[0319] S1305: AM sends an access request to MM. Correspondingly, MM receives the access request from AMF.

[0320] The access request may carry K MM MM receives K MM After that, we can use K MM , determine the security key; or, according to K MM The specific implementation principle of MM determining the security key can be referred to the relevant introduction of S1103 above, which will not be repeated here.

[0321] It is understandable that MM can be used according to K MM After the security key is determined, proceed to S1306.

[0322] S1306: The MM sends a NAS SMC message to the UE. Correspondingly, the UE receives the NAS SMC message from the MM.

[0323] The NAS SMC message is the first message in the aforementioned S603.

[0324] S1307: The UE sends a NAS SMC complete message to the MM. Correspondingly, the MM receives the NAS SMC complete message from the UE.

[0325] The NAS SMC completion message is the second message in the aforementioned S603.

[0326] The specific implementation principles of S1301-S1307 can refer to the relevant introduction of S1101-S1103 above, which will not be repeated here.

[0327] It is understood that the above scenarios 1 to 6 are different implementations, and the specific implementation is not limited. In addition, there can be other implementations. For example, the MM in the above scenarios 3, 4, and 6 can also be replaced by a proxy or LB or other sub-network network access entry function. Accordingly, when the third network function is a proxy, the first key can be K Proxy Or the subnet granularity key Knet, Knet is used to indicate the key used by a subnet; when the third network function is LB, the first key can be K LBOr Knet. For example, after receiving a service request, AMF can generate K NF , and the K NF Carried in the service request sent to NF; or, after receiving the access request, AM can generate K by itself MM , and the K MM Carried in the access request sent to MM.

[0328] The above describes in detail the method for determining the security key provided by the embodiment of the present application in conjunction with Figures 6 to 13. The following describes in detail a communication device for executing the method for determining the security key provided by the embodiment of the present application in conjunction with Figures 14 and 15.

[0329] For example, Figure 14 is a structural diagram of a communication device according to an embodiment of the present application. As shown in Figure 14, a communication device 1400 includes a transceiver module 1401 and a processing module 1402. For ease of illustration, Figure 14 only shows the main components of the communication device.

[0330] In some embodiments, the communication device 1400 may be applicable to the communication system shown in FIG. 4 , and execute the function of the first network function in the method for determining the security key shown in FIG. 6 to FIG. 13 .

[0331] The transceiver module 1401 is configured to receive a first request; the processing module 1402 is configured to obtain a first key for a first network function based on the first request; and the processing module 1402 is further configured to determine a security key based on the first key. The first request is used by a terminal to request service establishment with the first network function, or the first request is used by a terminal to request network access. The first network function is a network function other than the second network function in the network. The second network function is used for terminal access management. The security key is used to establish a secure connection between the terminal and the first network function.

[0332] In one possible design scheme, the processing module 1402 is specifically used to generate a second request based on the first request; the transceiver module 1401 is further used to send the second request to the third network function; receive a first response from the third network function; the third network function is used to determine the key of the first network function, the second request is used to request the third network function to derive the key of the first network function, the first response carries the first key, and the first response is a response message to the second request.

[0333] In one possible design scheme, the processing module 1402 is specifically used to obtain the second key according to the first request; determine the first key according to the second key; the second key is the key of the third network function, and the key of the third network function is used to determine the key of the first network function.

[0334] Optionally, the third network function is any one of the following: access and mobility management function AMF, access management AM, security anchor function SEAF.

[0335] Optionally, the processing module 1402 is specifically used to determine the first key based on the second key and the first information; the first information is at least one of the following: terminal information, first request information, first network function information, network identification, and network security parameters.

[0336] Furthermore, the second key is carried in the first request, or the second key is pre-configured locally in the first network function.

[0337] In one possible design, processing module 1402 is specifically configured to determine a security key based on a first key and second information; the second information being at least one of the following: terminal information, first request information, first network function information, a network identifier, and network security parameters. In this manner, the second information can enhance the security of the security key and further ensure communication security between the terminal and the first network function.

[0338] In one possible design, the processing module 1402 is specifically configured to determine a third key for the first network function based on the first key and information of the first request; and determine a security key based on the third key.

