Method and apparatus for communication
By using KMF to determine encryption and integrity algorithms, the problem of increased message overhead and storage overhead in future network information exchange is solved, achieving more efficient network security protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-10
- Publication Date
- 2026-04-17
Smart Images

Figure CN121890123A_ABST
Abstract
Description
Cross-reference to related applications
[0001] This application relates to and claims priority to U.S. Provisional Patent Application No. 63 / 586,462, filed on September 29, 2023, entitled “System and methods for activation on security protection communications.”
[0002] The disclosure of the above application is incorporated herein by reference in its entirety. Technical Field
[0003] The present invention relates to the field of communication technology, and more specifically, to methods and apparatus for communication. Background Technology
[0004] Encryption and integrity algorithms are used to protect the security of communication between user equipment (UE) and network functions in a network. However, as new applications and services supported by the network in the future will generate new interfaces, the exchange of information related to these algorithms will lead to high message overhead. Furthermore, storing information related to these algorithms by relevant network functions will result in additional storage overhead and security risks. Summary of the Invention
[0005] This application provides methods and apparatus for communication, which can reduce message exchange overhead.
[0006] According to a first aspect, embodiments of this application provide a communication method, which can be executed by a key management function (KMF) or a chip installed in the KMF. The KMF is a network function responsible for key management. The method includes: determining a first algorithm based on a first security capability and security requirements for communication between a device and a first network function, wherein the security requirements for communication include security requirements for services, applications, tasks, or sessions, wherein the service, application, task, or session is related to the communication, and the first algorithm includes an encryption algorithm for protecting the communication and / or an integrity algorithm for protecting the communication; sending a first message to the first network function, wherein the first message includes the first algorithm.
[0007] According to a second aspect, embodiments of this application provide a communication method, which can be executed by a first network function or a chip installed in the first network function. The method includes: receiving a first message from a KMF, wherein the first message includes a first algorithm, the first algorithm being determined based on a first security capability and security requirements for communication between the device and the first network function, the security requirements for the communication including security requirements for services, applications, tasks, or sessions related to the communication, and the first algorithm including an encryption algorithm for protecting the communication and / or an integrity algorithm for protecting the communication.
[0008] According to the above technical solution, the KMF is responsible for key management. The algorithm used to protect communication is determined by the KMF. For communication between the UE and the first network function, since the algorithm used to protect communication is configured by the KMF for the first network function, message exchange overhead can be reduced and network performance efficiency can be improved. Furthermore, since the algorithm can be determined based on the security requirements of communication-related services, applications, tasks, or sessions, it can meet the different needs of different scenarios.
[0009] In conjunction with the first or second aspect, in some embodiments, the first security capability of the communication includes at least one of the following: the security capability of the device or the security capability of the first network function.
[0010] According to the above technical solution, the algorithm used for security protection is determined based on the device's security capabilities and / or the security capabilities of the first network function. This is conducive to the effective implementation of security protection.
[0011] In conjunction with the first or second aspect, in some embodiments, the method further includes: sending or receiving a second message, wherein the second message includes an identifier of the device and the security requirements of the communication. The second message is used to determine whether security protection for the communication needs to be activated.
[0012] In conjunction with the first aspect, in some embodiments, the method further includes: sending a first request for collecting the first security capability, wherein the first request is determined based on the security requirements of the communication; receiving a third message, wherein the third message includes at least one of the following: the security capability of the device or the security capability of the first network function.
[0013] In conjunction with the second aspect, in some embodiments, the first security capability includes the security capabilities of the device, and the method further includes: receiving a first request for collecting the security capabilities of the device, wherein the first request is determined based on the security requirements of the communication; collecting the security capabilities of the device based on the first request; and sending a third message, wherein the third message includes the security capabilities of the device.
[0014] Referring to the first or second aspect, in some embodiments, the third message further indicates at least one of the following: a plurality of encryption algorithms that can be used by the first network function to protect the communication, or a plurality of integrity algorithms that can be used by the first network function to protect the communication.
[0015] Referring to the first or second aspect, in some embodiments, the first message further includes an identifier of a first anchor key, and the first algorithm is associated with the first anchor key.
[0016] Referring to the first or second aspect, in some embodiments, the method further includes sending or receiving a fourth message, wherein the fourth message includes an indication for generating a new anchor key.
[0017] In some implementations, the first anchor key includes the new anchor key.
[0018] Referring to the first or second aspect, in some embodiments, the first message further includes first information indicating whether the new anchor key is generated.
[0019] Referring to the second aspect, in some embodiments, the first algorithm includes the integrity algorithm for protecting the communication and the encryption algorithm for protecting the communication. The method further includes: initiating integrity protection of the communication based on the integrity algorithm; sending a fifth message to the device, wherein the fifth message includes the integrity algorithm, the encryption algorithm, and an identifier of an anchor key associated with the first algorithm.
[0020] According to a third aspect, a communication device is provided, the communication device having functions or modules for performing the method of the first aspect or the method of the second aspect or any implementation thereof.
[0021] According to a fourth aspect, a chip (chip system) is provided. The chip includes at least one processor coupled to at least one memory. The at least one memory is used to store one or more instructions and / or executable computer code. The at least one processor is used to invoke the one or more instructions and / or executable computer code to cause a communication device mounted on the chip to perform the method of the first aspect or the method of the second aspect or any possible implementation thereof.
[0022] Optionally, the chip may also include at least one memory. Optionally, the chip may also include a communication interface for inputting and / or outputting information or data.
[0023] According to a fifth aspect, a communication device is provided. The communication device includes one or more circuits and one or more communication interfaces. The one or more communication interfaces may include a first interface for receiving (i.e., inputting) information and / or data to be processed by the one or more circuits, and a second interface for transmitting (i.e., outputting) the information and / or data processed by the one or more circuits. The one or more circuits are used to process the information and / or data to be processed, causing the communication device to perform the method of the first aspect or the method of the second aspect, or any possible implementation of these aspects.
[0024] According to a sixth aspect, a communication system is provided. The communication system may include the communication devices described in the third to fifth aspects. For example, the communication system may include one or more of the following: KMF or a first network function. The communication system may also include equipment.
[0025] According to a seventh aspect, a computer storage medium is provided storing executable computer code, the executable computer code being used to execute one or more instructions of the method described in the first aspect or any possible implementation thereof, or the second aspect or any possible implementation thereof.
[0026] According to the eighth aspect, a computer program product comprising one or more instructions is provided, wherein when the computer program product is run on a computer, the computer performs the method described in the first aspect or any possible implementation thereof, or in the second aspect or any possible implementation thereof. Attached Figure Description
[0027] Figure 1 This is a simplified diagram of a communication system.
[0028] Figure 2 An exemplary communication system is shown.
[0029] Figure 3 Another example of an ED and a base station is shown.
[0030] Figure 4 The unit or module in the device is shown.
[0031] Figure 5 The conceptual architecture of a 6G system is shown.
[0032] Figure 6 These are some network scenarios provided by embodiments of this application.
[0033] Figure 7 This is a key management architecture provided by some embodiments of this application.
[0034] Figure 8 This is a schematic flowchart of a communication method provided in an embodiment of this application.
[0035] Figure 9 This is a schematic flowchart illustrating a communication method provided in some embodiments of this application.
[0036] Figure 10 These are examples of call flows for the security activation process provided in some embodiments of this application.
[0037] Figure 11 This is another example of the call flow for the security activation process provided in some embodiments of this application.
[0038] Figure 12 This is a schematic block diagram of the communication device 10 provided in the embodiments of this application.
[0039] Figure 13 This is a schematic block diagram of the communication device 10 provided in the embodiments of this application. Detailed Implementation
[0040] To better understand the features and technical content of the embodiments of this application, the implementation methods of the embodiments of this application will be described in detail below with reference to the accompanying drawings. The drawings are for reference and illustration only and are not intended to limit the embodiments of this application. In the following technical description, many details will be set forth for ease of explanation to provide a thorough understanding of the disclosed embodiments.
[0041] The present invention includes at least the following parts.
[0042] (1) Design method for security protection of data sessions The basic concept is that a network function (called the key management function, KMF) is used for selecting security protection algorithms for a session or RB. Furthermore, the KMF collects factors related to the selection of security protection algorithms for a session or RB.
[0043] (2) Design the C / M session security protection activation process This embodiment provides a C / M session security protection activation process.
[0044] (3) Provide C / M RB security protection activation process This embodiment provides detailed information on the C / M RB security protection activation process.
[0045] To better understand the technical solution proposed in this application, the relevant technologies and concepts are introduced first.
[0046] This invention generally relates to wireless communication.
[0047] Many emerging trends will trigger considerations and designs for 6G / future wireless networks: new network infrastructure capabilities (e.g., widely deployed cloud-native / cloud-friendly infrastructure); new or relatively mature technologies (e.g., large-scale artificial intelligence (AI) models, data privacy, blockchain, etc.), which have made significant progress and have had a major impact on society and human life; new applications and services (e.g., AI services, data or sensing services, digital world services, etc.), which are widely used in industries / businesses and by individual customers; and a more globalized / open / collaborative operating trend (i.e., more open and collaborative operating models are becoming common practice in many fields).
[0048] New expectations and stricter requirements for future networks have also driven a rethinking and development of next-generation wireless networks. These requirements include privacy and trustworthiness, simplified standardization, and rapid deployment.
[0049] All of these factors have driven the research on the sixth-generation (6G) network architecture.
[0050] Our proposed 6G network architecture (centered on X) is based on SBA (XaaS service) and / or cloud-native. X as a service can be represented as XaaS.
[0051] The requirements for 6G system network architecture design include: (1) The proposed 6G network architecture needs to support new 6G services, which can be developed / deployed by third parties.
[0052] (2) The proposed 6G network architecture needs to embrace a more open ecosystem and open its doors to technically capable third parties.
[0053] (3) The proposed 6G network architecture needs to achieve better trusted management.
[0054] A solution is needed to achieve the above requirements.
[0055] To facilitate understanding of the embodiments of this application, let's first take... Figures 1 to 4 Taking the communication system shown as an example, the communication system applicable to the embodiments of this application will be described in detail below.
[0056] refer to Figure 1 This diagram, provided as an illustrative example and not as limiting, is a simplified schematic of a communication system. Communication system 100 includes a radio access network 120. Radio access network 120 may be a next-generation (e.g., 6G or later) radio access network, or a traditional (e.g., fifth-generation, fourth-generation, third-generation, or second-generation, 2G) radio access network. One or more electronic devices (EDs) 110a to 110j (generally referred to as 110) may be interconnected with each other or connected to one or more network nodes (170a, 170b, generally referred to as 170) within radio access network 120. Core network 130 may be part of the communication system and may depend on or be independent of the radio access technology used in communication system 100. Furthermore, communication system 100 includes a public switched telephone network (PSTN) 140, the Internet 150, and other networks 160.
