Communication method, network element, terminal, device, and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING XIAOMI MOBILE SOFTWARE CO LTD
- Filing Date
- 2024-09-27
- Publication Date
- 2026-05-29
AI Technical Summary
In the communication architecture, information exchange between the terminal and different network functions needs to be relayed through AMF, which leads to complexity and potential delays, and lacks the security guarantee of direct communication.
The introduction of a service-based interface (SBI) allows terminals to interact directly with network functions and independently maintain the non-access stratum (NAS) context through the first network element, requesting a re-authentication process to ensure security.
Direct information exchange and re-authentication processes enhance communication security and efficiency, reduce dependencies between network functions and the number of processing points, and ensure the security of NAS communication.
Smart Images

Figure CN122122945A_ABST
Abstract
Description
Communication method, network element, terminal, device and storage medium TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and particularly relates to a communication method, a network element, a terminal, a device and a storage medium. BACKGROUND
[0002] In a communication architecture, different network functions (NFs) have strong dependency relationships, for example, in a 5G core (5GC), information between a terminal or user equipment (UE) and different NFs or nodes needs to be relayed through an AMF. To simplify this transmission mode, a service-based interface (SBI) is introduced, which allows direct information interaction between the terminal and the NF.
[0003] SUMMARY
[0004] In a scenario where information interaction can be directly performed between a terminal and an NF, the terminal and different NFs can need to support non-access stratum (NAS) communication, and the security of the communication needs to be ensured.
[0005] Embodiments of the present disclosure provide a communication method, a network element, a terminal, a device and a storage medium.
[0006] In a first aspect, embodiments of the present disclosure provide a communication method, and the method comprises:
[0007] A first network element sends first information, the first information being used to request triggering of a re-authentication process, wherein the first network element independently maintains a non-access stratum (NAS) context for communication with a terminal.
[0008] In a second aspect, embodiments of the present disclosure provide a communication method, and the method comprises:
[0009] A second network element receives first information sent by a first network element, the first information being used to request triggering of a re-authentication process, wherein the first network element independently maintains a NAS context for communication with a terminal.
[0010] In a third aspect, embodiments of the present disclosure provide a communication method, and the method comprises:
[0011] A third network element receives first information or fourth information, the first information being used to request triggering of a re-authentication process, and the fourth information being used to request triggering of a re-authentication process; and the third network element is configured to determine whether to perform the re-authentication process.
[0012] In a fourth aspect, an embodiment of the present disclosure provides a communication device, comprising:
[0013] The communication device is configured to perform the method of the first aspect, or the method of the second aspect, or the method of the third aspect.
[0014] In a fifth aspect, an embodiment of the present disclosure provides a communication system, comprising a first network element, a second network element and a third network element, wherein the first network element is configured to perform the method of the first aspect, the second network element is configured to perform the method of the second aspect, and the third network element is configured to perform the method of the third aspect.
[0015] In a sixth aspect, an embodiment of the present disclosure provides a storage medium, which stores instructions, when the instructions are executed on a communication device, causing the communication device to perform the method of the first aspect, or the method of the second aspect, or the method of the third aspect.
[0016] In a seventh aspect, an embodiment of the present disclosure provides a program product, comprising instructions, when the program product is executed on a communication device, causing the communication device to perform the method of the first aspect, or the method of the second aspect, or the method of the third aspect.
[0017] In a seventh aspect, an embodiment of the present disclosure provides a program product, comprising instructions, when the program product is executed on a communication device, causing the communication device to perform the method of the first aspect, or the method of the second aspect, or the method of the third aspect.
[0018] In an embodiment of the present disclosure, the first network element can request triggering of the re-authentication procedure, thereby ensuring security in NAS communication. BRIEF DESCRIPTION OF DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.