[0339] Optionally, the processing module 1402 is specifically used to determine the security key based on the third key and the second information; the second information is at least one of the following: terminal information, first request information, first network function information, network identification, and network security parameters.

[0340] In an optional design solution, the transceiver module 1401 is further configured to send a first message to the terminal, where the first message includes information indicating a key of the first network function.

[0341] Optionally, the first message further includes: information for indicating an encryption algorithm, where the encryption algorithm is an algorithm used by the terminal for encryption.

[0342] Optionally, the transceiver module 1401 is further configured to receive a second message from the terminal, where the second message is used to indicate whether the terminal has determined the security key.

[0343] In one possible design, the second network function is AMF or AM.

[0344] Optionally, when the second network function is AMF, the first network function is at least one of the following: session management function SMF, policy control function PCF, positioning management function LMF, network data analysis function NWDAF, short message service function SMSF.

[0345] Optionally, when the second network function is AM, the first network function is at least one of the following: mobility management MM, proxy, load balancing LB.

[0346] Optionally, the transceiver module 1401 may include a receiving module and a sending module (not shown in FIG14 ). The transceiver module is used to implement the sending and receiving functions of the communication device 1400. Optionally, the communication device 1400 may further include a storage module (not shown in FIG14 ) that stores a program or instruction. When the processing module 1402 executes the program or instruction, the communication device 1400 can perform the function of the first network function in the communication method shown in any one of FIG6-FIG13 .

[0347] It should be understood that the processing module 1402 involved in the communication device 1400 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1401 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0348] It should be noted that the communication device 1400 can be a terminal device or a network device, or a chip (system) or other parts or components that can be set in the terminal device or network device, or a device that includes a terminal device or a network device. This application does not limit this.

[0349] In addition, the technical effects of the communication device 1400 can refer to the technical effects of the security key determination method shown in any one of Figures 6 to 13, and will not be repeated here.

[0350] In some other embodiments, the communication device 1400 may be applicable to the communication system shown in FIG. 4 , and perform the function of the second network function in the communication method shown in FIG. 6 to FIG. 13 .

[0351] The transceiver module 1401 is configured to receive a first request; the processing module 1402 is configured to obtain a first key for the first network function based on the first request; and the processing module 1402 is further configured to send the first key to the first network function. The second network function is used for terminal access management, the first request is used by the terminal to request service establishment with the first network function, or the first request is used by the terminal to request network access, the first network function is a network function other than the second network function in the network, and the first key is used to determine a security key used by the terminal to establish a secure connection with the first network function.

[0352] In one possible design scheme, the processing module 1402 is specifically used to generate a second request based on the first request; the transceiver module 1401 is further used to send the second request to the third network function; receive a first response from the third network function; the third network function is used to determine the key of the first network function, the second request is used to request the third network function to derive the key of the first network function, the first response carries the first key, and the first response is a response message to the second request.

[0353] In one possible design, the processing module 1402 is specifically configured to determine the first key according to the key of the second network function.

[0354] Optionally, the processing module 1402 is specifically used to determine the first key based on the key of the second network function and the first information; the first information is at least one of the following: terminal information, first request information, first network function information, network identification, and network security parameters.

[0355] In one possible design scheme, the first request is a service request, the second network function receives the first request, and the transceiver module 1401 is specifically used to receive the service request from the terminal, and the service request is used by the terminal to request to establish a service with the first network function; and send the service request carrying the first key to the first network function.

[0356] In one possible design scheme, the first request is an access request, the second network function receives the first request, and the transceiver module 1401 is specifically used to receive the access request from the terminal, and the access request is used by the terminal to request access to the network; and send the access request carrying the first key to the first network function.

[0357] In one possible design scheme, the second network function is the access and mobility management function AMF or access management AM.

[0358] Optionally, when the second network function is AMF, the first network function is at least one of the following: session management function SMF, policy control function PCF, positioning management function LMF, network data analysis function NWDAF, short message service function SMSF.

[0359] Optionally, when the second network function is AM, the first network function is at least one of the following: mobility management MM, proxy, load balancing LB.

