Information processing method, communication device and storage medium

CN121890127APending Publication Date: 2026-04-17BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING XIAOMI MOBILE SOFTWARE CO LTD
Filing Date
2024-08-15
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

The existing 5G security key hierarchy cannot effectively protect the NAS signaling security between user equipment and other core network nodes, and there is a risk that the signaling information may be tampered with or eavesdropped on.

Method used

A first key is generated through the Secure Anchor Function (SEAF), a second key is generated based on the first key to protect the communication security between the user equipment and the second node, and a third key is generated based on the second key to protect the communication security between the user equipment and the second node.

Benefits of technology

It enables direct and secure communication between user equipment and core network nodes, improving communication security and preventing signaling information from being tampered with or eavesdropped on.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121890127A_ABST
    Figure CN121890127A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an information processing method, communication equipment and a storage medium. The information processing method performed by the UE may include: generating a second key according to a first key of a first node; generating a third key according to the second key; the third key is used for protecting communication security between user equipment (UE) and a second node; wherein the first node has a security anchor point function.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, communication device, and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and particularly relates to an information processing method, a communication device and a storage medium. BACKGROUND

[0002] The sixth generation mobile communication system (6 th Generantion, 6G) architecture needs to streamline network functions (Network Function, NF). Streamlining NF has significant advantages in capacity, coverage, signaling overhead, scaling, and energy overhead.

[0003] SUMMARY

[0004] The embodiments of the present disclosure provide an information processing method, a communication device and a storage medium.

[0005] According to a first aspect of the embodiments of the present disclosure, an information processing method is provided, wherein the method is performed by a user equipment (UE), and the method comprises: generating a second key according to a first key of a first node; generating a third key according to the second key; the third key is used to protect the security of communication between the UE and a second node; and the first node is a security anchor function.

[0006] According to a second aspect of the embodiments of the present disclosure, an information processing method is provided, wherein the method is performed by a third node, and the method comprises:

[0007] receiving a first message sent by a user equipment (UE), the first message being protected by a third key; the third key is generated according to a second key, and the second key is generated based on a first key of a first node; a receiving node of the first message is a second node; the first node is a security anchor function; and sending the first message to the second node.

[0008] According to a third aspect of the embodiments of the present disclosure, an information processing method is provided, wherein the method is performed by a first node, and the method comprises:

[0009] generating a fifth key according to a first key of the first node; sending the fifth key to a second node, the fifth key being used by the second node to generate a fourth key; the fourth key is used to protect the security of communication between the second node and the UE; and the first node is a security anchor function.

[0010] According to a fourth aspect of the embodiments of the present disclosure, an information processing method is provided, wherein the method is performed by a second node, and the method comprises:

[0011] receive a fifth key sent by the first node; the fifth key is generated according to the first key of the first node; generate a fourth key according to the fifth key; the fourth key is used to protect the security of the communication between the second node and the user equipment UE; the first node is a security anchor function.

[0012] According to the fifth aspect of the embodiments of the present disclosure, a user equipment UE is provided, wherein the UE comprises: a processing module configured to generate a second key according to a first key of a first node; generate a third key according to the second key; the third key is used to protect the security of the communication between the user equipment UE and a second node; wherein the first node is a security anchor function.

[0013] According to the sixth aspect of the embodiments of the present disclosure, a third node is provided, wherein the third node comprises: a receiving module configured to generate a second key according to a first key of a first node; a sending module configured to generate a third key according to the second key; the third key is used to protect the security of the communication between the user equipment UE and a second node; wherein the first node is a security anchor function.

[0014] According to the seventh aspect of the embodiments of the present disclosure, a first node is provided, wherein the first node comprises: a processing module configured to generate a fifth key according to a first key of the first node; a sending module configured to send the fifth key to a second node; the fifth key is used by the second node to generate a fourth key; the fourth key is used to protect the security of the communication between the second node and the UE; the first node is a security anchor function.

[0015] According to the eighth aspect of the embodiments of the present disclosure, a second node is provided, wherein the second node comprises: a receiving module configured to receive a fifth key sent by the first node; the fifth key is generated according to the first key of the first node; a processing module configured to generate a fourth key according to the fifth key; the fourth key is used to protect the security of the communication between the second node and the user equipment UE; the first node is a security anchor function.

[0016] According to the ninth aspect of the embodiments of the present disclosure, a communication system is provided, wherein the communication system comprises a user equipment UE, a first node, a second node and a third node; the UE is used to execute the method of any technical solution of the first aspect; the third node is used to execute the method of any technical solution of the second aspect; the first node is used to execute the method of any technical solution of the third aspect; the second node is used to execute the method of any technical solution of the fourth aspect.

[0017] According to the tenth aspect of the embodiments of the present disclosure, a communication device is provided, wherein the communication device comprises: one or more processors; wherein the processor is used to call instructions to make the communication device execute the information processing method provided by any technical solution of the first aspect to the fifth aspect.

[0018] According to an eleventh aspect of the present disclosure, a storage medium is provided, wherein the storage medium stores instructions that, when executed on a communication device, cause the communication device to perform the information processing method provided by any one of the first to fifth aspects.

[0019] According to a twelfth aspect of the present disclosure, a program product is provided, wherein the program product includes a computer program, and when the computer program is executed by a communication device, the communication device is able to implement the information processing method provided by any of the technical means of the first to fifth aspects.

[0020] The technical method provided in this disclosure generates a second key based on the first key of the Security Anchor Function (SEAF), and protects the communication security between the UE and the second node through the second key. In this way, the UE can communicate securely and directly with the second node.

[0021] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit the embodiments of this disclosure. Attached Figure Description

[0022] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of embodiments of this disclosure.

[0023] Figure 1A is a schematic diagram of the architecture of a communication system according to an exemplary embodiment;

[0024] Figure 1B is a schematic diagram of the architecture of a communication system according to an exemplary embodiment;

[0025] Figure 1C is a schematic diagram illustrating the connection between a user equipment (UE), a radio access network (RAN), and a core network according to an exemplary embodiment.

[0026] Figure 1D is a schematic diagram illustrating another connection between the UE and RAN and the core network according to an exemplary embodiment;

[0027] Figure 1E is a schematic diagram of a security architecture according to an exemplary embodiment;

[0028] Figure 1F is a schematic diagram of a security architecture according to an exemplary embodiment;

[0029] Figure 1G is a schematic diagram of a security architecture according to an exemplary embodiment;

[0030] FIG. 2A is a flow diagram illustrating an information processing method according to an example embodiment;

[0031] FIG. 2B is a flow diagram illustrating an information processing method according to an example embodiment;

[0032] FIG. 3 is a flow diagram illustrating an information processing method according to an example embodiment;

[0033] FIG. 4A is a flow diagram illustrating an information processing method according to an example embodiment;

[0034] FIG. 4B is a flow diagram illustrating an information processing method according to an example embodiment;

[0035] FIG. 5A is a flow diagram illustrating an information processing method according to an example embodiment;

[0036] FIG. 5B is a flow diagram illustrating an information processing method according to an example embodiment;

[0037] FIG. 6A is a flow diagram illustrating an information processing method according to an example embodiment;

[0038] FIG. 6B is a flow diagram illustrating an information processing method according to an example embodiment;

[0039] FIG. 7A is a flow diagram illustrating an information processing method according to an example embodiment;

[0040] FIG. 7B is a flow diagram illustrating an information processing method according to an example embodiment;

[0041] FIG. 8A is a structural diagram illustrating a user equipment (UE) according to an example embodiment;

[0042] FIG. 8B is a structural diagram illustrating a source node according to an example embodiment;

[0043] FIG. 8C is a structural diagram illustrating a target node according to an example embodiment;

[0044] FIG. 8D is a structural diagram illustrating a core network node according to an example embodiment;

[0045] FIG. 9A is a structural diagram illustrating a communication device according to an example embodiment;

[0046] FIG. 9B is a structural diagram illustrating a chip according to an example embodiment. DETAILED DESCRIPTION

[0047] The embodiments of the present disclosure provide an information processing method, a communication device, a communication system and a storage medium.

[0048] The first aspect provides an information processing method, wherein the method is performed by a user equipment (UE), and the method comprises: generating a second key according to a first key of a first node; generating a third key according to the second key; the third key is used to protect the security of communication between the UE and a second node; and the first node is a security anchor function (SEAF).

[0049] According to the above scheme, the second key is generated according to the first key of the security anchor function (SEAF), and the security of communication between the UE and the second node is protected by the second key, so that the UE can directly and securely communicate with the second node.

[0050] In some embodiments of the first aspect, the second key is generated according to the first key of the first node, including at least one of: generating the second key according to the first key and a type of the second node; and generating the second key according to the first key and an instance identity (ID) of the second node.

[0051] According to the above scheme, if the second key is generated according to the first key and the type of the second node, the UE can generate the second key even if it does not know the specific second node it actually accesses. If the second key is generated according to the instance ID of the second node and the first key, the communication between the UE and the second node of the same type but different instances has different keys, which can further improve the security of communication.

[0052] In some embodiments of the first aspect, the second key is generated according to the first key and the type of the second node, including at least one of: generating the second key according to the first key, the type of the second node and a first count value; the first count value is a count of uplink non-access stratum (NAS) messages sent by the UE to the second node; generating the second key according to the first key, the type of the second node and first time information; and the first time information indicates a time period for generating the second key.

[0053] According to the above scheme, the implementation of how to generate the second key is given. By introducing the first count value and the first time information, the key for the UE to communicate with the second node at different times can be different, which further improves the security of communication between the UE and the second node.

[0054] In some embodiments of the first aspect, the second key is generated according to the first key and an instance identifier ID of the second node, including: the UE is preconfigured with the instance ID of the second node, and the second key is generated according to the first key and the instance identifier ID of the second node.

[0055] Based on the above scheme, it can be known that: in the case that the UE is preconfigured with the instance ID of the second node, the second key is generated according to the first key and the instance ID of the second node, and in the case that the UE is not preconfigured with the instance ID of the second node, the second key can be generated in other ways such as generating the second key according to the type of the second node and the first key, so that the UE can generate the second key regardless of whether the instance ID of the second node is preconfigured.

[0056] In some embodiments of the first aspect, the second key is generated according to the first key and an instance identifier ID of the second node, including at least one of: the second key is generated according to the first key, the instance ID of the second node, and a first count value; the first count value is a count of uplink non-access stratum (NAS) messages sent by the UE to the second node; the second key is generated according to the first key, the instance ID of the second node, and first time information; and the first time information indicates a time period for generating the second key.

[0057] Based on the above scheme, specific implementation manners for generating the second key are given. By introducing the first count value and the first time information, the key for the UE to communicate with the second node at different times can be different, which further improves the security of communication between the UE and the second node.

[0058] In some embodiments of the first aspect, the method further includes: sending a first radio resource control (RRC) message to a third node, the first RRC message being a first message; the first message is protected by a third key; and the second node is a receiving node of the first message.

[0059] Based on the above scheme, the first message is encapsulated in the first RRC message and sent to the third node, so that the third node correctly receives the first message by receiving the RRC message, thereby realizing the transparent transmission or forwarding of the first message.

[0060] In some embodiments of the first aspect, the first message includes at least one of: non-access stratum (NAS) signaling; an ID of the UE; and a first algorithm identifier, wherein the first algorithm identifier is used to identify a security algorithm for protecting the first message.

[0061] Based on the above scheme, the first message includes one or more of NAS signaling transmitted to the second node, an ID of the UE, and an identification of the first algorithm. The NAS signaling is signaling transmitted to the second node. The ID of the UE is used to identify the UE to the second node. The identification of the first algorithm can be an identification of a security algorithm used when the UE communicates with the first node, thereby saving the process of specifically negotiating the security algorithm and improving the efficiency of key generation.

[0062] In some embodiments of the first aspect, the first RRC message is protected by an access stratum (AS) security context of the UE.

[0063] Based on the above scheme, the first message is protected using the AS security context, thereby ensuring the security of the first message over the air interface by borrowing the AS security context.