[0020] FIG. 1a is an exemplary schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure;
[0021] FIG. 1b is a schematic diagram of a communication system in a multi-NAS architecture scenario according to an embodiment of the present disclosure;
[0022] FIG. 1c is a schematic diagram of a multi-NAS architecture scenario according to an embodiment of the present disclosure;
[0023] FIG. 1d is a protocol stack schematic diagram of a multi-NAS architecture scenario according to an embodiment of the present disclosure;
[0024] FIG. 1e is a schematic diagram of an encryption algorithm according to an embodiment of the present disclosure;
[0025] FIG. 1f is a schematic diagram of an integrity algorithm according to an embodiment of the present disclosure;
[0026] FIG. 2a to FIG. 2b are an exemplary interaction diagram of a method according to an embodiment of the present disclosure;
[0027] FIG. 3a to FIG. 3c are an exemplary flow chart of a method according to an embodiment of the present disclosure;
[0028] FIG. 4a to FIG. 4c are an exemplary flow chart of a method according to an embodiment of the present disclosure;
[0029] FIG. 5a to FIG. 5c are an exemplary flow chart of a method according to an embodiment of the present disclosure;
[0030] FIG. 6a to FIG. 6b are an exemplary flow chart of a method according to an embodiment of the present disclosure;
[0031] FIG. 7a to FIG. 7d are an exemplary interaction diagram of a method according to an embodiment of the present disclosure;
[0032] FIG. 8a is a structural diagram of a communication device according to an embodiment of the present disclosure;
[0033] FIG. 8b is a structural diagram of a communication device according to an embodiment of the present disclosure;
[0034] FIG. 8c is a structural diagram of a communication device according to an embodiment of the present disclosure;
[0035] FIG. 8d is a structural diagram of a communication device according to an embodiment of the present disclosure;
[0036] FIG. 9a is a schematic diagram of a communication device according to an embodiment of the present disclosure;
[0037] FIG. 9b is a schematic diagram of a communication device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0038] Embodiments of the present disclosure provide a communication method, a network element, a terminal, a device and a storage medium.
[0039] In a first aspect, embodiments of the present disclosure provide a communication method, and the method comprises:
[0040] The first network element sends first information, and the first information is used to request triggering a re-authentication process, wherein the first network element independently maintains a non-access stratum (NAS) context for communication with a terminal.
[0041] In the above embodiments, the re-authentication process can be requested to be triggered by the first network element, thereby ensuring the security in the NAS communication.
[0042] In combination with the embodiments of the first aspect, in some embodiments, the first network element sending the first information comprises:
[0043] The first network element is located in a home network, and the first network element sends the first information to a second network element, where the second network element is configured to determine whether to trigger a re-authentication process.
[0044] In the above embodiment, when the first network element is located in the home network, the third network element can be indirectly requested to perform the re-authentication process through the second network element in the home network, thereby ensuring the security of the NAS communication between the first network element and the terminal in the home network.
[0045] With reference to the embodiments of the first aspect, in some embodiments, the first network element sending the first information comprises:
[0046] The first network element is located in a serving network, and the first network element sends the first information to a third network element, where the third network element is configured to determine whether to perform a re-authentication process.
[0047] In the above embodiment, when the first network element is located in the serving network, the third network element can be directly requested to perform the re-authentication process, thereby ensuring the security of the NAS communication between the first network element and the terminal in the serving network.
[0048] With reference to the embodiments of the first aspect, in some embodiments, the method further comprises:
[0049] The first network element receives second information sent by the second network element or the third network element, where the second information is used to respond to the first information.
[0050] In the above embodiment, after the first network element directly or indirectly requests to trigger the re-authentication process, the corresponding response can be received, thereby knowing whether the re-authentication process is requested or allowed, and updating the key in time.
[0051] With reference to the embodiments of the first aspect, in some embodiments, the second information is used to indicate confirmation of triggering the re-authentication process or confirmation of performing the re-authentication process, where the second network element determines to trigger the re-authentication process or the third network element determines to perform the re-authentication process.
[0052] In the above embodiment, the second information can be used to allow or confirm the request of the first network element, to inform the first network element that the requested re-authentication process is about to be performed, facilitate updating the key in time, and ensure the security of the NAS communication.
[0053] With reference to the embodiments of the first aspect, in some embodiments, the second information comprises a reason for being unable to trigger the re-authentication process or a reason for being unable to perform the re-authentication process, where the second network element determines to be unable to trigger the re-authentication process or the third network element determines to be unable to perform the re-authentication process.
[0054] In the above embodiments, the second information can be used to reject the request of the first network element and carry a related cause, so that the first network element can learn that the current re-authentication is not allowed in time and can re-initiate or perform other security operations at a suitable time.
[0055] In combination with the embodiments of the first aspect, in some embodiments, the method further includes:
[0056] The first network element receives third information sent by the third network element, and the third information includes the first key after the update.