[0057] Figure 2An exemplary communication system 100 is illustrated. Typically, the communication system 100 enables multiple wireless or wired components to transmit data and other content. The purpose of the communication system 100 may be to provide content such as voice, data, video, and / or text via broadcast, multicast, ensemble, unicast, etc. The communication system 100 can operate by sharing resources (e.g., carrier spectrum bandwidth) among its components. The communication system 100 may include terrestrial communication systems and / or non-terrestrial communication systems. The communication system 100 can provide a wide range of communication services and applications (e.g., earth monitoring, remote sensing, passive sensing and positioning, navigation and tracking, autonomous delivery and mobility, etc.). The communication system 100 can provide high availability and robustness through the joint operation of terrestrial and non-terrestrial communication systems. For example, integrating a non-terrestrial communication system (or components thereof) into a terrestrial communication system can enable a heterogeneous network comprising multiple layers. Compared to traditional communication networks, heterogeneous networks can achieve better overall performance through efficient multi-link joint operation, more flexible function sharing, and faster physical layer link switching between terrestrial and non-terrestrial networks.
[0058] Terrestrial communication systems and non-terrestrial communication systems can be considered subsystems of a communication system. Figure 2 In the example shown, communication system 100 includes electronic devices (EDs) 110a to 110d (generally referred to as ED 110), radio access networks (RANs) 120a and 120b, a non-terrestrial communication network 120c, a core network 130, a public switched telephone network (PSTN) 140, the Internet 150, and other networks 160. RANs 120a and 120b include corresponding base stations (BSs) 170a and 170b, which may generally be referred to as terrestrial transmit and receive points (T-TRPs) 170a and 170b. The non-terrestrial communication network 120c includes an access node 172, which may generally be referred to as a non-terrestrial transmit and receive point (NT-TRP) 172.
[0059] Any ED 110 can be used alternatively or additionally to connect, access, or communicate with any T-TRP 170a and 170b, NT-TRP 172, Internet 150, core network 130, PSTN 140, other network 160, or any combination thereof. In some examples, ED 110a can transmit uplink and / or downlink to T-TRP 170a via terrestrial air interface 190a. In some examples, ED 110a to 110d can also communicate directly with each other via one or more sidelink air interfaces 190b. In some examples, ED 110d can transmit uplink and / or downlink to NT-TRP 172 via non-terrestrial air interface 190c.
[0060] Air interfaces 190a and 190b can use similar communication technologies, such as any suitable wireless access technology. For example, communication system 100 can implement one or more channel access methods in air interfaces 190a and 190b, such as code division multiple access (CDMA), space division multiple access (SDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), and single-carrier FDMA (SC-FDMA) (or discrete fourier transform spread OFDMA (DFT-s-OFDMA)). Air interfaces 190a and 190b can utilize other high-dimensional signal spaces, which may involve combinations of orthogonal and / or non-orthogonal dimensions.
[0061] The non-terrestrial air interface 190c enables communication between the ED 110d and one or more NT-TRP 172s via a wireless link or a simple link. For some examples, the link is a dedicated connection for unicast transmission, a connection for broadcast transmission, or a connection between a group of ED 110s and one or more NT-TRP 172s for multicast transmission.
[0062] RANs 120a and 120b communicate with core network 130 to provide various services, such as voice, data, and other services, to EDs 110a, 110b, and 110c. RANs 120a and 120b and / or core network 130 may communicate directly or indirectly with one or more other RANs (not shown), which may or may not be directly served by core network 130 and may or may not use the same radio access technology as RANs 120a, RAN 120b, or both. Core network 130 may also serve as a gateway access between (i) RANs 120a and 120b or EDs 110a, 110b, and 110c, or both, and (ii) other networks (e.g., PSTN 140, Internet 150, and other networks 160). Furthermore, some or all of EDs 110a, 110b, and 110c may include the ability to communicate with different wireless networks via different radio links using different radio technologies and / or protocols. Instead of wireless communication (or other than wireless communication), ED 110a, 110b, and 110c can also communicate with service providers or exchanges (not shown) via wired communication channels and with the Internet 150. PSTN 140 may include a circuit-switched telephone network for providing plain old telephone service (POTS). The Internet 150 may include a network of computers and / or subnets (internal networks) and incorporate protocols such as Internet Protocol (IP), Transmission Control Protocol (TCP), and User Datagram Protocol (UDP). ED 110a, 110b, and 110c may be multimode devices capable of operating under various wireless access technologies and include multiple transceivers required to support these wireless access technologies.
[0063] Figure 3Another example of an ED 110 and base stations 170a, 170b, and / or 170c is shown. The ED 110 is used to connect people, objects, machines, etc. The ED 110 can be widely used in various scenarios, including, for example, cellular communication, device-to-device (D2D), vehicle-to-everything (V2X), peer-to-peer (P2P), machine-to-machine (M2M), machine-type communication (MTC), Internet of Things (IoT), virtual reality (VR), augmented reality (AR), mixed reality (MR), virtual reality, digital twins, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearable devices, smart transportation, smart cities, drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery and mobility, etc.
[0064] Each ED 110 represents any suitable end-user equipment used for wireless operation and may include, for example (or may be referred to as), user equipment (UE), wireless transmit / receive unit (WTRU), mobile station, fixed or mobile subscriber unit, cellular phone, station (STA), machine type communication (MTC) device, personal digital assistant (PDA), smartphone, laptop, computer, tablet, wireless sensor, consumer electronics device, smart book, vehicle, car, truck, bus, train, or IoT device, wearable device (e.g., watch, glasses, head-mounted device, etc.), industrial equipment, or devices in or including the above-mentioned equipment (e.g., communication module, modem, or chip). Next-generation ED 110 may be referred to using other terms. Base stations 170a and 170b are T-TRPs, hereinafter referred to as T-TRP 170. Also in Figure 3 As shown, NT-TRP is referred to below as NT-TRP 172. Each ED 110 connected to T-TRP 170 and / or NT-TRP 172 can be dynamically or semi-statically turned on (i.e., established, activated, or enabled), turned off (i.e., released, deactivated, or disabled), and / or configured in response to one or more of connectivity availability and connectivity necessity.
[0065] ED 110 includes a transmitter 201 and a receiver 203 coupled to one or more antennas 204. To avoid clutter, only one antenna 204 is shown in the figure. One, some, or all of the antennas 204 may also be panels. The transmitter 201 and receiver 203 may be integrated, for example, as a transceiver. The transceiver is used to modulate data or other content for transmission by at least one antenna 204 or a network interface controller (NIC). The transceiver is also used to demodulate data or other content received by at least one antenna 204. Each transceiver includes any suitable structure for generating signals for wireless or wired transmission and / or for processing signals received wirelessly or wiredly. Each antenna 204 includes any suitable structure for transmitting and / or receiving wireless or wired signals.
[0066] ED 110 includes at least one memory 208. Memory 208 stores instructions and data used, generated, or collected by ED 110. For example, memory 208 may store software instructions or modules for implementing some or all of the functions and / or embodiments described herein, and executed by one or more processing units (e.g., processor 210). Each memory 208 includes any suitable one or more volatile and / or non-volatile storage devices with one or more retrieval devices. Any suitable type of memory can be used, such as random access memory (RAM), read-only memory (ROM), hard disk, optical disk, subscriber identity module (SIM) card, memory stick, secure digital (SD) memory card, on-processor cache, etc.
[0067] ED 110 may also include one or more input / output devices (not shown) or interfaces (e.g., connected to...). Figure 1 (Wired interface of Internet 150 in the network). Input / output devices or interfaces can interact with users or other devices in the network. Each input / output device or interface includes any suitable structure for providing or receiving information from the user, and / or for network interface communication. Suitable structures include, for example, speakers, microphones, keypads, keyboards, displays, touchscreens, etc.
[0068] ED 110 includes a processor 210 for performing operations related to: preparing uplink transmissions to NT-TRP 172 and / or T-TRP 170, processing downlink transmissions received from NT-TRP 172 and / or T-TRP 170, and processing sidelink transmissions with another ED 110. Processing operations related to preparing uplink transmissions may include operations such as encoding, modulation, transmit beamforming, and generating symbols for transmission. Processing operations related to processing downlink transmissions may include operations such as receive beamforming, demodulation, and decoding of received symbols. According to an embodiment, the downlink transmissions may be received by receiver 203 possibly using receive beamforming, and processor 210 may extract signaling from the downlink transmissions (e.g., by detecting and / or decoding signaling). Examples of signaling may be reference signals transmitted by NT-TRP 172 and / or T-TRP 170. In some embodiments, processor 210 performs transmit beamforming and / or receive beamforming based on beam direction indications received from T-TRP 170, such as beam angle information (BAI). In some embodiments, processor 210 may perform operations related to network access (e.g., initial access) and / or downlink synchronization, such as operations related to detecting synchronization sequences, decoding, and acquiring system information. In some embodiments, processor 210 may perform channel estimation, for example, using reference signals received from NT-TRP 172 and / or T-TRP 170.
[0069] Although not shown, processor 210 may form part of transmitter 201 and / or receiver 203. Although not shown, memory 208 may form part of processor 210.
[0070] The processor 210, the processing components of the transmitter 201, and the processing components of the receiver 203 may each be implemented by one or more processors, which are used to execute instructions stored in memory (e.g., in memory 208). Alternatively, some or all of the processor 210, the processing components of the transmitter 201, and the processing components of the receiver 203 may each be implemented using dedicated circuitry, such as a programmable field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), a graphics processing unit (GPU), or a hardware accelerator such as an artificial intelligence (AI) accelerator.
[0071] In some implementations, the T-TRP 170 can use other names, such as base station, basetransceiver station (BTS), wireless base station, network node, network device, network-side device, transmit / receive node, Node B, evolved Node B (eNodeB or eNB), home eNodeB, next-generation Node B (gNB), transmission point (TP), site controller, access point (AP), wireless router, relay station, ground node, ground network device, ground base station, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The T-TRP 170 can be a macro BS, pico BS, relay node, host node, or a combination thereof. T-TRP 170 may refer to the aforementioned equipment or a device within the aforementioned equipment (e.g., a communication module, modem, or chip).
[0072] In some embodiments, the various parts of T-TRP 170 may be distributed. For example, some modules of T-TRP 170 may be located remotely from the device housing the antenna 256 of T-TRP 170 and may be coupled to the device housing the antenna 256 via a communication link (not shown) (sometimes referred to as a fronthaul, such as a Common Public Radio Interface (CPRI)). Therefore, in some embodiments, the term T-TRP 170 may also refer to modules on the network side that perform processing operations such as ED110 location determination, resource allocation (scheduling), message generation, and encoding / decoding, which are not necessarily part of the device housing the antenna 256 of T-TRP 170. These modules may also be coupled to other T-TRPs. In some embodiments, T-TRP 170 may actually be multiple T-TRPs that operate together, for example, by using the Cooperative Multicast Service ED 110.