[0360] Optionally, the transceiver module 1401 may include a receiving module and a sending module (not shown in FIG14 ). The transceiver module is used to implement the sending and receiving functions of the communication device 1400. Optionally, the communication device 1400 may further include a storage module (not shown in FIG14 ) that stores a program or instruction. When the processing module 1402 executes the program or instruction, the communication device 1400 can perform the function of the first network function in the communication method shown in any one of FIG6-FIG13 .

[0361] It should be understood that the processing module 1402 involved in the communication device 1400 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1401 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0362] It should be noted that the communication device 1400 can be a terminal device or a network device, or a chip (system) or other parts or components that can be set in the terminal device or network device, or a device that includes a terminal device or a network device. This application does not limit this.

[0363] In addition, the technical effects of the communication device 1400 can refer to the technical effects of the security key determination method shown in any one of Figures 6 to 13, and will not be repeated here.

[0364] In some other embodiments, the communication device 1400 may be applicable to the communication system shown in FIG. 4 , and perform the function of the third network function in the communication method shown in FIG. 6 to FIG. 13 .

[0365] Transceiver module 1401 is configured to receive a second request; processing module 1402 is configured to obtain a first key for a first network function based on the second request; and transceiver module 1401 is further configured to send a first response. The second request is used to request a third network function to derive a key for the first network function; the key for the first network function is used to determine a security key used by a terminal to establish a secure connection with the first network function; the first network function is a network function other than the second network function in the network; the second network function is used for terminal access management; the first response carries the first key, and the first response is a response message to the second request.

[0366] In one possible design, the transceiver module 1401 is specifically configured to receive a second request from a second network function; and send a first response to the second network function.

[0367] In one possible design, the transceiver module 1401 is specifically configured to receive a second request from the first network function; and send a first response to the first network function.

[0368] In one possible design, processing module 1402 is specifically configured to determine the first key based on the second key; the second key is a key of a third network function, and the key of the third network function is used to determine the key of the first network function.

[0369] Optionally, the processing module 1402 is specifically used to determine the first key based on the second key and the first information; the first information is at least one of the following: terminal information, first request information, first network function information, network identification, and network security parameters.

[0370] In one possible design scheme, the second network function is the access and mobility management function AMF or access management AM.

[0371] Optionally, when the second network function is AMF, the first network function is at least one of the following: session management function SMF, policy control function PCF, positioning management function LMF, network data analysis function NWDAF, short message service function SMSF.

[0372] Optionally, when the second network function is AM, the first network function is at least one of the following: mobility management MM, proxy, load balancing LB.

[0373] Optionally, the transceiver module 1401 may include a receiving module and a sending module (not shown in FIG14 ). The transceiver module is used to implement the sending and receiving functions of the communication device 1400. Optionally, the communication device 1400 may further include a storage module (not shown in FIG14 ) that stores a program or instruction. When the processing module 1402 executes the program or instruction, the communication device 1400 can perform the function of the first network function in the communication method shown in any one of FIG6-FIG13 .

[0374] It should be understood that the processing module 1402 involved in the communication device 1400 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1401 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0375] It should be noted that the communication device 1400 can be a terminal device or a network device, or a chip (system) or other parts or components that can be set in the terminal device or network device, or a device that includes a terminal device or a network device. This application does not limit this.

[0376] In addition, the technical effects of the communication device 1400 can refer to the technical effects of the security key determination method shown in any one of Figures 6 to 13, and will not be repeated here.

[0377] In some other embodiments, the communication device 1400 may be applicable to the communication system shown in FIG. 4 , and perform the functions of the terminal in the communication methods shown in FIG. 6 to FIG. 13 .

[0378] Transceiver module 1401 is configured to receive a first message from a first network function; processing module 1402 is configured to generate a second message; and transceiver module 1401 is further configured to send the second message to the first network function. The first message includes information indicating a key for the first network function, where the first network function is a network function other than the second network function in the network, and the second network function is configured to manage terminal access. The second message indicates whether the terminal has determined a security key for establishing a secure connection between the terminal and the first network function.

