Information transmission method, communication system and communication device
Patent Information
- Application Number
- CN202380100332.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-31
- Publication Date
- 2026-02-13
AI Technical Summary
The security functions and communication functions in existing communication protocols are tightly coupled, resulting in complex deployment and update of security functions, and it is difficult to evolve independently and flexibly deploy.
Introducing independent security nodes is responsible for providing security functions and establishing communication connections with network nodes, transmitting trusted signaling and data, and realizing the decoupling of security and communication.
Through independent security nodes to manage and execute security functions, the deployment and update of security functions are simplified, the flexibility and independence of security functions are improved, and the dependence on communication protocols is reduced.
Smart Images

Figure CN121533053A_ABST
Abstract
Description
Information transmission method, communication system and communication device Technical Field
[0001] The embodiments of the present application relate to the field of wireless communication technologies, and more specifically, to an information transmission method, a communication system, and a communication device. Background Art
[0002] Currently, network communication protocols can be roughly divided into two categories: those responsible for connection and those responsible for communication services. Security is integrated into the functionality of multiple protocols. Security and communication functions are tightly coupled, so updating or upgrading security features requires modifying the protocols of multiple communication nodes, such as terminals, access network equipment, and core network devices. This is a labor-intensive and complex task. Addressing the numerous issues arising from the current deployment of security features in existing communication protocols is a worthy consideration.
[0003] Summary of the Invention
[0004] The embodiments of the present application provide a solution that, by introducing independent nodes to support security functions, can achieve decoupling of security and communication, which is conducive to the independent evolution and flexible deployment of security functions.
[0005] In a first aspect, a method for information transmission is provided. This method can be performed by a security node. The security node can be a communication device (such as a terminal device, an access network device, a core network device, or a cloud server), or a chip or circuit used in a communication device, although this application does not limit this. The following description uses the first security node as an example.
[0006] The method is applied to a communication network, which includes a first security node and at least one network node. The first security node is used to provide security functions for the communication network. The method includes: the first security node establishes a communication connection with the at least one network node; the first security node transmits trusted signaling and / or trusted data with the at least one network node through the communication connection.
[0007] Based on the above technical solution, security functions in the communication network can be provided by independent security nodes. Specifically, the security nodes are independently deployed and establish a communication connection with the network nodes. This communication connection allows the security nodes and the network nodes to transmit trusted signaling and / or trusted data, enabling the security nodes to provide security functions for the communication system. Furthermore, the independent deployment of the security nodes decouples security from communication, facilitating the independent evolution and flexible deployment of security functions.
[0008] In certain implementations of the first aspect, the first security node includes a first node and / or a second node, the first node is used to manage the security function, and the second node is used to execute the security function.
[0009] Based on the above technical solution, a standalone first node can be designed to manage security functions. This allows the standalone security node to centrally control security functions, simplifying operations. Alternatively, a standalone second node can be designed to execute security functions, allowing other network nodes to focus on communication functions and improving operational efficiency.
[0010] In some implementations of the first aspect, the first security node includes a trusted protocol layer that processes trusted signaling and / or trusted data.
[0011] Based on the above technical solution, a trusted protocol layer is configured for independently deployed security nodes, which can provide standardized and more diversified security technologies, provide more flexible and advanced security support for communication networks, and enable other communication protocols to focus on communication functions.
[0012] In certain implementations of the first aspect, the first security node also includes one or more of the following protocol layers located below the trusted protocol layer: a protocol layer for data packet processing, a protocol layer for transmission, a protocol layer for establishing a connection, and a protocol layer for establishing a channel.
[0013] In combination with the first aspect, in some implementations of the first aspect, trusted signaling is used for one or more of the following functions: management of trusted functions, management of trusted requirements, negotiation of trusted policies, notification of trusted services, or request for trusted services.
[0014] In certain implementations of the first aspect, the management of the trusted function includes one or more of the following: establishment of the trusted function, activation of the trusted function, initial configuration of the trusted function, update of the trusted function, addition of the trusted function, deletion of the trusted function, or transition of the state of the trusted function.
[0015] Based on the above technical solutions, the security node provided by this application can support the management of trusted capabilities, making trusted capabilities more flexible and diverse.
[0016] In certain implementations of the first aspect, the trusted service includes one or more of the following: an authentication service, an authorization service, a trust measurement service, a blockchain service, a situational awareness service, or a network-global trust policy service.
[0017] Based on the above technical solutions, the security nodes provided by this application can support a variety of trusted services, improving diverse and rich security support.
[0018] In certain implementations of the first aspect, the trusted data includes one or more of the following: situational awareness-related data, homomorphic encryption-related data, homomorphic computing-related data, blockchain-related data, or a key.
[0019] In certain implementations of the first aspect, at least one network node includes a first network node, and the first security node establishes a communication connection with the at least one network node, including: the first security node obtains identity information and / or address information of the first network node; the first security node transmits trusted signaling and / or trusted data with the first network node based on the identity information and / or address information of the first network node.
[0020] Based on the above technical solution, the security node can obtain the identity information and / or address information of the network node, and then communicate with the network node based on the identity information and / or address information, such as transmitting trusted signaling and / or trusted data.
[0021] In certain implementations of the first aspect, the first security node obtains the identity information and / or address information of the first network node, including any one of the following: the first security node receives the identity information and / or address information of the first network node from the first network node; the first security node receives the identity information and / or address information of the first network node from other network nodes; the first security node determines the identity information and / or address information of the first network node by itself; the first security node receives the identity information and / or address information of the first network node from a management node; or, the first security node receives the identity information and / or address information of the first network node from other security nodes.
[0022] Optionally, the management node is a node that manages identity information and / or address information of each node. As an example, the management node is an operation administration and maintenance (OAM) system.
[0023] Based on the above technical solution, the security node can obtain the identity information and / or address information of the network node through various means, such as from the network node, other security nodes, etc.
[0024] In certain implementations of the first aspect, the method further includes: the first security node sending one or more of the following to the first network node: trusted services that the first security node can provide, identity information of the first security node, or address information of the first security node.
[0025] Based on the above technical solution, the security node can also provide its identity information and / or address information to the network node, facilitating the network node's transmission of trusted signaling and / or trusted data. Alternatively, the security node can also provide the network node with information about the trusted services it can provide, allowing the network node to perform certain operations based on the trusted services provided by the security node. For example, the network node can verify whether the security node meets its trust requirements based on the trusted services it provides. For another example, in subsequent communications, the network node can request corresponding security functions from the security node based on the trusted services it provides.
[0026] In certain implementations of the first aspect, the communication network further includes a second security node, and the method further includes: the first security node transmitting trusted signaling and / or trusted data with the second security node.
[0027] Based on the above technical solution, security nodes can have communication connections and transmit trusted signaling and / or trusted data.
[0028] In certain implementations of the first aspect, before the first security node transmits trusted signaling and / or trusted data with the second security node, the method further includes: the first security node obtaining identity information and / or address information of the second security node.
[0029] In certain implementations of the first aspect, the first security node obtains the identity information and / or address information of the second security node, including any one of the following: the first security node receives the identity information and / or address information of the second security node from the second security node; the first security node receives the identity information and / or address information of the second security node from at least one network node; the first security node determines the identity information and / or address information of the second security node by itself; the first security node receives the identity information and / or address information of the second security node from the management node; or, the first security node receives the identity information and / or address information of the second security node from other security nodes.
[0030] Optionally, the management node is a node that manages identity information and / or address information of each node. As an example, the management node is an OAM system.
[0031] Based on the above technical solution, the security node (i.e., the first security node) can obtain the identity information and / or address information of the opposite security node (i.e., the second security node) through various means, such as from network nodes, other security nodes, etc.
[0032] In certain implementations of the first aspect, the method further includes: the first security node sending one or more of the following to the second security node: trusted services that the first security node can provide, identity information of the first security node, or address information of the first security node.
[0033] Based on the above technical solution, a security node (i.e., the first security node) can also provide its identity information and / or address information to a peer security node (i.e., the second security node), thereby facilitating the peer security node's transmission of trusted signaling and / or trusted data. Alternatively, the security node can also provide the peer security node with its own trusted services, allowing the peer security node to perform security-related operations based on the trusted services provided by the security node.
[0034] In certain implementations of the first aspect, the method further includes: the first security node receiving, from the second security node, a trusted service that the second security node can provide.
[0035] Based on the above technical solution, the peer security node (i.e., the second security node) can also provide its identity information and / or address information to the security node (i.e., the first security node), thereby facilitating the security node to transmit trusted signaling and / or trusted data to the peer security node. Alternatively, the peer security node can also provide the security node with trusted services it can provide, thereby facilitating the security node to determine the trusted services it can provide based on this information.
[0036] In combination with the first aspect, in some implementations of the first aspect, at least one network node includes one or more of the following: at least one access network device, at least one core network device, and at least one terminal device.
[0037] In a second aspect, a method for information transmission is provided. This method can be performed by a network node (e.g., a terminal, an access network node, or a core network node). The network node can be a communications device, or a chip or circuit for a communications device, which is not limited in this application. The following description uses a first network node as an example.
[0038] The method is applied to a communication network, which includes a first network node and a first security node. The first security node is used to provide security functions for the communication network. The method includes: the first network node establishes a communication connection with the first security node; the first network node transmits trusted signaling and / or trusted data with the first security node through the communication connection.
[0039] In some implementations of the second aspect, the first network node includes a trusted protocol layer that processes trusted signaling and / or trusted data.
[0040] In certain implementations of the second aspect, the first network node further includes one or more of the following protocol layers below the trusted protocol layer: a protocol layer for data packet processing, a protocol layer for transmission, a protocol layer for establishing a connection, and a protocol layer for establishing a channel.
[0041] In certain implementations of the second aspect, the trusted signaling is used for one or more of the following functions: management of trusted functions, management of trusted requirements, negotiation of trusted policies, notification of trusted services, or request of trusted services.
[0042] In certain implementations of the second aspect, the management of the trusted function includes one or more of the following: establishment of the trusted function, activation of the trusted function, initial configuration of the trusted function, update of the trusted function, addition of the trusted function, deletion of the trusted function, or transition of the state of the trusted function.
[0043] In certain implementations of the second aspect, the trusted service includes one or more of the following: an authentication service, an authorization service, a trust measurement service, a blockchain service, a situational awareness service, or a network-global trust policy service.
[0044] In certain implementations of the second aspect, the trusted data includes one or more of the following: situational awareness-related data, homomorphic encryption-related data, homomorphic computing-related data, blockchain-related data, and keys.
[0045] In certain implementations of the second aspect, the first network node establishes a communication connection with the first security node, including: the first network node obtains identity information and / or address information of the first security node; and the first network node transmits trusted signaling and / or trusted data with the first security node based on the identity information and / or address information of the first security node.
[0046] In certain implementations of the second aspect, the first network node obtains the identity information and / or address information of the first security node, including any one of the following: the first network node receives the identity information and / or address information of the first security node from the first security node; the first network node receives the identity information and / or address information of the first security node from other network nodes; the first network node determines the identity information and / or address information of the first security node by itself; the first network node receives the identity information and / or address information of the first security node from a management node, or the first network node receives the identity information and / or address information of the first security node from other security nodes.
[0047] In certain implementations of the second aspect, the method further includes: the first network node sending one or more of the following to the first security node: identity information of the first network node, or address information of the first network node.
[0048] In certain implementations of the second aspect, the first network node transmits trusted signaling and / or trusted data with the first security node through a communication connection, including: the first network node receives a trusted service that the first security node can provide from the first security node.
[0049] In certain implementations of the second aspect, the first network node is any one of the following: an access network device, a core network device, and a terminal device.
[0050] The beneficial effects of the second aspect can be referred to the relevant description in the first aspect and will not be repeated here.
[0051] In a third aspect, a communication system is provided. The system includes at least one security node and at least one network node. The at least one security node is configured to provide security functions for the communication system. The at least one security node establishes a communication connection with at least one network node. The at least one security node transmits trusted signaling and / or trusted data with the at least one network node via the communication connection.
[0052] In certain implementations of the third aspect, the at least one security node includes a first security node, and the first security node is used to execute the method of the first aspect.
[0053] In some implementations of the third aspect, the at least one network node includes a first network node, and the first network node is configured to execute the method of the second aspect.
[0054] In a fourth aspect, a method for information transmission is provided. This method can be performed by a security node. The security node can be a communication device (such as a terminal device, an access network device, a core network device, or a cloud server), or a chip or circuit used in a communication device, which is not limited in this application. The following description uses the first security node as an example.
[0055] The method includes: a first security node receives a request message from a network node, the request message includes an identifier of a prover, and the request message is used to request provision of a trusted measurement service; the first security node obtains a measurement result of the trusted measurement based on the identifier of the prover; and the first security node sends the measurement result of the trusted measurement to the network node.
[0056] The first security node is the security node described in the first aspect.
[0057] Based on the above technical solution, a secure process for trusted measurement is provided, which may be supported by future mobile networks. Specifically, trusted measurement services can be provided by independently deployed security nodes. Compared with the traditional process of nodes invoking security functions, trust measurement services provided by secure nodes are more secure and flexible.
[0058] In certain implementations of the fourth aspect, the first security node obtains the measurement result of the trust metric based on the identifier of the prover, including: the first security node obtains the measurement result of the trust metric through local query based on the identifier of the prover.
[0059] In certain implementations of the fourth aspect, the first security node obtains a measurement result of the trusted metric based on the identifier of the prover, including: the first security node obtains a trusted proof parameter based on the identifier of the prover; the first security node sends the trusted proof parameter to the second security node; the first security node receives the measurement result of the trusted metric from the second security node, and the measurement result of the trusted metric is determined based on the trusted proof parameter.
[0060] Based on the above technical solution, compared to the traditional process of nodes invoking security functions, a secure node (such as a second secure node) provides the relevant parameters for the trust metric, reducing the workload of the traditional node and allowing it to focus on communication. Furthermore, having the secure node provide the relevant parameters for the trust metric avoids security issues caused by the exchange of these parameters between communicating nodes, thereby improving the security of the relevant parameters for the trust metric.
[0061] In certain implementations of the fourth aspect, the first security node obtains a measurement result of the trusted metric based on the identifier of the prover, including: the first security node obtains a trusted proof parameter based on the identifier of the prover; the first security node sends the trusted proof parameter to the second security node; the first security node receives the measurement result of the trusted metric to be verified from the second security node, and the measurement result of the trusted metric to be verified is determined based on the trusted proof parameter; the first security node determines the measurement result of the trusted metric based on the measurement result of the trusted metric to be verified.
[0062] Based on this technical solution, compared to the traditional process of nodes invoking security functions, a security node (such as a second security node) provides the relevant parameters for the trust measurement, reducing the workload of the traditional node and allowing it to focus on communication. In addition, verification by the first security node improves the security of the measurement results.
[0063] A fifth aspect provides a method for information transmission. This method can be performed by a security node. The security node can be a communications device, or a chip or circuit used in a communications device, though this application does not limit this. The following description uses the second security node as an example.
[0064] The method includes: a second security node receives a request message from a first security node, where the request message is used to indicate the addition of a post-quantum cryptography (PQC) algorithm; the second security node updates a trusted service list based on the request message, where the updated trusted service list of the second security node includes the PQC algorithm.
[0065] Based on the above technical solution, the PQC algorithm can be introduced into the communication network, so that the threat posed by quantum computing in the communication network can be reduced through the PQC algorithm.
[0066] In certain implementations of the fifth aspect, the method further includes: the second security node sending the trusted service list updated by the second security node to the access network device.
[0067] In certain implementations of the fifth aspect, the method further includes: the second security node receives a plaintext message; the second security node performs an encryption operation on the plaintext message based on a PQC algorithm to obtain a ciphertext message; and the second security node sends the ciphertext message to a third security node.
[0068] Based on the above technical solution, the relevant operations of the PQC algorithm can be performed by the security node, which not only improves security but also reduces the computing energy consumption and overhead of the communication node.
[0069] In certain implementations of the fifth aspect, the method further includes: the second security node receiving the ciphertext message; and the second security node performing a decryption operation on the ciphertext message based on a PQC algorithm to obtain a plaintext message.
[0070] In certain implementations of the fifth aspect, the method further includes: the second security node sending a plaintext message to the access network device.
[0071] In certain implementations of the fifth aspect, the access network device is an access network device serving the second security node.
[0072] It should be understood that the various implementations of each of the above-mentioned first to fifth aspects can be referenced to each other.
[0073] In a sixth aspect, a communication device is provided, comprising modules or units for executing the methods in any one of the first to fifth aspects, or any possible implementation of any one of the aspects.
[0074] In the seventh aspect, a communication device is provided, comprising at least one processor, wherein the at least one processor is used to execute a computer program or instruction, and / or, through a logic circuit, so that the communication device performs a method as in any aspect of the first to fifth aspects, or any possible implementation of these aspects.
[0075] In certain implementations of the seventh aspect, at least one processor is coupled to at least one memory, wherein the at least one memory stores the computer program or instructions. Optionally, the communication device further includes the at least one memory. Optionally, the at least one processor and the at least one memory are integrated.
[0076] In an eighth aspect, a chip is provided, comprising a processor and a communication interface, wherein the communication interface is used to receive information and / or data to be processed and send the information and / or data to be processed to the processor, and the processor is used to process the information and / or data to be processed, so that a communication device in which the chip is installed executes a method as in any aspect of the first to fifth aspects, or any possible implementation of these aspects.
[0077] In a ninth aspect, a computer-readable storage medium is provided, in which computer instructions are stored. When the computer instructions are executed on a computer, the method of any one of the first to fifth aspects, or any possible implementation of these aspects, is implemented.
[0078] In a tenth aspect, a computer program product is provided, which includes a computer program code. When the computer program code is run on a computer, the method in any aspect from the first to the fifth aspect, or any possible implementation of these aspects, is implemented.
[0079] In the eleventh aspect, a wireless communication system is provided, comprising the communication device as described in the sixth aspect or the seventh aspect.
[0080] The technical effects of the technical solutions of aspects 6 to 11 can be referred to the description of the corresponding technical effects of aspects 1 to 5 and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0081] Figure 1 is a schematic diagram of the 5G network protocol stack.
[0082] FIG2 is a schematic diagram of a network architecture in which a security node provided in an embodiment of the present application is an independent node.
[0083] FIG3 is a schematic diagram of an interface of a security node provided in an embodiment of the present application.
[0084] FIG4 is a schematic diagram of an information transmission method 400 provided in an embodiment of the present application.
[0085] FIG5 is a schematic diagram of an end-to-end protocol stack proposed in an embodiment of the present application.