[0064] In some embodiments of the first aspect, the method further includes receiving a second RRC message sent by the third node, the second RRC message including a second message; the second message is from the second node; the second message is protected using a fourth key; the fourth key is generated from a fifth key, and the fifth key is generated from the first key.

[0065] Based on the above scheme, the UE receives the second message transmitted or forwarded by the third node through the second RRC message, so that the UE can receive the second message through the RRC connection between the UE and the second node. In the embodiments of the present disclosure, the second message is protected using the fourth key, and in this case, the second RRC message can be protected using the AS security context or can not be protected using the AS security context, which can be determined according to the communication requirement.

[0066] In some embodiments of the first aspect, the second RRC message is protected by an access stratum (AS) security context of the UE.

[0067] Based on the above scheme, the second RRC message is protected by the AS security context of the UE, which means that the first message has two layers of security protection, thereby further improving the security of the second message.

[0068] The second aspect provides an information processing method, wherein the method is performed by a third node and includes: receiving a first message sent by a user equipment (UE), the first message being protected using a third key; the third key is generated from a second key, and the second key is generated based on a first key of a first node; a receiving node of the first message is a second node; the first node is a security anchor function; and the first message is sent to the second node.

[0069] In some embodiments of the second aspect, before sending the first message to the second node, the method further comprises: sending a third message to the first node, the third message being used to request the first node to generate a fifth key, the fifth key being used to generate the fourth key; and the fourth key being used for the second node to verify the security of the first message.

[0070] In some embodiments of the second aspect, the method further comprises: receiving a fourth message sent by the first node; and the fourth message being used to indicate whether the fifth key has been generated.

[0071] In some embodiments of the second aspect, sending the first message to the second node comprises: the fourth message indicating that the fifth key has been generated, and sending the first message to the second node.

[0072] In some embodiments of the second aspect, sending the third message to the first node comprises: determining that the first node has not been requested by the UE to generate the fifth key for the second node, and sending the third message to the first node.

[0073] In some embodiments of the second aspect, receiving the first message sent by the user equipment (UE) comprises: receiving a first radio resource control (RRC) message sent by the UE, the first RRC message comprising the first message.

[0074] In some embodiments of the second aspect, the first RRC message is protected by an access stratum (AS) security context.

[0075] In some embodiments of the second aspect, the first RRC message further comprises at least one of: type information of the second node; an instance ID of the second node; and address information of the second node.

[0076] The third aspect provides an information processing method, wherein the method is performed by a first node, and the method comprises: generating a fifth key according to a first key of the first node; sending the fifth key to a second node, the fifth key being used by the second node to generate a fourth key; and the fourth key being used to protect the security of communication between the second node and a user equipment (UE); and the first node being a security anchor function.

[0077] In some embodiments of the third aspect, generating the fifth key according to the first key of the first node comprises: receiving a third message sent by a third node, and generating the fifth key according to the first key; and the third message being used to request the first node to generate the fifth key for the first node.

[0078] In some embodiments of the third aspect, the method further comprises: sending a fourth message to the third node; and the fourth message being used to inform the third node whether the fifth key has been generated.

[0079] In some embodiments of the third aspect, the third message comprises at least one of: type information of the second node; an instance ID of the second node; and an identifier of the UE.

[0080] In some embodiments of the third aspect, generating the fifth key according to the first key of the first node comprises: receiving a fifth message from the second node, and generating the fifth key according to the first key; the fifth message is used for the second node to request to generate the fifth key.

[0081] In some embodiments of the third aspect, the fifth message comprises at least one of: type information of the second node; an instance ID of the second node; a second count value; the second count value is a count of uplink non-access stratum (NAS) messages of a user equipment (UE) received by the second node; and an identity of the UE.

[0082] In some embodiments of the third aspect, generating the fifth key according to the first key of the first node comprises: generating the fifth key according to the first key and a type of the second node; and generating the fifth key according to the first key and an instance identification (ID) of the second node.

[0083] In some embodiments of the third aspect, generating the fifth key according to the first key and the type of the second node comprises at least one of: generating the fifth key according to the first key, the type of the second node, and a second count value; the second count value is a count of uplink non-access stratum (NAS) messages of a user equipment (UE) received by the second node; and generating the fifth key according to the first key, the type of the second node, and second time information; the second time information indicates a time period for generating the fifth key.

[0084] In some embodiments of the third aspect, generating the fifth key according to the first key and the instance identification (ID) of the second node comprises: the fifth message comprises the instance ID of the second node, and generating the fifth key according to the first key and the instance identification (ID) of the second node.

[0085] In some embodiments of the third aspect, generating the fifth key according to the first key and the instance identification (ID) of the second node comprises at least one of: generating the fifth key according to the first key, the instance ID of the second node, and a second count value; the second count value is a count of uplink non-access stratum (NAS) messages of a user equipment (UE) received by the second node; and generating the fifth key according to the first key, the instance ID of the second node, and second time information; the second time information indicates a time period for generating the fifth key.

[0086] The fourth aspect provides an information processing method, wherein the method is performed by a second node, and the method comprises: receiving a fifth key sent by a first node; the fifth key is generated according to a first key of the first node; generating a fourth key according to the fifth key, the fourth key is used to protect security of communication between the second node and a user equipment (UE); and the first node is a security anchor function.

[0087] In some embodiments of the fourth aspect, the method further comprises: receiving the first message sent by the third node, sending a fifth message to the first node, the fifth message being used to request a fifth key; the first message is protected by a third key, the third key being generated according to the second key; the second key is generated according to the first key of the first node.

[0088] In some embodiments of the fourth aspect, the fifth message comprises at least one of: type information of the second node; an instance ID of the second node; a second count value; the second count value being a count of uplink non-access stratum (NAS) messages received by the second node from a user equipment (UE); and an identity of the UE.

[0089] In some embodiments of the fourth aspect, the method further comprises: sending a second message to the third node, the second message being protected using a fourth key.

[0090] The fifth aspect provides a user equipment (UE), wherein the UE comprises: a processing module configured to generate a second key according to a first key of a first node; generate a third key according to the second key; the third key being used to protect the security of communication between the UE and a second node; and wherein the first node is a security anchor function.

[0091] The sixth aspect provides a third node, wherein the third node comprises: a receiving module configured to receive a first message sent by a user equipment (UE), the first message being protected using a third key; the third key being generated by the UE based on a second key, the second key being generated based on a first key of a first node; and the receiving node of the first message being a second node.

[0092] The seventh aspect provides a first node, wherein the first node comprises: a processing module configured to generate a fifth key according to a first key of the first node; and a sending module configured to send the fifth key to a second node, the fifth key being used by the second node to generate a fourth key; the fourth key being used to protect the security of communication between the second node and a UE; and the first node being a security anchor function.

[0093] The eighth aspect provides a second node, wherein the second node comprises: a receiving module configured to receive a fifth key sent by a first node; the fifth key being generated according to a first key of the first node; and a processing module configured to generate a fourth key according to the fifth key, the fourth key being used to protect the security of communication between the second node and a user equipment (UE); and the first node being a security anchor function.

[0094] The ninth aspect provides a communication system, wherein the communication system comprises a user equipment (UE), a first node, a second node and a third node; the UE is configured to perform the method provided in any of the technical solutions of the first aspect; the third node is configured to perform the method provided in any of the technical solutions of the second aspect; the first node is configured to perform the method provided in any of the technical solutions of the third aspect; and the second node is configured to perform the method provided in any of the technical solutions of the fourth aspect.

[0095] The tenth aspect provides a program product, wherein the program product comprises a computer program, and the computer program is configured to enable a communication device to implement the information processing method described in the optional implementation manners of the first aspect to the fifth aspect when the computer program is executed by the communication device.

[0096] The eleventh aspect provides a computer program, which is configured to enable a computer to perform the information processing method described in the optional implementation manners of the first aspect to the fifth aspect when the computer program is executed by the computer.

[0097] It can be understood that the UE, the network device, the communication system, the program product and the computer program are all configured to perform the method provided in the embodiments of the present disclosure. Therefore, the beneficial effects achieved by the above-mentioned UE, the network device, the communication system, the program product and the computer program can refer to the beneficial effects of the corresponding method, which will not be described here.

[0098] The embodiments of the present disclosure provide an information processing method, a communication device, a communication system and a storage medium. The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the method after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, some or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation manners of other embodiments.

[0099] In the embodiments of the present disclosure, the terms and / or descriptions of the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0100] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.

[0101] In the embodiments of the present disclosure, an element expressed in singular form, such as "a", "an", "the", "said", "the aforementioned", "the foregoing", "this", and the like, unless otherwise specified, can represent "one and only one", or can represent "one or more", "at least one", and the like. For example, in the case of using an article such as "a", "an", "the", and the like in English, the noun after the article can be understood as a singular expression, or can be understood as a plural expression.

[0102] In the embodiments of the present disclosure, "plurality" refers to two or more.

[0103] In some embodiments, the terms "at least one of", "one or more of", "a plurality of", "multiple", and the like can be replaced with each other.

[0104] In some embodiments, the description manner such as "at least one of A, B", "A and / or B", "A in one case, and B in another case", "A in one case, and B in another case", and the like can include the following technical manners according to the case: A is executed in some embodiments (A is executed regardless of B); B is executed in some embodiments (B is executed regardless of A); A and B are selectively executed in some embodiments (A and B are selectively executed); A and B are executed in some embodiments (A and B are both executed). When there are more branches such as A, B, C, and the like, it is similar to the above.

[0105] In some embodiments, the description manner such as "A or B", and the like can include the following technical manners according to the case: A is executed in some embodiments (A is executed regardless of B); B is executed in some embodiments (B is executed regardless of A); A and B are selectively executed in some embodiments (A and B are selectively executed). When there are more branches such as A, B, C, and the like, it is similar to the above.

[0106] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments in the context, and should not be construed as redundant limitation because of the use of the prefix words. For example, the ordinal words in front of the description objects "field" in "first field" and "second field" do not limit the position or order between the "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the ordinal words in front of the description objects "level" in "first level" and "second level" do not limit the priority between the "levels". For another example, the quantity of the description objects is not limited by the ordinal words, and can be one or more. For example, "first device", in which the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description objects are "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different; for another example, the description objects are "information", and "first type of information" and "second type of information" can be the same information or different information, and the contents thereof can be the same or different.

[0107] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0108] In some embodiments, the terms of "…", "determining …", "in the case of …", "when …", "when …", "if …", "if …" and the like can be replaced with each other.

[0109] In some embodiments, the terms of "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms of "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.

[0110] In some embodiments, the apparatus and the like can be interpreted as physical or virtual, and the name thereof is not limited to the name recorded in the embodiments. The terms of "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.

[0111] In some embodiments, “network” can be interpreted as a device or network function of the network side contained in the network, such as an access network device, a core network device, and the like.

[0112] In some embodiments, the terms “access network device (AN device)”, “radio access network device (RAN device)”, “base station (BS)”, “radio base station”, “fixed station”, “node”, “access point”, “transmission point (TP)”, “reception point (RP)”, “transmission / reception point (TRP)”, “panel”, “antenna panel”, “antenna array”, “node (cell)”, “macro node”, “small node”, “femto node”, “pico node”, “sector”, “cell group”, “serving node”, “carrier”, “component carrier”, “bandwidth part (BWP)”, and the like can be replaced with each other.

[0113] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user UE," "mobile station (MS)," "mobile UE (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access UE," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.

[0114] In some embodiments, the access network device, the core network device, or the network device can be replaced with the UE. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the UE is replaced with communication between a plurality of UEs (e.g., device-to-device (D2D), vehicle-to-everything (V2X), and so on). In this case, the structure in which the UE has all or part of the functions of the access network device can also be provided. In addition, the terms "uplink," "downlink," and so on can also be replaced with terms corresponding to the inter-UE communication (e.g., "side"). For example, the uplink channel, the downlink channel, and so on can be replaced with the side channel, and the uplink, the downlink, and so on can be replaced with the sidelink.

[0115] In some embodiments, the UE can be replaced with the access network device, the core network device, or the network device. In this case, the structure in which the access network device, the core network device, or the network device has all or part of the functions of the UE can also be provided.