[0073] T-TRP 170 includes at least one transmitter 252 and at least one receiver 254 coupled to one or more antennas 256. To avoid drawing clutter, only one antenna 256 is shown in the figure. One, some, or all of the antennas 256 may also be panels. The transmitter 252 and receiver 254 may be integrated as a transceiver. T-TRP 170 also includes a processor 260 for performing operations including: preparing transmissions for downlink transmission to ED 110, processing uplink transmissions received from ED 110, preparing transmissions for backhaul transmission to NT-TRP 172, and processing transmissions received from NT-TRP 172 via backhaul. Processing operations related to preparing for downlink or backhaul transmissions may include operations such as encoding, modulation, precoding (e.g., multiple-input multiple-output (MIMO) precoding), transmit beamforming, and generating symbols for transmission. Processing operations related to uplink transmissions or transmissions received via backhaul transmissions may include operations such as receive beamforming, demodulation, and decoding of received symbols. Processor 260 may also perform operations related to network access (e.g., initial access) and / or downlink synchronization, such as generating the contents of a synchronization signal block (SSB), generating system information, etc. In some embodiments, processor 260 also generates a beam direction indication (e.g., BAI), which can be scheduled by scheduler 253 for transmission. Processor 260 performs other network-side processing operations described herein, such as determining the location of ED 110, determining the deployment location of NT-TRP 172, etc. In some embodiments, processor 260 may generate signaling, such as configuring one or more parameters of ED 110 and / or one or more parameters of NT-TRP 172. Any signaling generated by processor 260 is transmitted by transmitter 252. It should be noted that the term "signaling" as used herein may also be referred to as control signaling. Signaling can be transmitted in physical layer control channels (e.g., physical downlink control channel (PDCCH)). In this case, the signaling can be called dynamic signaling. Signaling transmitted in the downlink physical layer control channel can be called downlink control information (DCI). Signaling transmitted in the uplink physical layer control channel can be called uplink control information (UCI). Signaling transmitted in the sidelink physical layer control channel can be called sidelink control information (SCI).Signaling can be included in higher-layer (e.g., above the physical layer) data packets transmitted in physical layer data channels (e.g., in the physical downlink shared channel, PDSCH). In this case, the signaling can be referred to as higher-layer signaling, static signaling, or semi-static signaling. Higher-layer signaling can also refer to radio resource control (RRC) protocol signaling or media access control-control element (MAC-CE) signaling.
[0074] Scheduler 253 may be coupled to processor 260. Scheduler 253 may be included within or operate separately from T-TRP 170. Scheduler 253 may schedule uplink, downlink, lateral link, and / or backhaul transmissions, including issuing scheduling authorizations and / or configuring scheduling-free (e.g., "configured authorization") resources. T-TRP 170 also includes memory 258 for storing information and data. Memory 258 stores instructions and data used, generated, or collected by T-TRP 170. For example, memory 258 may store software instructions or modules executed by one or more processors 260 for implementing some or all of the functions and / or embodiments described herein.
[0075] Although not shown, processor 260 may form part of transmitter 252 and / or receiver 254. Furthermore, although not shown, processor 260 may implement scheduler 253. Although not shown, memory 258 may form part of processor 260.
[0076] The processing components of processor 260, scheduler 253, transmitter 252, and receiver 254 may each be implemented by one or more processors, which may be the same or different, for executing instructions stored in memory (e.g., memory 258). Alternatively, some or all of the processing components of processor 260, scheduler 253, transmitter 252, and receiver 254 may be implemented using dedicated circuitry such as a programmable FPGA, hardware accelerator (e.g., GPU or AI accelerator), or ASIC.
[0077] Although the NT-TRP 172 is shown as an example of a drone only, it can be implemented in any suitable non-terrestrial form, such as satellites and high-altitude platforms, including international mobile communication base stations and unmanned aerial vehicles. Furthermore, in some implementations, the NT-TRP 172 may use other names, such as a non-terrestrial node, a non-terrestrial network device, or a non-terrestrial base station. The NT-TRP 172 includes a transmitter 272 and a receiver 274 coupled to one or more antennas 280. To avoid cluttering the drawing, only one antenna 280 is shown. One, some, or all of the antennas may also be panels. The transmitter 272 and receiver 274 may be integrated as a transceiver. The NT-TRP 172 also includes a processor 276 for performing operations including: preparing transmissions for downlink transmission to ED 110, processing uplink transmissions received from ED 110, preparing transmissions for backhaul transmission to T-TRP 170, and processing transmissions received from T-TRP 170 via backhaul. Processing operations related to preparing for downlink or backhaul transmission may include operations such as encoding, modulation, precoding (e.g., MIMO precoding), transmit beamforming, and generating symbols for transmission. Processing operations related to processing transmissions received during uplink transmission or via backhaul transmission may include operations such as receive beamforming, demodulation, and decoding of received symbols. In some embodiments, processor 276 performs transmit beamforming and / or receive beamforming based on beam direction information (e.g., BAI) received from T-TRP 170. In some embodiments, processor 276 may generate signaling, such as configuring one or more parameters of ED 110. In some embodiments, NT-TRP 172 implements physical layer processing but does not implement higher-layer functions, such as medium access control (MAC) or radio link control (RLC) layer functions. Since this is only an example, more generally, NT-TRP 172 may implement higher-layer functions in addition to physical layer processing.
[0078] The NT-TRP 172 also includes a memory 278 for storing information and data. Although not shown, a processor 276 may form part of the transmitter 272 and / or receiver 274. Although not shown, the memory 278 may form part of the processor 276.
[0079] The processor 276, the processing components of the transmitter 272, and the processing components of the receiver 274 may each be implemented using one or more processors, which are the same or different, to execute instructions stored in memory (e.g., in memory 278). Alternatively, some or all of the processor 276, the processing components of the transmitter 272, and the processing components of the receiver 274 may be implemented using dedicated circuitry such as a programmable FPGA, hardware accelerator (e.g., a GPU or AI accelerator), or ASIC. In some embodiments, the NT-TRP 172 may actually be multiple NT-TRPs that operate together to serve ED 110, for example, through cooperative multicast.
[0080] T-TRP 170, NT-TRP 172 and / or ED 110 may include other components, but for clarity these components are omitted.
[0081] according to Figure 4 One or more steps of the methods in the various embodiments provided herein can be performed by the corresponding units or modules. Figure 4 Units or modules in the device are shown, such as in ED 110, T-TRP 170, or NT-TRP 172. For example, signals may be transmitted by a transmitting unit or transmitting module. Signals may be received by a receiving unit or receiving module. Signals may be processed by a processing unit or processing module. Other steps may be performed by an AI or machine learning (ML) module. The corresponding units or modules may be implemented using hardware, one or more components or devices executing software, or a combination thereof. For example, one or more units or modules in the unit or module may be circuits such as integrated circuits. Examples of integrated circuits include programmable FPGAs, GPUs, or ASICs. For example, one or more units or modules in the unit or module may be logic, such as logical functions executed by circuits, a portion of an integrated circuit, or software instructions executed by a processor. It should be understood that if the above modules are implemented using software executed by a processor, etc., these modules may be retrieved by the processor, wholly or partially, individually or collectively, for processing, or in one or more instances as needed, and these modules themselves may include instructions for further deployment and instantiation.
[0082] Further details regarding ED 110, T-TRP 170, and NT-TRP 172 are known to those skilled in the art. Therefore, these details are omitted herein.
[0083] The solutions described in this application are applicable to next-generation (e.g., 6G or higher) networks or traditional (e.g., 5G, 4G, 3G or 2G) networks.
[0084] The proposed 6G system architecture is defined as supporting 6G XaaS services through the use of technologies such as network function virtualization and network slicing. The 6G system architecture utilizes service-based interactions between 6G services.
[0085] 6G systems utilize a service-based architecture and the XaaS concept. XaaS services in 6G systems are categorized into three layers. For illustrative purposes, Figure 5 The conceptual architecture of a 6G system is shown.
[0086] The infrastructure layer includes the infrastructure that supports 6G services. This includes wireless network infrastructure (e.g., RAN and core network (CN)), cloud / data center infrastructure, satellite networks, storage / database infrastructure, and sensor networks. This infrastructure can be provided by a single provider or by multiple providers.
[0087] Each of these infrastructures can have its own control and management functions, represented as C / M functions, for infrastructure management. Each of these infrastructures is an Infrastructure as a Service.
[0088] The control and management (C / M) layer comprises the control and management services for the 6G system. These are developed and deployed using slicing technology and leverage the resources provided by the infrastructure layer. In the conceptual architecture of a 6G system: Resource management (RM) as a service provides lifecycle management of various slices and the ability to allocate over-the-air resources to wireless devices. Mission management (MM) is a service that provides the ability to offer mission services through XaaS service provision at the service layer. A 6G mission is defined as a service provided by the 6G system to its customers. A mission can be a service type provided by a single 6G XaaS service, or a service type that requires contributions from multiple XaaS services. - Confederation Network (CONET) as a service provides the ability for multiple partners to jointly deliver 6G services. This capability is provided through the negotiation of federation formation, mutual authentication and authorization among partners, and protocols for recording and backtracking selected actions performed by partners, ensuring a trusted environment for the operation of 6G systems.
[0089] Service provisioning management (SPM) is a service that provides control and management over customer access to 6G services and the provision of requested services. This capability is provided through unified mutual authentication, authorization and policies, key management, quality of service (QoS) guarantees, and billing between any pair of XaaS service providers and customers. Customers include not only end customers in the physical world but also digital representatives in the digital world.
[0090] - Connectivity management (CM) as a service leverages 5G connectivity management capabilities but extends to include the digital world.
[0091] Protocol as a Service (PCA) provides the ability to customize protocol stacks for the design services of identified interfaces. Protocol stacks can be predefined for selection on demand, or designed on demand.
[0092] - Cybersecurity as a Service provides infrastructure owners with the ability to detect potential security risks to their infrastructure.
[0093] XaaS services in the C / M layer support the control and management of the 6G system itself and provide support to vertical services upon request. For example, the RM service can provide air resource management services to the RAN, and also provide services to vertical services to enable the allocation of air resources to their end customers. XaaS in the C / M layer can be deployed using slicing technology.
[0094] The service layer includes 6G services provided to customers. In the 6G system conceptual architecture: - AI services are represented as NET4AI as a Service. Artificial intelligence services provide AI capabilities to support a wide range of AI applications.
[0095] Data collection, data cleansing, data analysis, and data delivery services are referred to as DAM as a Service. This service provides the ability to manage the lifecycle of statistical data, including acquiring, de-privatizing, analyzing, and delivering data (i.e., information statistics) from any type of sensor, device, network function, etc.
[0096] - The data storage and sharing service is represented as NET4Data as a Service. This service provides the ability to reliably store and share data under the control of the data owner and in accordance with recognized authorities' regulations on the control and identification of data.
[0097] Services that provide access to the digital world are represented as NET4DW as a Service. Digital world services provide the ability to build, control, and manage the digital world. The digital world is defined as the digital realization of the physical world.
[0098] The 6G blockchain service is represented as NET4BC as a service. This service provides the capability to support 6G blockchain services.
[0099] -6G connectivity services are represented as NET4CON as a service. Enhanced connectivity services, such as Connectivity Network (NET4CON) as a service, provide the ability to exchange messages and data between supporting new 6G services.
[0100] All XaaS services in this layer are developed and deployed using resources provided within the infrastructure and leveraging network function virtualization and slicing technologies. The capabilities of each 6G service are provided by its control and management functions, as well as service-specific data processing capabilities.