[0086] FIG6 is a schematic diagram of a trusted protocol stack between security node #1 and a network node provided in an embodiment of the present application.
[0087] FIG7 is another schematic diagram of the trusted protocol stack of the security node #1 and the network node provided in an embodiment of the present application.
[0088] FIG8 is a schematic flow chart of configuring trusted functions on demand at security node #1.
[0089] FIG9 is a schematic flowchart of security node #1 providing trusted services.
[0090] Figure 10 is a schematic diagram of a trusted protocol stack between security nodes #1 provided in an embodiment of the present application.
[0091] Figure 11 is another schematic diagram of the trusted protocol stack between security nodes #1 provided in an embodiment of the present application.
[0092] FIG12 is a schematic flowchart of hierarchical management of security node #1.
[0093] FIG13 is a schematic flow chart of hierarchical control of security node #1.
[0094] FIG14 is a schematic flowchart of security node #1 providing trusted services.
[0095] Figure 15 is a schematic diagram of the trusted protocol stack between the security node #2 and the network node provided in an embodiment of the present application.
[0096] Figure 16 is another schematic diagram of the trusted protocol stack between the security node #2 and the network node provided in an embodiment of the present application.
[0097] FIG17 is a schematic flow chart of on-demand configuration of trusted functions by security node #2.
[0098] FIG18 is a schematic flowchart of security node #2 providing trusted services.
[0099] Figure 19 is a schematic diagram of a trusted protocol stack between security nodes #2 provided in an embodiment of the present application.
[0100] Figure 20 is another schematic diagram of the trusted protocol stack between security nodes #2 provided in an embodiment of the present application.
[0101] FIG21 is a schematic flowchart of the negotiation of the trust policy of security node #2.
[0102] FIG22 is a schematic flowchart of security node #2 providing trusted services.
[0103] FIG23 is a schematic flow chart of information subscription provided by security node #2.
[0104] Figure 24 is a schematic diagram of the trusted protocol stack between security node #1 and security node #2 provided in an embodiment of the present application.
[0105] Figure 25 is another schematic diagram of the trusted protocol stack between security node #1 and security node #2 provided in an embodiment of the present application.
[0106] FIG26 is a schematic flowchart of how safety node #1 manages safety node #2.
[0107] FIG27 is a schematic flowchart of security node #1 providing trusted services.
[0108] FIG28 is a schematic flow chart of establishing a communication connection between security node #1 and a network node.
[0109] FIG29 is another schematic flow chart of establishing a communication connection between security node #1 and a network node.
[0110] FIG30 is another schematic flowchart of establishing a communication connection between security node #1 and a network node.
[0111] FIG31 is a schematic flow chart of establishing a communication connection between security node #2 and a network node.
[0112] FIG32 is another schematic flow chart of establishing a communication connection between security node #2 and a network node.
[0113] FIG33 is another schematic flow chart of establishing a communication connection between security node #2 and a network node.
[0114] FIG34 is another schematic flow chart of establishing a communication connection between security node #2 and a network node.
[0115] FIG35 is another schematic flow chart of establishing a communication connection between security node #2 and a network node.
[0116] FIG36 is a schematic flow chart of establishing a communication connection between security nodes #1.
[0117] FIG37 is another schematic flow chart of establishing a communication connection between safety nodes #1.
[0118] FIG38 is another schematic flow chart of establishing a communication connection between safety nodes #1.
[0119] FIG39 is a schematic flow chart of establishing a communication connection between security nodes #2.
[0120] FIG40 is another schematic flow chart of establishing a communication connection between safety nodes #2.
[0121] FIG41 is another schematic flow chart of establishing a communication connection between safety nodes #2.
[0122] FIG42 is a schematic flow chart of establishing a communication connection between safety node #1 and safety node #2.
[0123] FIG43 is another schematic flowchart of establishing a communication connection between safety node #1 and safety node #2.
[0124] FIG44 is another schematic flowchart of establishing a communication connection between safety node #1 and safety node #2.
[0125] FIG45 is another schematic flowchart of establishing a communication connection between safety node #1 and safety node #2.
[0126] Figure 46 is a schematic flowchart of the trust measurement provided in an embodiment of the present application.
[0127] Figure 47 is a schematic flowchart of the configuration encryption algorithm provided in an embodiment of the present application.
[0128] FIG48 is a schematic flow chart of the application of the PQC algorithm.
[0129] Figure 49 is a schematic diagram of a hybrid mode network architecture.
[0130] Figure 50 is a schematic diagram of the interface of a node under a hybrid mode network architecture.
[0131] Figure 51 is a schematic diagram of a trusted protocol stack of a base station including a security function module engine.
[0132] Figure 52 is a schematic diagram of a trusted protocol stack of a base station including a security function module gear.
[0133] Figure 53 is a schematic diagram of a trusted protocol stack of a base station including security function modules gear and engine.
[0134] Figure 54 is a schematic diagram of a communication device provided in an embodiment of the present application.
[0135] Figure 55 is a schematic diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0136] The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings.
[0137] The technical solutions provided in this application can be applied to various communication systems, such as fifth generation (5G) or satellite communication systems, sixth generation (6G) mobile communication systems, and other communication systems evolved after 5G, such as new radio (NR) systems, or fusion systems of multiple systems. The technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.
[0138] A node in a communication system can send signals to or receive signals from another node. The signals may include information, signaling, or data. The term "node" may also be replaced by an entity, network entity, device, communication device, communication module, network element, communication node, etc. This disclosure uses a node as an example for description.
[0139] In order to facilitate understanding of the technical solution of this application, relevant technical concepts involved in the embodiments of this application are introduced.
[0140] Existing network communication protocols can be roughly divided into two categories: connection-related protocols and communication-related protocols. Connection-related protocols include, but are not limited to, the physical layer (PHY), medium access control (MAC), radio link control (RLC), packet data convergence protocol (PDCP), internet protocol (IP) layer, stream control transmission protocol (SCTP), and transmission control protocol (TCP). Communication-related protocols include, but are not limited to, radio resource control (RRC), non-access stratum (NAS), Xn application protocol (XnAP), NG application protocol (NGAP), and service data adaptation protocol (SDAP). Xn represents the Xn interface, which supports message exchange between next-generation NodeBs (gNBs) and NG-evolved NodeBs (NG-eNBs). The NG interface is the interface between the gNB or NG-eNB and the core network.
[0141] Figure 1 is a schematic diagram of the 5G network protocol stack. As shown in Figure 1, the marked protocol layers in the protocol stack (i.e., the gray-filled protocol layers) have security functions. For example, the NAS protocol supports security algorithm selection, authentication of user equipment (UE) by the core network, and encryption / decryption and integrity protection of messages between the core network and the UE. For another example, the PDCP protocol supports encryption / decryption and integrity protection functions of air interface messages. For another example, the Internet protocol security (IPSec) supports encryption / decryption and integrity protection functions between base stations and network functions (NF) of the core network. For another example, the transport layer security (TLS) protocol supports authentication, encryption / decryption and integrity protection functions between NFs of the core network. Among them, with regard to the NF of the core network, reference can be made to the relevant definitions of existing protocols or future protocols, and this is not limited. As an example, the NF of the core network includes but is not limited to: unified data management (UDM), network exposure function (NEF), network storage function (NF repository function, NRF), policy control function (PCF), application function (AF), access and mobility management function (AMF), session management function (SMF), and user plane function (UPF).
[0142] As shown in Figure 1, security functions are dispersed across multiple protocols and are tightly coupled with communication protocols. Updating security functions requires modifying multiple protocols across multiple communication nodes. Furthermore, the variety of security functions is limited, primarily supporting encryption / decryption and integrity protection.
[0143] In view of this, this application proposes that a protocol specifically supporting security functions can be designed to address the problem that existing security functions are tightly coupled with communication protocols and lack the ability to be independently upgraded or updated. In addition, the security function-related protocol proposed in this application (referred to as a trusted protocol or security protocol in this application) can support multiple security technologies and the management of security technologies.
[0144] It is understood that the names of network elements, protocol layers, names of data units corresponding to some protocol layers, names of interfaces between network elements, etc. involved in this application are only examples. In future communication networks, the names of these network elements, protocol layers, names of data units corresponding to protocol layers, names of interfaces between network elements, etc. may also adopt other names. As long as they have the same or similar functions and achieve the same or similar technical purposes, they should all fall within the technical scope covered by this application. For example, in a 5G network, a network function may be represented as NF, a terminal device may also be referred to as UE, a medium access control layer may be represented as MAC layer, a protocol data unit may be represented as PDU, a service data unit may be represented as SDU, etc. In a 6G network, these names may also adopt new names.
[0145] For the sake of brevity in description, the following embodiments describe network elements, protocol layers, data units corresponding to some protocol layers, etc., using some abbreviations as examples. However, these abbreviations are only examples and can be replaced with other abbreviations or names without limitation.
[0146] The technical solution provided by this application is described in detail below.
[0147] First, the communication system proposed in this application is introduced.
[0148] An embodiment of the present application provides a communication system, which includes at least one security node and at least one network node. The at least one security node is used to provide security functions for the communication system. The at least one security node establishes a communication connection with the at least one network node. The at least one security node and the at least one network node can transmit trusted signaling and / or trusted data based on the communication connection.
[0149] Based on the embodiments of the present application, security functions can be supported by security nodes. Specifically, by designing independently deployed security nodes and establishing communication connections between these independently deployed security nodes and network nodes, not only can the security nodes provide security functions for the communication system, but they can also achieve the decoupling of security and communication, which is conducive to the independent evolution and flexible deployment of security functions.
[0150] Optionally, the at least one network node includes one or more of the following: at least one access network device, at least one core network device, and at least one terminal device. Based on this, the network node can be an access network device or a component of an access network device (such as a chip, a chip system, a logic module, a circuit, etc.); or a core network device or a component of a core network device (such as a chip, a chip system, a logic module, a circuit, etc.); or a terminal device or a component of a terminal device (such as a chip, a chip system, a logic module, a circuit, etc.).
[0151] In an embodiment of the present application, a security node may act as an independent node and establish a communication connection, such as a direct connection or an indirect connection, with a network node in a communication system, thereby transmitting trusted signaling and / or trusted data.
[0152] The at least one security node includes at least one security node #1 and / or at least one security node #2. The following describes three scenarios. Security node #1 is a security node in the communication network, i.e., a node that provides security functions for the communication network. Security node #1 can be a device (such as a terminal device, an access network device, a core network device, or a cloud server), or a component of a device (such as a chip, a chip system, a logic module, a circuit, etc.).
[0153] Security Node #2 is a security node in the communication network, specifically a node that provides security functions for the communication network. The difference between Security Node #2 and Security Node #1 is that Security Node #1 manages (or controls) security functions, while Security Node #2 performs security-related functions. Security Node #2 can be a device (e.g., a terminal device, an access network device, a core network device, or a cloud server), or a component of a device (e.g., a chip, a chip system, a logic module, a circuit, etc.).
[0154] Case 1: the at least one safety node includes at least one safety node #1.
[0155] Security Node #1 can function as an independent node, managing (or controlling) security functions. For example, Security Node #1 can serve as the central decision-making and management scheduling unit for network trust capabilities, responsible for formulating and sending security-related policies to communicating parties, and performing security management functions such as establishment, maintenance, and updates.
[0156] Security node #1 can also be called an engine, and its naming does not limit the scope of protection of the embodiments of this application. The following embodiments are mainly described using security node #1 as an example.
[0157] Optionally, security node #1 is deployed in the core network and / or access network. For example, security node #1 in the core network is represented by an independent NF mounted on a bus. In this case, security node #1 can also be called a trustworthiness engine function (TEF). For example, security node #1 in the access network is represented by a virtual function module or an independent node (similar to an access network node).
[0158] FIG2 is a schematic diagram of a network architecture in which a security node is provided as an independent node in an embodiment of the present application. As shown in FIG2 , security node #1 can be deployed in both the core network and the access network. As can be seen from (1) in FIG2 , a communication connection can be established between security node #1 and an access network node (such as a radio access network (RAN) node, denoted as RAN#1 and RAN#2 for distinction), and between other security nodes #1. It can be understood that FIG2 is merely an example, and the embodiments of the present application are not limited thereto. For example, a communication connection can also be established between security node #1 and a core network node.
[0159] Optionally, a security module (or security function module) may be deployed in the network node, and the security module performs security-related functions for the network node. As shown in (1) in Figure 2, a security module may be deployed in the UE. In the embodiment of the present application, the security module deployed in the network node is the same as security node #2, except that the security module is an internal function module of the network node, while security node #2 is an independent node that performs security-related functions by establishing a communication connection with other nodes.
[0160] Based on the above solution, by introducing an independent node security node #1 in the communication system, the security node #1 provides security functions for the communication system, such as management security functions, so that the security functions in the communication system can be uniformly managed and deployed by an independent security node.
[0161] Case 2: the at least one safety node includes at least one safety node #2.
[0162] Security Node #2 can be used as an independent node to perform security-related functions. For example, Security Node #2 can be used as a unit for negotiation, execution, and self-evolution of network trust capabilities for P2P capability execution.
[0163] Safety node #2 may also be referred to as a gear, and its naming does not limit the scope of protection of the embodiments of the present application. The following embodiments are mainly described using safety node #2 as an example.
[0164] Optionally, the communication system includes multiple security nodes #2. In one possible implementation, each network node has its own corresponding security node #2, i.e., a security node #2 that provides services for itself. In another possible implementation, multiple network nodes can share a single security node #2, i.e., a single security node #2 can provide services for multiple network nodes.
[0165] Optionally, Security Node #2 is deployed in at least one of the following: a core network, an access network, or a terminal. For example, Security Node #2 in the terminal can be a virtual function module, an independent hardware card, or integrated with the terminal's smart card. For example, Security Node #2 in the access network can be a virtual function module or an independent node (similar to an access network node). For example, Security Node #2 in the core network can be an independent network function mounted on a bus. In this case, Security Node #2 can also be referred to as a Trustworthiness Gear Function (TGF).
[0166] As shown in Figure 2, security node #2 can be deployed in both the core network and the access network. Figure 2 shows that communication connections can be established between security node #2 and access network nodes (such as RAN #1 and RAN #2), between security nodes #2, between security node #2 and security node #1, and between security node #2 and core network nodes (such as security node #1 deployed in the core network).
[0167] Based on the above solution, by introducing an independent node security node #2 into the communication system, the security node #2 provides security functions for the communication system, such as executing security functions. In this way, when the security functions are updated and evolved, they can be executed by the independent security node, which is simple to operate.
[0168] Case 3: the at least one safety node includes at least one safety node #1 and at least one safety node #2.
[0169] Security node #1 and security node #2 can be independent devices, or they can be integrated into the same device to implement different functions. They can also be network elements in hardware devices, or they can be software functions running on dedicated hardware, or they can be virtualized functions instantiated on a platform (for example, a cloud platform). This application does not limit the specific form of the above-mentioned security nodes.
[0170] The above describes the case where at least one security node includes security node #1 and / or security node #2 in combination with three examples. In the following embodiments, the example of at least one security node including security node #1 and security node #2 is mainly used for description.
[0171] After safety node #1 and safety node #2 are introduced into the communication system, the connection between safety node #1 and safety node #2 can be implemented in the following two ways:
[0172] One possible implementation is direct connection between security nodes. In this way, security nodes can directly establish a connection and communicate with each other.
[0173] As shown in (1) in Figure 2, a communication connection can be directly established between the security nodes deployed in the core network (such as security node #1 and security node #2) and the security nodes deployed in the access network (such as security node #1 and security node #2), and trusted signaling and / or trusted data can be directly transmitted.
[0174] Another possible implementation involves establishing connections between security nodes through other nodes, specifically by transmitting trusted signaling and / or trusted data through other nodes. This allows security nodes to establish connections through other nodes and, consequently, communicate through these other nodes. Thus, if a network node and a security node cannot connect directly, or if direct connection is inappropriate, a connection can be established through other nodes, allowing the security node to provide services to the network node through these other nodes.
[0175] Assume that security node #1 is deployed in the core network, and security node #1 and security node #2 are deployed in the access network. As shown in (2) in Figure 2, security node #1 and security node #2 deployed in the access network can establish a communication connection with security node #1 deployed in the core network through the access network node (RAN#2); or, security node #1 and security node #2 deployed in the access network can establish a communication connection with security node #1 deployed in the core network through the access network node (RAN#2) and the core network node (NF).
[0176] After the introduction of safety nodes #1 and #2 into the communication system, some interfaces will be added, as shown in Figure 3.
[0177] Figure 3 is a schematic diagram of the interfaces of the security nodes provided in an embodiment of the present application. As shown in Figure 3, after introducing security node #1 into the communication system, the following interfaces may be added to the network: the interface between security node #1 and the network node, the interface between security node #1, and the interface between security node #1 and security node #2. After introducing security node #2 into the communication system, the following interfaces may be added to the network: the interface between security node #2 and the network node, the interface between security node #2, and the interface between security node #2 and security node #1.
[0178] As shown in Figure 3, the introduction of Security Node #1 and Security Node #2 into the communication system may introduce the following five new interfaces: the interface between Security Node #1 and a network node, the interface between Security Node #1 itself, the interface between Security Node #2 and a network node, the interface between Security Node #2 itself, and the interface between Security Node #1 and Security Node #2. Based on this, this application designs five trusted protocols: a trusted protocol between Security Node #1 and a network node, a trusted protocol between Security Node #1 itself, a trusted protocol between Security Node #2 and a network node, a trusted protocol between Security Node #2 itself, and a trusted protocol between Security Node #1 and Security Node #2. This section will be described in detail later in conjunction with the method.
[0179] The above introduces the relevant content about Security Node #1 and Security Node #2. The following introduces trusted signaling and trusted data.
[0180] Trusted signaling refers to security-related signaling. Optionally, trusted signaling is used for one or more of the following functions: management of trusted functions, management of trusted requirements, negotiation of trusted policies, notification of trusted services, or request for trusted services.
[0181] As an example, the management of the trusted function includes one or more of the following: establishment of a trusted function, activation of a trusted function, initial configuration of a trusted function, update of a trusted function, addition of a trusted function, deletion of a trusted function, or transition of a state of a trusted function.
[0182] As an example, the trusted service includes one or more of the following: an authentication service, an authorization service, a trust measurement service, a blockchain service, a situational awareness service, or a network-wide trust policy service.