[0379] In one possible design scheme, the first message also includes information for indicating an encryption algorithm, where the encryption algorithm is the algorithm used for encryption by the terminal. The processing module 1402 is also used to determine the security key based on the information of the key of the first network function and the information for indicating the encryption algorithm.

[0380] In one possible design scheme, before receiving the first message from the first network function, the transceiver module 1401 is also used to send a first request to the second network function; the first request is used by the terminal to request to establish a service with the first network function, or the first request is used by the terminal to request to access the network.

[0381] In one possible design scheme, the second network function is the access and mobility management function AMF or access management AM.

[0382] Optionally, when the second network function is AMF, the first network function is at least one of the following: session management function SMF, policy control function PCF, positioning management function LMF, network data analysis function NWDAF, short message service function SMSF.

[0383] Optionally, when the second network function is AM, the first network function is at least one of the following: mobility management MM, proxy, load balancing LB.

[0384] Optionally, the transceiver module 1401 may include a receiving module and a sending module (not shown in FIG14 ). The transceiver module is used to implement the sending and receiving functions of the communication device 1400. Optionally, the communication device 1400 may further include a storage module (not shown in FIG14 ) that stores a program or instruction. When the processing module 1402 executes the program or instruction, the communication device 1400 can perform the function of the first network function in the communication method shown in any one of FIG6-FIG13 .

[0385] It should be understood that the processing module 1402 involved in the communication device 1400 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1401 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0386] It should be noted that the communication device 1400 can be a terminal device or a network device, or a chip (system) or other parts or components that can be set in the terminal device or network device, or a device that includes a terminal device or a network device. This application does not limit this.

[0387] In addition, the technical effects of the communication device 1400 can refer to the technical effects of the security key determination method shown in any one of Figures 6 to 13, and will not be repeated here.

[0388] For example, FIG15 is a second structural diagram of a communication device provided in an embodiment of the present application. The communication device may be a terminal device or a network device, or may be a chip (system) or other component or assembly that can be provided in a terminal device or a network device. As shown in FIG15 , the communication device 1500 may include a processor 1501. Optionally, the communication device 1500 may further include a memory 1502 and / or a transceiver 1503. The processor 1501 is coupled to the memory 1502 and the transceiver 1503, such as by a communication bus.

[0389] The following is a detailed introduction to the various components of the communication device 1500 with reference to FIG15 :

[0390] The processor 1501 is the control center of the communication device 1500 and can be a single processor or a collective term for multiple processing elements. For example, the processor 1501 can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0391] Optionally, the processor 1501 may execute various functions of the communication device 1500 by running or executing a software program stored in the memory 1502 and calling data stored in the memory 1502 .

[0392] In a specific implementation, as an embodiment, the processor 1501 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG15 .

[0393] In a specific implementation, as an embodiment, the communication device 1500 may also include multiple processors, such as the processor 1501 and the processor 1504 shown in FIG15 . Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0394] The memory 1502 is used to store the software program for executing the solution of the present application, and the execution is controlled by the processor 1501. The specific implementation method can refer to the above method embodiment and will not be repeated here.

[0395] Alternatively, the memory 1502 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1502 may be integrated with the processor 1501 or exist independently and be coupled to the processor 1501 via an interface circuit (not shown in FIG. 15 ) of the communication device 1500. This embodiment of the present application does not specifically limit this.

[0396] Transceiver 1503 is used for communication with other communication devices. For example, if communication device 1500 is a terminal device, transceiver 1503 can be used to communicate with a network device or another terminal device. For another example, if communication device 1500 is a network device, transceiver 1503 can be used to communicate with a terminal device or another network device.

[0397] Optionally, the transceiver 1503 may include a receiver and a transmitter (not shown separately in FIG15 ), wherein the receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.

[0398] Optionally, the transceiver 1503 can be integrated with the processor 1501, or can exist independently and be coupled to the processor 1501 through the interface circuit of the communication device 1500 (not shown in Figure 15). This embodiment of the present application does not specifically limit this.