[0057] In the above embodiments, in the case where the request triggering the re-authentication is allowed, the first network element can obtain the first key after the update from the third network element, so as to protect the security of the NAS communication based on the first key.
[0058] In combination with the embodiments of the first aspect, in some embodiments, the method further includes:
[0059] The first network element generates a second key according to the third information, and the second key is used to protect the NAS signaling between the first network element and the terminal.
[0060] In the above embodiments, after receiving the first key, the first network element can generate the second key used to protect the NAS signaling, so as to refresh the key in time and improve the security of the NAS communication.
[0061] In combination with the embodiments of the first aspect, in some embodiments, the method further includes:
[0062] Initiating a Safe Mode Command (SMC) procedure according to the second key;
[0063] After the SMC procedure is successfully completed, setting the NAS count to an initial value.
[0064] In the above embodiments, when the SMC is supported, the first network element can initiate the SMC procedure to activate the security of the new NAS connection with the terminal, and can set the NAS count to the initial value on the premise of ensuring the security.
[0065] In combination with the embodiments of the first aspect, in some embodiments, the method further includes:
[0066] After the second key is generated, setting the NAS count to an initial value.
[0067] In the above embodiments, if the SMC is not supported, the first network element can ensure the security of the NAS communication based on the new NAS connection with the terminal, and can set the NAS count to the initial value on the premise of ensuring the security.
[0068] In some embodiments of the first aspect, the method further comprises:
[0069] The first network element re-establishes the NAS connection with the terminal.
[0070] In the above embodiments, the first network element can establish a new NAS connection with the terminal based on the updated key, thereby ensuring the security of the NAS communication.
[0071] In some embodiments of the first aspect, the first network element receives third information sent by a third network element, the third information comprising:
[0072] The third network element maintains network element information of a plurality of first network elements, and the plurality of first network elements receive the third information sent by the third network element.
[0073] In the above embodiments, when the home network includes a plurality of first network elements, the third network element can respectively issue the updated key to different first network elements to ensure the security of the NAS communication of different first network elements.
[0074] In some embodiments of the first aspect, the first information is sent when the non-access stratum (NAS) count stored in the first network element is about to rotate to an initial value.
[0075] In the above embodiments, the first network element can request triggering of the re-authentication process when the conditions of the embodiments are met, thereby requesting re-authentication in a timely manner in a scenario where the security may have been compromised, and ensuring the security of the communication.
[0076] In some embodiments of the first aspect, the first information comprises at least one of:
[0077] A terminal identifier;
[0078] Network element information of the first network element;
[0079] Indication information.
[0080] In the above embodiments, the first network element can carry any of the above information when requesting triggering of the re-authentication process, thereby facilitating the second network element or the third network element to learn the corresponding NAS information.
[0081] In some embodiments of the first aspect, the network element information comprises at least one of:
[0082] An identifier of the first network element;
[0083] An IP address of the first network element.
[0084] In the above embodiments, different network element information can be used to indicate the corresponding first network element.
[0085] In a second aspect, the embodiments of the present disclosure provide a communication method, and the method comprises the following steps.
[0086] The second network element receives the first information sent by the first network element, and the first information is used to request triggering the re-authentication process, wherein the first network element independently maintains the NAS context in communication with the terminal.
[0087] In the above embodiment, the second network element can directly receive the request of the first network element, which is beneficial to timely triggering the re-authentication process, so as to ensure the security of the NAS communication.
[0088] In combination with the embodiments of the second aspect, in some embodiments, the method further comprises:
[0089] The second network element determines to trigger the re-authentication process according to the first information and the local policy.
[0090] The second network element sends second information to the first network element, and the second information is used to respond to the first information.
[0091] In combination with the embodiments of the second aspect, in some embodiments, the method further comprises:
[0092] The second network element sends fourth information to the third network element, and the fourth information is used to request triggering the re-authentication process, and the third network element is used to determine whether to perform the re-authentication process.
[0093] In combination with the embodiments of the second aspect, in some embodiments, the method further comprises:
[0094] The second network element receives fifth information sent by the third network element, and the fifth information is used to respond to the fourth information.
[0095] In combination with the embodiments of the second aspect, in some embodiments, the fourth information comprises at least one of the following:
[0096] The terminal identifier;
[0097] The network element information of the first network element.