[0116] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country where the location is situated.

[0117] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.

[0118] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0119] FIG. 1A is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.

[0120] As shown in FIG. 1A, the communication system 100 includes a terminal 101 and a network device 102. The network device 102 can include an access network device and / or a core network device. The terminal can also be referred to as a UE.

[0121] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a Pad, a computer with wireless transceiver function, a virtual reality (VR) UE device, an augmented reality (AR) UE device, a wireless UE device in industrial control, a wireless UE device in self-driving, a wireless UE device in remote medical surgery, a wireless UE device in smart grid, a wireless UE device in transportation safety, a wireless UE device in smart city, a wireless UE device in smart home, and the like, but is not limited thereto.

[0122] In some embodiments, the UE is also referred to as a User Equipment (UE).

[0123] In some embodiments, the access network device may, for example, be at least one of a node or a device that accesses a UE to a wireless network, and the access network device may, for example, include at least one of an evolved NodeB (eNB), a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.

[0124] In some embodiments, the technical means of the present disclosure can be applicable to an Open RAN architecture, at which time, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0125] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers can be controlled by the CU, and the rest or all of the protocol layers can be distributed in the DU and controlled by the CU, but is not limited thereto.

[0126] In some embodiments, the core network device can be one device including the first network element, etc., or can be multiple devices or device groups, each including the first network element. The network element can be virtual or physical. The core network may, for example, include at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next generation core (NGC).

[0127] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical means of the embodiments of the present disclosure, and does not constitute a limitation on the technical means provided by the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new service scenarios appear, the technical means provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0128] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1A or part of the subjects, but are not limited thereto. The subjects shown in FIG. 1A are exemplary, and the communication system can include all or part of the subjects in FIG. 1A, or other subjects other than FIG. 1A. The number and form of each subject is arbitrary, and the connection relationship between the subjects is exemplary. The subjects can not be connected or can be connected, and the connection can be in any manner, can be direct connection or indirect connection, and can be wired connection or wireless connection.

[0129] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other resources, next-generation system extended based thereon, and the like. Further, a plurality of systems can be combined (for example, LTE and NR can be combined).

[0130] As mentioned above, the network functions (NFs) in the 6G architecture are slimmed down in order to significantly improve performance in terms of capacity, coverage, signaling overhead, scalability, and energy consumption, etc. The dependencies between NFs can lead to unnecessary complexity and even delays. The number of dependencies and processing points can be reduced by redesigning the network functions. One way is the possibility of direct signaling between enhanced NFs of the 6G system to eliminate potential bottlenecks. Today, many services require information to be transmitted from a new generation radio access network (NG-RAN) node to a user terminal device via a (5th Generation Core, 5GC). In the 5th Generation Core (5GC), information is delivered to the NG-RAN node via the AMF, and rarely does it not involve the AMF. To simplify this transmission, the introduction of a service-based interface (SBI) to the NG-RAN node will allow this information to be exchanged directly between the NG-RAN and the NFs without going through the access management function (AMF), as shown in FIG. IB.

[0131] If the RAN evolves in the service-based direction, it means that the RAN node can be a consumer or producer of services to other network functions in addition to the AMF. In the 5th Generation (5G) system, non-access stratum (NAS) signaling is supported only between the AMF of the core network and the UE. Typically, NAS signaling is transparently transmitted through the RAN node. If the RAN can evolve to communicate directly with other core NFs without going through the AMF, it means that NAS signaling needs to be supported between the user equipment (UE) and other core network NFs in addition to the AMF.

[0132] However, the NAS security of the NAS signaling is currently supported only by the UE and the AMF. According to the key hierarchy structure shown in FIG. 1C, the root key (K AMF ) for NAS security is derived by the UE and the security anchor function (SEAF). K AMF is used to derive the NAS integrity key K NASint and / or the NAS confidentiality protection key K NASencand no other core NF can derive NAS security keys. Since the current key hierarchy design of other core NFs does not support NAS security, the NAS signaling between the UE and other core NFs cannot be protected. If the NAS signaling between the UE and the NF is not protected, there is a risk that the NAS signaling information will be tampered with or eavesdropped when the RAN node forwarding the NAS signaling is attacked. Therefore, it is necessary to study how to protect the security of the 6G multi-NAS architecture. That is, the existing 5G security key hierarchy does not support the security protection of the NAS signaling between the UE and other core network NFs. FIG. 1D, FIG. 1E and FIG. 1F are schematic diagrams of the hierarchy of the 5G security key.

[0133] As shown in FIG. 2A, the embodiments of the present disclosure provide an information processing method, which is executed by the communication system shown in FIG. 1A. The method can include:

[0134] S2101: The UE generates a second key according to a first key of a first node.

[0135] The communication system can be the communication system shown in FIG. 1A. The UE is the terminal 101 shown in FIG. 1A. The first node can be one of the network devices 102 shown in FIG. 1A. Illustratively, the first node can be a core network node. In some embodiments, the first node can include, but not limited to, a Security Anchor Function (SEAF).

[0136] In some embodiments, the second key is an intermediate key for generating a third key. In some embodiments, the first node and the second node can both be core network nodes.

[0137] In some embodiments, the second key is generated according to the first key and a type of the second node. Illustratively, the UE can determine the type of the second node according to the requested network service or function. For example, the UE requests a user plane session, and the type of the second node is a Session Management Function (SMF). The UE requests positioning, and the type of the second node can be a Location Management Function (LMF). In some embodiments, the second node can be any node in the network serving the UE except the first node. Illustratively, the second node can be any core network node in the network serving the UE except the first node. Illustratively, the second node is not necessarily a core network node.

[0138] In some embodiments, the UE uses a Key Derivation Function (KDF) to derive the second key, with the first key as the input and the type of the second node as the derivation parameter.

[0139] In some embodiments, the second key is generated according to the first key, the type of the second node, and a first count value. The first count value can be a count of uplink number messages sent by the UE to the second node. For example, the first count value can be a count of uplink non-access stratum (NAS) messages sent by the UE to the second node.

[0140] For example, the first count value can be a number of uplink NAS messages that have been sent by the UE to the second node. If the UE has not sent any uplink NAS message to the second node, the first count value can be 0.

[0141] In some embodiments, the second key is generated according to the first key, the type of the second node, and first time information. The first time information indicates a time period for generating the second key.

[0142] In some embodiments, the unit of the time period can be millisecond or second, so that the time difference between the time when the UE generates the second key and the time when the first node generates the fifth key can be negligible. For example, the time period can be greater than the time required for transmitting information from the UE to the first node.

[0143] In some embodiments, the second key is generated according to the first key and an instance identity (ID) of the second node. In some embodiments, the UE can be preconfigured with the instance ID of the second node. In this case, the UE can also generate the second key according to the instance ID of the second node and the first key.

[0144] In some embodiments, the UE can obtain the instance ID of the second node after the first node selects the second node serving the UE through information interaction between the UE and the first node, and returns the instance ID of the second node to the UE. In this case, the UE can also obtain the instance ID of the second node before generating the second key. For example, the UE can be preconfigured with the instance ID of the second node, and generate the second key according to the first key and the instance ID of the second node.

[0145] In some embodiments, the UE ID can also be used as a parameter for generating the second key. In this case, the second key can be generated according to the first key and one or more of the type of the second node, the instance ID of the second node, the first count value, the first time information, and the UE ID. If the second key is generated according to the UE ID and the first key, the second keys corresponding to different UEs are different, so that the communication security between different UEs and the second node can be isolated.

[0146] In some embodiments, the UE ID can be any information capable of identifying the UE. Exemplarily, an International Mobile Subscriber Identification Number (IMSI), an International Mobile Equipment Identity (IMEI), a 5G Globally Unique Temporary Identifier (GUTI), a Network Access Identifier (NAI), etc. of the UE can be the information capable of uniquely identifying the UE.

[0147] In some embodiments, the second key can be generated according to the first key using at least one of the following parameters: P0 = the UE ID; L0 = the length of P0; P1 = the type of the NF or the NF Instance ID; for example, the type of the NF is LMF, SMF, etc.; L1 = the length of P1; P2 = the value of the UTC or the number of uplink NAS messages; L2 = the length of P2.

[0148] Of course, the above is only an example, and the specific implementation is not limited to the above example.

[0149] S2102: The UE generates a third key according to the second key.

[0150] In some embodiments, the third key is used to protect the security of the communication between the UE and the second node. Exemplarily, the third key is used to protect the security of the NAS communication between the UE and the second node. Here, the security of the NAS communication can include the security of the NAS message.

[0151] In some embodiments, the third key can include at least one of the following: an integrity key; a confidentiality key; a scrambling key. The integrity key can be used for integrity protection (or integrity verification). The confidentiality key can be used for confidentiality protection, for example, encryption or decryption. The scrambling key can be used for information scrambling or descrambling.

[0152] In some embodiments, different user terminal devices or core network devices can support different security algorithms corresponding to the third key, and when the third key is generated according to the second key, the algorithm identifier needs to be used as a generation parameter of the third key.

[0153] In some embodiments, the second key is used as the input of the KDF, and one or more of the following parameters are combined to generate the third key:

[0154] P0 = algorithm type distinguisher; exemplary types of security algorithms herein include, but are not limited to, integrity algorithms and / or confidentiality algorithms;

[0155] L0 = length of P0;

[0156] P1 = security algorithm ID; exemplary IDs include, but are not limited to, ID for Advanced Encryption Standard (AES), ID for ZUC, etc.

[0157] L1 = length of algorithm ID.

[0158] In embodiments of the present disclosure, the third key can be used to protect a NAS message sent by the UE to the second node.

[0159] S2103: The UE sends a first message to the third node.

[0160] In some embodiments, the third node can be an access network node, and in particular, can be various types of base stations.

[0161] In some embodiments, the first message is carried in a first RRC message using a message container.

[0162] In some embodiments, to further enhance the security of the first message, the first RRC message is protected using an AS security context, which can include a key used for communication between the UE and the access network node, exemplary ly. For example, the first RRC message is encrypted and / or integrity protected.

[0163] In some embodiments, the first message includes at least one of: non-access stratum (NAS) signaling; an ID of the UE; and a first algorithm identification, the first algorithm identification identifying a security algorithm used to protect the first message.

[0164] In some embodiments, the NAS signaling can be a NAS message that the UE needs to send to the second node. The NAS signaling can be carried in the first RRC message by means of a container. In some embodiments, the encapsulation protocol of the NAS signaling can be different for different types of second nodes. In some embodiments, the signaling content of the NAS signaling can be different for different types of second nodes. In some embodiments, the second node is an LMF, then the NAS signaling can be an encapsulated Long Term Evolution (LTE) Positioning Protocol (LPP) NAS signaling, and / or the NAS message is related to absolute positioning and / or relative positioning of the UE. In some embodiments, the second node is an SMF, then the signaling content of the NAS signaling is related to establishment, connection or release of a Protocol Data Unit (PDU).

[0165] In some embodiments, the ID of the UE can include, but is not limited to, various types of IDs of the UE, such as IMEI, IMSI or NAI, etc.

[0166] In some embodiments, the first algorithm identity can be used to identify a specific algorithm, such as an integrity algorithm or a confidentiality algorithm.

[0167] In some embodiments, the first algorithm identity can be an input parameter for the UE to generate a third key.

[0168] In some embodiments, the first algorithm identity indicates a security algorithm that can be the same as the NAS security algorithm negotiated between the UE and the first node, so that the security algorithm negotiation between the UE and the second node can not be needed. For example, assuming that the first node is an AMF or an SAEF, when the UE registers to the network, the UE needs to generate K AMF or K SEAF , K AMF or K SEAFThe first key is used by the UE and the first node to generate a NAS security key for protecting the security of the access stratum communication between the UE and the first node. At this time, the generation of the NAS security key between the UE and the first node can also require an algorithm identifier as an input parameter. In the embodiments of the present disclosure, the UE generates the third key based on the second key, and the algorithm identifier required for using the security algorithm can be the algorithm identifier used by the UE and the first node for the non-access stratum communication by default. In this case, the UE does not need to additionally negotiate the algorithm with the second node, and does not need to send the capability of the algorithm supported by the UE to the network, thereby simplifying the process and reducing the signaling overhead. In this case, the first message can carry the first algorithm identifier or can not carry the first algorithm identifier. For example, the first message is sent to the first node via the third node, and the first node knows the security algorithm identifier (i.e., the second algorithm identifier) negotiated by the first node and the UE, which can be provided to the second node by the first node. Of course, if the first message carries the first algorithm identifier, the first node does not need to additionally provide the algorithm identifier to the second node. In summary, the first algorithm identifier is optional content of the first message.