[0399] It should be noted that the structure of the communication device 1500 shown in FIG15 does not constitute a limitation on the communication device. An actual communication device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0400] In addition, the technical effects of the communication device 1500 can refer to the technical effects of the communication method described in the above method embodiment, and will not be repeated here.

[0401] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0402] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0403] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0404] An embodiment of the present application also provides a communication chip having instructions stored therein. When the communication chip runs on a communication device, the method provided in the embodiment of the present application is implemented.

[0405] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0406] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0407] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0408] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0409] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0410] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0411] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0412] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0413] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0414] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A method for determining a security key, characterized in that: The method comprises: The first network function receives a first request; the first request is used by a terminal to request to establish a service with the first network function, or the first request is used by the terminal to request to access a network, the first network function is a network function other than the second network function in the network, and the second network function is used for access management of the terminal; The first network function obtains, according to the first request, a first key of the first network function; The first network function determines a security key according to the first key, and the security key is used for the terminal to establish a secure connection with the first network function.

2. The method according to claim 1, characterized in that The first network function acquiring, according to the first request, a first key of the first network function, including: The first network function sends a second request to a third network function according to the first request; the third network function is used to determine the key of the first network function, and the second request is used to request the third network function to derive the key of the first network function; The first network function receives a first response from the third network function, where the first response carries the first key and is a response message to the second request.

3. The method according to claim 1, characterized in that The first network function acquiring, according to the first request, a first key of the first network function, including: The first network function obtains a second key according to the first request; the second key is a key of a third network function, and the key of the third network function is used to determine the key of the first network function; The first network function determines the first key according to the second key.

4. The method according to claim 3, characterized in that The first network function determines the first key according to the second key, including: The first network function determines the first key according to the second key and first information; the first information is at least one of the following: information of the terminal, information of the first request, information of the first network function, an identifier of the network, and security parameters of the network.

5. The method according to any one of claims 1 to 4, characterized in that The first network function determines a security key according to the first key, including: The first network function determines a third key of the first network function according to the first key and information of the first request; The first network function determines the security key according to the third key.

6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: The first network function sends a first message to the terminal, where the first message includes information indicating a key of the first network function.

7. A method for determining a security key, characterized in that: The method comprises: The second network function receives the first request; the second network function is used for access management of the terminal, the first request is used by the terminal to request to establish a service with the first network function, or the first request is used by the terminal to request to access the network, and the first network function is other network function in the network except the second network function; The second network function obtains, according to the first request, a first key of the first network function, where the first key is used to determine a security key used by the terminal to establish a secure connection with the first network function; The second network function sends the first key to the first network function.

8. The method according to claim 7, characterized in that The second network function obtaining, according to the first request, a first key of the first network function, including: The second network function sends a second request to a third network function according to the first request; the third network function is used to determine the key of the first network function, and the second request is used to request the third network function to derive the key of the first network function; The second network function receives a first response from the third network function, where the first response carries the first key and is a response message to the second request.

9. The method according to claim 7, characterized in that: The second network function obtaining, according to the first request, a first key of the first network function, including: The second network function determines the first key according to the key of the second network function.

10. The method according to claim 9, characterized in that The second network function determines the first key according to the key of the second network function, including: The second network function determines the first key according to the key of the second network function and first information; the first information is at least one of the following: information of the terminal, information of the first request, information of the first network function, an identifier of the network, and a security parameter of the network.

11. A method for determining a security key, characterized in that: The method comprises: The third network function receives the second request; the second request is used to request the third network function to derive a key of the first network function, the key of the first network function is used to determine a security key used by the terminal to establish a secure connection with the first network function, the first network function is a network function other than the second network function in the network, and the second network function is used for access management of the terminal; The third network function obtains, according to the second request, a first key of the first network function; The third network function sends a first response, where the first response carries the first key, and the first response is a response message to the second request.

12. The method according to claim 11, characterized in that The third network function receives the second request, including: The third network function receives the second request from the second network function; The third network function sends the first response, including: The third network function sends the first response to the second network function.

13. The method according to claim 11, characterized in that The third network function receives the second request, including: The third network function receives the second request from the first network function; The third network function sends the first response, including: The third network function sends the first response to the first network function.