[0183] The authentication service provider provides an authentication response / authentication result to the requester. For example, the authentication result can be the final authentication result or an intermediate parameter in the authentication process. For example, the authentication service can be authentication authorization between the RAN and the core network NF, or authentication authorization between core network NFs. This authentication authorization includes, for example, identity authentication for secure access, such as authentication vectors and authentication parameters.
[0184] The authorization service provider provides the requester with an access token / authorization result. For example, the authorization result can be the final authorization result or an intermediate parameter in the authorization process. For example, the authorization service can be authorization between the RAN and the core network NF, or authorization between core network NFs. This authorization can include static authorization or token-based authorization.
[0185] In the trusted measurement service, the provider provides measurement evidence (provider acting as an attester) or measurement results (provider acting as a verifier) to the requester. For example, the measurement result can be the final result or an intermediate parameter of the measurement process. For example, the trusted measurement service can be trusted measurement between the RAN and the core network NF, or trusted measurement between core network NFs. This trusted measurement includes, for example, device trustworthiness measurement, such as the acquisition of trusted attestation vectors and trusted attestation parameters.
[0186] Among them, the blockchain service provider provides blockchain control capabilities to the requester, which can include blockchain creation, update, deletion, blockchain / chain node management, etc.
[0187] Among them, the situational awareness service provider provides the situational awareness control capability or situational awareness results to the requester, which may include the configuration of parameter types, parameter types, and the extraction of parameter information.
[0188] Among them, the network global trusted policy service provider provides the network global trusted policy to the requester, mainly as one of the input parameters of the trusted policy negotiation.
[0189] It can be understood that in this application, expressions related to "trusted" can also be replaced by expressions related to "secure". For example, trusted functions can also be expressed as secure functions, trusted information can also be expressed as secure information, etc. The names of these functions, messages or information are not limited.
[0190] Trusted data refers to security-related data. Optionally, the trusted data includes one or more of the following: situational awareness-related data, homomorphic encryption-related data, homomorphic computing-related data, blockchain-related data, or keys.
[0191] The specific applications of trusted signaling and trusted data will be explained in detail later in conjunction with different scenarios.
[0192] The system provided by this application is introduced above, and the method provided by this application is introduced below. The terms mentioned below can refer to the above description and will not be repeated below.
[0193] Figure 4 is a schematic diagram of a method 400 for information transmission provided in an embodiment of the present application. For ease of description, the following is an illustrative explanation using the execution subject of method 400 as a security node as an example. It can be understood that the security node can be a device (such as a terminal device, an access network device, a core network device, or a cloud server), or a component of a device (such as a chip, a chip system, a logic module, a circuit, etc.), without limitation. Method 400 is applied to a communication network, which includes a first security node and at least one network node. Method 400 may include the following steps.
[0194] 401. A first security node establishes a communication connection with at least one network node.
[0195] The first security node is used to provide security functions for the communication network.
[0196] The term "communication connection" refers to a connection between a security node and a network node. It can be a logical concept rather than a physical entity. Simply put, the first security node and the network node are both independent nodes that can communicate by establishing a communication connection between them.
[0197] Optionally, the first security node includes a first node and / or a second node, where the first node is used to manage security functions, and the second node is used to execute security functions. The first node is referred to as security node #1, and the second node is referred to as security node #2. For consistency and without loss of generality, the following description uses security node #1 and security node #2.
[0198] 402 : A first security node transmits trusted signaling and / or trusted data with at least one network node via a communication connection.
[0199] Based on the above technical solution, security functions in the communication network can be provided by independent security nodes. Specifically, the security nodes are independently deployed and establish a communication connection with the network nodes. This communication connection allows the security nodes and the network nodes to transmit trusted signaling and / or trusted data, enabling the security nodes to provide security functions for the communication system. Furthermore, the independent deployment of the security nodes decouples security from communication, facilitating the independent evolution and flexible deployment of security functions.
[0200] Optionally, the first security node includes a trusted protocol layer, or in other words, the protocol stack of the first security node includes a trusted protocol layer, which processes trusted signaling and / or trusted data. Based on this, by designing a trusted protocol and a trusted protocol stack, it is possible to enable an independently deployed security node to process trusted signaling and / or trusted data between the security node and another node (referred to as Node #A for differentiation), thereby improving the security of the trusted signaling and / or trusted data. The other nodes include security nodes (such as Security Node #1 and Security Node #2) and network nodes.
[0201] For example, the first security node is security node #1, and a trusted protocol layer is deployed on security node #1. This trusted protocol layer can process trusted signaling and / or trusted data between security node #1 and other nodes. For another example, the first security node is security node #2, and a trusted protocol layer is deployed on security node #2. This trusted protocol layer can process trusted signaling and / or trusted data between security node #2 and other nodes.
[0202] Further optionally, the protocol stack of the first security node also includes one or more of the following protocol layers located below the trusted protocol layer: a protocol layer for data packet processing, a protocol layer for transmission, a protocol layer for establishing a connection, and a protocol layer for establishing a channel.
[0203] For example, if the first security node is deployed on a terminal, that is, the first security node is a terminal device, the first security node may also include one or more of the following protocol layers below the trusted protocol layer: PDCP, RLC, MAC, PHY, SDAP, and other protocol layers, as well as possible future evolutions of these protocol layers. The protocol layers used for packet processing may include PDCP and SDAP, and the protocol layers used for connection establishment may include PHY, MAC, and RLC.
[0204] For another example, if the first security node is deployed in an access network, that is, the first security node is an access network device, then the first security node may also include one or more of the following protocol layers below the trusted protocol layer: PDCP, RLC, MAC, PHY, IP, data link layer (DLL), SCTP, user datagram protocol (UDP), and other protocol layers, as well as possible future evolution versions of these protocol layers. The protocol layer for packet processing may include PDCP; the protocol layer for transmission may include SCTP and UDP; and the protocol layer for connection establishment may include PHY, MAC, and RLC.
[0205] For another example, if the first security node is deployed in the access network, that is, the first security node is a NF in the core network, then the first security node may also include one or more of the following protocol layers below the trusted protocol layer: IP, SCTP, UDP, TCP, TLS, Hypertext Transfer Protocol (HTTP), and other protocol layers, as well as possible future evolutions of these protocol layers. The protocol layer for packet processing may include HTTP, and the protocol layer for transmission may include SCTP, TCP, and UDP.
[0206] Figure 5 is a schematic diagram of the end-to-end protocol stack proposed in an embodiment of the present application. In Figure 5, engine and TEF represent security node #1, and gear and TGF represent security node #2.
[0207] For ease of description and distinction, the following definitions are made in the embodiments of this application:
[0208] The trusted protocol between Security Node #1 and the network node is called TNE, the trusted control plane protocol is called TNE-C, and the trusted service plane protocol is called TNE-U. The trusted protocol between Security Node #1 and Security Node #1 is called TEP, which is a trusted control plane protocol. The trusted protocol between Security Node #2 and the network node is called TNG, the trusted control plane protocol is called TNG-C, and the trusted service plane protocol is called TNG-U. The trusted protocol between Security Node #2 and Security Node #2 is called TGP, the trusted control plane protocol is called TGP-C, and the trusted service plane protocol is called TGP-U. The trusted protocol between Security Node #1 and Security Node #2 is called TEG, the trusted control plane protocol is called TEG-C, and the trusted service plane protocol is called TEG-U.
[0209] T stands for trustworthiness, which can include both trust and security. N represents a network node. E represents security node #1. As mentioned earlier, security node #1 can also be called an engine, so E is used to represent security node #1. G represents security node #2. As mentioned earlier, security node #2 can also be called a gear, so G is used to represent security node #2. P stands for protocol. -C represents the control plane, and -U represents the user plane.
[0210] It can be understood that the above definitions and naming are only for distinction and are examples, and do not limit the scope of protection of the embodiments of the present application.
[0211] Depending on whether the execution node of the trusted protocol is security node #1 (i.e., engine) or security node #2 (i.e., gear), the end-to-end protocol stack proposed in the embodiments of this application can be divided into the following two types:
[0212] 1. End-to-end protocol stack related to security node #1: as shown in (1) and (2) in Figure 5. (1) in Figure 5 is the end-to-end trusted control plane protocol stack related to security node #1, and (2) in Figure 5 is the end-to-end trusted service plane protocol stack related to security node #1.
[0213] As an example, when the rightmost node is the core network TEF (that is, security node #1 deployed in the core network), there may be other base stations and NFs between the base station and the TEF responsible for forwarding trusted protocol messages.
[0214] 2. End-to-end protocol stack independent of security node #1: As shown in (3) and (4) in Figure 5. (3) in Figure 5 is the end-to-end trusted control plane protocol stack independent of security node #1, and (4) in Figure 5 is the end-to-end trusted service plane protocol stack independent of security node #1.
[0215] As an example, when the rightmost node is the core network TGF (that is, security node #2 deployed in the core network), there may be other base stations and NFs between the base station and the TGF responsible for forwarding trusted protocol messages.
[0216] It is understood that FIG5 is an example and does not limit this. For example, different trusted protocols can also be located in the same layer. Taking (1) in FIG5 as an example, the TEG and TNE protocols can be located in the same layer.
[0217] As mentioned above, this application designs five trusted protocols, which are introduced in detail below.
[0218] 1. Trusted protocol between Security Node #1 and network nodes.
[0219] Trusted signaling and trusted data can be transmitted between the security node #1 and the network node, so the trusted protocol may include a trusted control plane protocol and a trusted service plane protocol.
[0220] In the first possible scenario, security node #1 is directly connected to the network node. In this case, trusted signaling and trusted data are directly transmitted between security node #1 and the network node, improving transmission efficiency.
[0221] Figure 6 is a schematic diagram of the trusted protocol stack between Security Node #1 and a network node, as provided in an embodiment of the present application. In the example shown in Figure 6, Security Node #1 is directly connected to a network node (e.g., a base station). As shown in Figure 6, trusted signaling is transmitted between Security Node #1 and the network node via the trusted control plane protocol TNE-C, and trusted data is transmitted via the trusted service plane protocol TNE-U.
[0222] In the second possible scenario, Security Node #1 connects to network nodes through other nodes. In this scenario, trusted signaling and trusted data are transmitted between Security Node #1 and network nodes through other nodes. In some cases, even when a direct connection between network nodes and Security Node #1 is unavailable, trusted signaling and trusted data can be transmitted through other nodes, enabling Security Node #1 to provide security functions for each network node in the communication network.
[0223] Figure 7 is another schematic diagram of the trusted protocol stack of security node #1 and network node provided by an embodiment of the present application. In the example shown in Figure 7, security node #1 and network node are connected through other nodes. As shown in Figure 7, when the network node is a UE, the base station transparently transmits the trusted signaling and trusted data between security node #1 and network node #1. When the network node is a base station (such as base station #1), other base stations (such as base station #2) or NF transparently transmit the trusted signaling and trusted data between security node #1 and network node #1.
[0224] As an example, trusted data between Security Node #1 and a network node includes data to be processed provided by the network node. For example, the network node sends one or more of the following to Security Node #1: situational awareness data, homomorphic encryption data, homomorphic computation data, blockchain data, or a key, and Security Node #1 processes one or more of the above data.
[0225] As an example, trusted signaling between security node #1 and the network node may be used for one or more of the following functions:
[0226] Establishing a communication connection between security node #1 and the network node (i.e., establishing trusted functions): such as network node perception, registration, and deregistration;
[0227] Trusted function update: For example, security node #1 updates the security function module inside security node #1 according to the needs of network nodes;
[0228] Deletion and addition of trusted functions: For example, security node #1 can delete or add security function modules inside security node #1 according to the needs of network nodes;
[0229] Notification of trusted services: For example, security node #1 provides authentication services, blockchain services, and trust measurement services.
[0230] Here are some examples.
[0231] FIG8 is a schematic flow chart of configuring a trusted function on demand at security node #1. As shown in FIG8 , as an example, the process of configuring a trusted function on demand at security node #1 includes the following steps:
[0232] 801. A network node sends a management request message to security node #1. The management request message includes a trust requirement parameter. Security node #1 receives the management request message.
[0233] The trusted requirement parameters may be carried through messages of the trusted protocol layer (eg, TNE-C).
[0234] 802 , security node #1 processes the security function module of security node #1 according to the trusted requirement parameters.
[0235] For example, if the trust requirement parameter in step 801 is to add a security function module, then in step 802, security node #1 adds the security function module of security node #1. For another example, if the trust requirement parameter in step 801 is to delete a security function module, then in step 802, security node #1 deletes the security function module of security node #1. For another example, if the trust requirement parameter in step 801 is to update the status of the security function module, then in step 802, security node #1 updates the status of the security function module.
[0236] In this case, the security node #1 can process the security function module of the security node #1 according to the trust requirement parameters at the trusted protocol layer (for example, TNE-C).
[0237] 803 , the safety node #1 sends a management response message to the network node. The management response message includes the capability parameters of the safety node #1 , and the network node receives the management response message.
[0238] The capability parameters of security node #1 may be carried in a message of a trusted protocol layer (eg, TNE-C).
[0239] Based on the above technical solution, security node #1 can configure corresponding security function modules based on the trust requirements of the network node, and then provide corresponding security functions for the network node.
[0240] Figure 9 is a schematic flow chart of security node #1 providing trusted services. As shown in Figure 9, as an example, the process of security node #1 providing trusted services includes the following steps:
[0241] 901. A network node sends a service request message to a safety node #1. The service request message includes a service type parameter. The safety node #1 receives the service request message.
[0242] The service type parameter may be carried in a message of a trusted protocol layer (eg, TNE-C).
[0243] As an example, the service type parameter includes at least one of the following: authentication, blockchain establishment, and trustworthiness measurement.
[0244] 902, security node #1 executes the trusted service according to the service type parameter.
[0245] Among them, security node #1 can perform trusted services at the trusted protocol layer (e.g., TNE-C).
[0246] 903 , security node #1 sends the execution result of the trusted service to the network node, and the network node receives the execution result of the trusted service.
[0247] For example, if the service type parameter in step 901 includes authentication, the execution result in step 903 may include authentication success or authentication failure. Further optionally, the execution result includes the reason for the authentication failure.
[0248] For another example, if the service type parameter in step 901 includes a trust metric, the execution result in step 903 may include a trust metric success or a trust metric failure. Further optionally, the execution result includes a reason for the trust metric failure.
[0249] The execution result of the trusted service may be carried through a message of the trusted protocol layer (eg, TNE-C).
[0250] Based on the above technical solution, security node #1 can perform corresponding trusted services for the network node based on the request of the network node.
[0251] The above is an example and is not limiting. For relevant content about trusted signaling, trusted functions, trusted services, etc., please refer to the relevant description above.
[0252] 2. Trusted protocol between security nodes #1.
[0253] Trusted signaling can be transmitted between security nodes #1, so the trusted protocol may include a trusted control plane protocol.
[0254] In the first possible scenario, the security nodes #1 are directly connected to each other. Based on this, the security nodes #1 directly transmit trusted signaling to each other.
[0255] Figure 10 is a schematic diagram of a trusted protocol stack between security nodes #1 provided in an embodiment of the present application. In the example shown in Figure 10, security nodes #1 are directly connected. As shown in Figure 10, trusted signaling is transmitted between security nodes #1 via the trusted protocol TEP.
[0256] In the second possible scenario, the security nodes #1 are connected via other nodes. Based on this, the security nodes #1 transmit trusted signaling via other nodes.
[0257] Figure 11 is another schematic diagram of the trusted protocol stack between security nodes #1 provided in an embodiment of the present application. In the example shown in Figure 11, security nodes #1 are connected through other nodes. As shown in Figure 11, the base station or NF transparently transmits trusted signaling between security nodes #1.
[0258] Optionally, when the communication network includes at least two security nodes #1, one or more of the at least two security nodes #1 may have a function of managing, configuring, or controlling the other security nodes #1.
[0259] In one possible implementation, security nodes #1 have a hierarchical structure, where some security nodes #1 are high-level security nodes and some are low-level security nodes. High-level security nodes manage, configure, or control low-level security nodes. For example, security nodes #1 deployed in the core network are high-level security nodes, while security nodes #1 deployed in the access network are low-level security nodes.
[0260] As an example, trusted signaling between security nodes #1 may be used for one or more of the following functions:
[0261] Establishing communication connections between security nodes #1: such as registration and deregistration of low-level security node #1;
[0262] High-level security node #1 manages low-level security node #1: such as creating, updating, deleting, and adding internal security function modules;
[0263] High-level security node #1 controls the blockchain capabilities of low-level security node #1, such as the transmission of blockchain operation parameters;
[0264] The high-level security node #1 controls the situational awareness of the low-level security node #1 and provides the situational awareness configuration information, such as the information of the perceived object (e.g., type, node ID / IP, etc.), the information of the data to be perceived (e.g., data type, data size, data storage location, etc.), and the perception method;
[0265] Homomorphic control of lower-layer security node #1 by higher-layer security node #1, such as key distribution and homomorphic task configuration;
[0266] Mutual awareness between two security nodes #1;
[0267] A security node #1 provides trusted services, such as authentication results and measurement results, to another security node #1.
[0268] It is understood that the above description mainly uses high-level security node #1 and low-level security node #1 as examples, and the present application is not limited thereto. For example, the high-level security node #1 and low-level security node #1 can also be any two security nodes #1.
[0269] Here are some examples.
[0270] Figure 12 is a schematic flowchart of hierarchical management of security node #1. As shown in Figure 12, as an example, assuming that security node #11 (e.g., security node #11 is a high-level security node) manages security node #12 (e.g., security node #12 is a low-level security node), the hierarchical management process includes the following steps:
[0271] 1201. Safety node #11 sends a management request message to safety node #12. The management request message includes management parameters. Safety node #12 receives the management request message.
[0272] The management parameters may be carried through messages of a trusted protocol layer (eg, TEP).
[0273] The management parameters include, for example, one or more of the following: a trusted policy and a profile of security node #12. The profile of security node #2 is a set of parameters used to configure and describe information about security node #2, including the identity of security node #2 (i.e., parameters describing its identity), the network node identifier (ID) / type corresponding to security node #2, and other parameters describing the network node served by security node #2, and capability information of security node #2.
[0274] 1202 , the safety node #12 processes the safety function module of the safety node #12 according to the management parameters.
[0275] Among them, the security node #12 can process the security function module of the security node #12 at the trusted protocol layer (e.g., TEP).
[0276] Step 1202 is similar to step 802 and will not be described in detail here.
[0277] 1203. Safety node #12 sends a management response message to safety node #11. The management response message includes the profile of safety node #12. Safety node #11 receives the management response message.
[0278] The profile of security node #12 may be carried via a message of a trusted protocol layer (eg, TEP).