[0169] The first RRC message further includes at least one of the following: type information of the second node; an instance ID of the second node; address information of the second node.

[0170] In some embodiments, the type information of the second node is carried in the first RRC message, so that the third node or the first node can know the type of the second node, and the second node can be selected for the UE according to the location information of the UE and / or the second node reachable by the third node.

[0171] In some embodiments, the instance ID of the second node can be an identifier of the second node pre-configured on the UE, and the like. In some embodiments, the instance ID of the second node is obtained by the UE according to the second node in the historical communication.

[0172] In some embodiments, the address information of the second node can include but is not limited to an Internet Protocol (IP) address.

[0173] In some embodiments, in order to improve the security of the first message, the first RRC message is further protected using an AS security context. In some embodiments, the AS security context can include a confidentiality key and / or an integrity key for the communication between the UE and the third node.

[0174] S2104: The third node sends the first message to the second node.

[0175] In the embodiments of the present disclosure, after the third node determines the receiving node of the first message, the third node sends the first message to the second node.

[0176] In some embodiments, the third node sends the first message to the second node via SBI or tunneling or the like. For example, the first message is sent to the second node according to the instance ID of the second node contained in the first message. For another example, the third node sends the first message to the second node of the type indicated by the first message according to the type of the second node indicated by the first message.

[0177] S2105: The second node sends a fifth message to the first node.

[0178] In some embodiments, the fifth message is used by the second node to request generation of the fifth key.

[0179] In some embodiments, the fifth message includes, but is not limited to, at least one of the following: an identity of the UE; a type of the second node; an instance identity of the second node; the first count value.

[0180] In some embodiments, the fifth message can carry an input parameter for the first node to generate the fifth key.

[0181] In some embodiments, the identity of the UE is used to indicate the UE, and the identity of the UE can be used by the first node to determine the second algorithm identity.

[0182] In some embodiments, the fifth message is also used to request the second algorithm identity. For example, the fifth message includes an indicator requesting the algorithm identity, so that the second node, upon receiving the fifth message containing the indicator, sends the second algorithm identity and the fifth key to the second node.

[0183] In other embodiments, the indicator requesting the algorithm identity is optional content of the fifth message, for example, the second node sends the second algorithm identity to the first node by default, so the fifth message does not need to contain the indicator. For another example, the second node does not need to obtain the second algorithm identity from the first node in the case that the first message contains the first algorithm identity. For another example, the generation of the third key and the fourth key does not use the algorithm identity, so it is obvious that the transmission of the first algorithm identity and the second algorithm identity between the UE and the network and between different nodes does not need to be performed.

[0184] S2106: The first node generates the fifth key.

[0185] In some embodiments, the first node generates the fifth key according to the first key. In some embodiments, the first node receives the fifth message sent by the second node and generates the fifth key. In some embodiments, the first node can be a SAEF, and the first key of the first node can be K SAEFIn some embodiments, the fifth key is generated according to the first key and the type of the second node, including at least one of: generating the fifth key according to the first key, the type of the second node, and a first count value; the first count value being a count of uplink non-access stratum (NAS) messages sent by the UE to the second node; generating the fifth key according to the first key, the type of the second node, and second time information; the second time information indicating a time period for generating the fifth key.

[0186] In some embodiments, the fifth key is generated according to the first key and the type of the second node, including at least one of: generating the fifth key according to the first key, the type of the second node, and a first count value; the first count value being a count of uplink non-access stratum (NAS) messages sent by the UE to the second node; generating the fifth key according to the first key, the type of the second node, and second time information; the second time information indicating a time period for generating the fifth key.

[0187] If the fifth key is generated according to the count of NAS messages or the second time information, the second key and the fifth key are different when the same UE communicates with the same second node at different time periods, thereby further improving the security of direct NAS communication between the UE and the second node.

[0188] In some embodiments, the fifth key is generated according to the first key and the instance ID of the second node, including at least one of: generating the fifth key according to the first key, the instance ID of the second node, and a first count value; the first count value being a count of uplink non-access stratum (NAS) messages sent by the UE to the second node; generating the fifth key according to the first key, the instance ID of the second node, and second time information; the second time information indicating a time period for generating the fifth key.

[0189] In some embodiments, the fifth key is generated according to the first key and the instance ID of the second node, including at least one of: generating the fifth key according to the first key, the instance ID of the second node, and a first count value; the first count value being a count of uplink non-access stratum (NAS) messages sent by the UE to the second node; generating the fifth key according to the first key, the instance ID of the second node, and second time information; the second time information indicating a time period for generating the fifth key.

[0190] In some embodiments, the fifth key is generated according to the first key, and at least one of the following parameters can be used: P0 = UE ID; L0 = length of P0; P1 = type of NF or NF instance ID (NF Instance ID); for example, the type of the NF is LMF, SMF, etc. L1 = length of P1; P2 = value of UTC or number of uplink NAS messages; L2 = length of P2. Of course, the above is only an example, and the specific implementation is not limited to the above example.

[0191] S2107: The first node sends the fifth key to the second node.

[0192] In some embodiments, the first node further sends a second algorithm identity to the second node. In some embodiments, the second algorithm identity is used to identify a security algorithm that protects the first message. In other embodiments, the second algorithm identity is an input parameter for generating the fourth key. Illustratively, the second algorithm identity can be sent to the second node together with the fifth key. Alternatively, the second algorithm identity can be sent to the second node separately.

[0193] In some embodiments, the second algorithm identity can be an identity of an algorithm that the first node and the UE have negotiated to protect the communication between the UE and the first node.

[0194] In some embodiments, the first message contains the first algorithm identity. If the UE and the first node have agreed to carry the first algorithm identity in the first message by default, the first node can not need to send the second algorithm identity to the second node. In some embodiments, the first algorithm identity is used to identify a security algorithm that the UE and the first node have negotiated to protect the communication between the UE and the first node. In some embodiments, the second algorithm identity is used to identify a security algorithm that the first node and the UE have negotiated to protect the communication between the UE and the first node.

[0195] If the UE is a UE that has successfully registered to the first node, the first algorithm identity and the second algorithm identity should be the same.

[0196] S2108: The second node generates the fourth key according to the fifth key.

[0197] In some embodiments, the fourth key is used as an input of a KDF, and the third key is generated in combination with one or more of the following parameters: P0 = an algorithm type distinguisher; illustratively, the type of the security algorithm herein includes but is not limited to an integrity algorithm and / or a confidentiality algorithm; L0 = the length of P0;

[0198] P1 = a security algorithm ID; illustratively, an ID for an Advanced Encryption Standard (AES), an ID for ZUC, etc.; L1 = the length of the algorithm ID.

[0199] S2109: The second node sends a second message to a third node.

[0200] In some embodiments, the second message is protected using the fourth key. Illustratively, the second message is integrity protected using the fourth key, or the second message is confidentiality protected using the fourth key.

[0201] In some embodiments, the second node successfully verifies the first message using the fourth key, and the second node sends a second message to the third node. In some embodiments, the second node fails to verify the first message using the fourth key, and the second node sends a rejection message to the third node. The rejection message can be used to indicate rejection of UE access. Illustratively, the rejection message sent by the second node to the third node can further include a failure cause. The failure cause can indicate the reason for rejection of UE access to the second node.

[0202] In some embodiments, the second node allows UE access to the second node and sends a second message. The second message can be a response message of the first message.

[0203] S2110: The third node sends the second message to the UE.

[0204] In some embodiments, the third node sends a second RRC message to the UE, and the second RRC message includes the second message.

[0205] In some embodiments, the second RRC message is protected using an AS security context.

[0206] In some embodiments, the UE receives the second message sent by the third node. Illustratively, after receiving the second message, the UE can be considered to have completed one message interworking between the UE and the second node.

[0207] In some embodiments, after receiving the second message, the UE can send a subsequent NAS message to the second node if needed, and at this time, the third node receives the NAS message and directly transmits or forwards it to the second node. The third node will also directly receive the NAS message sent by the second node to the UE and forward or transmit the NAS message received from the second node to the UE.

[0208] As shown in FIG. 2B, embodiments of the present disclosure provide an information processing method, which is executed by the communication system shown in FIG. 1A. The method can include:

[0209] S2201: The UE generates a second key according to a first key of the first node.

[0210] In some embodiments, the first node, the first key, and the second key can be described in the corresponding embodiments of FIG. 2A.

[0211] In some embodiments, the optional implementation of the UE generating the second key according to the first node can be described in the optional implementation of S2101 of the corresponding embodiments of FIG. 2A.

[0212] S2202: The UE generates a third key according to the second key.

[0213] In some embodiments, the second key and / or the third key can be generated by the UE according to the corresponding embodiment of FIG. 2A.

[0214] In some embodiments, the UE can generate the third key according to the optional implementation of the second key, which can be seen in the optional implementation of S2102 of the corresponding embodiment of FIG. 2A.

[0215] S2203: The UE sends a first message to a third node.

[0216] In some embodiments, the third node and the first message can be described with reference to the corresponding embodiment of FIG. 2A.

[0217] In some embodiments, the UE can send the first message to the third node according to the optional implementation, which can be seen in S2103 of the corresponding embodiment of FIG. 2A.

[0218] S2204: The third node sends a third message to the first node.

[0219] In some embodiments, the third message is sent to the first node before the first message is sent to the second node, when it is determined that the first node has not been requested by the UE to generate a fifth key for the second node.

[0220] In some embodiments, the third node determines that the first message is the first message sent by the UE to the second node, and the third message is sent to the first node before the first message is sent to the second node.

[0221] In some embodiments, the third node determines that the first message is not the first message sent by the UE to the second node, and skips the step of sending the third message to the first node, and directly enters the step of sending the first message to the second node.

[0222] In some embodiments, the third node does not obtain the historical communication record between the UE and the second node, and the third message is sent to the first node before the first message is sent to the second node.

[0223] In some embodiments, the third message is used to request the first node to generate a fifth key for the second node.

[0224] In some embodiments, the fifth key is used to generate a fourth key. For example, the fourth key can include, but is not limited to, an integrity key and / or a confidentiality key.

[0225] In some embodiments, the fourth key is used to protect the security of the communication between the second node and the UE.

[0226] In some embodiments, the third message comprises at least one of: an ID of the UE; a type of the second node; an instance ID of the second node.

[0227] Of course, the above is only an example of the third message, and the information content of the third message in the actual implementation is not limited to the above example.

[0228] S2205: The first node sends a fourth message to the third node.

[0229] In some embodiments, the fourth message is used for the third node to determine whether the fifth key has been generated; or the fourth message is used to indicate that the first node has sent the fifth key to the second node. In summary, the fourth message can be used for the third node to determine whether the first message can be sent to the second node.

[0230] In some embodiments, if the first node needs to select the second node for the UE, the first node can also send the second information to the third node. In some embodiments, if the first node does not need to select the second node for the UE, the first node does not need to send the second information to the third node. For example, if the third message carries the instance ID of the second node or the address information of the second node, it means that the first node does not need to select the second node for the UE, otherwise, the first node needs to select the second node for the UE. Of course, in some cases, the first node can also update the third node to determine the second node for the UE or the UE to select the second node by itself according to the load rate and / or abnormal condition of different second nodes without the need to select the second node for the UE. In this case, if the first node reselects the second node for the UE, the second information of the second node needs to be sent to the third node.