14. The method according to any one of claims 11 to 13, characterized in that The third network function acquiring, according to the second request, a first key of the first network function, comprising: The third network function determines the first key according to a second key, where the second key is the key of the third network function, and the key of the third network function is used to determine the key of the first network function.

15. The method according to claim 14, characterized in that The third network function determines the first key according to the second key, including: The third network function determines the first key according to the second key and first information; the first information is at least one of the following: information of the terminal, information of the first request, information of the first network function, an identifier of the network, and security parameters of the network.

16. A method for determining a security key, characterized in that: The method comprises: The terminal receives a first message from a first network function; the first message includes information for indicating a key of the first network function, the first network function is a network function other than a second network function in a network, and the second network function is used for access management of the terminal; The terminal sends a second message to the first network function, where the second message is used to indicate whether the terminal has determined a security key for establishing a secure connection between the terminal and the first network function.

17. The method according to claim 16, characterized in that The first message further includes information for indicating an encryption algorithm, where the encryption algorithm is an algorithm used for encryption by the terminal, and the method further includes: The terminal determines the security key according to the information of the key of the first network function and the information indicating the encryption algorithm.

18. The method according to claim 16 or 17, characterized in that Before the terminal receives the first message from the first network function, the method further includes: The terminal sends a first request to the second network function; the first request is used by the terminal to request to establish a service with the first network function, or the first request is used by the terminal to request to access the network.

19. A communication device, characterized in that: The device comprises: a transceiver module, configured to receive a first request; the first request is used by the terminal to request to establish a service with the first network function, or the first request is used by the terminal to request to access the network, the first network function is a network function other than the second network function in the network, and the second network function is used for access management of the terminal; a processing module, configured to obtain a first key of the first network function according to the first request; The processing module is further used to determine a security key based on the first key, where the security key is used to establish a secure connection between the terminal and the first network function.

20. The device according to claim 19, characterized in that The processing module is specifically used to generate a second request according to the first request; the transceiver module is further used to send the second request to a third network function; the third network function is used to determine the key of the first network function, and the second request is used to request the third network function to derive the key of the first network function; A first response is received from the third network function, where the first response carries the first key, and the first response is a response message to the second request.

21. The device according to claim 19, characterized in that The processing module is specifically configured to obtain a second key according to the first request; the second key is a key of a third network function, and the key of the third network function is used to determine the key of the first network function; The first key is determined according to the second key.

22. The device according to claim 21, characterized in that The processing module is specifically used to determine the first key based on the second key and first information; the first information is at least one of the following: information of the terminal, information of the first request, information of the first network function, an identifier of the network, and security parameters of the network.

23. The device according to any one of claims 19 to 22, characterized in that The processing module is specifically configured to determine a third key of the first network function according to the first key and information of the first request; and determine the security key according to the third key.

24. The device according to any one of claims 19 to 23, characterized in that The transceiver module is further used to send a first message to the terminal, where the first message includes information indicating a key of the first network function.

25. A communication device, characterized in that: The device comprises: a transceiver module, configured to receive a first request; the first request is used by a terminal to request to establish a service with a first network function, or the first request is used by the terminal to request to access a network, the first network function is a network function other than the second network function in the network, and the second network function is used for access management of the terminal; a processing module, configured to obtain, according to the first request, a first key of the first network function, where the first key is used to determine a security key used by the terminal to establish a secure connection with the first network function; The transceiver module is further used to send the first key to the first network function.

26. The device according to claim 25, characterized in that The processing module is specifically used to generate a second request according to the first request; the transceiver module is further used to send the second request to a third network function; the third network function is used to determine the key of the first network function, and the second request is used to request the third network function to derive the key of the first network function; A first response is received from the third network function, where the first response carries the first key, and the first response is a response message to the second request.

27. The device according to claim 25, characterized in that The processing module is specifically configured to determine the first key according to the key of the second network function.

28. The device according to claim 27, characterized in that The processing module is specifically used to determine the first key based on the key of the second network function and the first information; the first information is at least one of the following: information of the terminal, information of the first request, information of the first network function, an identifier of the network, and security parameters of the network.