[0101] In addition to supporting 6G XaaS services at the service layer, the 6G system also utilizes the 5G system to provide vertical services. The difference between 6G XaaS services and other vertical services is that a vertical service is a pure client that requires other XaaS services to support its operation, while each service in the XaaS service provides its capabilities to the 6G client.
[0102] In a 6G system, any pair of XaaS services can also act as both customer and provider to each other. Some examples include infrastructure owners providing their resources to XaaS services in the service layer and C / M layer; RM services potentially requiring the capabilities provided by NET4AI, DAM, and NET4DW for vertical slice resource management; and CONET and NET4Data services potentially requiring the capabilities provided by NET4BC to function.
[0103] Key concepts of 6G systems include: - Basic XaaS services are defined by decoupling comprehensive types of services into basic XaaS services. Basic XaaS services provide unique capabilities to enable specific types of services, such as NET4AI services, NET4DW services, DAM services, NET4Data services, blockchain services, task management services, etc.
[0104] -Supports multiple partners to jointly operate the 6G system.
[0105] - Define the data plane of the 6G system, including the data plane processing capabilities of XaaS services. By programming the interconnection of these capabilities through task management services, various customized customer services can be supported.
[0106] -Simplify the 6G system architecture by categorizing basic control and management services and combining them into basic XaaS services in the C / M layer.
[0107] - Define the C / M plane of the 6G system, which includes C / M functionality in XaaS services and may include 5G CP (e.g., AMF) depending on the implementation options.
[0108] - Define the basic architecture structure (BAS), which is a unified basic structure with a minimal number of interfaces and is independent of the infrastructure type.
[0109] - The BAS concept simplifies the standardization, development, and deployment of 6G systems, while supporting a variety of infrastructure deployment scenarios.
[0110] - By applying BAS or subsets of it to the infrastructure based on the capabilities, capacity, and needs of the infrastructure network, it can be adapted to a variety of deployment scenarios.
[0111] -Utilize the SBI interface concept and apply SBI interaction in the 6G C / M plane and 6G data plane.
[0112] -Simplify the SBI interface by introducing a trusted gateway (GW) in the data plane and C / M plane of the 6G system.
[0113] - Improve trustworthiness from the perspective of 6G system operation by introducing CONET capabilities, NET4BC capabilities and anonymity service configurations provided by a trusted GW into the C / M plane and data plane of the 6G system.
[0114] - Enhance trustworthiness from the perspective of end-customer privacy protection by providing unified mutual authentication, IDM, data cleansing, etc. through SPM service, DAM service and 6G blockchain service.
[0115] - Simplify roaming management of wireless devices in the physical and digital worlds through unified authentication (including all participating partners and customers).
[0116] - By defining multiple architecture options, it supports multiple development paths from 5G systems to 6G systems, requiring minimal work due to the introduction of the BAS concept.
[0117] - By leveraging the advantages of SBA and its additional features, backward compatibility is supported. 5G users can use 6G systems to access 5G services.
[0118] - Supporting future expansion by adding new XaaS services minimizes the impact on standardization and deployment, thanks to the anonymous service configuration concept introduced in the Trusted GW implemented in the 6G C / M plane and 6G data plane.
[0119] Currently, when user equipment (UE) is able to connect to the network, a security process is involved between the UE and network functions. For illustrative purposes, the key hierarchy or key framework involved in the current security process may include: keys for protecting non-access stratum (NAS) signals using specific integrity / encryption algorithms (also known as keys for NAS integrity / encryption), keys for protecting user plane (UP) traffic using specific integrity / encryption algorithms (also known as keys for UP integrity / encryption), and keys for protecting RRC signaling using specific integrity / encryption algorithms (also known as keys for RRC integrity / encryption). These keys can be used to securely protect the NAS interface, data from the UE to the RAN, and the RRC interface, respectively; these keys can be derived from long-term shared keys known to the UE and the network. For example, keys for UP integrity / encryption can be indirectly derived from long-term shared keys and information about the UE and the service network. UE information may include PCI or the UE ID. These keys for UP integrity / encryption are used to protect data from the UE to the RAN after a PDU session is established. These keys for UP integrity / encryption can be used for secure multiple PDU sessions. However, using the same key in multiple secure communication sessions can lead to data leaks if the key is corrupted.
[0120] As mentioned above, future networks will support new applications and services, such as AI services, data services, sensing services, and digital world services. These services can utilize resources provided by infrastructure (e.g., wireless access networks, data centers, or other infrastructure) and leverage network function virtualization and slicing technologies for development and deployment. Any service can be referred to as anything as a service (XaaS). An XaaS module can contain multiple network functions. These network functions can be categorized into two types: client / management (C / M) functions and data processing functions. Data processing functions are used to process data and can only exist in the XaaS service layer. C / M functions are used for control and management and can exist in both the XaaS service layer and the C / M layer. XaaS service providers can also be referred to as XaaS services.
[0121] Figure 6 These are some network scenarios provided by embodiments of this application. For example... Figure 6As shown, the Control / Management Trusted Gateway (C / M-TW-GW) is a network function that can be defined as an endpoint of a network-side C / M session. A C / M session is established to send control messages to a device or XaaS service. A C / M session can be defined as a secure logical connection between a device (e.g., a UE) and its serving C / M-TW-GW. The Data Trustworthy Gateway (Data-TW-GW) is a network function that can be defined as an endpoint of a device's data session. A data session is established to allow a device or XaaS service to participate in data processing. A data session can be defined as a secure logical connection between a device and its serving Data-TW-GW. The Radio Bearer (RB) handler is a network function that can be implemented as a radio access network (RAN). An RB handler can be defined as a logical function that performs RB protocol stack operations after obtaining configuration. RB handlers can connect to other infrastructure (e.g., the core network and / or a third-party cloud) and the C / M-TW-GW. Communication between the device and the RB handler can include C / M RB or data RB. A C / M plane RB can be defined as an air connection used to carry control signaling for air interface management and C / M plane messages. A data plane RB can be an air connection used to carry data plane traffic. In this scenario, there may be more network functions, such as authentication servers and authorization servers.
[0122] like Figure 6 As shown, in a network scenario, there are several interfaces used to connect these NFs. For example, interface I can be defined as a set of security features that enable devices to securely authenticate and access services and prevent attacks on the radio interface. As another example, interface II can be defined as a set of security features that enable... Figure 6 The system shown can securely exchange C / M sessions between the device and the C / M-TW-GW, or securely exchange data sessions between the device and the Data-TW-GW. For example, Interface III can be defined as a set of security features enabling the system to securely exchange C / M sessions between the XaaS service and the C / M-TW-GW, or securely exchange data sessions between the XaaS service and the Data-TW-GW. In other words, Interface I can support connections between the device and the RB processor; Interface II can support connections between the device and the C / M-TW-GW / Data-TW-GW; and Interface III can support connections between the XaaS service and the C / M-TW-GW / Data-TW-GW. For example, Interface IV can support connections between the RB processor and the C / M-TW-GW / Data-TW-GW.
[0123] In this scenario, when a device (e.g., a UE) is able to connect to the network, security procedures are involved between the device and network functions. For example, when the device is able to connect to the C / M-TW-GW and / or the RB handler, the security procedures may include a primary authentication and key negotiation process. The primary authentication and key negotiation process is to achieve mutual authentication between the device and the serving network and to provide key materials that can be used between the device and the serving network. These key materials can be used for signaling security protection on Interface I and Interface II in subsequent security procedures. As another example, when the device requests a service, the security procedures may include a secondary primary authentication and key negotiation process. The secondary authentication and key negotiation process is to achieve mutual authentication between the device and the XaaS service and to provide key materials that can be used between the device and the XaaS service in subsequent security procedures. These key materials can be used for data security protection on Interface I and Interface II in subsequent security procedures.
[0124] Because future networks may involve new services, network functions, and interfaces, the security protection of these new interfaces may become necessary. For illustrative purposes, [the following is used as an example]. Figure 6 Taking the scenario shown as an example, there can be multiple intermediate keys and terminal keys used for security protection, such as keys for protecting C / M sessions (also known as C / M session keys or keys for C / M sessions), keys for protecting data sessions (also known as data session keys or keys for data sessions), keys for protecting C / M RBs (also known as C / M RB keys or keys for C / M RBs), keys for protecting data RBs (also known as data RB keys or keys for data RBs), etc.
[0125] 6G systems should allow the use of encryption and integrity protection algorithms for C / M session keys, C / M RB keys, data session keys, and data RB keys (derived from shared keys). The keys used for C / M sessions, C / M RBs, data sessions, and data RBs should depend on the algorithms used. C / M session keys or data session keys can be derived from anchor keys and can be configured for the serving C / M-TW-GW / Data-TW-GW. Anchor keys can be generated based on shared keys known to the device and network. C / MRB keys and data RB keys can be derived from the keys of the RB processors and can be configured for the RB endpoints. RB processor keys can be intermediate keys and derived from anchor keys. All keys are generated by SPM-KMF (also known as KMF). These SPM-KMFs can be deployed in a hierarchical structure (…). Figure 6 (This is a scenario example), responsible for key generation, key refresh, and key revocation.
[0126] Security protections on these interfaces may include integrity and confidentiality protection, which may involve integrity and encryption algorithms associated with these keys. For example, a C / M session key may include a key for protecting the C / M session using a specific integrity algorithm and a key for protecting the C / M session using a specific encryption algorithm. In other words, Figure 6 The system shown can support the use of integrity and encryption algorithms for C / M session keys, data session keys, C / M RB keys, and data RB keys. The keys used to protect C / M sessions, data sessions, C / M RBs, and data RBs should depend on the algorithms used to protect them.
[0127] In some implementations, future networks may involve a key management function (KMF). The KMF can be a network function responsible for key generation and configuration. Furthermore, the KMF can be responsible for key refresh and revocation. For example, the C / M session key, data session key, C / M RB key, and data RB key can be generated by one or more KMFs.
[0128] Before securing C / M sessions, Data sessions, C / M RBs, and Data RBs, both communicating parties must agree on encryption and integrity algorithms. Encryption and integrity protection are performed on the device and in the C / M-TW-GW, Data-TW-GW, and RB handlers. The choice of encryption method to use for protection on the sessions and RBs must be determined. In other words, activation of encryption and integrity protection for signaled and data messages should be completed before communication between the device and the network begins.
[0129] There are three questions: (1) Who chooses the encryption algorithm and the integrity algorithm? (2) What factors should be considered when choosing an algorithm? (3) How are these factors collected? In 3GPP 33.501, to activate security protection for NAS messages, the AMF should select a NAS encryption algorithm and a NAS integrity protection algorithm to establish a NAS security context. To activate security protection for RB messages, the AMF should send a list of encryption and integrity algorithms to the gNB / ng-eNB. The gNB / ng-eNB should then select the encryption and integrity protection algorithms to establish an AS security context. However, the above method has the following problems: (1) High communication overhead Because changes to the AMF during N2 handover or mobility registration updates lead to changes in the algorithms used to establish NAS security, information exchange occurs between the old AMF and the target AMF. This information pertains to encryption algorithms and NAS integrity protection algorithms. This frequent information exchange can result in higher communication overhead. Similarly, during a handover from the source gNB to the target gNB via Xn, the source gNB should include the encryption and integrity algorithms used in the source cell in its handover request message. Furthermore, during a handover from the source gNB to the target gNB via N2, the target AMF should send the encryption and integrity algorithms to the target gNB. This information exchange can also incur significant communication overhead.