[0231] In some embodiments, the second information comprises at least one of the instance ID of the second node and the address information of the second node. In some embodiments, the second information can be included in the fourth message or not. The second information can be sent to the third node together with the fourth message or separately.

[0232] S2206: The first node sends the fifth key to the second node.

[0233] In some embodiments, the second node sends the fifth key and the second algorithm identifier to the second node. Of course, the first node sending the second algorithm identifier to the second node is optional. For example, the first message contains the first algorithm identifier, the second node can obtain the first algorithm identifier from the first message, and generate the fourth key based on the first algorithm identifier, at this time, the first node does not need to send the second algorithm identifier to the second node.

[0234] S2207: The third node sends the first message to the second node.

[0235] In some embodiments, the third node sends the first message to the second node after receiving the fourth message.

[0236] In some embodiments, the third node sends the first message to the second node at the same time as sending the third message to the first node.

[0237] In some embodiments, the first message comprises at least one of: non-access stratum (NAS) signaling; an ID of the UE; a first algorithm identifier, wherein the first algorithm identifier is used to identify a security algorithm that protects the first message.

[0238] The NAS signaling can comprise, but is not limited to, LPP signaling if the second node is an LMF. The NAS signaling can be signaling comprising, but not limited to, session establishment request, update or release, etc. if the second node is an SMF.

[0239] In some embodiments, the first algorithm identifier can be an algorithm identifier provided by the UE to the second node, and the first algorithm identifier can be used by the second node to generate the fourth key.

[0240] S2208: The second node generates the fourth key.

[0241] In some embodiments, the first node generates the fourth key according to the fifth key. The optional implementation of the second node generating the fourth key can refer to any optional implementation of S2108 of the corresponding embodiment of FIG. 2A.

[0242] S2209: The second node sends the second message to the third node.

[0243] In some embodiments, the optional implementation of the second node sending the second message to the third node can refer to any optional implementation of S2109 of the corresponding embodiment of FIG. 2A.

[0244] S2210: The third node sends the second message to the UE.

[0245] In some embodiments, the optional implementation of the third node sending the second message to the UE can refer to any optional implementation of S2110 of the corresponding embodiment of FIG. 2A.

[0246] As shown in FIG. 3, the embodiments of the present disclosure provide an information processing method, which is performed by a UE, and the method can comprise:

[0247] S3101: Generating a second key.

[0248] In some embodiments, the second key is generated according to a first key of the first node.

[0249] In some embodiments, the related descriptions of the first node, the second node, the third node, the first key and / or the second key can refer to the related descriptions in the corresponding embodiments of FIG. 2A.

[0250] In some embodiments, the optional implementation that the UE generates the third key according to the second key of the first node can refer to the related descriptions in the corresponding embodiments S2101 or S2201 of FIG. 2A or FIG. 2B.

[0251] S3102: Generating a third key.

[0252] In some embodiments, the third key is generated according to the second key.

[0253] In some embodiments, the optional implementation that the UE generates the third key according to the second key of the first node can refer to the related descriptions in the corresponding embodiments S2101 or S2201 of FIG. 2A or FIG. 2B.

[0254] S3103: Sending a first message.

[0255] In some embodiments, the UE sends the first message to the third node.

[0256] In some embodiments, the optional implementation that the UE sends the first message to the third node can refer to the related descriptions in the corresponding embodiments S2103 or S2203 of FIG. 2A or FIG. 2B.

[0257] S3104: Receiving a second message.

[0258] In some embodiments, the UE receives the second message from the second node forwarded or transparently transmitted by the third node.

[0259] In some embodiments, the related descriptions of the second message can refer to the corresponding embodiments of FIG. 2A and / or FIG. 2B.

[0260] As shown in FIG. 4A, the embodiments of the present disclosure provide an information processing method, which is performed by a third node. The method can include:

[0261] S4101: Receiving a first message.

[0262] In some embodiments, the third node receives the first message sent by the UE.

[0263] In some embodiments, the first message is protected using the third key.

[0264] In some embodiments, the third key is generated by the UE based on the second key.

[0265] In some embodiments, the second key is generated based on the first key of the first node.

[0266] In some embodiments, the receiving node of the first message is the second node.

[0267] In some embodiments, the first node, the second node, the third node, the first key, the second key, and the first message can refer to the corresponding descriptions in the embodiment S2101 of FIG. 2A.

[0268] S4102: sending the first message.

[0269] In some embodiments, the third node sends the first message to the second node.

[0270] In some embodiments, the optional way of sending the first message by the third node to the second node can refer to the embodiment S2104 of FIG. 2A.

[0271] S4103: receiving the second message.

[0272] In some embodiments, the second message is received by the third node.

[0273] In some embodiments, the second message can refer to the corresponding descriptions in the aforementioned embodiment of FIG. 2A.

[0274] S4104: sending the second message.

[0275] In some embodiments, the third node sends the second message to the UE.

[0276] In some embodiments, the optional implementation of sending the second message by the third node to the UE can refer to the embodiment S2110 of FIG. 2A.

[0277] In some embodiments, S4102 to S4104 can be optional steps. If the second node is determined by the third node for the UE, if the third node fails to select the second node for the UE, or if the first RRC message security verification fails through the AS security context verification, the first node does not need to send the first message, and thus will not receive the second message returned based on the first message.

[0278] In some embodiments, after the third node receives the first message and sends the first message, the second node refuses to communicate with the UE, the third node can not receive the second message, and thus does not need to send the second message. In this case, S4103 and S4104 are optional steps.

[0279] As shown in FIG. 4B, the embodiments of the present disclosure provide an information processing method, which is executed by a third node. The method can include:

[0280] S4201: receiving a first message.

[0281] In some embodiments, the first node receives the first message sent by the UE.

[0282] In some embodiments, the first message is protected using a third key.

[0283] In some embodiments, the third key is generated by the UE based on the second key.

[0284] In some embodiments, the second key is generated based on the first key of the first node.

[0285] In some embodiments, the receiving node of the first message is the second node.

[0286] In some embodiments, the first node, the second node, the third node, the first key, the second key, and the first message can refer to the descriptions in the corresponding embodiment S2201 in FIG. 2B.

[0287] S4202: sending a third message.

[0288] In some embodiments, the third node sends the third message to the first node.

[0289] In some embodiments, the description of the third message can refer to the description in the corresponding embodiment in FIG. 2B.

[0290] In some embodiments, the optional implementation of the third message can refer to S2204 in the corresponding embodiment in FIG. 2B.

[0291] S4203: receiving a fourth message.

[0292] In some embodiments, the third node receives the fourth message sent by the first node.

[0293] In some embodiments, the description of the fourth message can refer to the description in the corresponding embodiment in FIG. 2B.

[0294] In some embodiments, the optional implementation of the fourth message can refer to S2204 in the corresponding embodiment in FIG. 2B.

[0295] In some embodiments, the third node sends the first message to the first node or the second node.

[0296] In some embodiments, the optional implementation of the third node sending the first message to the first node or the second node can refer to S2104 in the corresponding embodiment in FIG. 2A.

[0297] S4204: receiving a second message.

[0298] In some embodiments, the third node receives the second message sent by the second node.

[0299] In some embodiments, the related description of the second message can refer to the related description of the corresponding embodiment of FIG. 2B.

[0300] S4205: sending the second message. In some embodiments, the optional implementation of the second message sent by the third node to the UE can refer to S2209 of the corresponding example of FIG. 2B.

[0301] As shown in FIG. 5A, the embodiments of the present disclosure provide an information processing method, which is performed by a first node. The method can include:

[0302] S5101: receiving a fifth message.

[0303] In some embodiments, the first node can be an SEAF.

[0304] In some embodiments, the first node receives the fifth message sent by a second node.

[0305] In some embodiments, the related description of the first node and the second node and the fifth message can refer to the related description in S2105 of the corresponding embodiment of FIG. 2A.

[0306] S5102: generating a fifth key.

[0307] In some embodiments, the fifth key is generated according to the first key of the first node.

[0308] In some embodiments, the fifth key is generated upon receiving the fifth message.

[0309] In some embodiments, the related description of the fifth key can refer to S2106 of the corresponding embodiment of FIG. 2A.

[0310] In some embodiments, the optional implementation of the fifth key generated by the first node can refer to any optional implementation of S2106 of the corresponding embodiment of FIG. 2A.

[0311] S5103: sending the fifth key.

[0312] In some embodiments, the first node sends the fifth key and the first message to the second node.

[0313] In some embodiments, the method further includes that the first node sends a second algorithm identifier and / or node information of the third node. Exemplarily, the related description of the second algorithm identifier can refer to any optional implementation of S2106 of the corresponding embodiment of FIG. 2A. Exemplarily, the node information of the third node can include the node identifier, the tunnel address, the SBI interface, and the like of the third node, which can be used by the second node to determine the third node.

[0314] In an embodiment, the fifth key can be used by the second node to generate the fourth key. The fourth key can be used to protect the security of the communication between the second node and the UE.

[0315] As shown in FIG. 5B, the embodiment of the present disclosure provides an information processing method, which is performed by a first node. The method can include:

[0316] S5201: receiving a third message.

[0317] In some embodiments, the first node receives the third message sent by a third node.

[0318] In some embodiments, the third message is used to request the first node to generate a fifth key for the second node. In some embodiments, the fifth key is used to generate a fourth key. Exemplarily, the fourth key can include, but is not limited to, an integrity key and / or a confidentiality key.

[0319] In some embodiments, the fourth key is used to protect the security of the communication between the second node and the UE.

[0320] In some embodiments, the fourth key is used by the second node to protect the security of the communication with the UE,

[0321] In some embodiments, the related descriptions of the first node, the second node, the third node, the first key, the second key, and the third message can be referred to the related descriptions in S2204 in FIG. 2B.

[0322] S5202: generating a fifth key.

[0323] In some embodiments, the fifth key is generated according to the first key of the first node.

[0324] In some embodiments, the fifth key is generated in the case that the third message is received.

[0325] In some embodiments, the optional implementation of the first node generating the fifth key can be referred to any optional implementation of the corresponding embodiment S2205 in FIG. 2B.

[0326] In some embodiments, the method further includes: the first node sending a second algorithm identifier and / or node information of the third node. Exemplarily, the related description of the second algorithm identifier can be referred to any optional implementation of the corresponding embodiment S2105 in FIG. 2A.

[0327] S5203: sending the fifth key.

[0328] In some embodiments, the first node sends the fifth key to the second node.

[0329] In some embodiments, the optional implementation of sending the fifth key can refer to any optional implementation of the corresponding embodiment S2106 of FIG. 2A.

[0330] In some embodiments, the first node can further send a second algorithm identification to the second node. Illustratively, the second algorithm identification can be used to identify a security algorithm used to protect the second message. Further illustratively, the second algorithm identification can also be used as an input parameter for generating the fourth key.

[0331] S5204: sending the fourth message.

[0332] In some embodiments, the description of the fourth message can refer to the description of the corresponding embodiment of FIG. 2B.

[0333] In some embodiments, the sending of the fourth message can be an optional step. For example, the third node and the first node can have a default that the first node will automatically generate the fifth key after receiving the third message without confirmation.

[0334] As shown in FIG. 6A, the embodiments of the present disclosure provide an information processing method, which is performed by a second node, and can include:

[0335] S6101: receiving a first message.

[0336] In some embodiments, the second node receives the first message of the UE forwarded by the third node. In some embodiments, the description of the first message can refer to the corresponding embodiment of FIG. 2A.

[0337] S6102: sending a fifth message.

[0338] In some embodiments, the second node sends the fifth message to the first node. The fifth message can include parameters required for generating the fifth key, such as the first count value, etc. Illustratively, the fifth message includes the identification of the UE, so that the fifth keys of different UEs will be different.

[0339] In some embodiments, the description of the fifth message can refer to S2105 of the corresponding embodiment of FIG. 2A.

[0340] S6103: receiving a fifth key.

[0341] In some embodiments, the second node receives the fifth key sent by the first node.

[0342] In some embodiments, the fifth key is generated by the first node according to the first key.

[0343] In some embodiments, the fifth key is generated by the first node after receiving the fifth message sent by the third node.