29. A communication device, characterized in that: The device comprises: a transceiver module, configured to receive a second request; the second request is used to request the third network function to derive a key of a first network function, the key of the first network function is used to determine a security key used by a terminal to establish a secure connection with the first network function, the first network function is a network function other than the second network function in the network, and the second network function is used for access management of the terminal; a processing module, configured to obtain a first key of the first network function according to the second request; The transceiver module is further used to send a first response, where the first response carries the first key and the first response is a response message to the second request.

30. The device according to claim 29, characterized in that The transceiver module is specifically used to receive the second request from the second network function; and send the first response to the second network function.

31. The device according to claim 29, characterized in that The transceiver module is specifically used to receive the second request from the first network function; and send the first response to the first network function.

32. The device according to any one of claims 29 to 31, characterized in that The processing module is specifically configured to determine the first key according to a second key, where the second key is a key of the third network function, and the key of the third network function is used to determine the key of the first network function.

33. The device according to claim 32, characterized in that The processing module is specifically used to determine the first key based on the second key and first information; the first information is at least one of the following: information of the terminal, information of the first request, information of the first network function, an identifier of the network, and security parameters of the network.

34. A communication device, characterized in that: The device comprises: a transceiver module, configured to receive a first message from a first network function; the first message includes information for indicating a key of the first network function, the first network function is a network function other than a second network function in a network, and the second network function is used for access management of a terminal; a processing module, configured to generate a second message, wherein the second message is used to indicate whether the terminal has determined a security key for establishing a secure connection between the terminal and the first network function; The transceiver module is further used to send a second message to the first network function.

35. The device according to claim 34, characterized in that The first message also includes information for indicating an encryption algorithm, where the encryption algorithm is an algorithm used for encryption by the terminal. The processing module is further used to determine the security key based on the information of the key of the first network function and the information for indicating the encryption algorithm.

36. The device according to claim 34 or 35, characterized in that Before receiving the first message from the first network function, the transceiver module is also used to send a first request to the second network function; the first request is used by the terminal to request to establish a service with the first network function, or the first request is used by the terminal to request to access the network.

37. A communication device, characterized in that: include: A processor and a communication interface, the processor being used to execute computer instructions, the communication interface being used to communicate, so that the method as claimed in any one of claims 1 to 6 is implemented, or the method as claimed in any one of claims 7 to 10 is implemented, or the method as claimed in any one of claims 11 to 15 is implemented, or the method as claimed in any one of claims 16 to 18 is implemented.

38. A communication device, characterized in that: include: A memory and a processor, the memory being used to store computer instructions, the processor being used to execute the computer instructions, so that the method according to any one of claims 1 to 6 is implemented, or the method according to any one of claims 7 to 10 is implemented, or the method according to any one of claims 11 to 15 is implemented, or the method according to any one of claims 16 to 18 is implemented.

39. A communication system, characterized in that: The communication system includes at least one of the following: a first network function for executing the method according to any one of claims 1 to 6, a second network function for executing the method according to any one of claims 7 to 10, a third network function for executing the method according to any one of claims 11 to 15, and a terminal for executing the method according to any one of claims 16 to 18.

40. A communication chip, characterized in that: Instructions are stored therein, and when the chip runs on a communication device, the method as claimed in any one of claims 1 to 6 is implemented, or the method as claimed in any one of claims 7 to 10 is implemented, or the method as claimed in any one of claims 11 to 15 is implemented, or the method as claimed in any one of claims 16 to 18 is implemented.

41. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a computer program or instructions, which, when executed on a computer, causes the computer to execute the method according to any one of claims 1 to 6, or the method according to any one of claims 7 to 10, or the method according to any one of claims 11 to 15, or the method according to any one of claims 16 to 18.

42. A computer program product, characterized in that The computer program product includes a computer program or instructions, and when the computer program or instructions are executed by a communication device, the method according to any one of claims 1 to 6 is executed, or the method according to any one of claims 7 to 10 is executed, or the method according to any one of claims 11 to 15 is executed, or the method according to any one of claims 16 to 18 is executed.