[0130] (2) High storage overhead As mentioned earlier, AMF and gNB store the encryption and integrity algorithms used for the exchange. This may introduce additional storage overhead and some security risks. For example, if one of them is corrupted, the information will be compromised.
[0131] As mentioned above, in 6G systems, SPM-KMF is introduced to manage keys and configure keys for RB processors, C / M-TW-GW, and Data-TW-GW. To address the aforementioned issues, SPM-KMF is enabled to generate security capabilities and activate security protection for session messages and RB messages. The steps are: (1) Who triggers the activation of security protection? Is it the RB processor, C / M-TW-GW, Data-TW-GW, SPM-KMF, or AF (e.g., XaaS service)? What is the call flow for activating security protection? (2) Currently, the main input to security capabilities is only the algorithm ID. However, in 6G systems, there may be more factors, such as service ID, application ID, or session ID. Therefore, how to select an algorithm to improve efficiency is very important.
[0132] For illustrative purposes, Figure 7 The following illustrations show the key management architecture provided by some embodiments of this application.
[0133] like Figure 7 As shown, SPM-KMF-Anchor (also known as KMF-Anchor) is responsible for generating and refreshing anchor keys. Anchor keys can be used to determine whether authentication is required between the device and the network.
[0134] SPM-KMF-Session (also known as KMF-Session) is responsible for generating and refreshing session keys. A session key is used to protect the session between the device and the C / M-TW-GW / Data-TW-GW. In other words, a session key can include a C / M session key and / or a data session key. Furthermore, KMF-Session can be responsible for configuring session keys. For example, a C / M-TW-GW or Data-TW-GW can connect to KMF-Session, and KMF-Session can configure session keys for the C / M-TW-GW or Data-TW-GW.
[0135] SPM-KMF-RB (also known as KMF-RB) is responsible for generating and refreshing RB keys. RB keys are used to protect the RB between the device and the RB handler. In other words, RB keys can include C / M RB keys and / or data RB keys. KMF-RB can also configure RB keys. For example, the RB handler can connect to the KMF-RB, and the KMF-RB can configure the RB keys for the RB handler. Furthermore, KMF-RB can activate security protections for communication between the device and the RB handler.
[0136] In some implementations, at least two of KMF-RB, KMF-Session, and KMF-Anchor are integrated into a single network function, such as KMF. For example, KMF#1 is a network function in which KMF-RB, KMF-Session, and KMF-Anchor can be integrated. In other implementations, KMF-RB, KMF-Session, and KMF-Anchor are distributed across different network functions. For example, KMF#2, KMF#3, and KMF#4 are different network functions, and KMF#2, KMF#3, and KMF#4 can serve as examples of KMF-Anchor, KMF-Session, and KMF-RB, respectively.
[0137] SPM-Authen (also known as the authentication server) is a network function responsible for triggering C / M signaling protection. C / M signaling protection may include C / M key generation and C / M key configuration. The C / M key may include at least one of a C / M session key and a C / M RB key. The authentication server can connect to the KMF-Anchor. After the device is successfully authenticated by the authentication server, the shared key can be sent to the KMF-Anchor. For illustrative purposes, the shared key can be a long-term key, such as an extended master session key (EMSK). The device should be aware of the shared key. These intermediate and terminal keys (e.g., the C / M session key, C / M RB key, and data session key) can be indirectly derived from the shared key.
[0138] The SPM-Author (also known as the Authorization Server) can be a network function used for service management. The Authorization Server can be responsible for triggering data protection, which may include data key generation and data key configuration. Data keys may include at least one of a data session key and a data RB key. The Authorization Server can connect to the KMF-Anchor. After a device is successfully authorized by the Authorization Server, a key for protecting the data session can be generated and configured for the Data-TW-GW.
[0139] Figure 8 This is a schematic flowchart illustrating a communication method provided in some embodiments of this application. Figure 8 The method 300 shown includes steps S310 to S320. Each step is described in detail below.
[0140] In S310, KMF determines the first algorithm based on the first security capability and the security requirements for communication between the device and the first network function.
[0141] In some embodiments, the first network function can be a C / M-TW-GW or a Data-TW-GW. Accordingly, communication between the device and the first network function can be a C / M session between the device and the C / M-TW-GW, or a data session with the endpoint being the Data-TW-GW. In this scenario, KMF can include a KMF-Session.
[0142] In some embodiments, the first network function may be an RB processor. Accordingly, communication between the device and the first network function may be a C / M RB or a data RB. In this scenario, KMF includes KMF-RB.
[0143] At least one service, application, session, or task may be associated with communication between the device and the first network function. A task may be a type of service provided by a single XaaS service or a type of service that requires contributions from multiple XaaS services; in some implementations, security requirements for communication may include security requirements for the service, application, session, or task.
[0144] For illustrative purposes, Task #1 may include Data Session #1, and Task #2 may include Data Session #2 and Data Session #3. Data Session #1 may be associated with Application #1 (e.g., a data analytics application provided or supported by DAM) and Application #2 (e.g., a data collection application provided or supported by DAM). Data Session #2 may be associated with Service #1 (e.g., a service provided or supported by NET4AI), and Data Session #3 may be associated with Service #2 (e.g., a service provided or supported by NET4Data) and Service #3 (e.g., a service supported or provided by NET4DW).
[0145] For example, the security requirements for data session #1 may include the security requirements for application #1 and application #2. As another example, the security requirements for data session #3 should include the security requirements for service #2 and service #3.
[0146] In some implementations, the keys used for security protection of communication between the device and the first network function can have different levels, such as keys for services / applications, keys for sessions, or keys for tasks. For illustrative purposes, keys for services / applications can be used to protect services / applications related to communication (e.g., C / M sessions or data sessions). Keys for sessions can be used to protect sessions related to communication. Keys for tasks can be used to protect all or one or more sessions belonging to a task. In some embodiments, keys for communication security protection can include keys for the device. Keys for the device can be used to protect all or one or more C / M sessions / one or more data sessions belonging to the device. In other words, security protection for C / M sessions or data sessions can be performed per service / application, per session, per task, or per device.
[0147] The first algorithm may include an encryption algorithm and / or an integrity algorithm for protecting communication between the device and the first network function. For illustrative purposes, taking a C / M session as an example, the key used to protect the C / M session may include a key for confidentiality protection of the C / M session and a key for integrity protection of the C / M session. The first algorithm may include an encryption algorithm associated with the key for confidentiality protection of the C / M session, and an integrity algorithm associated with the key for integrity protection of the C / M session.
[0148] For illustrative purposes, it is assumed that service #1 is associated with a C / M session and has high security requirements. KMF can select a more complex algorithm from several options to protect the C / M session.
[0149] In some implementations, the first security capability of communication may include at least one of the following: the security capability of the device or the security capability of the first network function. The security capability may indicate the process capability that can be provided to perform security protection on the communication. For example, the device's security process capability may indicate the encryption / integrity algorithms that the device can implement. As another example, the device's security capability may indicate at least one of the following: the efficiency, compatibility, or performance of the algorithm that the device can execute to protect the communication. As another example, the security process capability of the first network function may indicate the encryption / integrity algorithms that the first network function can implement.
[0150] In S320, KMF sends a first message to the first network function, the first message including the first algorithm. Correspondingly, the first network function receives the first message.
[0151] In some embodiments, the KMF can receive a second message from a first network function. The second message may include the device ID and security requirements for the communication. The KMF can determine whether security protection activation for the communication is required based on the security requirements. When security protection activation is required, the KMF can determine a first algorithm based on the communication's security requirements and a first security capability.
[0152] In some implementations, the KMF can send a first request to collect first security capabilities. The first request is determined based on the security requirements of the communication. The KMF can also receive a third message. The third message may also include at least one of the following: the security capabilities of the device or the security capabilities of a first network function. For example, the KMF can send a request for the security capabilities of the C / M-TW-GW to the C / M-TW-GW, and the C / M-TW-GW can send a response to the KMF including its security capabilities.
[0153] In some embodiments, the third message may indicate at least one of the following: a plurality of encryption algorithms that can be used by the first network function to protect the communication, or a plurality of integrity algorithms that can be used by the first network function to protect the communication.
[0154] For example, the C / M-TW-GW can send a message including a list of algorithms that can be executed at the C / M-TW-GW to perform protection on the C / M session. The KMF can receive the message and select the first algorithm from the list.
[0155] In some implementations, the first message may also include the ID of the first anchor key, wherein the first algorithm is associated with the first anchor key.
[0156] For illustrative purposes, C / M-TW-GW is used as an example of the first network function. The keys used to protect the C / M session between the device and C / M-TW-GW can be derived directly or indirectly from the anchor key, which can be used together with a specific encryption / integrity algorithm of choice to protect the C / M session.
[0157] In some implementations, KMF may receive a fourth message. This fourth message may include an indication for generating a new anchor key, wherein the first anchor key includes the new anchor key.
[0158] The fourth message can be sent by the first network function.
[0159] In some embodiments, the third message and the fourth message may be the same message. In other words, the message may include at least one of the following: the security capabilities of the device and the security capabilities of the first network function, and the message may also include an indication for generating a new anchor key.
[0160] In some implementations, the first message may also include information indicating whether a new anchor key should be generated.
[0161] In some implementations, the first algorithm includes an integrity algorithm for protecting communication and an encryption algorithm for protecting communication. A first network function can perform integrity protection of the communication based on the integrity algorithm and send a fifth message to the device. The fifth message includes the integrity algorithm, the encryption algorithm, and an identifier of the anchor key associated with the first algorithm.
[0162] For illustrative purposes, Figure 6 Taking the scenario shown as an example, combined with Figure 9 The communication method provided in this application is described.
[0163] In one embodiment, depending on the context of the key management framework (e.g.) Figure 6 As shown), this provides a basic concept of how to activate security protections for session communication and RB communication (e.g. Figure 9 (As shown). The purpose of this embodiment is to provide a method for activating security protection for session communication and RB communication. There are three ways to trigger the activation of security protection for session communication and RB communication: (1) device, (2) network (RB handler, C / M-TW-GW, Data-TW-GW), (3) SPM-KMF. This triggering can be accomplished by receiving requests from them.
[0164] refer to Figure 9This is provided as an illustrative example, not a limiting one, and offers a simplified diagram of the security protection principle. When the SPM-KMF receives a request from a device or network function (e.g., RB handler, C / M-TW-GW, or Data-TW-GW), the SPM-KMF should determine whether security protection activation is required. The SPM-KMF can be... Figure 7 The SPM-KMF-Session in the text can also be... Figure 7 The SPM-KMF-RB process then collects factors for selecting an encryption algorithm and an integrity protection algorithm. The SPM-KMF then selects the algorithm for encryption and the algorithm for integrity protection. The SPM-KMF configures these algorithms to the device, or C / M-TW-GW, or Data-TW-GW, or RB processor.