[0279] Based on the above technical solution, security node #1 can manage the trusted functions of security node #2.
[0280] Figure 13 is a schematic flowchart of hierarchical control of safety node #1. As shown in Figure 13, as an example, assuming that safety node #11 (e.g., safety node #11 is a high-level safety node) controls safety node #12 (e.g., safety node #12 is a low-level safety node), the hierarchical control process includes the following steps:
[0281] 1301. Safety node #11 sends a service control request message to safety node #12. The service control request message includes configuration parameters. Safety node #12 receives the service control request message.
[0282] The configuration parameters may be carried via messages of a trusted protocol layer (eg, TEP).
[0283] The configuration parameters represent configuration parameters of the trusted service, and may include, for example, blockchain configuration parameters, situational awareness configuration parameters, and homomorphic configuration parameters.
[0284] 1302. Safety node #12 configures the safety function module according to the configuration parameters.
[0285] In addition, security node #12 can also perform specific security services.
[0286] Among them, security node #12 can configure the security function module at the trusted protocol layer (for example, TEP).
[0287] 1303 , safety node #12 sends a service control response message to safety node #11 , where the service control response message includes the configuration result, and safety node #11 receives the service control response message.
[0288] The configuration result may be carried through a message of a trusted protocol layer (eg, TEP).
[0289] In addition, if the security node #12 executes the security service in step 1302, the service control response message may also include the execution result.
[0290] Figure 14 is a schematic flow chart of security node #1 providing trusted services. As shown in Figure 14, the process of security node #1 providing trusted services includes the following steps:
[0291] 1401. Safety node #11 sends a service request message to safety node #12. The service request message includes a service type parameter. Safety node #12 receives the service request message.
[0292] The service type parameter may be carried in a message of a trusted protocol layer (eg, TEP).
[0293] 1402, security node #12 executes the trusted service according to the service type parameter.
[0294] Among them, security node #12 can perform trusted services at the trusted protocol layer (e.g., TEP).
[0295] 1403. Safety node #12 sends the execution result of the trusted service to safety node #11, and safety node #11 receives the execution result of the trusted service.
[0296] The execution result of the trusted service may be carried through a message of the trusted protocol layer (eg, TEP).
[0297] Steps 1401-1403 may refer to steps 901-903 and are not described in detail here.
[0298] The above is an example and is not limiting. For relevant content about trusted signaling, trusted functions, trusted services, etc., please refer to the relevant description above.
[0299] 3. Trusted protocol between Security Node #2 and network nodes.
[0300] Trusted signaling and trusted data can be transmitted between the security node #2 and the network node, so the trusted protocol may include a trusted control plane protocol and a trusted service plane protocol.
[0301] In the first possible scenario, security node #2 is directly connected to the network node, which improves transmission efficiency. Based on this, trusted signaling and trusted data are directly transmitted between security node #2 and the network node.
[0302] Figure 15 is a schematic diagram of the trusted protocol stack between Security Node #2 and a network node, as provided in an embodiment of the present application. In the example shown in Figure 15 , Security Node #2 and the network node are directly connected. As shown in Figure 15 , the network node is a base station. Trusted signaling is transmitted between Security Node #2 and the base station via the trusted control plane protocol TNG-C, and trusted data is transmitted via the trusted service plane protocol TNG-U.
[0303] In the second possible scenario, Security Node #2 connects to the network node through another node. In this scenario, trusted signaling and trusted data are transmitted between Security Node #2 and the network node through the other node. In some cases, even when a direct connection between the network node and Security Node #2 is impossible, trusted signaling and trusted data can be transmitted through the other node, enabling Security Node #2 to provide security functions for each network node in the communication network.
[0304] Figure 16 is another schematic diagram of the trusted protocol stack between security node #2 and a network node provided by an embodiment of the present application. In the example shown in Figure 16, security node #2 and the network node are connected through other nodes. As shown in Figure 16, the network node is a UE, and the base station transparently transmits trusted signaling and trusted data between security node #2 and the UE. The network node is base station #1, and other base stations (such as base station #2) transparently transmit trusted signaling and trusted data between security node #2 and base station #1.
[0305] As an example, the trusted data between security node #2 and the network node includes one or more of the following: plaintext that the network node needs to encrypt, decrypted plaintext received by the network node, blockchain data that the network node needs to upload / download, and situational awareness data collected by security node #2 from the network node.
[0306] As an example, trusted signaling between security node #2 and the network node may be used for one or more of the following functions:
[0307] Establishing a communication connection between security node #2 and the network node: such as matching and activating security node #2 and the network node;
[0308] Notification of trust requirements of network nodes: For example, a network node sends a trust requirement notification message to security node #2 to notify security node #2 of the trust requirements of the network node;
[0309] The network node configures, updates, and deletes Security Node #2;
[0310] Trusted capability notification of security node #2: For example, security node #2 sends a trusted capability notification message to the network node to notify the network node of the trusted capability of security node #2;
[0311] Security node #2 provides security negotiation results;
[0312] Security node #2 provides authentication capabilities, such as providing authentication results;
[0313] Security Node #2 provides encryption and decryption capabilities, such as providing encryption and decryption results;
[0314] Security node #2 provides authorization capabilities, such as providing authorization results;
[0315] Security Node #2 provides blockchain capabilities, such as data upload and download results.
[0316] Security Node #2 provides situational awareness capabilities, such as perception results;
[0317] Security Node #2 provides trusted measurement capabilities, such as measurement results.
[0318] Here are some examples.
[0319] Figure 17 is a schematic flow chart of configuring trusted functions on demand for security node #2. As shown in Figure 17, as an example, the process of configuring trusted functions on demand for security node #2 includes the following steps:
[0320] 1701. The network node sends a management request message to security node #2. The management request message includes a trust requirement parameter. Security node #2 receives the management request message.
[0321] The trusted requirement parameters may be carried via messages of a trusted protocol layer (eg, TNG-C).
[0322] 1702 , security node #2 processes the security function module of security node #2 according to the trusted requirement parameters.
[0323] In this case, security node #2 can process the security function module of security node #2 according to the trust requirement parameters at the trusted protocol layer (e.g., TNG-C).
[0324] 1703 , safety node #2 sends a management response message to the network node. The management response message includes the capability parameters of safety node #2. The network node receives the management response message.
[0325] The capability parameters of security node #2 may be carried via a message of a trusted protocol layer (eg, TNG-C).
[0326] Steps 1701-1703 are similar to steps 801-803 and are not described in detail here.
[0327] Figure 18 is a schematic flow chart of security node #2 providing trusted services. As shown in Figure 18, as an example, the process of security node #2 providing trusted services includes the following steps:
[0328] 1801. The network node sends a service request message to the safety node #2. The service request message includes a service type parameter. The safety node #2 receives the service request message.
[0329] The service type parameter may be carried in a message of a trusted protocol layer (eg, TNG-C).
[0330] As an example, the service type parameter includes at least one of the following: authentication, blockchain establishment, trust measurement, encryption and decryption, and situational awareness.
[0331] 1802, security node #2 executes the trusted service according to the service type parameter.
[0332] Among them, security node #1 can perform trusted services at the trusted protocol layer (e.g., TNG-C).
[0333] 1803 , security node #2 sends the execution result of the trusted service to the network node, and the network node receives the execution result of the trusted service.
[0334] The execution result of the trusted service may be carried through a message of the trusted protocol layer (eg, TNG-C).
[0335] Steps 1801-1803 are similar to steps 901-903 and are not described in detail here.
[0336] The above is an example and is not limiting. For relevant content about trusted signaling, trusted functions, trusted services, etc., please refer to the relevant description above.
[0337] 4. Trusted protocol between security nodes #2.
[0338] Trusted signaling and trusted data can be transmitted between security nodes #2, so the trusted protocol may include a trusted control plane protocol and a trusted service plane protocol.
[0339] In the first possible scenario, the security nodes #2 are directly connected to each other. Based on this, the security nodes #2 directly transmit trusted signaling and trusted data to each other.
[0340] Figure 19 is a schematic diagram of a trusted protocol stack between security nodes #2 according to an embodiment of the present application. In the example shown in Figure 19, security nodes #2 are directly connected. As shown in Figure 19, trusted signaling is transmitted between security nodes #2 using the trusted control plane protocol TGP-C, and trusted data is transmitted using the trusted service plane protocol TGP-U.
[0341] In the second possible scenario, the security nodes #2 are connected through other nodes. Based on this, the security nodes #2 transmit trusted signaling and trusted data through other nodes.
[0342] Figure 20 is another schematic diagram of the trusted protocol stack between security nodes #2 provided in an embodiment of the present application. In the example shown in Figure 20, security nodes #2 are connected through other nodes. As shown in Figure 20, the base station or NF transparently transmits trusted signaling and trusted data between security nodes #2.
[0343] As an example, the trusted data between security nodes #2 includes one or more of the following: encrypted ciphertext, blockchain data (such as blockchain transaction / block synchronization data), homomorphically encrypted ciphertext, and homomorphic computing results.
[0344] As an example, trusted signaling between security nodes #2 may be used for one or more of the following functions:
[0345] Establishing a communication connection between security nodes #2: such as perception between security nodes #2;
[0346] Security policy negotiation and key negotiation between security nodes #2;
[0347] Security Node #2 provides authentication capabilities, such as providing authentication results, authentication parameters such as random numbers (rand), and authentication responses (res);
[0348] Security Node #2 provides authorization capabilities, such as providing authorization parameters such as authorization tokens;
[0349] Security Node #2 provides trusted measurement capabilities, such as measurement results and measurement parameters such as reference value (RV), challenge value (challenge), and evidence (evidence);
[0350] Security Node #2 provides the above capability information and subscription to its own information.
[0351] Here are some examples.
[0352] Figure 21 is a schematic flow chart of the negotiation of the trusted policy of security node #2. As shown in Figure 21, taking security node #21 and security node #22 as an example, the negotiation process of the trusted policy of security node #2 includes the following steps:
[0353] 2101. Safety node #21 sends a negotiation request message to safety node #22, and safety node #22 receives the negotiation request message.
[0354] For example, safety node #21 sends a TGP-C protocol negotiation request message to safety node #22.
[0355] 2102. Safety node #22 sends a negotiation response message to safety node #21, and safety node #21 receives the negotiation response message.
[0356] For example, safety node #22 sends a negotiation response message of the TGP-C protocol to safety node #21.
[0357] 2103. Safety node #21 sends the negotiation result to safety node #22, and safety node #22 receives the negotiation result.
[0358] The negotiation result may be carried by a message of a trusted protocol layer (eg, TGP-C).
[0359] Figure 22 is a schematic flow chart of security node #2 providing trusted services. As shown in Figure 22, taking security node #21 and security node #22 as examples, the process of security node #2 providing trusted services includes the following steps:
[0360] 2201. Safety node #21 sends a service request message to safety node #22. The service request message includes a service type parameter. Safety node #22 receives the service request message.
[0361] The service type parameter may be carried in a message of a trusted protocol layer (eg, TGP-C).
[0362] As an example, the service type parameter includes at least one of the following: authentication, blockchain establishment, trust measurement, encryption and decryption, and situational awareness.
[0363] 2202, security node #22 executes the trusted service according to the service type parameter.
[0364] Among them, security node #22 can perform trusted services at the trusted protocol layer (such as TGP-C).
[0365] 2203. Safety node #22 sends the intermediate parameters of the trusted service to safety node #21, and safety node #21 receives the intermediate parameters of the trusted service.
[0366] For example, if the trusted service is an authentication service, the intermediate parameters of the trusted service may be rand and res in the authentication process. For another example, if the trusted service is a trust measurement, the intermediate parameters of the trusted service may be evidence in the trust measurement process.
[0367] The intermediate parameters of the trusted service may be carried through messages of the trusted protocol layer (eg, TGP-C).
[0368] Figure 23 is a schematic flow chart of information subscription provided by security node #2. As shown in Figure 23, taking security node #21 and security node #22 as examples, the process of information subscription provided by security node #2 includes the following steps:
[0369] 2301. Safety node #21 sends a subscription request message to safety node #22, and safety node #22 receives the subscription request message.
[0370] For example, safety node #21 sends a subscription request message of the TGP-C protocol to safety node #22.
[0371] The subscription request message includes, for example, the type of trusted information requested for subscription (such as capability information of security node #22), a subscription reason, and the like.
[0372] 2302. Safety node #22 sends a subscription notification message to safety node #21, and safety node #21 receives the subscription notification message.
[0373] For example, safety node #22 sends a subscription notification message of the TGP-C protocol to safety node #21.
[0374] The subscription notification message may be used to indicate rejection of subscription or acceptance of subscription.
[0375] For example, if a subscription is accepted, the subscription notification message will include the trusted information subscribed to by Safety Node #21. In other words, if the subscription notification message includes the trusted information subscribed to by Safety Node #21, this subscribed trusted information can also indirectly indicate to Safety Node #22 that it has accepted the subscription. Furthermore, if the subscription is accepted, if the subscribed trusted information changes, the provider can send a notification of the trusted information to the subscriber. This notification notifies the subscriber of the change and may include output information, such as the modified trusted information.
[0376] For another example, if the subscription is rejected, the subscription notification message includes a failure indication. Optionally, the subscription notification message includes a rejection reason parameter, etc.
[0377] The above is an example and is not limiting. For relevant content about trusted signaling, trusted functions, trusted services, etc., please refer to the relevant description above.
[0378] 5. Trusted protocol between Security Node #1 and Security Node #2.
[0379] Trusted signaling and trusted data can be transmitted between security node #1 and security node #2, so the trusted protocol may include a trusted control plane protocol and a trusted service plane protocol.
[0380] In the first possible scenario, safety node #1 and safety node #2 are directly connected. Based on this, trusted signaling and trusted data are directly transmitted between safety node #1 and safety node #2.
[0381] Figure 24 is a schematic diagram of the trusted protocol stack between Security Node #1 and Security Node #2, provided in an embodiment of the present application. In the example shown in Figure 24, Security Node #1 and Security Node #2 are directly connected. As shown in Figure 24, trusted signaling is transmitted between Security Node #1 and Security Node #2 via the trusted control plane protocol TEG-C, and trusted data is transmitted via the trusted service plane protocol TEG-U.
[0382] In the second possible scenario, safety node #1 and safety node #2 are connected via other nodes. Based on this, safety node #1 and safety node #2 transmit trusted signaling and trusted data via other nodes.
[0383] Figure 25 is another schematic diagram of the trusted protocol stack between Safety Node #1 and Safety Node #2, provided in an embodiment of the present application. In the example shown in Figure 25 , Safety Node #1 and Safety Node #2 are connected via other nodes. As shown in Figure 25 , the base station or NF transparently transmits trusted signaling and trusted data between Safety Node #1 and Safety Node #2.
[0384] As an example, trusted data between Security Node #1 and Security Node #2 includes data provided by Security Node #2. For example, Security Node #2 sends one or more of the following to Security Node #1: situational awareness data, homomorphic encryption data, homomorphic computation data, blockchain data, or a key, and Security Node #1 processes one or more of these data items.
[0385] As an example, trusted signaling between Safety Node #1 and Safety Node #2 may be used for one or more of the following functions:
[0386] Establishing a connection between Security Node #1 and Security Node #2: such as sensing, registration, and deregistration of Security Node #2;
[0387] Notification of network policy and capability information of safety node #1: For example, safety node #1 sends a notification message to safety node #2 to inform safety node #2 of the capability information and / or network policy of safety node #1;
[0388] Security Node #1 manages Security Node #2, such as creating, updating, and deleting;
[0389] Security Node #1 controls the blockchain capabilities of Security Node #2, such as blockchain creation, update, and deletion, blockchain / chain node management, and chain node identity management;
[0390] Security Node #1 controls the situational awareness of Security Node #2 and provides situational awareness configuration information, such as information about the data to be sensed (e.g., data type, data size, data storage location, etc.) and the sensing method;
[0391] Security Node #1's homomorphic control over Security Node #2, such as key distribution and task configuration;
[0392] Security Node #1 provides trusted services, such as authentication results and measurement results;
[0393] Security node #2 provides authentication capabilities, such as providing authentication results;
[0394] Security Node #2 provides trusted measurement capabilities, such as providing measurement results;
[0395] Security node #2 provides the above capabilities and subscriptions to its own information: For example, security node #2 can provide security node #1 with subscribed information including security node #2's capability information, authentication results, trust measurement results, etc.
[0396] Here are some examples.
[0397] Figure 26 is a schematic flow chart of how security node #1 manages security node #2. As shown in Figure 26, as an example, the process of how security node #1 manages security node #2 includes the following steps:
[0398] 2601. Safety node #1 sends a management request message to safety node #2, and safety node #2 receives the management request message.
[0399] For example, safety node #1 sends a management request message of the TEG-C protocol to safety node #2.
[0400] In one possible scenario, the management request message includes management-related information, wherein the management-related information may include one or more of the following: network policy, capability information of security node #1, profile of security node #2 generated by security node #1, etc.
[0401] In another possible scenario, the management request message includes the service type and configuration parameters that need to be controlled. The service type that needs to be controlled includes, for example, blockchain, situational awareness, homomorphism, etc.
[0402] 2602, security node #2 performs configuration and verification.
[0403] Among them, security node #2 can be configured and verified at the trusted protocol layer (e.g., TEG-C).
[0404] Security Node #2 is configured and verified based on the management-related information provided by Security Node #1. For example, Security Node #2 is configured based on the configuration information provided by Security Node #1, such as Security Node #2's profile. For another example, Security Node #2 can verify the identity of Security Node #1.
[0405] Optionally, security node #2 may not be verified, for example, if security node #2 has low security, or security node #1 is trusted.
[0406] 2603. Safety node #2 sends a management response message to safety node #1, and safety node #1 receives the management response message.
[0407] For example, safety node #2 sends a management response message of the TEG-C protocol to safety node #1.
[0408] In one possible scenario, the management request message in step 2601 includes management-related information, and the management response message in step 2603 includes the profile of security node #2.
[0409] In another possible situation, the management request message in step 2601 includes the service type and configuration parameters that need to be controlled, and the management response message in step 2603 includes the configuration result.
[0410] Figure 27 is a schematic flow chart of security node #1 providing trusted services. As shown in Figure 27, as an example, the process of security node #1 providing trusted services includes the following steps:
[0411] 2701. Safety node #2 sends a service request message to safety node #1. The service request message includes a service type parameter. Safety node #1 receives the service request message.
[0412] The service type parameter may be carried by a message of a trusted protocol layer (eg, TEG-C).
[0413] 2702, security node #1 executes the trusted service according to the service type parameter.