[0344] In some embodiments, the method further comprises receiving a second algorithm identity. The second algorithm identity can be one of the parameters for generating the fourth key.

[0345] S6104: Generating the fourth key.

[0346] In some embodiments, the second node generates the fourth key according to the fifth key.

[0347] In some embodiments, the second node generates the optional implementation of the fourth key, which can be referred to S2108 of the corresponding embodiment of FIG. 2A.

[0348] S6105: Sending the second message.

[0349] In some embodiments, the second node verifies the first message using the fourth key, and if the first message passes the verification, sends the second message. If the first message fails the verification, the second node does not send the second message, but sends a rejection message.

[0350] In some embodiments, the second node verifies the first message using the fourth key includes but is not limited to at least one of the following: integrity verification of the first message using the fourth key; confidentiality verification of the first message using the fourth key; and ciphering and deciphering verification of the first message using the fourth key.

[0351] As shown in FIG. 6B, the embodiments of the present disclosure provide an information processing method, which is performed by a second node, and can comprise:

[0352] S6201: Receiving a fifth key.

[0353] In some embodiments, the second node receives the fifth key sent by the first node.

[0354] In some embodiments, the first node, the second node, and the related description of the fifth key can be referred to the corresponding embodiments of FIG. 2B.

[0355] S6202: Receiving a first message.

[0356] In some embodiments, the second node receives the first message sent by the first node.

[0357] In some embodiments, there can be no certain sequence between S6201 and S6202, for example, S6201 can be executed first and then S6202, or S6202 can be executed first and then S6201, or S6201 and S6202 can be executed simultaneously.

[0358] In some embodiments, the related description of the first message can be referred to the related description of the corresponding embodiment of FIG. 2B.

[0359] S6203: Generating the fourth key.

[0360] In some embodiments, the second node generates the fourth key according to the fifth key.

[0361] In some embodiments, the second node generates the fourth key, see S2208 of the corresponding embodiment of FIG. 2B.

[0362] S6204: sending the second message.

[0363] In some embodiments, the second node verifies the first message using the fourth key, and if the first message passes the verification, sends the second message. If the first message does not pass the verification, does not send the second message, but sends a rejection message.

[0364] In some embodiments, the second node verifies the first message using the fourth key includes but is not limited to at least one of the following: integrity verification of the first message using the fourth key; confidentiality verification of the first message using the fourth key; deciphering and scrambling verification of the first message using the fourth key.

[0365] In some embodiments, the first message is received from a third node, and the second node sends the second message to the third node. In some embodiments, the related description of the second message can be referred to the related description in the corresponding embodiment of FIG. 2B.

[0366] Embodiments of the present disclosure provide a method, which on one hand enhances the existing 5G security key hierarchy to support 6G multi-NAS architecture protection between UE and core NF (non-AMF); on the other hand, completes the NAS security establishment without algorithm negotiation to support 6G multi-NAS architecture protection between UE and core NF. AMF is a key derived by the UE and the SEAF from K SEAF . When performing horizontal key derivation, K AMF is further derived by the UE and the AMF. K NASINT is a key obtained by the UE and the AMF from K AMF , which can only be used to protect NAS signaling with a specific integrity algorithm.

[0367] K NASENC is a key derived by the UE and the AMF from K AMF , which can only be used to protect NAS signaling through a specific encryption algorithm.

[0368] In order to protect NAS or NF signaling between the UE and the core NF, instead of the AMF, embodiments of the present disclosure propose that K NF needs to be derived as the security root of NAS or NF signaling between the UE and the NF. In the sixth generation mobile communication (6 thIn a Generatyion (6G) system, assuming the UE can communicate directly with the NF (such as LMF, SMF) without going through the AMF and the NF is not determined or selected by the AMF, then K is proposed. NF From K respectively by UE and SEAF SEAF Derivation. Based on K NF The UE and the target NF further derive the NAS security key between the UE and the NF, namely K. NFint K is used to protect the integrity of NAS or NF signaling between the UE and NF. NFenc This is used to protect the confidentiality of NAS or NF signaling between the UE and NF. Therefore, the new key hierarchy is shown in Figure 1G.

[0369] When SEAF and UE are based on K SEAF Export K NF When using KDF, the following parameters are used to form the input: fc = To Be Dertermined (TBD); p0 = UE ID; for example, the UE ID can be IMSI, NAI, GCI, or GLI; l0 = P0 length; p1 = NF type (such as LMF, SMF) or NF instance ID; l1 = P1 length; p2 = uplink NAS or NF count or UTC count; l2 = P2 length; p3 = ABBA parameter, which indicates the security features currently used by the network to prevent attackers from using low-security features to perform dimensionality reduction attacks on high-security features. Currently, the ABBA parameter only has one value, 0x0000, indicating the initial security features of the 5G network. l3 = P3 length.

[0370] P0 can be any type of UE ID shared between the UE and the target NF. P1 can be the NF type (such as LMF, SMF) or the NF instance ID (if available on the UE or RAN node). P2 can be the derived K. NF The time point is based on UTC, or it can be the uplink NAS or NF count in the UE and NF. Assume the UE maintains a separate NAS count for each directly communicating NF, such as an uplink NAS / LMF count. The input key to the key derivation function can be a 256-bit K... SEAF .

[0371] When K from NF and UE NF Export NAS or NF integrity key K NFint and NAS or NF encryption key K NFencAt this time, the following parameters are needed to form a string S. fc = To Be Dertermined (TBD); p0 = algorithm type distinguisher, for example, the algorithm type distinguisher for an integrity algorithm or an encryption algorithm has different values; l0 = length of the algorithm type distinguisher; p1 = algorithm identifier, typical algorithm identifiers can include but are not limited to the ID of AES, the ID of ZUC, etc. l1 = length of the algorithm identifier; the input key of the key derivation function KDF can be a 256-bit K NF .

[0372] When the UE connects to the network, the initial NAS procedure is performed between the UE and the AMF, the primary authentication and initial mobility registration are performed in the network, and in this procedure, the UE negotiates the integrity and encryption algorithms of the NAS / AMF security with the AMF through the NAS SMC procedure. Therefore, it can be considered that any initial NAS / NF message sent by the UE to the target NF other than the AMF is sent after the UE establishes the NAS / AMF security with the AMF. For the sake of simplicity, it can be assumed that all NFs in the same service network support the same set of algorithms and the same algorithm priority as the AMF, so the AMF can negotiate the NAS / NF security algorithm with the UE on behalf of other NFs. Under this assumption, the NAS / AMF security algorithm negotiated between the UE and the AMF through the NAS SMC procedure can be applied to the NAS / NF security between the UE and the NF other than the AMF, and no security mode negotiation is needed between the UE and other NFs. Alternatively, if the SEAF is taken as the anchor NF of all NFs in the same service network in the 6G system, it can also be assumed that the NAS / SEAF algorithm is negotiated between the UE and the SEAF during the initial registration. Under this assumption, the NAS / SEAF security algorithm negotiated between the UE and the SEAF can be applied to the NAS / NF security between the UE and all other NFs, so no security mode negotiation is needed between the UE and other NFs. After the establishment of the NAS / SEAF security ends, the SEAF should be able to inform other NFs of the negotiated NAS / SEAF security algorithm. In the embodiments of the present disclosure, " / " can represent "or", "and / or".

[0373] With these two options, K NF can be derived by the SEAF from K SEAF , or derived by the AMF from K AMF , when the NF receives the initial NAS / NF message from the UE through the RAN node, a key generation request can be sent to the SEAF or the AMF.

[0374] As shown in FIG. 7A, the method can include:

[0375] 1. Before the UE initiates a NAS message (such as a NAS or LPP message) to the LMF through the RAN node, the UE first derives KSEAF K NF is derived from K LMF , the input parameters of K NF include the ID of the UE, the type or instance ID of the target NF (in this example, LMF), and the uplink NAS / LMF COUNT. Note: K SEAF is previously derived by the UE in the authentication procedure.

[0376] 2. The UE further derives NAS / LMF keys from K LMF , exemplarily, K LMFint for NAS / LMF integrity and K LMFenc for NAS / LMF encryption. The security algorithm identity used for deriving K LMFint and K LMFenc is the same as the one negotiated between the UE and the AMF for NAS / AMF signaling security through the NAS / AMF SMC procedure.

[0377] 3. The UE protects the NAS / LPP message using the derived NAS / LMF keys and encapsulates the NAS / LPP message in a RRC message. If K NF is derived from K SEAF , the applied algorithms are included in the protected NAS / LPP message. The applied algorithms are the ones negotiated by the UE with the AMF or SEAF. The UE can also include the type or instance ID of the target NF (i.e., LMF) in the RRC message. The RRC message is protected using existing AS security.

[0378] 4. The RAN node forwards the protected NAS / LPP message to the LMF according to the received NAS / LPP message type or the UE specified target NF type.

[0379] 5. When receiving the protected NAS / LPP message, if the LMF does not have available NAS / LMF security context (exemplarily, NAS / LMF security keys) to verify the received NAS / LPP message, the LMF sends a key generation request message to the SEAF or AMF. The request message can include the UE ID (e.g., IMSI, SUPI, etc.) and the uplink NAS / LMF message COUNT. If the LMF already has the NAS / LMF security context for the UE, the LMF skips step 5 and proceeds to step 9.

[0380] Note: The LMF can obtain the UE ID from the UE through the NAS / LPP message or from the RAN node through IP mapping. The LMF obtains the uplink NAS / LMF COUNT from the NAS / LPP message.

[0381] 6. The SEAF or AMF derives K SEAF from the received UE ID and NAS / LMF count and the type or instance ID of the requesting NF (LMF) LMF .

[0382] 7. The SEAF returns a key generation response to the LMF that requests the derivation of K LMF . Alternatively, the AMF returns a key generation response to the LMF that contains the NAS / AMF message protection algorithm and the derived K LMF . If the NAS / SEAF message protection algorithm is negotiated between the UE and the SEAF during the initial registration of the UE, the SEAF can also send the negotiated NAS / SEAF message protection algorithm to the LMF.

[0383] 8. The LMF derives the NAS / LMF keys (i.e., K LMF for NAS / LMF integrity and K LMFint for NAS / LMF encryption) from K LMFenc based on the algorithm identity included in the NAS / LPP message by the UE or sent by the SEAF / AMF.

[0384] 9. The LMF protects the NAS / LPP response message using the NAS / LMF keys and sends it to the RAN node.

[0385] 10. The RAN node encapsulates the protected NAS / LPP message response in a RRC message and sends it to the UE.

[0386] As shown in FIG. 7B, embodiments of the present disclosure provide a method that can include:

[0387] 1. Before the UE initiates a NAS message (e.g., LPP / SLPP message) to the LMF via the RAN node, the UE derives K SEAF from K AMF or K NF (e.g., K LMF ), where the input parameters for generating K NF are the UE’s ID, the type or instance ID of the target NF (in this case, the LMF), and a UTC-based counter.

[0388] Steps 2-3 are the same as steps 2-3 of the corresponding embodiment of FIG. 7A.

[0389] 4. When the RAN node receives the protected NAS / LPP message included in the RRC message, if it has not previously requested NAS / LMF key generation for the same UE and the same target NF, it sends a key generation request message to the SEAF or AMF, which includes the UE ID and the type or instance ID of the target NF (LMF). If the RAN node has already requested NAS / LMF key generation for a previous NAS / LPP message for the same UE and the same target NF, the RAN node skips step 4 and proceeds to step 7.

[0390] 5. The SEAF or AMF derives K SEAF from K LMF , generates K LMF , and sends K LMF to the target NF (LMF). Or the AMF sends the NAS / AMF message protection algorithm together with the derived K LMF to the target NF (LMF). If the NAS / SEAF message protection algorithm is negotiated between the UE and the SEAF during initial registration of the 6G system, the SEAF can also send the negotiated NAS / SEAF message protection algorithm to the LMF. The LMF then responds to the SEAF or AMF with an acknowledgement.