[0165] Figure 9 The details are as follows: (1) How to determine whether security protection activation is required.
[0166] SPM-KMF should determine whether security protection activation is required based on service security requirements from the network and local policies from the network operator. It should be noted that network security requirements should include service security requirements from the device and network security performance.
[0167] (2) Factors in choosing an algorithm Factors influencing algorithm selection can include information from the network, the device, the C / M-TW-GW or Data-TW-GW, and the SPM-KMF. For example, network information may include the security level required by the device, the service / application, or the session. Device information may include the device's security capabilities, such as the efficiency, compatibility, and performance of encryption and integrity algorithms. C / M-TW-GW or Data-TW-GW information may include the security capabilities of the C / M-TW-GW or Data-TW-GW, such as the efficiency, compatibility, and performance of encryption and integrity algorithms. SPM-KMF information may include local policies or the verification time window for the selected algorithm.
[0168] (3) How to configure the algorithm An algorithm for session encryption should be configured for one device and one service, C / M-TW-GW. An algorithm for session integrity protection should be configured for one device and one service, Data-TW-GW. An algorithm for RB encryption should be configured for one device and one service, RB handler. An algorithm for RB integrity protection should be configured for one device and one service, RB handler.
[0169] Figure 9 This is a schematic flowchart of method 400 provided in some embodiments of this application. According to method 400, a method for activating security protection for session communication or RB communication can be provided. Figure 9 The method 400 shown may include steps S402 to S412. Each step is described in detail below.
[0170] In S402, requests are received from device or network functions.
[0171] There are different ways to trigger security protections for session communications and / or RB communications. Security protections can be triggered by devices, KMFs, or networks (e.g., RB handlers, C / M-TW-GW, or Data-TW-GW in the network).
[0172] In some implementations, a device or network function (e.g., an RB handler, C / M-TW-GW, or Data-TW-GW in the network) can send a request to trigger a security protection; correspondingly, the KMF can receive the request.
[0173] In S404, determine whether session communication and / or RB communication require security protection activation.
[0174] When a request is received from a device or network function, KMF should determine whether security protection activation is required. For illustrative purposes, [the following is used as an example]. Figure 7 Taking the scenario shown as an example, Figure 7 The KMF-Session or KMF-RB in the system can make this decision.
[0175] KMF can determine whether security protection activation is required based on at least one of the following: service security requirements from the network or local policies from the network operator. Security requirements from the network can include service security requirements from the device and network security performance.
[0176] In S406, factors for algorithm selection are collected.
[0177] When security protection is required to activate, KMF can collect factors for selecting encryption and integrity algorithms.
[0178] In some implementations, factors for selecting the algorithm may include at least one of the following: information from the network, information from the device, information from the C / M-TW-GW / Data-TW-GW, or information from the KMF. For example, information from the network may include: the security level required by the device, the security level required by the communication-related service / application, or the security level required by the communication-related session / task. As another example, information from the device may include the device's security capabilities. The device's security capabilities may indicate at least one of the following: the efficiency, compatibility, or performance of the algorithm that the device can execute to protect the communication. As another example, information from the C / M-TW-GW / Data-TW-GW may include the C / M-TW-GW / Data-TW-GW's security capabilities. The C / M-TW-GW / Data-TW-GW's security capabilities may indicate at least one of the following: the efficiency, compatibility, or performance of the algorithm that the C / M-TW-GW / Data-TW-GW can execute to protect the communication. As yet another example, information from the KMF may include local policies or the verification time window of the selected algorithm.
[0179] In S408, select the encryption / integrity algorithm.
[0180] KMF can generate keys for protecting communications.
[0181] KMF can select encryption and integrity algorithms associated with these keys.
[0182] For illustrative purposes, Figure 6 Taking the scenario shown as an example, Table 1 illustrates some examples of how to select an algorithm. As shown in Table 1, it is assumed that the communication-related services, applications, or sessions may have low, medium, or high security requirements. Furthermore, it is assumed that the devices or network functions (e.g., RB handlers, C / M-TW-GW, or Data-TW-GW) may have low, medium, or strong security capabilities.
[0183] Table 1: Factors for Algorithm Selection
[0184] In one embodiment, as shown in Table 1, when communication-related services have high security requirements and devices have strong security capabilities, KMF can select a high-complexity algorithm from multiple algorithms.
[0185] In another embodiment, as shown in Table 1, when communication-related sessions have high security requirements and the device has low security capabilities, KMF can select a medium-complexity algorithm.
[0186] In S410, the algorithm is configured.
[0187] KMF can configure the selected algorithm to the device and related network functions (e.g., C / M-TW-GW / Data-TW-GW or RB processor).
[0188] In one embodiment, for a C / M session, encryption and integrity algorithms can be configured for the device and the C / M-TW-GW. For example, the KMF can send a message indicating the ID of the selected algorithm to both the device and the C / M-TW-GW.
[0189] In another embodiment, for data sessions, encryption and integrity algorithms can be configured for the device and service Data-TW-GW.
[0190] In yet another embodiment, for a C / M RB or a data RB, encryption and integrity algorithms can be configured for the device and the RB handler.
[0191] Compared with the existing technology in 3GPP 33.501, the method for activating security protection can have the following new features.
[0192] (1) SPM-KMF has a new feature, namely, determining which algorithm to use for security protection.
[0193] (2) SPM-KMF selects an algorithm based on collected factors These new features bring several benefits, such as reduced communication overhead due to handover and reduced storage overhead due to saving exchanged information.
[0194] For illustrative purposes, a C / M session is used as an example of communication between a device and a first network function. Figure 10 Examples of call flows for the security activation process provided by some embodiments of this application are shown.
[0195] Before activating C / M session security protection, the service C / M-TW-GW and the device need to establish a C / M session security context. The C / M session security context is created as a result of the authentication and key generation processes between the service C / M-TW-GW and the device. The C / M session security context should include the anchor key and the associated 6g Key Set Identifier (6gKSI), device security capabilities, and uplink and downlink C / M session COUNT values. The Key Set Identifier 6gKSI contains the value of the anchor key. Device security capabilities should include session-level algorithms and RB layer algorithms.
[0196] When a new C / M session security context is derived using the same anchor key, the SPM-KMF-Session notification should not derive the new anchor key to the serving C / M-TW-GW. The serving C / M-TW-GW should increment the downlink C / M session COUNT. When a new C / M session security context is created from the new anchor key, the SPM-KMF-Session notification should derive the new anchor key to the serving C / M-TW-GW. Then, the serving C / M-TW-GW should set both the uplink and downlink C / M session COUNT counters for that C / M session security context to zero. Details of C / M session security protection activation are as follows (see...). Figure 10 ).
[0197] It should be noted that the details of this embodiment can be used for activating data session security protection. In this scenario, C / M-TW-GW needs to be replaced with Data-TW-GW.
[0198] like Figure 10 As shown, the C / M-TW-GW service is used as an example of the first network function, and it can be used... Figure 7 The KMF-Session shown determines the algorithm used to protect the C / M session.
[0199] In S501, service C / M-TW-GW sends message 1 to KMF-Session.
[0200] Message 1 can be used to request the device's security context. Message 1 may include the device's ID and security requirements.
[0201] Message 1 can serve as an example of the second message mentioned in method 300.
[0202] In S502, KMF-Session determines whether security protection activation is required.
[0203] In S503, KMF-Session sends message 3 to C / M-TW-GW.
[0204] Message 3 can be used to request one or more factors for the selection algorithm. Message 3 may include a request instruction for one or more factors.
[0205] Message 3 can serve as an example of the first request mentioned in method 300.
[0206] In S504, C / M-TW-GW collects factors from the equipment.
[0207] These factors can include the equipment's safety capabilities and its safety requirements.
[0208] In S505, C / M-TW-GW sends message 5 to KMF-Session.
[0209] Message 5 may include factors for selecting the algorithm. For example, Message 5 may include: the security capabilities of the device and / or the security capabilities of the C / M-TW-GW. Message 5 may also include a list of algorithms that can be executed at the device and the C / M-TW-GW to protect the C / M session.
[0210] Message 5 can be seen as an example of the third message mentioned in method 300.
[0211] In some embodiments, message 5 may also include an indication to generate a new anchor key and an uplink or downlink C / M session COUNT value. In this scenario, message 5 can serve as an example of the fourth message mentioned in method 300.
[0212] In S506, KMF-Session selects the algorithm used to protect C / M sessions.
[0213] For example, KMF-Session can configure the list of encryption algorithms and integrity algorithms allowed by the device and C / M-TW-GW. KMF-Session can select at least one encryption algorithm and at least one integrity algorithm to protect the C / M session based on the security capabilities included in Message 5.
[0214] In some implementations, KMF-Session can generate a new anchor key based on the downlink C / M session COUNT value and an instruction to generate a new anchor key. KMF-Session can determine the ID of the anchor key associated with the selected algorithm. The anchor key ID can also be called the 6th generation keyset identifier (6gKSI).
[0215] For example, when generating a new anchor key, KMF-Session can derive a new C / M session key from the new anchor key. When the selected algorithm is used to protect the C / M session with the new C / M session key, the selected algorithm is associated with the new anchor key.
[0216] In some embodiments, KMF-Session can determine a new anchor key flag that indicates whether KMF-Session has generated a new anchor key.
[0217] In S507, KMF-Session sends message 7 to C / M-TW-GW.
[0218] Message 7 may include the selected algorithm and the 6gKSI associated with the selected algorithm. Message 7 may serve as an example of the first message mentioned in method 300.
[0219] In some implementations, message 7 also includes a new anchor key flag and a new anchor key.
[0220] In S508, C / M-TW-GW performs integrity protection for C / M sessions.
[0221] Step S508 may include steps S508a to S508c.
[0222] In S508a, C / M-TW-GW initiates integrity protection for C / M sessions.
[0223] C / M-TW-GW can activate C / M session integrity protection before sending message 8b to the device.
[0224] In some embodiments, when the new anchor key flag instructs the KMF-Session to generate a new anchor key, the C / M-TW-GW can reset the downlink C / M session COUNT value to zero.
[0225] In S508b, C / M-TW-GW sends message 8b to the device.
[0226] Message 8b may include the device’s security capabilities, the selected algorithm, and the 6gKSI associated with the selected algorithm.
[0227] Message 8b may also include a message authentication code (MAC).
[0228] In some embodiments, message 8b may also include a flag requesting a complete initial C / M session message. In some embodiments, message 8b may also include a new anchor key flag. For example, when the new anchor key flag instructs the KMF-Session to generate a new anchor key, the new anchor key flag may indicate that the device should generate a new anchor key.
[0229] Message 8b can be seen as an example of the fifth message mentioned in method 300.
[0230] In S508c, C / M-TW-GW initiates uplink decryption of the C / M session.
[0231] The C / M-TW-GW can activate uplink decryption for the C / M session after sending message 8b.
[0232] In S509, the device performs security protection for C / M sessions.