[0414] Among them, security node #1 can perform trusted services at the trusted protocol layer (e.g., TEG-C).
[0415] 2703 , safety node #1 sends the execution result of the trusted service to safety node #2, and safety node #2 receives the execution result of the trusted service.
[0416] The execution result of the trusted service may be carried by a message of the trusted protocol layer (eg, TEG-C).
[0417] Steps 2701-2703 are similar to steps 901-903 and are not repeated here.
[0418] Figure 27 illustrates the scenario where Security Node #1 provides a trusted service. As previously mentioned, Security Node #2 can also provide a trusted service. For example, Security Node #2 receives a service request message and performs a trusted service based on the service type parameter. The scenario where Security Node #2 provides a trusted service is similar to that where Security Node #1 provides a trusted service and is not further described here.
[0419] The above is an example and is not limiting. For relevant content about trusted signaling, trusted functions, trusted services, etc., please refer to the relevant description above.
[0420] The above introduces the content related to the trusted protocol. The following introduces the relevant solutions for establishing connections between security nodes and network nodes.
[0421] In one possible implementation, at least one network node includes a first network node, and the first security node establishes a communication connection with the at least one network node, including: the first security node obtaining identity information and / or address information of the first network node; and the first security node transmitting trusted signaling and / or trusted data with the first network node based on the identity information and / or address information of the first network node. Further optionally, the first network node obtains the identity information and / or address information of the first security node, so that the first network node can send trusted signaling and / or trusted data to the first security node based on the identity information and / or address information of the first security node.
[0422] The node identity information refers to information used to identify the node. For example, the node identity information includes one or more of the following: node ID, network ID, token, permission, etc.
[0423] The node ID is used to identify the node. Optionally, a unique ID can be designed for a node (such as a security node or a network node), so that the node's address can be derived from the node ID. For example, a mapping relationship exists between the node's ID and the node's address.
[0424] The network ID refers to the ID of the network that the node wants to connect to, or the ID of the network to which the node belongs. Different operators can use different network IDs.
[0425] A token or license can be built into a node (such as a security node or network node) by the equipment manufacturer at the factory, issued by the operator through the management plane, or issued by the core network NF through the control plane. A node with a token or license can prove that it is authorized by the equipment manufacturer / operator to access the network. For example, a token can include multiple parameters such as the node ID and the requested resources. For example, a license includes parameters that indicate whether the equipment manufacturer / operator that issued the license agrees to allow the node to join a specific network.
[0426] For the sake of brevity, the identity information and / or address information is referred to as parameter #A.
[0427] The following description will be made by taking the first safety node as safety node #1 and safety node #2 as examples.
[0428] 1. The first security node is security node #1
[0429] In this scenario, security node #1 can obtain the identity information and / or address information of the first network node, and the first network node can also obtain the identity information and / or address information of security node #1, so that trusted signaling and / or trusted data can be transmitted between security node #1 and the first network node.
[0430] Optionally, the security node #1 sends capability information of the security node #1 to the first network node, such as trusted services that the security node #1 can provide.
[0431] The following describes how Security Node #1 and the network node obtain parameter #A, combining two scenarios: a direct connection between Security Node #1 and the network node and a third-party assisted connection.
[0432] Scenario 1: Security Node #1 and Network Node are directly connected.
[0433] In a first possible implementation manner, the first network node itself determines the parameter #A of the security node #1, and the security node #1 obtains the parameter #A of the first network node from the first network node.
[0434] In this way, the network node can determine the parameter #A of the security node (such as security node #1) by itself, so that the network node can send a message to the security node based on the parameter #A of the security node, such as providing its own parameter #A to the security node, and then the security node and the network node can establish a communication connection, and then can transmit trusted signaling and / or trusted data.
[0435] As an example, this approach may be applicable to a scenario where a network node and a security node (such as security node #1) can communicate directly.
[0436] Figure 28 is a schematic flow chart of establishing a communication connection between security node #1 and a network node. As an example, the process of establishing a communication connection between security node #1 and a network node includes the following steps.
[0437] 2801. The first network node sends a registration request message to the safety node #1. The registration request message includes the parameter #A of the first network node. The safety node #1 receives the registration request message.
[0438] The parameter #A of the first network node may be carried by a message of a trusted protocol layer (eg, TNE-C).
[0439] For example, after the first network node joins the network, the management plane configures parameter #A of security node #1 for the first network node. Thereafter, the first network node can use parameter #A of security node #1 to send a registration request message to security node #1.
[0440] 2802. Security node #1 and the first network node perform an authentication process.
[0441] As an example, node identity is verified by its ID. For example, security node #1 stores a list of valid network node IDs and verifies the legitimacy of the node identity by comparing the received parameter #A with the list.
[0442] The embodiment of the present application does not limit the specific authentication method. For example, the authentication method may also be authentication and key agreement (AKA) or extensible authentication protocol-AKA (EAP-AKA).
[0443] 2803. Safety node #1 sends a registration response message to the first network node, and the first network node receives the registration response message.
[0444] For example, the security node #1 sends a registration response message of the TNE-C protocol to the first network node.
[0445] Optionally, the registration response message includes capability information of security node #1, such as trusted services that security node #1 can provide.
[0446] In a second possible implementation, the first network node itself determines the parameter #A of the security node #1, and the security node #1 itself determines the parameter #A of the first network node.
[0447] In this way, the network node can determine the parameter #A of the security node (such as security node #1) by itself, and the security node can also determine the parameter #A of the first network node by itself, so that the security node and the network node can establish a communication connection and transmit trusted signaling and / or trusted data.
[0448] As an example, this approach may be applicable to a scenario where a network node and a security node can communicate directly.
[0449] For example, after a first network node joins the network, the management plane configures parameter #A of security node #1 for the first network node and also configures parameter #A of the first network node for security node #1. Afterward, security node #1 and the first network node can communicate directly. It is understood that in this case, the registration process between security node #1 and the first network node is not required.
[0450] In a third possible implementation, the first network node obtains parameter #A of safety node #1 from safety node #1, and safety node #1 determines parameter #A of the first network node itself.
[0451] In this way, the security node (such as security node #1) can determine the parameter #A of the network node by itself, so that the security node can send a message to the network node based on the parameter #A of the network node, such as providing its own parameter #A to the network node, and then the security node and the network node can establish a communication connection, and then can transmit trusted signaling and / or trusted data.
[0452] As an example, this approach is applicable to scenarios where a network node and a security node (such as security node #1) can communicate directly. Furthermore, this approach is applicable to scenarios where the security node can obtain parameter #A of each network node in the network.
[0453] For example, after a first network node joins the network, Security Node #1 obtains Parameter #A of the first network node and initiates an authentication process with the newly joined first network node. After authentication, the first network node obtains Parameter #A of Security Node #1. Optionally, Security Node #1 stores the capability information of the first network node. It is understood that in this case, the registration process between Security Node #1 and the first network node is not necessary.
[0454] As an example, security node #1 obtains parameter #A of the first network node, including: security node #1 obtains network topology information from known network nodes in real time through situational awareness, and then obtains parameter #A of the first network node; or, security node #1 obtains parameter #A of the first network node, including: the network node periodically reports its own connection status to security node #1, so that after the first network node joins the network, security node #1 can obtain parameter #A of the first network node.
[0455] In scenario 2, Security Node #1 and the network node establish a connection through the assistance of a third party.
[0456] In a fourth possible implementation, the first network node obtains parameter #A of security node #1 from other nodes (such as other network nodes or management nodes), and security node #1 obtains parameter #A of the first network node from the first network node.
[0457] In this way, the network node can obtain the parameters of the security node (such as security node #1) from other nodes, and then send messages to the security node based on the parameters of the security node, such as providing its own parameter #A to the security node. Even if the security node and the network node may not be able to communicate directly, a communication connection can be established based on this method, and trusted signaling and / or trusted data can be transmitted between the security node and the network node.
[0458] As an example, this approach may be applicable to scenarios where it is difficult for a network node and a security node (such as security node #1) to communicate directly.
[0459] Figure 29 is another schematic flow chart of establishing a communication connection between security node #1 and a network node. As an example, the process of establishing a communication connection between security node #1 and a network node includes the following steps.
[0460] 2901. The first network node obtains parameter #A of the safety node #1 from other network nodes, and the other network nodes receive parameter #A of the safety node #1.
[0461] For example, after joining the network, the first network node obtains parameter #A of security node #1 from other network nodes (such as the first network node's adjacent network node). Thereafter, the first network node can use parameter #A of security node #1 to send a registration request message to security node #1.
[0462] 2902. The first network node sends a registration request message to safety node #1. The registration request message includes parameter #A of the first network node. Safety node #1 receives the registration request message.
[0463] For example, the first network node sends a registration request message of the TNE-C protocol to the security node #1.
[0464] 2903 , security node #1 and the first network node perform an authentication process.
[0465] 2904. Security node #1 sends a registration response message to the first network node, and the first network node receives the registration response message.
[0466] For example, the security node #1 sends a registration response message of the TNE-C protocol to the first network node.
[0467] Steps 2902-2904 are similar to steps 2801-2803 and will not be repeated here.
[0468] In a fifth possible implementation, the first network node notifies the security node #1 of the parameter #A of the first network node through other nodes (such as other network nodes or management nodes), and the security node #1 notifies the first network node of the parameter #A of the security node #1 through other nodes.
[0469] In this way, the network node and the security node (such as security node #1) can exchange their respective parameters #A through other nodes. In this way, if the network node in the communication network cannot communicate directly with the security node, a communication connection can also be established in this way, so that the security node can provide security functions for the communication network.
[0470] As an example, this approach may be applicable to scenarios where it is difficult for a network node and a security node (such as security node #1) to communicate directly. Furthermore, this approach may be applicable to scenarios where both the network node and the security node have communication connections with other nodes.
[0471] Figure 30 is another schematic flow chart of establishing a communication connection between security node #1 and a network node. As an example, the process of establishing a communication connection between security node #1 and a network node includes the following steps.
[0472] 3001. A first network node sends a registration request message to another network node. The registration request message includes parameter #A of the first network node. The other network node receives the registration request message.
[0473] 3002. Other network nodes send the parameter #A of the first network node to the safety node #1, and the safety node #1 receives the parameter #A of the first network node.
[0474] The parameter #A of the first network node may be carried by a message of a trusted protocol layer (eg, TNE-C).
[0475] 3003. Security node #1 and the first network node perform an authentication process.
[0476] 3004. Safety node #1 sends a registration response message to the first network node through other network nodes, and the first network node receives the registration response message.
[0477] Optionally, the registration response message includes capability information of security node #1, such as trusted services that security node #1 can provide.
[0478] 2. The first security node is security node #2
[0479] In this scenario, security node #2 can obtain the identity information and / or address information of the first network node, and the first network node can also obtain the identity information and / or address information of security node #2, so that trusted signaling and / or trusted data can be transmitted between security node #2 and the first network node.
[0480] Optionally, security node #2 sends capability information of security node #2 to the first network node, such as trusted services that security node #2 can provide.
[0481] The following describes how Security Node #2 and the network node obtain parameter #A, combining two scenarios: a direct connection between Security Node #2 and the network node, and a third-party assisted connection. For the benefits and applicable scenarios of each method, please refer to the description of the connection between Security Node #1 and the network node above. For the sake of brevity, we will not elaborate on it here.
[0482] Scenario 1: Security Node #2 and Network Node are directly connected.
[0483] In a first possible implementation manner, the first network node itself determines the parameter #A of the security node #2, and the security node #2 obtains the parameter #A of the first network node from the first network node.
[0484] Figure 31 is a schematic flow chart of establishing a communication connection between security node #2 and a network node. As an example, the process of establishing a communication connection between security node #2 and a network node includes the following steps.
[0485] 3101. The first network node sends a setup request message to the safety node #2. The setup request message includes the parameter #A of the first network node. The safety node #2 receives the setup request message.
[0486] The parameter #A of the first network node may be carried by a message of a trusted protocol layer (eg, TNG-C).
[0487] For example, after the first network node joins the network, the management plane configures parameter #A of security node #2 for the first network node. Thereafter, the first network node can use parameter #A of security node #2 to send an establishment request message to security node #2.
[0488] Optionally, the establishment request message further includes a trust requirement parameter of the first network node.
[0489] Optionally, at 3102 , security node #2 and the first network node perform an authentication and / or configuration process.
[0490] Security node #2 may verify the identity of the first network node. Alternatively, security node #2 may not verify the identity of the first network node, for example, if security node #2 trusts the identity parameter sent by the first network node; or if security node #2 has a lower security level and verification is not required.
[0491] Optionally, if the establishment request message includes the trust requirement parameters of the first network node, security node #2 may be configured according to the trust requirement parameters of the first network node, such as activating or deactivating some security function modules of security node #2.
[0492] 3103. Safety node #2 sends a setup response message to the first network node, and the first network node receives the setup response message.
[0493] For example, the security node #2 sends a TNG-C protocol establishment response message to the first network node.
[0494] Optionally, the establishment response message includes capability information of security node #2, such as trusted services that security node #2 can provide.
[0495] In a second possible implementation, the first network node itself determines the parameter #A of the security node #2, and the security node #2 itself determines the parameter #A of the first network node.
[0496] For example, after the first network node joins the network, the management plane configures parameter #A of security node #2 for the first network node and also configures parameter #A of the first network node for security node #2. Afterward, security node #2 and the first network node can communicate directly. It is understood that in this case, the establishment process between security node #2 and the first network node is not required.
[0497] Scenario 2: Security Node #2 and the network node establish a connection through the assistance of a third party.
[0498] In a first possible scenario, the third party is security node #1, that is, security node #2 and the first network node establish a connection with the assistance of security node #1.
[0499] In a third possible implementation, the first network node obtains parameter #A of security node #2 from security node #1, and security node #2 obtains parameter #A of the first network node from the first network node.
[0500] Figure 32 is another schematic flow chart of establishing a communication connection between security node #2 and a network node. As an example, the process of establishing a communication connection between security node #2 and a network node includes the following steps.
[0501] 3201. The first network node obtains parameter #A of safety node #2 from safety node #1.
[0502] For example, after the first network node establishes a connection with security node #1, it requests parameter #A of security node #2 from security node #1. Based on the request from the first network node, security node #1 sends parameter #A of security node #2 to the first network node. For another example, after the first network node establishes a connection with security node #1, security node #1 proactively sends parameter #A of security node #2 to the first network node.
[0503] 3202. The first network node sends a setup request message to safety node #2. The setup request message includes parameter #A of the first network node. Safety node #2 receives the setup request message.
[0504] The parameter #A of the first network node may be carried by a message of a trusted protocol layer (eg, TNG-C).
[0505] 3203 , security node #2 and the first network node perform an authentication and / or configuration process.
[0506] 3204. Safety node #2 sends a setup response message to the first network node, and the first network node receives the setup response message.
[0507] For example, the security node #2 sends a TNG-C protocol establishment response message to the first network node.
[0508] Steps 3202-3204 are similar to steps 3101-3103 and will not be repeated here.
[0509] In a fourth possible implementation, security node #2 obtains parameter #A of the first network node from security node #1, and the first network node obtains parameter #A of security node #2 from security node #2.
[0510] Figure 33 is another schematic flow chart of establishing a communication connection between security node #2 and a network node. As an example, the process of establishing a communication connection between security node #2 and a network node includes the following steps.
[0511] 3301. Safety node #2 obtains parameter #A of the first network node from safety node #1.
[0512] For example, after the first network node establishes a connection with security node #1, security node #1 sends parameter #A of the first network node to security node #2. Parameter #A of the first network node may be carried in a message of a trusted protocol layer (eg, TEG-C).
[0513] 3302. Safety node #2 sends parameter #A of safety node #2 to the first network node, and the first network node receives parameter #A of safety node #2.
[0514] Among them, parameter #A of security node #2 can be carried through a message of the trusted protocol layer (for example, TNG-C).
[0515] Optionally, the security node #2 also sends capability information of the security node #2 to the first network node, such as trusted services that the security node #2 can provide.
[0516] Optionally, in 3303 , the first network node performs an authentication process.
[0517] For example, the first network node may verify whether the capabilities of security node #2 meet its own trust requirements.
[0518] Optionally, at 3304 , the first network node returns an authentication result to security node #2, and security node #2 receives the authentication result.
[0519] The authentication result may be carried by a message of a trusted protocol layer (eg, TNG-C).
[0520] If the first network node fails in verification, for example, the capability of security node #2 cannot meet its own trust requirements, then in step 3204, the authentication result returned by the first network node to security node #2 may include the trust requirements of the first network node.
[0521] In the second possible scenario, the third party is another node (e.g., another network node or management node), that is, the connection between security node #2 and the first network node is established with the assistance of another node. The following mainly uses the other node as an example to illustrate.
[0522] In a fifth possible implementation, the first network node obtains parameter #A of security node #2 from other network nodes, and security node #2 obtains parameter #A of the first network node from the first network node.
[0523] Figure 34 is another schematic flow chart of establishing a communication connection between security node #2 and a network node. As an example, the process of establishing a communication connection between security node #2 and a network node includes the following steps.
[0524] 3401. A first network node obtains parameter #A of safety node #2 from other network nodes, and the other network nodes receive the parameter of safety node #2.
[0525] 3402. The first network node sends a setup request message to safety node #2. The setup request message includes parameter #A of the first network node. Safety node #2 receives the setup request message.
[0526] The parameter #A of the first network node may be carried by a message of a trusted protocol layer (eg, TNG-C).
[0527] 3403 , security node #2 and the first network node perform an authentication and / or configuration process.
[0528] 3404. Safety node #2 sends a setup response message to the first network node, and the first network node receives the setup response message.
[0529] For example, the security node #2 sends a TNG-C protocol establishment response message to the first network node.
[0530] Steps 3401-3404 are similar to steps 2901-2904 and will not be repeated here.
[0531] In a sixth possible implementation, the first network node notifies the safety node #2 of the parameter #A of the first network node through other network nodes, and the safety node #2 notifies the safety node #2 of the parameter #A of the first network node through other nodes.
[0532] Figure 35 is another schematic flow chart of establishing a communication connection between security node #2 and a network node. As an example, the process of establishing a communication connection between security node #2 and a network node includes the following steps.
[0533] 3501. A first network node sends an establishment request message to another network node. The establishment request message includes parameter #A of the first network node. The other network node receives the establishment request message.
[0534] 3502. Other network nodes send the parameter #A of the first network node to safety node #2, and safety node #2 receives the parameter #A of the first network node.
[0535] The parameter #A of the first network node may be carried by a message of a trusted protocol layer (eg, TNG-C).