[0391] 6. The SEAF sends the derived K LMF to the target NF (LMF). Or the AMF sends the NAS / AMF message protection algorithm together with the derived K LMF to the target NF (LMF). If the NAS / SEAF message protection algorithm is negotiated between the UE and the SEAF during initial registration of the 6G system, the SEAF can also send the negotiated NAS / SEAF message protection algorithm to the LMF. The LMF then responds to the SEAF or AMF with an acknowledgement.

[0392] 7. The SEAF or AMF returns a key generation acknowledgement to the RAN node.

[0393] 8. Upon receiving the key generation acknowledgement from the SEAF or AMF, the RAN node forwards the protected NAS / LPP message to the LMF.

[0394] Steps 9 to 11 can be the same as steps 8 to 10 in FIG. 7A.

[0395] In some embodiments, the UE can perform at least one of the following operations:

[0396] The UE should be able to derive K SEAF from K NF as the root key to protect NAS / NF signaling between the UE and the NF.

[0397] The UE should be able to derive K NF and K NFint from K NFenc as the NAS / NF security context to protect NAS / NF signaling between the UE and the NF.

[0398] The UE shall be able to include the NAS / AMF security algorithms negotiated between the UE and the AMF in the NAS / NF message sent to the target NF.

[0399] The UE shall be able to include the type of the target NF or the instance ID in the RRC message containing the NAS / NF message sent to the RAN node.

[0400] In some embodiments, the RAN can perform at least one of the following operations: The RAN node shall be able to send the protected NAS / NF message directly to the NF without going through the AMF. Upon receiving the protected NAS / NF message from the UE, the RAN node shall be able to send a NAS / NF key generation request to the SEAF. The RAN node shall be able to receive a NAS / NF key generation confirmation from the SEAF. Upon receiving the NAS / NF key generation confirmation from the SEAF, the RAN node shall be able to forward the protected NAS / NF message from the UE to the NF. The SEAF shall be able to receive and understand the key generation request sent by the NF or the RAN node. Upon receiving the key generation request, the SEAF shall be able to derive K SEAF from K NF . The SEAF shall be able to send the NAS / SEAF security algorithms negotiated between the UE and the SEAF to the target NF. The AMF shall be able to receive and understand the key generation request sent by the NF or the RAN node. Upon receiving the key generation request, the AMF shall be able to derive K AMF from K NF . The AMF shall be able to send the NAS / AMF security algorithms together with K NF to the target NF.

[0401] In some embodiments, the NF can perform at least one of the following operations: Upon receiving the protected NAS / NF message from the RAN node, the NF shall be able to send a NAS / NF key generation request to the SEAF or the AMF. The NF shall be able to receive the derived K NF from the SEAF or the AMF. The NF shall be able to receive the applied NAS security algorithms from the SEAF or the AMF. Upon receiving the derived K NF , the NF shall be able to send a confirmation to the SEAF or the AMF. The NF shall be able to derive K NF and K NFint from K NFenc as the NAS / NF security context for protecting the NAS / NF signaling between the UE and the NF.

[0402] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or combined with optional implementation manners of other embodiments.

[0403] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or combined with optional implementation manners of other embodiments.

[0404] The embodiments of the present disclosure further provide a device for implementing any of the above methods, for example, providing a device, the device comprising units or modules for implementing the steps performed by the UE in any of the above methods. For another example, another device is provided, comprising units or modules for implementing the steps performed by the network device (for example, an access network device, or a core network device, etc.) in any of the above methods.

[0405] It should be understood that the division of units or modules in the above device is only a logical function division, and all or part of them can be integrated into one physical entity, or physically separated. In addition, the units or modules in the device can be implemented in the form of processor calling software: for example, the device includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules of the device, wherein the processor is, for example, a general processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be implemented by the design of hardware circuit, and the hardware circuit can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are implemented by the design of the logical relationship of elements in the circuit; for another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to implement the functions of part or all of the units or modules. All units or modules of the above device can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules can be implemented in the form of processor calling software, and the remaining part can be implemented in the form of hardware circuit.

[0406] In embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), etc. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0407] As shown in FIG. 8A, embodiments of the present disclosure provide a UE, wherein the UE comprises:

[0408] The processing module 7101 is configured to generate a second key according to a first key of a first node; generate a third key according to the second key; and the third key is used to protect the security of communication between the user equipment (UE) and a second node; wherein the first node is a security anchor function.

[0409] In some embodiments, the UE further comprises a sending module and / or a receiving module. The sending module can correspond to the network interface and / or the transceiving antenna of the UE. In some embodiments, the processing module can be used by the UE to perform steps related to information processing in any one of the information processing methods. In some embodiments, the sending module can be used by the UE to perform steps related to information sending in any one of the information processing methods. In some embodiments, the receiving module can be used by the UE to perform steps related to information sending in any one of the information processing methods.

[0410] In some embodiments, the processing module is configured to perform at least one of the following: generating the second key according to the first key and a type of the second node; generating the second key according to the first key and an instance ID of the second node.

[0411] In some embodiments, the processing module is configured to perform at least one of the following: generating the second key according to the first key, a type of the second node, and a first count value; the first count value is a count of uplink non-access stratum (NAS) messages sent by the UE to the second node; generating the second key according to the first key, a type of the second node, and first time information; the first time information indicates a time period for generating the second key.

[0412] In some embodiments, the processing module is configured to generate the second key according to the first key and an instance ID of the second node, the UE being preconfigured with the instance ID of the second node.

[0413] In some embodiments, the processing module is configured to generate the second key according to the first key, an instance ID of the second node, and a first count value; the first count value is a count of uplink non-access stratum (NAS) messages sent by the UE to the second node; generate the second key according to the first key, an instance ID of the second node, and first time information; the first time information indicates a time period for generating the second key.

[0414] In some embodiments, the sending module is configured to send, to a third node, a first radio resource control (RRC) message, the first RRC message comprising a first message; the first message is protected by a third key; the second node is a receiving node of the first message.

[0415] In some embodiments, the first message comprises at least one of the following: non-access stratum (NAS) signaling; an ID of the UE; a first algorithm identifier, wherein the first algorithm identifier is used to identify a security algorithm for protecting the first message. In some embodiments, the first RRC message is protected by an access stratum (AS) security context of the UE.

[0416] In some embodiments, the receiving module is configured to receive a second RRC message sent by the third node, the second RRC message comprising a second message; the second message is from the second node; the second message is protected by a fourth key; the fourth key is generated from a fifth key, the fifth key being generated according to the first key.

[0417] In some embodiments, the second RRC message is protected by an access stratum (AS) security context of the UE. In some embodiments, the first RRC message further comprises at least one of the following: type information of the second node; an instance ID of the second node; address information of the second node.

[0418] As shown in FIG. 8B, the embodiment of the present disclosure provides a third node, wherein the third node comprises: a receiving module 7201 configured to generate a second key according to a first key of a first node; and a sending module 7202 configured to generate a third key according to the second key, wherein the third key is used to protect the security of communication between a user equipment (UE) and a second node, and wherein the first node is a security anchor function.

[0419] In some embodiments, the third node further comprises a processing module. In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the third node. In some embodiments, the processing module can be used by the third node to perform steps related to information processing in any one of the information processing methods. In some embodiments, the sending module can be used by the third node to perform steps related to information sending in any one of the information processing methods. In some embodiments, the receiving module can be used by the third node to perform steps related to information sending in any one of the information processing methods.

[0420] In some embodiments, before sending the first message to the second node, the sending module is configured to send a third message to the first node, wherein the third message is used to request the first node to generate a fifth key, and the fifth key is used to generate the fourth key, and wherein the fourth key is used by the second node to verify the security of the first message.

[0421] In some embodiments, the receiving module is configured to receive a fourth message sent by the first node, and wherein the fourth message is used to indicate whether the fifth key has been generated. In some embodiments, the sending module is configured to send the first message to the second node when the fourth message indicates that the fifth key has been generated. In some embodiments, the sending module is configured to send the third message to the first node when it is determined that the fifth key has not been requested by the UE for the second node from the first node. In some embodiments, the receiving module is configured to receive a first radio resource control (RRC) message sent by the UE, and wherein the first RRC message comprises the first message.

[0422] In some embodiments, the first RRC message is protected by an access stratum (AS) security context.

[0423] In some embodiments, the first RRC message further comprises at least one of the following: type information of the second node; an instance ID of the second node; and address information of the second node.

[0424] As shown in FIG. 8C, the embodiment of the present disclosure provides a first node, wherein the first node comprises: a processing module 7301 configured to generate a fifth key according to a first key of the first node; and a sending module 7302 configured to send the fifth key to a second node, the fifth key being used by the second node to generate a fourth key, the fourth key being used to protect security of communication between the second node and a UE; and the first node being a security anchor function.

[0425] In some embodiments, the first node can further comprise a receiving module. In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the first node. In some embodiments, the processing module can be used by the first node to perform steps related to information processing in any one of the information processing methods. In some embodiments, the sending module can be used by the first node to perform steps related to information sending in any one of the information processing methods. In some embodiments, the receiving module can be used by the first node to perform steps related to information sending in any one of the information processing methods.

[0426] In some embodiments, the processing module is configured to receive a third message sent by a third node, and generate the fifth key according to the first key; the third message being used to request the first node to generate the fifth key for the first node.

[0427] In some embodiments, the sending module is configured to send a fourth message to the third node; the fourth message being used to inform the third node whether the fifth key has been generated.

[0428] In some embodiments, the third message comprises at least one of the following: type information of the second node; an instance identification ID of the second node; and an identification of the UE.

[0429] In some embodiments, the processing module is configured to receive a fifth message of the second node, and generate the fifth key according to the first key; the fifth message being used by the second node to request generation of the fifth key.

[0430] In some embodiments, the fifth message comprises at least one of the following: type information of the second node; an instance ID of the second node; a second count value; the second count value being a count of uplink non-access stratum NAS messages of the UE received by the second node; and an identification of the UE.

[0431] In some embodiments, the processing module is configured to generate the fifth key according to the first key and the type of the second node, and generate the fifth key according to the first key and the instance identification ID of the second node.

[0432] In some embodiments, the processing module is configured to perform at least one of the following: generating the fifth key according to the first key, the type of the second node, and the second count value, the second count value being a count of uplink non-access stratum (NAS) messages received by the second node from the UE; and generating the fifth key according to the first key, the type of the second node, and the second time information, the second time information indicating a time period for generating the fifth key.

[0433] In some embodiments, the processing module is configured to include the instance ID of the second node in the fifth message, and generate the fifth key according to the first key and the instance ID of the second node.

[0434] In some embodiments, the processing module is configured to generate the fifth key according to the first key, the instance ID of the second node, and the second count value, the second count value being a count of uplink non-access stratum (NAS) messages received by the second node from the UE; and generate the fifth key according to the first key, the instance ID of the second node, and the second time information, the second time information indicating a time period for generating the fifth key.

[0435] As shown in FIG. 8D, the embodiments of the present disclosure provide a second node, wherein the second node includes: a receiving module 7401 configured to receive a fifth key sent by a first node, the fifth key being generated according to a first key of the first node; and a processing module 7402 configured to generate a fourth key according to the fifth key, the fourth key being used to protect security of communication between the second node and a user equipment (UE), the first node being a security anchor function.

[0436] In some embodiments, the second node can further include a receiving module and a processing module. In some embodiments, the sending module and / or the receiving module can correspond to a network interface and / or a transceiving antenna of the second node. In some embodiments, the processing module can be used by the second node to perform steps related to information processing in any one of the information processing methods. In some embodiments, the sending module can be used by the second node to perform steps related to information sending in any one of the information processing methods. In some embodiments, the receiving module can be used by the second node to perform steps related to information sending in any one of the information processing methods.

[0437] In some embodiments, the receiving module is configured to receive a first message sent by a third node, and send a fifth message to the first node, the fifth message being used to request a fifth key, the first message being protected by a third key, the third key being generated according to a second key, the second key being generated according to a first key of the first node.

[0438] In some embodiments, the fifth message comprises at least one of the following: type information of the second node; an instance ID of the second node; the second count value; the second count value is a count of uplink non-access stratum (NAS) messages received by the second node from the UE; an identity of the UE.