[0233] The device should verify message 8b. For example, the device can check whether the security capabilities of the device in message 8b match the security capabilities of the device stored in the device. This ensures that the received message has not been modified by an attacker. As another example, the device can verify integrity protection using the indicated integrity algorithm and the C / M session integrity key associated with the indicated 6gKSI.
[0234] Step S509 may include steps S509a and S509b.
[0235] In S509a, the device initiates uplink encryption, downlink decryption, and integrity protection for C / M sessions.
[0236] In some embodiments, when the integrity of message 8b is successfully verified, the device can use the security context indicated by 6gKSI to initiate integrity protection of the C / M session and encryption / decryption of the C / M session.
[0237] In some embodiments, when the new anchor key flag indicates that a new anchor key should be generated at the device, the device can generate a new anchor key based on the downlink C / M session COUNT value. The device can generate a new C / M session key based on the new anchor key. When the new anchor key flag indicates that a new anchor key should be generated at the device, the device can reset the uplink C / M session COUNT value to zero.
[0238] In S509b, the device sends message 9b to C / M-TW-GW.
[0239] Message 9b can be a complete and encrypted message. Message 9b may include a MAC address.
[0240] In S510, C / M-TW-GW enables downlink encryption.
[0241] In one embodiment, the call flow for the C / M session activation process (e.g., as...) Figure 10 (As shown), the specific details are as follows: 1. Service C / M-TW-GW should send message 1 to SPM-KMF-Session.
[0242] Message 1 can serve as an example of the second message mentioned in method 300.
[0243] 2. SPM-KMF-Session determines whether security protection activation is required.
[0244] 3. SPM-KMF-Session sends message 3 to service C / M-TW-GW.
[0245] Message 3 can serve as an example of the first request mentioned in method 300.
[0246] 4. Service C / M-TW-GW collects factors from the equipment. These factors should include the equipment's security capabilities and security requirements.
[0247] 5. Service C / M-TW-GW sends message 5 to SPM-KMF-Session.
[0248] Message 5 can be seen as an example of the third message mentioned in method 300.
[0249] In some embodiments, message 5 may also be an example of the fourth message mentioned in method 300.
[0250] 6. Based on the indication of the required new anchor key, SPM-KMF-Session can generate a new anchor key based on the downlink C / M session COUNT value. SPM-KMF-Session selects a C / M session encryption algorithm and a C / M session integrity algorithm based on the device security capabilities, the 6gKSI used to identify the new anchor key, and a new anchor key flag indicating whether SPM-KMF-Session should generate a new anchor key. SPM-KMF-Session can then generate a new C / M session key.
[0251] It should be noted that each C / M-TW-GW service should have a list of allowed algorithms configured through network management. A list of C / M session integrity algorithms and C / M session encryption algorithms should also be provided.
[0252] 7. SPM-KMF-Session should send message 7 to service C / M-TW-GW.
[0253] Message 7 can be seen as an example of the first message mentioned in method 300.
[0254] 8. (a) The service C / M-TW-GW activates C / M session integrity protection before sending message 8b. If the new anchor key flag indicates that a new anchor key is required, the service C / M-TW-GW may reset the downlink C / M session COUNT value to zero.
[0255] (b) Service C / M-TW-GW sends message 8b to the device.
[0256] Message 8b can be seen as an example of the fifth message mentioned in method 300.
[0257] (c) Service C / M-TW-GW activates C / M session uplink decryption after sending message 8b.
[0258] 9. (a) The device shall verify message 8b. The device checks whether the device's security capabilities match the security capabilities stored in the device to ensure that these security capabilities have not been modified by an attacker, and verifies integrity protection using the indicated C / M session integrity algorithm and the C / M session integrity key based on the anchor key indicated by 6gKSI. If the integrity verification of message 8b is successful, the device shall initiate C / M session integrity protection and encrypt / decrypt using the security context indicated by 6gKSI. If the new anchor key flag indicates that a new anchor key is required, the device may generate a new anchor key based on the downlink C / M session COUNT value. The 6G device may generate a new C / M session key based on the new anchor key. If the new anchor key flag indicates that a new anchor key is required, the 6G device may reset the uplink C / M session COUNT value to zero.
[0259] (b) The device sends an encrypted and integrity-protected message 9b to the service C / M-TW-GW.
[0260] 10. Activate downlink encryption for C / M sessions in the C / M-TW-GW service.
[0261] This embodiment provides an example of how to activate C / M session security protection. This example illustrates the basic concepts of Embodiment 1. Subsequently, the C / M session activation process is provided. Compared to 3GPP, 33.501, in Figure 8 New features have been added (as shown in steps 1, 2, 3, 4, 5, 6, and 7). These new features can improve the efficiency of network performance.
[0262] For illustrative purposes, C / M RB is used as an example of communication between a device and a first network function. Figure 11 This paper illustrates another example of the call flow for the security activation process provided by some embodiments of this application.
[0263] Each RB handler should be configured with a list of allowed algorithms via network management. There should be an integrity algorithm list and an encryption algorithm list. The SPM-KMF-RB establishes device security capabilities and can also establish new C / M RB security contexts. See details below. Figure 11 The message names during the data download process are shown in Table 3, and the content of each message is also shown in Table 3. It should be noted that the details of this embodiment can be used for data RB security protection activation.
[0264] like Figure 11 As shown, the service RB handler serves as an example of the first network function. Figure 7 The KMF-RB shown can be used to determine the algorithm used to protect the C / M RB. The KMF-RB can establish device security capabilities and new C / M RB security contexts.
[0265] In S601, the RB handler sends message 1 to KMF-RB.
[0266] Message 1 can be used to request the device's security context. Message 1 may include the device's ID and security requirements.
[0267] Message 1 can serve as an example of the second message mentioned in method 300.
[0268] In S602, KMF-RB determines whether security protection activation of C / M RB is required.
[0269] In S603, KMF-RB sends at least one message to request one or more factors for the selection algorithm.
[0270] Step S603 may include steps S603a and S603b.
[0271] In S603a, KMF-RB sends message 3a to the RB handler.
[0272] Message 3a may include instructions for requests to one or more factors.
[0273] In S603b, KMF-RB sends message 3b to KMF-Session.
[0274] Message 3b may include an indication of a request for one or more factors, 6gKSI, and the device ID.
[0275] Messages 3a and 3B can serve as examples of the first request mentioned in method 300.
[0276] In S604, the RB process collects factors from the device.
[0277] For example, these factors may include the equipment's security capabilities and its security requirements.
[0278] In S605, the RB handler sends message 5 to the KMF-RB.
[0279] Message 5 may include the device’s security capabilities and / or the security capabilities of the RB process.
[0280] In some embodiments, message 5 may also include a list of algorithms that can be executed at the device and RB handler to protect the C / MRB.
[0281] Message 5 can be seen as an example of the third message mentioned in method 300.
[0282] In S606, KMF-Session sends message 6 to KMF RB.
[0283] In some embodiments, message 6 may include an indication to generate a new anchor key and an uplink or downlink C / M session COUNT value.
[0284] In some embodiments, message 6 may also include a new anchor key.
[0285] Message 6 can be seen as an example of the fourth message mentioned in method 300.
[0286] In S607, KMF-RB selects the algorithm used to protect the C / M RB.
[0287] For example, the KMF-RB can be configured with a list of encryption algorithms and a list of integrity algorithms that the device and RB handler are allowed to use. The KMF-RB can select at least one encryption algorithm and at least one integrity algorithm to protect the C / M RB.
[0288] In some embodiments, the KMF-RB may generate a new C / M RB key due to device mobility, due to local policies from the network operator, or due to an update of the anchor key.
[0289] In S608, KMF-RB sends message 8 to the RB handler.
[0290] Message 8 may include the selected algorithm.
[0291] In some embodiments, message 8 may include a new C / M RB key.
[0292] Message 8 can be seen as an example of the first message mentioned in method 300.
[0293] In S609, the RB process performs security protection on the C / M RB.
[0294] Step S609 may include S609a to S609d.
[0295] In S609a, the RB processing procedure is initiated to perform integrity protection on the C / M RB.
[0296] The RB processing procedure can activate C / M RB integrity protection.
[0297] In S609b, the RB handler sends message 9b to the device.
[0298] Message 9b can be protected for integrity using the current key based on the RB processor with a C / M RB integrity key. Message 9b may include one or more selected integrity algorithms and selected encryption algorithms. Message 9b may also include a message authentication code-integrity (MAC-I).
[0299] Message 9b can be seen as an example of the fifth message mentioned in method 300.
[0300] In S609c, the RB handler initiates downlink encryption of the C / M RB.
[0301] KMF-RB can activate C / M RB downlink encryption at the RB handler after sending message 9b.
[0302] In S609d, the RB handler initiates uplink decryption of the C / M RB.
[0303] The RB handler can activate C / M RB uplink decryption at the RB handler location after receiving message 10b.
[0304] In the S610, the device performs safety protection for the C / M RB.
[0305] Step S610 may include S610a to S610c.
[0306] In S610a, the device verifies MAC-I and initiates downlink decryption and integrity protection for the C / M session.
[0307] In some embodiments, the device can verify message 9b. When the device successfully verifies the integrity of message 9b, the device can initiate integrity protection and downlink decryption of the C / M RB.
[0308] In S610b, the device sends message 10b to the RB handler.
[0309] Message 10b may include MAC-I.
[0310] In the S610c, the device initiates uplink encryption for the C / M RB.
[0311] After the device sends message 10b, the device can activate uplink encryption at the device location.
[0312] The methods proposed in the embodiments of this application have been described in detail above. The communication device provided in this application will be described in detail below.
[0313] In one embodiment, the call flow for the C / M RB activation process (such as...) Figure 11(As shown), the specific details are as follows: 1. The service RB handler should send message 1 to the SPM-KMF-RB.
[0314] Message 1 can serve as an example of the second message mentioned in method 300.
[0315] 2. SPM-KMF-RB determines whether security protection activation is required.
[0316] 3. SPM-KMF-RB sends message 3a to the service RB handler. SPM-KMF-RB sends message 3b to SPM-KMF-Session.
[0317] Messages 3a and 3B can serve as examples of the first request mentioned in method 300.
[0318] 4. The service RB processing procedure collects factors from the equipment. These factors should include the equipment's security capabilities and security requirements.
[0319] 5. The service RB handler sends message 5 to the SPM-KMF-RB.
[0320] Message 5 can be seen as an example of the third message mentioned in method 300.
[0321] 6. SPM-KMF-Session sends message 6 to SPM-KMF-RB.
[0322] Message 6 can be seen as an example of the fourth message mentioned in method 300.
[0323] 7. SPM-KMF-RB selects a C / M RB encryption algorithm and a C / M RB integrity algorithm. SPM-KMF-RB can also generate new C / M RB keys due to device mobility, local policies from the operator, or new anchor keys.
[0324] 8. SPM-KMF-RB should send message 8 to the service RB handler.
[0325] Message 8 can be seen as an example of the first message mentioned in method 300.
[0326] 9. (a) The RB process activates C / M RB integrity protection.