[0536] 3503 , security node #2 and the first network node perform an authentication and / or configuration process.
[0537] 3504. Safety node #2 sends an establishment response message to the first network node through other nodes, and the first network node receives the establishment response message.
[0538] Optionally, the establishment response message includes capability information of security node #2, such as trusted services that security node #2 can provide.
[0539] The above describes the connection between security nodes and network nodes. The following describes the connection between security nodes.
[0540] Optionally, the communication network further includes a second security node, and the method further includes: the first security node and the second security node transmitting trusted signaling and / or trusted data, wherein the second security node may include security node #1 and / or security node #2.
[0541] Further optionally, the first security node obtains the identity information and / or address information of the second security node. Further optionally, the second security node obtains the identity information and / or address information of the first security node, so that trusted signaling and / or trusted data can be transmitted between the first security node and the second security node.
[0542] The following description will be made by taking the first safety node as safety node #1 and safety node #2, and the second safety node as safety node #1 and safety node #2 as an example.
[0543] 1. The first safety node is safety node #1 (for distinction, referred to as safety node #11), and the second safety node is safety node #1 (for distinction, referred to as safety node #12).
[0544] In this scenario, security node #11 can obtain the identity information and / or address information of security node #12, and security node #12 can also obtain the identity information and / or address information of security node #11, so that trusted signaling and / or trusted data can be transmitted between security node #11 and security node #12.
[0545] Optionally, safety node #11 sends capability information of safety node #11 to safety node #12, such as the trusted services that safety node #11 can provide, and safety node #12 sends capability information of safety node #12 to safety node #11, such as the trusted services that safety node #12 can provide.
[0546] The following describes two scenarios: direct connection between security nodes #1 and third-party assisted connection.
[0547] Scenario 1: Security Node #11 and Security Node #12 are directly connected.
[0548] In a first possible implementation, safety node #12 determines parameter #A of safety node #11 by itself, and safety node #11 obtains parameter #A of safety node #12 from safety node #12.
[0549] In this way, a communication connection can be established between security nodes (such as security node #1), thereby transmitting trusted signaling and / or trusted data.
[0550] As an example, this approach may be applicable to a scenario where security nodes (such as security node #1) can communicate directly.
[0551] In one example, the authentication and registration process is not performed between security node #11 and security node #12.
[0552] For example, after safety node #12 joins the network, the management plane configures parameter #A for other safety nodes #1 (including at least safety node #11). Safety node #12 then sends a notification message to other safety nodes #1, which includes parameter #A for safety node #12. Optionally, the message also includes capability information for safety node #12. Furthermore, the other safety nodes return their capability information to safety node #12. Furthermore, the other safety nodes store the capability information for safety node #12.
[0553] In another example, an authentication and registration process is performed between security node #11 and security node #12. For example, security node #12 is a low-level security node, and security node #11 is a high-level security node.
[0554] Figure 36 is a schematic flow chart of establishing a communication connection between security nodes #1. Taking security nodes #11 and #12 as an example, the process of establishing a communication connection between security nodes #1 includes the following steps.
[0555] 3601. Safety node #12 sends a registration request message to safety node #11. The registration request message includes parameter #A of safety node #12. Safety node #11 receives the registration request message.
[0556] Among them, parameter #A of security node #12 can be carried through a message of the trusted protocol layer (e.g., TEP).
[0557] 3602, security node #11 and security node #12 perform registration and authentication processes.
[0558] 3603. Safety node #11 sends a registration response message to safety node #12, and safety node #12 receives the registration response message.
[0559] For example, safety node #11 sends a registration response message of the TEP protocol to safety node #12.
[0560] Optionally, the registration response message includes one or more of the following: capability information of security node #11, such as trusted services, network policies, and configuration parameters (i.e., profile of security node #12) that security node #11 can provide. The configuration parameters are used for configuration of security node #12.
[0561] Steps 3601-3603 are similar to steps 2801-2803 and will not be repeated here.
[0562] In a second possible implementation, safety node #12 itself determines parameter #A of safety node #11, and safety node #11 itself determines parameter #A of safety node #12.
[0563] In this way, a safety node (such as safety node #1) can obtain parameter #A of other safety nodes (such as other safety node #1), and then establish a communication connection to transmit trusted signaling and / or trusted data.
[0564] As an example, this approach may be applicable to a scenario where security nodes (such as security node #1) can communicate directly.
[0565] For example, after safety node #12 joins the network, the management plane configures safety node #11's parameter #A for safety node #12 and also configures safety node #11's parameter #A for safety node #12. After that, safety nodes #11 and #12 can communicate directly. It's understood that in this case, the registration process between safety nodes #11 and #12 doesn't need to be performed.
[0566] In a third possible implementation, safety node #12 obtains parameter #A of safety node #11 from safety node #11, and safety node #11 determines parameter #A of safety node #12 by itself.
[0567] In this way, a communication connection can be established between security nodes (such as security node #1), thereby transmitting trusted signaling and / or trusted data.
[0568] As an example, this approach may be applicable to a scenario where security nodes (such as security node #1) can communicate directly.
[0569] For example, after security node #12 joins the network, security node #11 obtains security node #12's parameter #A and initiates an authentication process with the newly joined security node #12. After authentication, security node #12 obtains security node #11's parameter #A. Optionally, security node #11 stores security node #12's detailed information. It is understood that in this case, the registration process between security node #11 and security node #12 is not necessary.
[0570] As an example, safety node #11 obtains parameter #A of safety node #12, including: safety node #11 obtains network topology information from known network nodes in real time through situational awareness, and then obtains parameter #A of safety node #12; or, safety node #11 obtains parameter #A of safety node #12, including: the network node regularly reports its own connection status to safety node #11, so that after safety node #12 joins the network, safety node #11 can obtain parameter #A of safety node #12.
[0571] In a fourth possible implementation, safety node #11 obtains parameter #A of safety node #12 from the management node, and safety node #12 obtains parameter #A of safety node #11 from the management node.
[0572] In this way, a safety node (such as safety node #1) can obtain parameter #A of other safety nodes from the management node, and then a communication connection can be established between the safety nodes to transmit trusted signaling and / or trusted data.
[0573] As an example, this approach may be applicable to a scenario where the management node is responsible for managing parameter #A of each safety node (such as safety node #1).
[0574] In one example, the management node is Security Node #1. For example, the network assigns a Security Node #1 (e.g., Security Node #13) as the centralized management node. All other Security Nodes #1 register with Security Node #13 and receive management and control from Security Node #13. Subsequently, Security Node #13 may optionally send a list of Security Node #1s to other Security Nodes #1, including Parameter #A of the Security Node #1s registered with Security Node #13.
[0575] Figure 37 is another schematic flow chart of establishing a communication connection between safety nodes #1. As an example, taking safety nodes #11 and #12 as an example, the process of establishing a communication connection between safety nodes #1 includes the following steps.
[0576] 3701. Safety node #11 sends a registration request message to safety node #13. The registration request message includes parameter #A of safety node #11. Safety node #13 receives the registration request message.
[0577] Among them, parameter #A of security node #11 can be carried through a message of the trusted protocol layer (e.g., TEP).
[0578] 3702. Safety node #13 sends a registration response message to safety node #11, and safety node #11 receives the registration response message.
[0579] The registration response message includes parameter #A of safety node #1 (ie, safety node #1 registered with safety node #13).
[0580] 3703. Safety node #12 sends a registration request message to safety node #13. The registration request message includes parameter #A of safety node #12. Safety node #13 receives the registration request message.
[0581] Among them, parameter #A of security node #12 can be carried through a message of the trusted protocol layer (e.g., TEP).
[0582] 3704. Safety node #13 sends a registration response message to safety node #12, and safety node #12 receives the registration response message.
[0583] The registration response message includes parameter #A of safety node #1 (ie, safety node #1 registered with safety node #13).
[0584] 3705, communication is performed between safety node #11 and safety node #12.
[0585] Optionally, security node #11 and security node #12 may first be authenticated and then communicated, without limitation.
[0586] A fifth possible implementation method is to build a blockchain that includes all security nodes #1. Whenever a new security node #1 joins, a peer-to-peer (P2P) protocol is used to achieve mutual awareness among all security nodes #1.
[0587] For example, a security node (e.g., Security Node #11) sends its stored Security Node IP Address List 1 to all connected security nodes (e.g., Security Node #12 and Security Node #13). Security Node #12 and Security Node #13 then compare their stored Security Node IP Address List 2 and Security Node IP Address List 3 with the received Security Node IP Address List 1, supplement Security Node IP Address List 2 and Security Node IP Address List 3, and send Security Node IP Address List 2 and Security Node IP Address List 3 to all connected security nodes (e.g., excluding Security Node #11). After several iterations, all security nodes in the entire network can obtain all security node IP addresses.
[0588] In this way, a communication connection can be established between security nodes (such as security node #1), thereby transmitting trusted signaling and / or trusted data.
[0589] As an example, this approach may be applicable to scenarios where a security node (such as security node #1) supports blockchain services.
[0590] Scenario 2: Security Node #1 establishes a connection with each other through third-party assistance.
[0591] In a sixth possible implementation, security node #12 obtains parameter #A of security node #11 from other nodes (such as other network nodes or management nodes), and security node #11 obtains parameter #A of security node #12 from security node #12.
[0592] In this way, a security node (such as security node #1) can obtain the parameters of other security nodes (such as security node #1) from other nodes, and then send messages to the other security nodes based on the parameters of the other security nodes, such as providing its own parameters #A to the other security nodes. Even if the security nodes may not be able to communicate directly with each other, a communication connection can be established based on this method, and trusted signaling and / or trusted data can be transmitted between the security nodes.
[0593] As an example, this approach may be applicable to scenarios where direct communication between security nodes (such as security node #1) is difficult.
[0594] This method can refer to the relevant description in Figure 29, just replace the first network node in Figure 29 with security node #12, and replace security node #1 with security node #11.
[0595] In a seventh possible implementation method, safety node #12 notifies safety node #11 of parameter #A of safety node #12 through other nodes (such as other network nodes or management nodes), and safety node #11 notifies safety node #12 of parameter #A of safety node #11 through other nodes.
[0596] In this way, security nodes (such as security node #1) can exchange their respective parameters #A through other nodes. In this way, if the security nodes in the communication network cannot communicate directly with each other, a communication connection can also be established in this way, so that the security nodes can provide security functions for the communication network.
[0597] As an example, this approach may be applicable to scenarios where direct communication between security nodes (such as security node #1) is difficult.
[0598] Figure 38 is another schematic flow chart of establishing a communication connection between safety nodes #1. As an example, the process of establishing a communication connection between safety nodes #1 includes the following steps.
[0599] 3801. Safety node #12 sends a request message to other nodes. The request message includes parameter #A of safety node #12. Other nodes receive the request message.
[0600] Taking other nodes as network nodes as an example, the parameter #A of the security node #12 can be carried through a message of the trusted protocol layer (eg, TNE-C).
[0601] 3802. Other nodes send parameter #A of safety node #12 to safety node #11, and safety node #11 receives parameter #A of safety node #12.
[0602] Taking other nodes as network nodes as an example, parameter #A of security node #12 may be carried through a message of a trusted protocol layer (eg, TNE-C).
[0603] 3803, security node #11 and security node #12 perform the authentication process.
[0604] 3804. Safety node #11 sends a response message to safety node #12 through other nodes, and safety node #12 receives the response message.
[0605] Optionally, the response message includes capability information of security node #11, such as trusted services that security node #11 can provide.
[0606] 2. The first safety node is safety node #2 (for distinction, referred to as safety node #21), and the second safety node is safety node #2 (for distinction, referred to as safety node #22).
[0607] In this scenario, security node #21 can obtain the identity information and / or address information of security node #22, and security node #22 can also obtain the identity information and / or address information of security node #21, so that trusted signaling and / or trusted data can be transmitted between security node #21 and security node #22.
[0608] Optionally, safety node #21 sends capability information of safety node #21 to safety node #22, such as the trusted services that safety node #21 can provide, and safety node #22 sends capability information of safety node #22 to safety node #21, such as the trusted services that safety node #22 can provide.
[0609] The following describes two scenarios: direct connection between security nodes #2 and third-party assisted connection.
[0610] Scenario 1: Security Node #1 and Network Node are directly connected.
[0611] In a first possible implementation, safety node #22 determines parameter #A of safety node #21 by itself, and safety node #21 obtains parameter #A of safety node #22 from safety node #22.
[0612] Figure 39 is a schematic flow chart of establishing a communication connection between safety nodes #2. As an example, the process of establishing a communication connection between safety nodes #2 includes the following steps.
[0613] 3901. Safety node #22 sends parameter #A of safety node #22 to safety node #21, and safety node #21 receives parameter #A of safety node #22.
[0614] Among them, parameter #A of security node #22 can be carried through a message of the trusted protocol layer (for example, TGP-C).
[0615] For example, after safety node #22 joins the network, the management plane configures parameter #A of safety node #21 for safety node #22. After that, safety node #22 can use parameter #A of safety node #21 to send messages to safety node #21.
[0616] Optionally, safety node #22 also sends capability information of safety node #22 to safety node #21.
[0617] Optionally, at 3902 , security node #21 and security node #22 perform an authentication process.
[0618] That is, security node #21 verifies security node #22.
[0619] 3903. Safety node #21 sends the capability information of safety node #21 to safety node #22, and safety node #22 receives the capability information of safety node #21.
[0620] The capability information of the security node #21 may be carried via a message of a trusted protocol layer (eg, TGP-C).
[0621] In a second possible implementation, safety node #22 itself determines parameter #A of safety node #21, and safety node #21 itself determines parameter #A of safety node #22.
[0622] For example, after safety node #22 joins the network, the management plane configures parameter #A of safety node #21 for safety node #22, and simultaneously configures parameter #A of safety node #22 for safety node #21. After that, safety node #21 and safety node #22 can communicate directly.
[0623] Scenario 2: Security Node #2 establishes a connection with each other through the assistance of a third party.
[0624] In the first possible scenario, the third party is security node #1, that is, security node #2 establishes a connection with the assistance of security node #1.
[0625] In a third possible implementation, safety node #22 obtains parameter #A of safety node #21 from safety node #1, and safety node #21 obtains parameter #A of safety node #22 from safety node #22.
[0626] Figure 40 is another schematic flow chart of establishing a communication connection between safety nodes #2. As an example, the process of establishing a communication connection between safety nodes #2 includes the following steps.
[0627] 4001, safety node #22 obtains parameter #A of safety node #21 from safety node #1.
[0628] For example, after establishing a connection with safety node #1, safety node #22 requests parameter #A of safety node #21 from safety node #1. Based on the request, safety node #1 sends parameter #A of safety node #21 to safety node #22. Optionally, safety node #22 also sends a reason for requesting parameter #A of safety node #21 to safety node #1.
[0629] For another example, after safety node #22 establishes a connection with safety node #1, safety node #1 actively sends parameter #A of safety node #21 to safety node #22.
[0630] It is understandable that safety node #22 can obtain parameter #A of a certain safety node #2 from safety node #1, or can also obtain parameter #A of all safety nodes #2 connected to safety node #1, without limitation.
[0631] 4002. Safety node #22 sends a notification message to safety node #21. The notification message includes parameter #A of safety node #22. Safety node #21 receives the notification message.
[0632] The parameter #A of the security node #22 may be carried in a message of a trusted protocol layer (eg, TGP-C). Optionally, the notification message may also include capability information of the security node #22, such as trusted services that the security node #22 can provide.
[0633] Optionally, at 4003 , security node #21 and security node #22 perform an authentication process.
[0634] That is, security node #21 verifies security node #22.
[0635] 4004. Safety node #21 sends a response message to safety node #22, and safety node #22 receives the response message.
[0636] For example, safety node #21 sends a TGP-C protocol response message to safety node #22.
[0637] Optionally, the response message includes parameter #A of safety node #21.
[0638] In a fourth possible implementation, safety node #22 obtains parameter #A of safety node #21 from safety node #1, and safety node #21 obtains parameter #A of safety node #22 from safety node #1.
[0639] For example, after a security node #2 (such as security node #21 and security node #22) establishes a connection with security node #1, security node #1 sends information about all security nodes #2 registered with it, such as parameter #A and / or capability information, such as the trusted services it can provide. For another example, security node #1 periodically sends a security node #2 list to all security nodes #2 registered with it, allowing direct communication between security nodes #2.
[0640] In the second possible scenario, the third party is a network node, that is, the connection between security node #2 is established with the assistance of the network node.
[0641] In a fifth possible implementation, safety node #22 obtains parameter #A of safety node #21 from a network node, and safety node #21 obtains parameter #A of safety node #22 from safety node #22.
[0642] Figure 41 is another schematic flow chart of establishing a communication connection between safety nodes #2. As an example, the process of establishing a communication connection between safety nodes #2 includes the following steps.
[0643] 4101. The network node sends a trusted service request message to the safety node #22. The trusted service request message includes the parameter #A of the safety node #21. The safety node #22 receives the trusted service request message.
[0644] The parameter #A of the security node #21 may be carried via a message of a trusted protocol layer (eg, TGP-C).
[0645] 4102. Safety node #22 sends a notification message to safety node #21. The notification message includes parameter #A of safety node #22. Safety node #21 receives the notification message.
[0646] Among them, parameter #A of security node #22 can be carried through a message of the trusted protocol layer (for example, TGP-C).
[0647] Optionally, the notification message includes capability information of security node #22, such as trusted services that security node #22 can provide.
[0648] Optionally, at 4103, security node #21 and security node #22 perform an authentication process.
[0649] That is, security node #21 verifies security node #22.
[0650] 4104, safety node #21 sends a response message to safety node #22, and safety node #22 receives the response message.
[0651] For example, safety node #21 sends a TGP-C protocol response message to safety node #22.
[0652] Optionally, the response message includes capability information of security node #21, such as trusted services that security node #21 can provide.
[0653] 3. The first safety node is safety node #1, and the second safety node is safety node #2.
[0654] In this scenario, security node #1 can obtain the identity information and / or address information of security node #2, and security node #2 can also obtain the identity information and / or address information of security node #1, so that trusted signaling and / or trusted data can be transmitted between security node #1 and security node #2.
[0655] Optionally, security node #1 sends capability information of security node #1 to security node #2, such as the trusted services that security node #1 can provide, and security node #2 sends capability information of security node #2 to security node #1, such as the trusted services that security node #2 can provide.