[0439] In some embodiments, the sending module is configured to send, to the third node, a second message, the second message being protected using a fourth key.

[0440] The embodiments of the present disclosure also provide a communication device, which can include one or more processors; wherein the processor is configured to invoke instructions to cause the communication device to perform the information processing method implemented by any one of the preceding embodiments.

[0441] In some embodiments, as shown in FIG. 9A and / or FIG. 9B, the communication device 8100 further includes one or more memories 8102 for storing instructions. Alternatively, all or part of the memory 8102 can also be outside the communication device 8100.

[0442] The communication device can be the UE and the network device as described above. In some embodiments, the network device can be the master node and / or the secondary node.

[0443] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps in the above method are performed by the transceiver 8103, and the other steps are performed by the processor 8101.

[0444] In some embodiments, the transceiver can include a receiver and a transmitter, which can be separate or integrated together. Alternatively, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be mutually replaced, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be mutually replaced, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be mutually replaced.

[0445] Alternatively, the communication device 8100 further includes one or more interface circuits 8104, which are connected with the memory 8102, and which can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read the instructions stored in the memory 8102 and send the instructions to the processor 8101.

[0446] The communication device 8100 described in the above embodiments can be a network device or a UE, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 can not be limited by FIG. 9A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: (1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a UE device, a smart UE device, a cellular phone, a wireless device, a handset, a mobile unit, a car-mounted device, a network device, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.

[0447] FIG. 9B is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 is a chip or a chip system, the structural schematic diagram of the chip 8200 shown in FIG. 9B can be referred to, but is not limited thereto.

[0448] The chip 8200 includes one or more processors 8201 for invoking instructions to cause the chip 8200 to perform any of the above information processing methods.

[0449] In some embodiments, the chip 8200 further includes one or more interface circuits 8202 connected with the memory 8203, which can be used to receive signals from the memory 8203 or other devices, and can be used to send signals to the memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201. Alternatively, the terms interface circuit, interface, transceiver pin, and transceiver can be replaced with each other.

[0450] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Alternatively, all or part of the memory 8203 can be outside the chip 8200.

[0451] The present disclosure also provides a storage medium having instructions stored thereon, which, when executed on the communication device 8100, cause the communication device 8100 to perform any of the above methods. Alternatively, the storage medium is an electronic storage medium. Alternatively, the storage medium is a computer-readable storage medium, but can also be a storage medium readable by other devices. Alternatively, the storage medium can be a non-transitory storage medium, but can also be a transitory storage medium.

[0452] The present disclosure also provides a program product which, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above information processing methods. Optionally, the program product is a computer program product.

[0453] The present disclosure also provides a computer program which, when executed on a computer, causes the computer to perform any of the above information processing methods.

[0454] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure embodiments following, in general, the principles of the present disclosure and including such features to the present known art or carrying out the present technology in other fields where the skilled artisan would recognize general applicability. The specification and examples are to be regarded as illustrative only, and the true scope and spirit of the present disclosure embodiments are indicated by the following claims.

[0455] It should be understood that the present disclosure is not limited to the precise structures herein described and illustrated in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is indicated by the appended claims, rather than by the description.

Claims

1. An information processing method, wherein, The method is performed by a user equipment (UE), and the method comprises: generating a second key according to a first key of a first node; generating a third key according to the second key; the third key is used to protect security of communication between the UE and a second node; wherein the first node is a security anchor function.

2. The method of claim 1, wherein, The generating the second key according to the first key of the first node comprises at least one of: generating the second key according to the first key and a type of the second node; generating the second key according to the first key and an instance identification (ID) of the second node.

3. The method of claim 2, wherein, The generating the second key according to the first key and the type of the second node comprises at least one of: generating the second key according to the first key, the type of the second node and a first count value; the first count value is a count of uplink messages sent by the UE to the second node; generating the second key according to the first key, the type of the second node and first time information; the first time information indicates a time period of generating the second key. The generating the second key according to the first key and the instance ID of the second node comprises:

4. The method of claim 2, wherein, The UE is preconfigured with the instance ID of the second node, and the second key is generated according to the first key and the instance ID of the second node. The generating the second key according to the first key and the instance ID of the second node comprises at least one of:

5. The method of claim 2 or 4, wherein, generating the second key according to the first key, the instance ID of the second node and the first count value; the first count value is a count of uplink messages sent by the UE to the second node; generating the second key according to the first key, the instance ID of the second node and first time information; the first time information indicates a time period of generating the second key. The method further comprises:

6. The method of claim 1, wherein, sending a first radio resource control (RRC) message to a third node, the first RRC message comprises a first message; the first message is protected by the third key; the second node is a receiving node of the first message. The first message comprises at least one of:

7. The method of claim 6, wherein, non-access stratum (NAS) signaling; an ID of the UE; a first algorithm identification, wherein the first algorithm identification is used to identify a security algorithm for protecting the first message. The first RRC message is protected by an access stratum (AS) security context of the UE.

8. The method of claim 7, wherein, The method further comprises:

9. The method of claim 7 or 8, wherein, receiving a second RRC message sent by the third node, the second RRC message comprises a second message; the second message is from the second node; the second message is protected by a fourth key; the fourth key is generated by a fifth key, and the fifth key is generated according to the first key. The second RRC message is protected by the AS security context of the UE.

10. The method of claim 9, wherein, The first RRC message further comprises at least one of:

11. The method according to any one of claims 7 to 10, wherein, type information of the second node; an instance ID of the second node; address information of the second node. The method is performed by a third node, and the method comprises:

12. An information processing method, wherein, ​ receiving a first message sent by a user equipment (UE), the first message being protected using a third key, the third key being generated according to a second key, the second key being generated based on a first key of a first node, a receiving node of the first message being a second node, the first node being a security anchor function; sending the first message to the second node.

13. The method of claim 12, wherein, Before sending the first message to the second node, the method further comprises: sending a third message to the first node, the third message being used to request the first node to generate a fifth key, the fifth key being used to generate a fourth key, the fourth key being used by the second node to verify security of the first message.

14. The method of claim 13, wherein, The method further comprises: receiving a fourth message sent by the first node, the fourth message being used to indicate whether the fifth key has been generated.

15. The method of claim 14, wherein, The sending the first message to the second node comprises: The fourth message indicates that the fifth key has been generated, and the first message is sent to the second node.

16. The method according to any one of claims 12 to 15, wherein, The sending the third message to the first node comprises: It is determined that the first node has not been requested by the UE to generate a fifth key for the second node, and the third message is sent to the first node.

17. The method of any one of claims 12 to 16, wherein, The receiving the first message sent by the UE comprises: Receiving a first radio resource control (RRC) message sent by the UE, the first RRC message comprising the first message.

18. The method of claim 17, wherein, The first RRC message is protected by an access stratum (AS) security context.

19. The method of claim 17 or 18, wherein, The first RRC message further comprises at least one of: type information of the second node; an instance ID of the second node; address information of the second node.

20. An information processing method, wherein, The method is performed by a first node, and the method comprises: generating a fifth key according to a first key of the first node; sending the fifth key to a second node, the fifth key being used by the second node to generate a fourth key, the fourth key being used to protect security of communication between the second node and a UE, the first node being a security anchor function.

21. The method of claim 20, wherein, The generating the fifth key according to the first key of the first node comprises: receiving a third message sent by a third node, and generating the fifth key according to the first key, the third message being used to request the first node to generate a fifth key for the first node.

22. The method of claim 21, wherein, The method further comprises: sending a fourth message to the third node, the fourth message being used to inform the third node whether the fifth key has been generated.

23. The method of claim 21 or 22, wherein, The third message comprises at least one of: type information of the second node; an instance ID of the second node; an identity of the UE.

24. The method of claim 20, wherein, The generating the fifth key according to the first key of the first node comprises: receiving a fifth message of the second node, and generating the fifth key according to the first key, the fifth message being used by the second node to request to generate the fifth key.

25. The method of claim 24, wherein, The fifth message comprises at least one of: type information of the second node; an instance ID of the second node; a second count value, the second count value being a count of uplink messages of the UE received by the second node; an identity of the UE.

26. The method of any one of claims 20 to 25, wherein, The fifth key is generated according to the first key and the type of the second node. The fifth key is generated according to the first key and the type of the second node. The fifth key is generated according to the first key and the instance ID of the second node.

27. The method of claim 26, wherein, The fifth key is generated according to the first key, the type of the second node, and a second count value; the second count value is the count of uplink messages of the UE received by the second node. The fifth key is generated according to the first key, the type of the second node, and second time information. The second time information indicates the time period of generating the fifth key. The fifth key is generated according to the first key and the instance ID of the second node.

28. The method of claim 26, wherein, The fifth message contains the instance ID of the second node, and the fifth key is generated according to the first key and the instance ID of the second node. The fifth key is generated according to the first key and the instance ID of the second node. The fifth key is generated according to the first key, the instance ID of the second node, and a second count value; the second count value is the count of uplink messages of the UE received by the second node.

29. The method of claim 26 or 28, wherein, The fifth key is generated according to the first key, the instance ID of the second node, and second time information. The second time information indicates the time period of generating the fifth key. The method is performed by the second node, and the method comprises: Receiving a fifth key sent by a first node; the fifth key is generated according to a first key of the first node; 30. An information processing method, wherein, Generating a fourth key according to the fifth key; the fourth key is used to protect the security of communication between the second node and a user equipment (UE); the first node is a security anchor function. The method further comprises: Receiving a first message sent by a third node, and sending a fifth message to the first node; the fifth message is used to request the fifth key; the first message is protected by a third key; the third key is generated according to a second key; the second key is generated according to a first key of the first node.

31. The method of claim 30, wherein, The fifth message comprises at least one of: Type information of the second node; 32. The method of claim 31, wherein, An instance ID of the second node; A second count value; the second count value is the count of uplink messages of the UE received by the second node; An identifier of the UE. The method further comprises: Sending a second message to the third node; the second message is protected by the fourth key.

33. The method of claim 31 or 32, wherein, The UE comprises: A processing module configured to generate a second key according to a first key of a first node; and generate a third key according to the second key; the third key is used to protect the security of communication between the UE and a second node; the first node is a security anchor function.

34. A user equipment (UE), wherein, The third node comprises a receiving module configured to generate a second key according to a first key of a first node; ​ 35. A third node, wherein, ​ The sending module is configured to generate a third key according to the second key; the third key is used to protect the security of communication between a user equipment (UE) and the second node; and the first node is a security anchor function.

36. A first node, wherein, The first node comprises: The processing module is configured to generate a fifth key according to the first key of the first node; The sending module is configured to send the fifth key to the second node, and the fifth key is used by the second node to generate a fourth key; the fourth key is used to protect the security of communication between the second node and the UE; and the first node is a security anchor function.

37. A second node, wherein, The second node comprises: The receiving module is configured to receive the fifth key sent by the first node; the fifth key is generated according to the first key of the first node; The processing module is configured to generate a fourth key according to the fifth key; the fourth key is used to protect the security of communication between the second node and the UE; and the first node is a security anchor function.

38. A communication system, wherein, The communication system comprises a user equipment (UE), a first node, a second node and a third node; the UE is used to execute the method in any one of claims 1 to 11; The third node is used to execute the method in any one of claims 12 to 19; The first node is used to execute the method in any one of claims 20 to 29; The second node is used to execute the method in any one of claims 30 to 33.

39. A communications device, comprising: The communication device comprises: One or more processors; The processor is used to call instructions to enable the communication device to execute the information processing method in any one of claims 1 to 11, 12 to 19, 20 to 29 or 30 to 33.

40. A storage medium, wherein, The storage medium stores instructions, and when the instructions are executed on the communication device, the communication device executes the information processing method in any one of claims 1 to 11, 12 to 19, 20 to 29 or 30 to 33.

41. A program product, wherein, The program product comprises a computer program, and when the computer program is executed by the communication device, the communication device can implement the information processing method in any one of claims 1 to 11, 12 to 19, 20 to 29 or 30 to 33.