[0327] (b) The RB handler sends message 9b to the device. Message 9b shall be protected for integrity using the C / M RB integrity key based on the current key of the RB handler.
[0328] Message 9b can be seen as an example of the fifth message mentioned in method 300.
[0329] (c) After sending message 9b, the RB handler activates C / M RB downlink encryption at the RB handler.
[0330] (d) After receiving message 10b, the RB handler activates C / M RB uplink deciphering at the RB handler.
[0331] 10. (a) The device shall verify message 9b. If the integrity verification of message 9b is successful, the device shall initiate C / MRB integrity protection and downlink decryption.
[0332] (b) The device sends message 10b to the RB process.
[0333] (c) After sending message 10b, the device activates uplink encryption at the device.
[0334] An example of how to activate C / M RB security protection is provided. The basic concepts of this embodiment are also illustrated, with new features added compared to 3GPP, 33.501 (as shown in steps 1, 2, 3, 4, 5, 6, 7, and 8). These new features can improve network performance efficiency.
[0335] Figure 12 This is a schematic block diagram of a communication device 10 provided in some embodiments of this application. The communication device may be a communication equipment or a device applied to a communication equipment and capable of implementing a corresponding function of any network function in the embodiments of this application. For example, the device may be a chip, a chip system, or a circuit, etc., and is not limited thereto. The communication equipment may be a KMF or a first network function, or a chip installed in any of these network functions.
[0336] The communication device 10 includes a processing module 11. The processing module 11 may be a processor, processing circuit, processing board, processing unit, or processing device, etc. The processing module 11 is used to implement processing and / or operations implemented within the communication device, excluding transmission and reception actions.
[0337] The communication device 10 may further include a communication module 12. The communication module 12 is used to implement sending and / or receiving operations. The communication module 12 may also be called a transceiver module, transceiver, or transceiver device, etc., and is used to implement receiving (which may be called input) and / or sending (which may be called output) operations.
[0338] For example, if communication device 10 corresponds to the KMF mentioned in method 300, then communication module 12 can be used to send a first message to the first network function.
[0339] For example, if the communication device 10 corresponds to the first network function mentioned in method 300, then the communication module 12 can be used to receive a second message from the first KMF.
[0340] In short, the operation and / or function of device 10 are designed to implement the corresponding steps of the above-described method embodiments.
[0341] Figure 13 This is a schematic block diagram of a communication device provided in an embodiment of this application. The communication device 20 includes at least one processor 21. The at least one processor 21 is coupled to at least one memory 22. The at least one memory 22 is used to store one or more instructions and / or executable computer code. The at least one processor 21 is used to invoke one or more instructions and / or executable computer code to cause the communication device 20 to implement the method provided in the embodiment of this application. Optionally, the communication device 20 may further include at least one memory 22. Optionally, the communication device 20 may further include at least one communication interface 23, and the at least one communication interface 23 is used to input and / or output information or data.
[0342] In one implementation, the communication device 20 can be any of the network functions in the method embodiments. For example, the communication device 20 can be a KMF-Session, KMF-RB, Serving C / M-TW-GW, or Serving RB processor. In this implementation, the processor 21 can be a baseband device, and the communication interface 23 can be a radio frequency device.
[0343] In another implementation, the communication device 20 can be a chip (or chip system) installed in communication equipment such as KMF-Session, KMF-RB, Service C / M-TW-GW, or Service RB processor. In this implementation, the processor 21 can be a circuit, such as a logic circuit or integrated circuit. The communication interface 23 can be a transceiver, interface circuit, input / output interface, bus, module, pin, or other type of interface.
[0344] This application also provides a communication system. The communication system may include any communication device provided in any of the method embodiments. For example, the communication system may include one or more of the following network functions: KMF or a first network function.
[0345] This application also provides a computer storage medium that can store one or more program instructions to execute any of the above methods.
[0346] This application also provides a computer program product that can store one or more instructions for performing any of the above methods.
[0347] In embodiments of this application, the input term "and / or" describes the association relationship between associated objects and indicates that three possible relationships exist. For example, A and / or B can represent the following three cases: only A exists, both A and B exist, and only B exists. The character " / " typically represents an "OR" relationship between associated objects. "At least one" refers to one or more. "At least one of A and B," similar to "A and / or B," describes the association relationship between associated objects, indicating that three possible relationships exist. For example, at least one of A and B can represent the following three cases: only A exists, both A and B exist, and only B exists.
[0348] Furthermore, unless the context clearly specifies otherwise, the use of the singular forms of “a,” “an,” and “the” in the embodiments of this application and the appended claims is also intended to include the plural forms.
[0349] Those skilled in the art will recognize that, in conjunction with the various examples described in connection with the embodiments disclosed in this specification, the units and algorithm steps can be implemented using electronic hardware or a combination of computer software and electronic hardware. Whether a function is executed using hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but these embodiments should not be considered beyond the scope of this application.
[0350] Those skilled in the art will understand that, for convenience and brevity, the detailed working process of the above-described systems, devices, and units can be referred to the corresponding process in the above-described method embodiments, and will not be repeated here.
[0351] Several embodiments are provided in this application, and the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For example, unit division is a logical functional division, and other division methods can be used in actual embodiments. For example, multiple units or components can be merged or integrated into another system, or some features can be ignored or not performed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed can be implemented using various communication interfaces. Indirect coupling or communication connection between devices or units can be implemented electronically, mechanically, or otherwise.
[0352] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0353] When these functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. The technical solution of this application can be implemented as a software product. The software product is stored in a storage medium and includes several instructions to instruct a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the embodiments of this application. The aforementioned storage medium includes any medium capable of storing program code, such as a USB flash drive, external hard drive, ROM, RAM, magnetic disk, or optical disk, etc.
[0354] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, the functional units in the various embodiments of this application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0355] The above descriptions are merely some specific implementations of this application and are not intended to limit the scope of protection of this application. Any variations or substitutions easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method performed by a key management function (KMF), characterized by, include: A first algorithm is determined based on a first security capability and the security requirements of communication between the device and a first network function, wherein the security requirements of the communication include security requirements of services, applications, tasks, or sessions, wherein the services, applications, tasks, or sessions are related to the communication, and the first algorithm includes an encryption algorithm for protecting the communication and / or an integrity algorithm for protecting the communication. Send a first message to the first network function, wherein the first message includes the first algorithm.
2. The method of claim 1, wherein, The first security capability of the communication includes at least one of the following: the security capability of the device or the security capability of the first network function.
3. The method according to claim 1 or 2, characterized in that, Also includes: Receive a second message from the first network function, wherein the second message includes the identifier of the device and the security requirements of the communication; Based on the security requirements of the communication, it is determined that the security protection for the communication needs to be activated.
4. The method according to any one of claims 1 to 3, characterized in that, Also includes: Send a first request to collect the first security capability, wherein the first request is determined based on the security requirements of the communication; Receive a third message, wherein the third message includes at least one of the following: the security capability of the device or the security capability of the first network function.
5. The method of claim 4, wherein, The third message also indicates at least one of the following: a plurality of encryption algorithms that can be used by the first network function to protect the communication, or a plurality of integrity algorithms that can be used by the first network function to protect the communication.
6. The method according to any one of claims 1 to 5, characterized in that, The first message also includes an identifier for a first anchor key, and the first algorithm is associated with the first anchor key.
7. The method according to claim 6, characterized in that, Also includes: A fourth message is received, wherein the fourth message includes an indication for generating a new anchor key, the first anchor key including the new anchor key.
8. The method according to claim 7, characterized in that, The first message also includes first information indicating whether the new anchor key has been generated.
9. A communication method performed by a first network function, characterized in that, include: A first message is received from a first KMF, wherein the first message includes a first algorithm, the first algorithm being determined based on a first security capability and security requirements for communication between the device and the first network function, the security requirements for the communication including security requirements for services, applications, tasks, or sessions related to the communication, and the first algorithm including an encryption algorithm for protecting the communication and / or an integrity algorithm for protecting the communication.
10. The method according to claim 9, characterized in that, The first security capability of the communication includes at least one of the following: the security capability of the device or the security capability of the first network function.
11. The method according to claim 9 or 10, characterized in that, Also includes: A second message is sent to the first KMF, wherein the second message includes the identifier of the device and the security requirements of the communication, and the second message is used to determine whether security protection for the communication needs to be activated.
12. The method according to any one of claims 9 to 11, characterized in that, The first security capability includes the security capabilities of the device, and the method further includes: Receive a first request for collecting the security capabilities of the device, the first request being determined based on the security requirements of the communication; The security capabilities of the device are collected based on the first request; Send a third message, wherein the third message includes the security capabilities of the device.
13. The method according to claim 12, characterized in that, The third message also indicates at least one of the following: a plurality of encryption algorithms that can be implemented by the first network function to protect the communication, or a plurality of integrity algorithms that can be implemented by the first network function to protect the communication.
14. The method according to any one of claims 9 to 13, characterized in that, The first message also includes an identifier for a first anchor key, and the first algorithm is associated with the first anchor key.
15. The method according to claim 14, characterized in that, Also includes: Send a fourth message, wherein the fourth message includes an instruction for generating a new anchor key.
16. The method according to claim 15, characterized in that, The first message also includes first information indicating whether the new anchor key has been generated.
17. The method according to any one of claims 9 to 16, characterized in that, The first algorithm includes the integrity algorithm for protecting the communication and the encryption algorithm for protecting the communication, and the method further includes: Initiate integrity protection for the communication based on the integrity algorithm described above; A fifth message is sent to the device, wherein the fifth message includes the integrity algorithm, the encryption algorithm, and the ID of the anchor key associated with the first algorithm.
18. A communication device, characterized in that, The communication device includes a processor for executing one or more instructions stored in a memory to cause the communication device to implement the method according to any one of claims 1 to 8 or the method according to any one of claims 9 to 17.
19. The communication device according to claim 18, characterized in that, The communication device also includes the memory.
20. The communication device according to claim 18 or 19, characterized in that, The communication device includes a communication interface, which is used to input and / or output information or data.
21. A communication device, characterized in that, The communication device includes functions or units for implementing the method according to any one of claims 1 to 8 or the method according to any one of claims 9 to 17.
22. A communication device, characterized in that, The communication device includes a circuit and a communication interface, the communication interface being used to receive information and / or data to be processed by the circuit, and to send the information and / or data to the circuit; the circuit is used to implement the method according to any one of claims 1 to 8 or the method according to any one of claims 9 to 17.
23. The communication device according to claim 22, characterized in that, The communication interface is also used to output information and / or data processed by the circuit.
24. A communication system, characterized in that, Includes one or more of the following communication devices: One or more communication devices for performing the method according to any one of claims 1 to 8; One or more communication devices that perform the method according to any one of claims 9 to 17.
25. A computer-readable storage medium, characterized in that, It includes one or more instructions, which, when executed on a computer, implement the method according to any one of claims 1 to 8 or the method according to any one of claims 9 to 17.
26. A computer program product, characterized in that, It includes one or more instructions, which, when executed on a computer, implement the method according to any one of claims 1 to 8 or the method according to any one of claims 9 to 17.