[0656] After obtaining the trusted services provided by Security Node #2, Security Node #1 can perform certain security-related operations. For example, Security Node #1 can verify whether Security Node #2 meets the requirements of the network's trusted policy based on the trusted services it provides. In another example, Security Node #1 can request certain security functions from Security Node #2 in subsequent communications based on the trusted services it provides. In another example, when executing a security function requiring the participation of multiple nodes, Security Node #1 can configure each Security Node #2 based on the trusted services it can provide. For example, when multiple nodes establish a blockchain, Security Node #1 can determine which Security Node #2s are full nodes, light nodes, or clients based on their capabilities. In another example, when implementing homomorphic encryption, Security Node #1 can determine which of its Security Node #2s are computing and which are encrypting. In another example, Security Node #1 can generate a network trusted policy based on the capabilities of each Security Node #2 to match its own trusted functions.
[0657] The following describes how Security Node #1 and Security Node #2 obtain parameter #A, combining two scenarios: direct connection between Security Node #1 and Security Node #2 and third-party assisted connection.
[0658] Scenario 1: Security Node #1 and Security Node #2 establish a connection.
[0659] In a first possible implementation, safety node #2 determines parameter #A of safety node #1 by itself, and safety node #1 obtains parameter #A of safety node #2 from safety node #2.
[0660] Figure 42 is a schematic flow chart of establishing a communication connection between safety node #1 and safety node #2. As an example, the process of establishing a communication connection between safety node #1 and safety node #2 includes the following steps.
[0661] 4201. Safety node #2 sends a registration request message to safety node #1. The registration request message includes parameter #A of safety node #2. Safety node #1 receives the registration request message.
[0662] Among them, parameter #A of security node #2 can be carried through a message of the trusted protocol layer (for example, TEG-C).
[0663] For example, after safety node #2 joins the network, the management plane configures parameter #A of safety node #1 for safety node #2. After that, safety node #2 can use parameter #A of safety node #1 to send a registration request message to safety node #1.
[0664] 4202, security node #1 and security node #2 perform authentication and registration processes.
[0665] 4203. Safety node #1 sends a registration response message to safety node #2, and safety node #2 receives the registration response message.
[0666] For example, safety node #1 sends a registration response message of the TEG-C protocol to safety node #2.
[0667] Optionally, the registration response message includes capability information of security node #1, such as trusted services that security node #1 can provide.
[0668] In a second possible implementation, safety node #2 itself determines parameter #A of safety node #1, and safety node #1 itself determines parameter #A of safety node #2.
[0669] For example, after Safety Node #2 joins the network, the management plane configures Safety Node #1's parameter #A for Safety Node #2 and also configures Safety Node #1's parameter #A for Safety Node #2. After that, Safety Node #1 and Safety Node #2 can communicate directly. It's understood that in this case, the registration process between Safety Node #1 and Safety Node #2 doesn't need to be performed.
[0670] In scenario 2, Security Node #1 and Security Node #2 establish a connection through the assistance of a third party.
[0671] In a third possible implementation, security node #2 obtains parameter #A of security node #1 from other nodes (such as a network node or a management node), and security node #1 obtains parameter #A of security node #2 from security node #2.
[0672] Figure 43 is another schematic flow chart of establishing a communication connection between safety node #1 and safety node #2. As an example, the process of establishing a communication connection between safety node #1 and safety node #2 includes the following steps.
[0673] 4301, safety node #2 obtains parameter #A of safety node #1 from the network node.
[0674] For example, after safety node #2 establishes a connection with the network node, safety node #2 requests parameter #A of safety node #1 from the network node, or the network node actively sends parameter #A of safety node #1. After that, safety node #2 can use parameter #A of safety node #1 to send a registration request message to safety node #1.
[0675] It should be understood that the example used here to illustrate the situation in which Safety Node #2 obtains Parameter #A of Safety Node #1 from a network node is not limiting. For example, the network node can be replaced with another node, such as a management node. For example, Safety Node #2 can request Parameter #A of Safety Node #1 from the management node, or the management node can proactively send Parameter #A of Safety Node #1.
[0676] 4302. Safety node #2 sends a registration request message to safety node #1. The registration request message includes parameter #A of safety node #2. Safety node #1 receives the registration request message.
[0677] Among them, parameter #A of security node #2 can be carried through a message of the trusted protocol layer (for example, TEG-C).
[0678] 4303. Safety node #1 sends a registration response message to safety node #2, and safety node #2 receives the registration response message.
[0679] For example, safety node #1 sends a registration response message of the TEG-C protocol to safety node #2.
[0680] In a fourth possible implementation, security node #1 obtains parameter #A of security node #2 through other nodes (such as other network nodes or management nodes), and security node #2 obtains parameter #A of security node #1 through security node #1.
[0681] Figure 44 is another schematic flow chart of establishing a communication connection between safety node #1 and safety node #2. As an example, the process of establishing a communication connection between safety node #1 and safety node #2 includes the following steps.
[0682] 4401. The network node sends parameter #A of safety node #2 to safety node #1, and safety node #1 receives parameter #A of safety node #2.
[0683] The parameter #A of the security node #2 may be carried via a message of the trusted protocol layer (eg, TNE-C).
[0684] For example, after security node #2 establishes a connection with the network node, the network node sends information about security node #2 to security node #1. The information about security node #2 includes parameters of security node #2. Optionally, the information about security node #2 includes capability information about security node #2, such as trusted services that security node #2 can provide.
[0685] 4402. Safety node #1 sends parameter #A of safety node #1 to safety node #2, and safety node #2 receives parameter #A of safety node #1.
[0686] Among them, parameter #A of security node #1 can be carried through a message of the trusted protocol layer (such as TEG-C).
[0687] Optionally, security node #1 also sends capability information of security node #1 to security node #2, such as the trusted services that security node #1 can provide.
[0688] Optionally, in 4403, safety node #2 sends the profile of safety node #2 to safety node #1, and safety node #1 receives the profile of safety node #2.
[0689] A fifth possible implementation method is that security node #2 notifies security node #1 of parameter #A of the first network node through other nodes (such as other network nodes, or management nodes), and security node #1 notifies security node #2 of parameter #A of security node #1 through other nodes.
[0690] Figure 45 is another schematic flow chart of establishing a communication connection between safety node #1 and safety node #2. As an example, the process of establishing a communication connection between safety node #1 and safety node #2 includes the following steps.
[0691] 4501. Safety node #2 sends a registration request message to the network node. The registration request message includes parameter #A of safety node #2. The network node receives the registration request message.
[0692] Among them, parameter #A of security node #2 can be carried through a message of the trusted protocol layer (for example, TNG-C).
[0693] For example, after security node #2 establishes a connection with the network node, security node #2 sends a registration request message to the network node. Optionally, the registration request message includes capability information of security node #2, such as trusted services that security node #2 can provide.
[0694] 4502. The network node sends parameter #A of safety node #2 to safety node #1, and safety node #1 receives parameter #A of safety node #2.
[0695] The parameter #A of the security node #2 may be carried via a message of the trusted protocol layer (eg, TNE-C).
[0696] Optionally, at 4503 , security node #1 and security node #2 perform an authentication process.
[0697] 4504. Safety node #1 sends a registration response message to safety node #2 through the network node, and safety node #2 receives the registration response message.
[0698] Optionally, the registration response message includes capability information of security node #1, such as trusted services that security node #1 can provide.
[0699] The preceding sections describe the trusted protocol stack for secure nodes, the connection between secure nodes and network nodes, and the solutions for connecting secure nodes. Next, we'll use trusted metrics and post-quantum cryptography (PQC) algorithms as examples to explain the specific applications of secure nodes.
[0700] In trust measurement, the entities involved are divided into attesters and verifiers. When the verifier needs to verify the attester's trustworthiness, it generates a challenge value and sends it to the attester. The attester generates trustworthiness measurement evidence based on the challenge value and returns it. The verifier compares the evidence with a reference value (RV) to verify the trustworthiness measurement evidence. Based on the verification result, it determines whether the attester is trustworthy and obtains the measurement result (AR).
[0701] Figure 46 is a schematic flow chart of the trustworthiness measurement provided by an embodiment of the present application. As shown in Figure 46, the trustworthiness measurement process may include the following steps.
[0702] 4601. The base station sends a trusted service request message to security node #1. The trusted service request message includes a trusted service type and a prover ID. Security node #1 receives the trusted service request message.
[0703] Among them, the trusted service type is trusted measurement.
[0704] As an example, the prover may be any device including a dedicated hardware module (such as a trusted platform module (TPM)). This application does not limit the form of the prover.
[0705] Optionally, at 4602, security node #1 queries AR based on the prover ID.
[0706] For example, Security Node #1 queries the AR locally based on the attestor ID, or obtains the AR from the blockchain.
[0707] In one possible scenario, security node #1 queries the AR based on the witness ID. In this case, the method includes step 4603: security node #1 sends the AR to the base station.
[0708] In another possible scenario, security node #1 fails to find the AR based on the prover ID. In this case, the method includes steps 4604 to 4614.
[0709] 4604, security node #1 obtains trusted proof parameters based on the prover ID.
[0710] As an example, the trusted proof parameters include: PK and / or RV corresponding to the prover.
[0711] In one possible implementation, a corresponding relationship is stored at security node #1, which includes the relationship between the prover ID and its corresponding trusted proof parameters, so that security node #1 can receive the prover ID and the stored corresponding relationship, or the trusted proof parameters corresponding to the prover ID.
[0712] In another possible implementation, security node #1 can request the trustworthy proof parameters corresponding to the prover ID from other nodes based on the prover ID. The other nodes store a corresponding relationship between the prover ID and its corresponding trustworthy proof parameters.
[0713] The corresponding relationship may exist in the form of a table, a function, or a character string, such as for storage or transmission.
[0714] 4605. Security node #1 sends the prover ID and trusted proof parameters to security node #2 serving the verifier, and security node #2 serving the verifier receives the prover ID and trusted proof parameters.
[0715] For example, security node #1 sends a TEG-C protocol message to security node #2 serving as a verifier, where the message includes a prover ID and trusted proof parameters.
[0716] 4606, security node #2 serving the verifier generates a challenge value based on the trusted proof parameters.
[0717] As an example, the generation method may be based on a public key (PK) of the prover, or based on a random number, a timestamp, etc.
[0718] 4607. Security node #2 serving the verifier sends a challenge value to security node #2 serving the prover, and security node #2 serving the prover receives the challenge value.
[0719] For example, secure node #2 serving as the verifier sends a TGP-C protocol message to secure node #2 serving as the prover, where the message includes a challenge value.
[0720] 4608. Security node #2 serving the prover generates evidence based on the challenge value.
[0721] For example, security node #2 serving the prover can use the challenge value and information generated by the device itself (such as the hash values of the files started sequentially when the device starts) as algorithm input parameters, and obtain evidence by processing these inputs, that is, the output parameters are the evidence.
[0722] 4609. Security node #2 serving the prover sends evidence to security node #2 serving the verifier, and security node #2 serving the verifier receives the evidence.
[0723] For example, the security node #2 serving as the prover sends a TGP-C protocol message to the security node #2 serving as the verifier, where the message includes evidence.
[0724] 4610, security node #2 serving the verifier verifies the evidence and obtains AR'.
[0725] 4611. Security node #2 serving the verifier sends AR' to security node #1, and security node #1 receives the AR'.
[0726] For example, security node #2 serving as a verifier sends a TEG-C protocol message to security node #1, where the message includes AR'.
[0727] 4612, security node #1 obtains AR based on AR'.
[0728] In one possible scenario, the security node #1 sends the AR' as the final measurement result to the base station.
[0729] In another possible scenario, security node #1 processes AR' to obtain the final measurement result AR. For example, AR' is signed by security node #2 serving the verifier using its own PK. After receiving it, security node #1 verifies the signature of security node #2 serving the verifier, removes the signature to obtain the pure measurement result, and adds the measurement result AR signed using its own PK. Generally speaking, security node #2 can register with security node #1, so security node #1 can verify the signature of security node #2. The base station may know the signature of security node #1 but not the PK of other security nodes #2 (that is, security nodes #2 other than the security node #2 serving itself). Therefore, the base station can verify the signature of security node #1, and the final measurement result provided by security node #1 to the base station can be the result signed with its own PK.
[0730] Optionally, safety node #1 saves the AR.
[0731] 4613. Safety node #1 sends an AR to the base station, and the base station receives the AR.
[0732] The above describes a trusted measurement solution. This solution allows Security Node #1 and Security Node #2 to perform trusted measurement. Furthermore, having Security Node #1 and Security Node #2 provide trusted measurement services improves security and eliminates the need for network nodes to process these parameters, reducing energy consumption and overhead.
[0733] Figure 47 is a schematic flow chart of configuring an encryption algorithm provided in an embodiment of the present application. As shown in Figure 47, the process of configuring PQC may include the following steps.
[0734] 4701. Safety node #1 sends trusted signaling to at least one safety node #2. The trusted signaling indicates updating of a trusted function. The at least one safety node #2 receives the trusted signaling.
[0735] For example, Security Node #1 triggers an update process by sending a TEG-C protocol management request message to at least one Security Node #2, requesting an update of a trusted function. In this embodiment of the present application, this trusted signaling indicates an update to a cryptographic module, such as the addition of one or more encryption algorithms, such as a PQC algorithm or a homomorphic encryption algorithm.
[0736] 4702, security node #2 configures the encryption algorithm based on trusted signaling.
[0737] For example, in step 4701, the trusted signaling indicates the addition of a PQC algorithm, and in step 4702, the security node #2 configures the PQC algorithm.
[0738] 4703. Safety node #2 sends the capability information of safety node #2 to the base station served by safety node #2, and the base station served by safety node #2 receives the capability information of safety node #2.
[0739] Specifically, the capability information of the safety node #2 is updated. Therefore, a notification message of the TNG-C protocol may be sent to the base station served by the safety node #2 to notify the safety node #2 of the new capability information.
[0740] Optionally, at 4704 , the base station verifies whether the capability information of security node #2 meets the trust requirements of the base station.
[0741] Through the above scheme, encryption algorithms (such as PQC algorithm) can be added to the communication network, so that the threats posed by quantum computing in the communication network can be reduced through encryption algorithms.
[0742] The following uses the PQC algorithm as an example to introduce the application of the encryption algorithm. It is understood that the PQC algorithm described below can also be replaced with other encryption algorithms, and this is not limited to this.
[0743] Figure 48 is a schematic flow chart of the application of the PQC algorithm. As shown in Figure 48, the process of applying the PQC algorithm may include the following steps.
[0744] 4801. Base station #1 sends a plaintext message to be encrypted to security node #2 serving base station #1, and security node #2 serving base station #1 receives the plaintext message to be encrypted.
[0745] Taking the PQC algorithm as an example, when base station #1 receives a PQC task with base station #2, it can send a plaintext message to be encrypted to the security node #2 serving base station #1 through the TNG-U protocol.
[0746] 4802. Security node #2 serving base station #1 performs PQC encryption on the plaintext message to obtain a ciphertext message.
[0747] 4803. Security node #2 serving base station #1 sends a ciphertext message to security node #2 serving base station #2, and security node #2 serving base station #2 receives the ciphertext message.
[0748] 4804. Security node #2 serving base station #2 performs PQC decryption on the ciphertext message.
[0749] Optionally, in 4805, the security node #2 serving the base station #2 sends the plaintext decrypted by PQC to the base station #2, and the base station #2 receives the plaintext decrypted by PQC.
[0750] If the message sent by base station #1 needs to be processed by base station #2, the security node #2 serving base station #2 can send the plaintext decrypted by PQC to base station #2 through the TNG-U protocol, and base station #2 can process it after receiving the plaintext.
[0751] Based on this technical solution, Security Node #2 can perform PQC encryption and decryption for data between network nodes. Furthermore, providing PQC services through Security Node #1 and Security Node #2 provides enhanced security and eliminates the need for network nodes to process these parameters, reducing energy consumption and overhead.
[0752] As mentioned above, security function modules may also be deployed in network nodes. Then, a hybrid network architecture may appear in the communication network, which includes both independent security nodes #1 and security nodes #2, as well as network nodes that include security function modules, as shown in Figure 49.
[0753] Figure 49 is a schematic diagram of a hybrid network architecture. As shown in Figure 49, RAN#2' includes a security function module gear and engine, RAN#1' includes a security function module gear, and the UE includes a security function module gear. This architecture also includes independent security node gear and engine. It can be understood that the engine deployed in the network node and the independent engine have the same functionality, differing only in their deployment methods. Similarly, the gear deployed in the network node and the independent gear have the same functionality, differing only in their deployment methods.
[0754] Figure 50 is a schematic diagram of the node interface in a hybrid network architecture.
[0755] In a first possible scenario, the network node includes a security function module engine.
[0756] As shown in FIG50 , taking a base station as an example, as an example, the interface types of the base station including the security function module engine include the following interfaces:
[0757] 1) Interface with Security Node #1: supports TEP protocol;
[0758] 2) Interface with security node #2: supports TEG and TNG protocols (if the base station also includes a security function module gear, it does not need to support the TNG protocol);
[0759] 3) Interface with network nodes: supports TNE, TEG (if the opposite node includes a security function module gear), and TEP (if the opposite node includes a security function module engine).
[0760] Figure 51 is a schematic diagram of the trusted protocol stack for a base station including the security function module "engine." In the figure, "engine base station" indicates a base station including the security function module "engine," "gear base station" indicates a base station including the security function module "gear," and "EG base station" indicates a base station including both the security function modules "engine" and "gear." Figure 51 illustrates the trusted control plane protocol stack. The trusted service plane protocol stack is similar and will not be further described here.
[0761] In one possible implementation, the trusted protocols can reside at different layers. For example, in Figure 51, where the peer is Security Node #2 (i.e., the gear), the TEG and TNG reside at different layers. For example, the TEG resides above the TNG. This allows Security Node #2 and the base station to establish a connection using the TEG protocol, and then communicate with the security function module engine in the base station.
[0762] Another possible implementation is that the trusted protocol can be located at the same layer. Taking the scenario in Figure 51 where the peer is the local node's security node #2 as an example, the TEG and TNG can be located at the same layer. For ease of description, Figure 51 only shows the different layers.
[0763] In a second possible scenario, the network node includes a security function module gear.
[0764] As shown in FIG50 , taking a base station as an example, as an example, the interface types of the base station including the security function module gear include the following interfaces:
[0765] 1) Interface with Security Node #1: supports TEG and TNE protocols;
[0766] 2) Interface with Security Node #2: supports TGP protocol;
[0767] 3) Interface with network nodes: supports TNE, TGP (if the opposite node includes a security function module gear), and TEG protocols (if the opposite node includes a security function module engine).
[0768] Figure 52 is a schematic diagram of a trusted protocol stack of a base station including a security function module gear. Figure 52 shows a trusted control plane protocol stack, and the trusted service plane protocol stack is similar and will not be described in detail here.
[0769] In one possible implementation, the trusted protocols can reside at different layers. For example, in Figure 52 , where the peer is security node #2 (i.e., gear), the TEG and TNE reside at different layers. As an example, the TEG resides above the TNE. It should be understood that Figure 52 is merely an example and not limiting. For example, in a scenario where the peer includes security function modules (engine and gear), the TNE could reside at the second layer, while the TGP and TEG could reside at the first layer.
[0770] Another possible implementation is that the trusted protocol can be located at the same layer. Taking the scenario in Figure 52 where the peer is security node #2 as an example, the TEG and TNE can be located at the same layer. For ease of description, Figure 52 only shows the different layers.
[0771] In the third possible scenario, the network node includes security function modules gear and engine.
[0772] Taking a base station as an example, as an example, the interface types of the base station including the security function modules gear and engine include the following interfaces:
[0773] 1) Interface with Security Node #1: supports TEP protocol;
[0774] 2) Interface with Security Node #2: supports TGP and TEG protocols;
[0775] 3) Interface with network nodes: supports TNE, TGP (if the opposite node includes the security function module gear), and TEP protocols (if the opposite node includes the security function module engine).
[0776] Figure 53 is a schematic diagram of a trusted protocol stack of a base station including security function modules gear and engine. Figure 53 shows a trusted control plane protocol stack, and the trusted service plane protocol stack is similar and will not be described in detail here.
[0777] In one possible implementation, the trusted protocols can reside at different layers. For example, in Figure 53, where the peer is Security Node #2, the TGP and TEG reside at different layers. As an example, the TGP resides above the TEG. It should be understood that Figure 53 is merely an example and not limiting. For example, if the peer includes the security function modules engine and gear, the TNE could reside at the second layer, while the TGP and TEG could reside at the first layer.
[0778] Another possible implementation is that the trusted protocol can be located at the same layer. Taking the scenario in Figure 53 where the peer is security node #2 as an example, TGP and TEG can be located at the same layer. For ease of description, Figure 53 only shows the different layers.
[0779] Based on the above technical solution, if the network node includes a security function module, a trusted protocol can be designed between the network node and the security node, and then the security node and the security function module in the network node can be responsible for security-related operations, which is simple to operate.
[0780] As can be seen from the above, the technical solution provided by this application can effectively achieve the decoupling of security functions and communication functions by providing independently deployed security nodes and corresponding trusted protocols, which is conducive to the independent evolution and flexible deployment of security functions. In addition, through trusted protocols, security functions can be service-oriented and the request and response processes of security services can be standardized. In addition, through independently deployed security nodes and trusted protocols, users can also choose and independently configure trusted functions and trusted services on demand. In addition, this application also provides security processes such as trusted metrics and PQC algorithms that may be supported by future mobile networks.
[0781] Compared with the integration of security functions into multiple protocol functions, there is no dedicated security protocol, and the security functions are tightly coupled with the communication functions, resulting in the upgrade and update of security functions requiring the modification of multiple protocols in multiple communication nodes, which is labor-intensive and complex to operate; at the same time, the communication standards pay less attention to security, and only have simple functions such as encryption, integrity protection, authentication and authorization, and lack a unified standard process for adding, deleting or changing security functions. Compared with many defects, the technical solution provided by this application has many of the above-mentioned advantages.
[0782] It is understood that in some of the above embodiments, when "transmission" is mentioned, unless otherwise specified, transmission includes receiving and / or sending. For example, transmitting a signal may include receiving a signal and / or sending a signal.
[0783] It is also understood that in some of the above embodiments, engine, TEF (i.e., the engine deployed in the core network), and security node #1 are sometimes used interchangeably. It is understood that, unless otherwise specified, they represent the same meaning. Gear, TGF (i.e., the gear deployed in the core network), and security node #2 are sometimes used interchangeably. It is understood that, unless otherwise specified, they represent the same meaning.
[0784] It can also be understood that in the embodiments of the present application, the name of the message (such as a management request message, a service request message) does not limit the scope of protection of the embodiments of the present application.
[0785] It can also be understood that in some of the above embodiments, the first safety node is used as an example for description. It can be understood that, unless otherwise specified, the first safety node can be replaced by safety node #1, or the first safety node can be replaced by safety node #2.
[0786] It can also be understood that in this application, expressions related to "trusted" can also be replaced by expressions related to "secure". For example, trusted functions can also be expressed as secure functions, trusted information can also be expressed as secure information, etc. The names of these functions, messages or information are not limited.
[0787] The communication method provided by this application is introduced in detail above. The communication device provided by this application is introduced below.
[0788] In order to implement the functions of each communication device in the above method embodiment, the communication device may include a hardware structure and / or a software module, and the corresponding functions of the communication device may be implemented in the form of a hardware structure, a software module, or a hardware structure plus a software module.
[0789] Figure 54 is a schematic diagram of a communication device provided in an embodiment of the present application. As shown in Figure 54, communication device 5400 includes a processing module 5410 and a communication module 5420. Communication device 5400 can be a network element, or a device applied to a network element and capable of executing a method executed on the network element side, such as a chip, a chip system, or a circuit. Optionally, the network element can include a security node (such as security node #1, security node #2), a terminal device, an access network device, or a core network device, without limitation.
[0790] The communication module may be a transceiver module, a transceiver, a transceiver, or a transceiver device. The processing module may be a processor, a processing board, a processing unit, or a processing device. Optionally, the communication module is used to perform the sending and / or receiving operations of each network element in the above method. The device used to implement the receiving function in the communication module can be regarded as a receiving unit, and the device used to implement the sending function in the communication module can be regarded as a sending unit. That is, the communication module includes a receiving unit and a sending unit.
[0791] The aforementioned communication module and / or processing module may be implemented by a virtual module, for example, the processing module may be implemented by a software functional unit or a virtual device, and the communication module may be implemented by a software function or a virtual device. Alternatively, the processing module and / or the communication module may also be implemented by a physical device, for example, the communication device may be implemented by a chip, a chip system or a circuit. In this implementation, the communication module may be an input / output circuit and / or a communication interface, performing input operations (corresponding to the aforementioned receiving operations) and output operations (corresponding to the aforementioned sending operations); the processing module is an integrated processor, microprocessor, integrated circuit or logic circuit, etc.
[0792] The division of modules in the above-mentioned device embodiment is schematic and is only a logical functional division. In actual implementation, there may be another division method, that is, a division method different from the division method of Figure 54. In addition, in the case where the functions of each communication device in the device embodiment are divided into multiple functional modules, the multiple functional modules can be integrated into one module, or they can exist physically separately, or two or more modules can be integrated into one module. Optionally, the integrated module can be implemented in the form of hardware, software functional modules, or hardware plus software functional modules, without limitation.
[0793] Figure 55 is a schematic diagram of another communication device provided in an embodiment of the present application. Optionally, the communication device 5500 can be a chip or a chip system. Optionally, in the present application, the chip system can be composed of a chip, or can include a chip and other discrete devices.
[0794] The communication device 5500 may include at least one processor 5510. Optionally, the processor 5510 is coupled to a memory, which may be located within the communication device, or the memory may be integrated with the processor, or the memory may be located outside the device. For example, the communication device 5500 may further include at least one memory 5520. The memory 5520 stores the necessary computer programs, instructions, and / or data for implementing any of the above examples, as well as the protocol stacks or protocol layers of the corresponding network elements (e.g., security nodes (such as security node #1, security node #2), terminal devices, access network devices, NFs of the core network, etc.) in the above method embodiments; the processor 5510 may execute the computer programs, protocol stacks, or protocol layers stored in the memory 5520 to complete the method performed by the corresponding network element in any of the above method embodiments.
[0795] Optionally, the communication device 5500 further includes a transceiver 5530, and the communication device 5500 can exchange information with other devices through the transceiver 5530. Exemplarily, the transceiver 5530 can be a circuit, a bus, a module, a pin, or another type of communication interface. When the communication device 5500 is a chip-type device or circuit, the transceiver 5530 in the communication device 5500 can also be an input-output circuit that can input information (or receive information) and output information (or send information). The processor is an integrated processor, microprocessor, integrated circuit, or logic circuit, etc., and the processor can determine output information based on the input information.
[0796] Coupling in this application refers to an indirect coupling or communication connection between devices, units, or modules, which can be electrical, mechanical, or other forms, and is used for information exchange between devices, units, or modules. The processor 5510 may operate in conjunction with the memory 5520 and the transceiver 5530. The specific connection medium between the processor 5510, memory 5520, and transceiver 5530 is not limited in this application.
[0797] Optionally, the processor 5510, the memory 5520 and the transceiver 5530 are interconnected via a bus.
[0798] In addition, the present application also provides a computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on a computer, the functions of the corresponding network elements (for example, terminal devices, access network nodes, NFs of the core network, etc.) in any of the above embodiments are implemented.
[0799] The present application also provides a computer program product, which includes computer program code. When the computer program code runs on a computer, the functions of the corresponding network elements in any of the above embodiments (for example, security nodes (such as security node #1, security node #2), terminal devices, access network nodes, NFs of the core network, etc.) are implemented.
[0800] The present application also provides a wireless communication system, comprising one or more network elements in any of the above-described method embodiments. Exemplarily, the communication system includes any combination of security nodes (e.g., security node #1 and security node #2), terminals, access network nodes, and NFs of a CN in the embodiments of the present application. Optionally, the number of any one network element is not limited to one or more.
[0801] In this application, a processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or execute the methods, steps, and logic block diagrams disclosed in this application. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in this application may be directly executed by a hardware processor, or by a combination of hardware and software modules within the processor.
[0802] In this application, the memory may be a non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), or a volatile memory, such as a random-access memory (RAM). The memory is any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory in this application may also be a circuit or any other device that can implement a storage function, for storing program instructions and / or data.
[0803] The technical solutions provided in this application can be implemented in whole or in part through software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in this application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a terminal device, an access network device, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital video disc (DVD)), or a semiconductor medium.
[0804] In this application, under the premise of no logical contradiction, the examples can reference each other, for example, the methods and / or terms between method embodiments can reference each other, for example, the functions and / or terms between device embodiments can reference each other, for example, the functions and / or terms between device examples and method examples can reference each other.
[0805] Unless otherwise specified, "plurality" means two or more than two. "At least one item" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0806] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship, for example, A / B can represent A or B; "and / or" in the present application is merely a description of the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural.
[0807] In various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0808] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0809] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0810] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0811] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0812] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0813] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0814] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A method for information transmission, characterized in that: Applied to a communication network, the communication network includes a first security node and at least one network node, the method includes: The first security node establishes a communication connection with the at least one network node, and the first security node is used to provide a security function for the communication network; The first security node transmits trusted signaling and / or trusted data with the at least one network node via the communication connection.
2. The method according to claim 1, characterized in that The first safety node includes a first node and / or a second node, the first node is used to manage the safety function, and the second node is used to execute the safety function.
3. The method according to claim 1 or 2, characterized in that: The first security node includes a trusted protocol layer, and the trusted protocol layer processes the trusted signaling and / or trusted data.
4. The method according to claim 3, characterized in that The first security node also includes one or more of the following protocol layers located below the trusted protocol layer: a protocol layer for data packet processing, a protocol layer for transmission, a protocol layer for establishing a connection, and a protocol layer for establishing a channel.
5. The method according to any one of claims 1 to 4, characterized in that The trusted signaling is used for one or more of the following functions: management of trusted functions, management of trusted requirements, negotiation of trusted policies, notification of trusted services, or request for trusted services.
6. The method according to claim 5, characterized in that The management of the trusted function includes one or more of the following: establishment of a trusted function, activation of a trusted function, initial configuration of a trusted function, update of a trusted function, addition of a trusted function, deletion of a trusted function, or conversion of a state of a trusted function.
7. The method according to claim 5 or 6, characterized in that: The trusted service includes one or more of the following: authentication service, authorization service, trusted measurement service, blockchain service, situational awareness service, or network global trusted policy service.
8. The method according to any one of claims 1 to 7, characterized in that The trusted data includes one or more of the following: situational awareness related data, homomorphic encryption related data, homomorphic computing related data, blockchain related data, or keys.
9. The method according to any one of claims 1 to 8, characterized in that The at least one network node includes a first network node, and the first security node establishes a communication connection with the at least one network node, including: The first security node obtains identity information and / or address information of the first network node; The first security node transmits trusted signaling and / or trusted data with the first network node based on the identity information and / or address information of the first network node.
10. The method according to claim 9, characterized in that The first security node obtains the identity information and / or address information of the first network node, including any one of the following: The first security node receives identity information and / or address information of the first network node from the first network node; The first security node receives identity information and / or address information of the first network node from other network nodes; The first security node itself determines the identity information and / or address information of the first network node; The first security node receives the identity information and / or address information of the first network node from the management node; or, The first security node receives the identity information and / or address information of the first network node from other security nodes.
11. The method according to claim 9 or 10, characterized in that: The method further comprises: The first security node sends one or more of the following to the first network node: trusted services that the first security node can provide, identity information of the first security node, or address information of the first security node.
12. The method according to any one of claims 1 to 11, characterized in that The communication network further includes a second security node, and the method further includes: The first safety node transmits trusted signaling and / or trusted data with the second safety node.
13. The method according to claim 12, characterized in that Before the first safety node transmits trusted signaling and / or trusted data with the second safety node, the method further includes: The first security node obtains the identity information and / or address information of the second security node.
14. The method according to claim 13, characterized in that The first security node obtains the identity information and / or address information of the second security node, including any one of the following: The first security node receives identity information and / or address information of the second security node from the second security node; The first security node receives identity information and / or address information of the second security node from the at least one network node; The first security node determines the identity information and / or address information of the second security node by itself; The first security node receives the identity information and / or address information of the second security node from the management node; or, The first safety node receives the identity information and / or address information of the second safety node from other safety nodes.
15. The method according to claim 13 or 14, characterized in that The method further comprises: The first security node sends one or more of the following to the second security node: trusted services that the first security node can provide, identity information of the first security node, or address information of the first security node.
16. The method according to any one of claims 12 to 15, characterized in that The method further comprises: The first security node receives, from the second security node, a trusted service that the second security node can provide.
17. The method according to any one of claims 1 to 16, characterized in that The at least one network node includes one or more of the following: at least one access network device, at least one core network device, and at least one terminal device.
18. A method for information transmission, characterized in that: Applied to a communication network, the communication network includes a first network node and a first security node, the method includes: The first network node establishes a communication connection with the first security node, and the first security node is used to provide a security function for the communication network; The first network node transmits trusted signaling and / or trusted data with the first security node via the communication connection.
19. The method according to claim 18, characterized in that The first network node comprises a trusted protocol layer, which processes the trusted signaling and / or trusted data.
20. The method according to claim 19, characterized in that The first network node also includes one or more of the following protocol layers located below the trusted protocol layer: a protocol layer for data packet processing, a protocol layer for transmission, a protocol layer for establishing a connection, and a protocol layer for establishing a channel.
21. The method according to any one of claims 18 to 20, characterized in that The trusted signaling is used for one or more of the following functions: management of trusted functions, management of trusted requirements, negotiation of trusted policies, notification of trusted services, or request for trusted services.
22. The method according to claim 21, characterized in that The management of the trusted function includes one or more of the following: establishment of a trusted function, activation of a trusted function, initial configuration of a trusted function, update of a trusted function, addition of a trusted function, deletion of a trusted function, or conversion of a state of a trusted function.
23. The method according to claim 21 or 22, characterized in that The trusted service includes one or more of the following: authentication service, authorization service, trusted measurement service, blockchain service, situational awareness service, or network global trusted policy service.
24. The method according to any one of claims 18 to 23, characterized in that The trusted data includes one or more of the following: situational awareness related data, homomorphic encryption related data, homomorphic computing related data, blockchain related data, and keys.
25. The method according to any one of claims 18 to 24, characterized in that The first network node establishing a communication connection with the first security node includes: The first network node obtains identity information and / or address information of the first security node; The first network node transmits trusted signaling and / or trusted data with the first security node based on the identity information and / or address information of the first security node.
26. The method according to claim 25, characterized in that The first network node obtains the identity information and / or address information of the first security node, including any one of the following: The first network node receives identity information and / or address information of the first security node from the first security node; The first network node receives identity information and / or address information of the first security node from other network nodes; The first network node determines the identity information and / or address information of the first security node by itself; The first network node receives the identity information and / or address information of the first security node from the management node, or, The first network node receives identity information and / or address information of the first security node from other security nodes.
27. The method according to claim 25 or 26, characterized in that The method further comprises: The first network node sends one or more of the following to the first security node: identity information of the first network node, or address information of the first network node.
28. The method according to any one of claims 18 to 27, characterized in that The first network node transmits trusted signaling and / or trusted data with the first security node through the communication connection, including: The first network node receives, from the first security node, a trusted service that the first security node can provide.
29. The method according to any one of claims 18 to 28, characterized in that The first network node is any one of the following: an access network device, a core network device, and a terminal device.
30. A communication system, characterized in that: comprising at least one security node and at least one network node, wherein the at least one security node is used to provide a security function for the communication system, The at least one security node establishes a communication connection with the at least one network node; The at least one security node transmits trusted signaling and / or trusted data with the at least one network node via the communication connection.
31. The system according to claim 30, characterized in that The at least one safety node comprises a first safety node, and the first safety node is used to perform the method according to any one of claims 1 to 17.
32. The system according to claim 30 or 31, characterized in that The at least one network node comprises a first network node, the first network node being configured to perform the method according to any one of claims 18 to 29.
33. A communication device, characterized in that: The method comprises modules or units for executing the method as claimed in any one of claims 1 to 29.
34. A communication device, characterized in that: include: A processor, the processor is coupled to a memory, the processor is configured to execute a computer program or instruction stored in the memory, so that the communication device executes the method according to any one of claims 1 to 29.
35. A chip, characterized in that: It includes a processor and a communication interface, wherein the communication interface is used to receive information and / or data to be processed and send the information and / or data to be processed to the processor, and the processor is used to process the information and / or data to be processed, so that the communication device installed with the chip executes the method as described in any one of claims 1 to 29.
36. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and when the computer instructions are executed on a computer, the method according to any one of claims 1 to 29 is implemented.
37. A computer program product, characterized in that The computer program product comprises a computer program code, which enables the method according to any one of claims 1 to 29 to be implemented when the computer program code is run on a computer.