[0098] In combination with the embodiments of the second aspect, in some embodiments, the first information comprises at least one of the following:
[0099] The terminal identifier;
[0100] The network element information of the first network element;
[0101] The indication information.
[0102] In combination with the embodiments of the second aspect, in some embodiments, the network element information comprises at least one of the following:
[0103] The identifier of the first network element;
[0104] The IP address of the first network element.
[0105] In a third aspect, the embodiments of the present disclosure provide a communication method, and the method comprises the following steps.
[0106] The third network element receives the first information or the fourth information, the first information is used for requesting triggering the re-authentication process, and the fourth information is used for requesting triggering the re-authentication process; and the third network element is configured to determine whether to perform the re-authentication process.
[0107] In the above embodiments, the third network element can receive the request for triggering the re-authentication process, and can make a decision based on the request information, so as to facilitate the re-authentication process at a suitable time and in a timely manner, and ensure the communication security.
[0108] With reference to the embodiments of the third aspect, in some embodiments, the third network element receives the first information or the fourth information, the first information and the fourth information are used for requesting triggering the re-authentication process; and the third network element is configured to determine whether to perform the re-authentication process.
[0109] With reference to the embodiments of the third aspect, in some embodiments, the third network element receives the first information, and the first information comprises the following information.
[0110] The third network element receives the first information sent by the first network element, and the first network element is a network function (NF) network element.
[0111] With reference to the embodiments of the third aspect, in some embodiments, the third network element receives the fourth information, and the fourth information comprises the following information.
[0112] The third network element receives the fourth information sent by the second network element, wherein the second network element sends the fourth information after receiving the first information, and the second network element is configured to determine whether to trigger the re-authentication process.
[0113] With reference to the embodiments of the third aspect, in some embodiments, in the NAS context of the terminal stored by the third network element, network element information of one or more first network elements connected with the terminal is maintained.
[0114] With reference to the embodiments of the third aspect, in some embodiments, the method further comprises the following steps.
[0115] The third network element determines whether to perform the re-authentication process according to a local policy and a terminal state.
[0116] With reference to the embodiments of the third aspect, in some embodiments, the method further comprises the following steps.
[0117] The third network element sends second information to the first network element, the second information is used for responding to the first information; or
[0118] The third network element sends fifth information to the second network element, and the fifth information is used for responding to the fourth information.
[0119] In some embodiments of the third aspect, the second information or the fourth information comprises a reason that the re-authentication procedure cannot be performed, and the third network element determines to perform the re-authentication procedure based on the reason.
[0120] In some embodiments of the third aspect, the second information or the fourth information is used to indicate to confirm to perform the re-authentication procedure, and the third network element determines to perform the re-authentication procedure.
[0121] In some embodiments of the third aspect, the method further comprises:
[0122] determining to perform the re-authentication procedure, and the third network element stores the network element information of the first network element.
[0123] In some embodiments of the third aspect, the method further comprises:
[0124] generating the first key after the update according to the network element information;
[0125] sending the third information to the first network element, and the third information comprises the first key after the update.
[0126] In some embodiments of the third aspect, the sending the third information to the first network element comprises:
[0127] The third network element maintains the network element information of a plurality of first network elements, and sends the third information to the plurality of first network elements; wherein the plurality of first network elements comprises the first network element triggering the re-authentication and other first network elements.
[0128] In some embodiments of the third aspect, the first information comprises at least one of:
[0129] a terminal identifier;
[0130] network element information of the first network element;
[0131] indication information.
[0132] In some embodiments of the third aspect, the network element information comprises at least one of:
[0133] an identifier of the first network element;
[0134] an IP address of the first network element.
[0135] In a fourth aspect, the embodiments of the present disclosure provide a communication method, and the method comprises:
[0136] After the re-authentication process in which the third network element participates is performed, the terminal re-establishes the NAS connection with the first network element; wherein the first network element triggers the re-authentication process by sending the first information, and the first network element independently maintains the NAS context for communication with the terminal.
[0137] In the above embodiment, after the first network element requests the re-authentication and the re-authentication process is performed, the terminal can re-establish the NAS connection with the first network element based on the updated key, thereby ensuring the security of the communication.
[0138] In combination with the embodiment of the fourth aspect, in some embodiments, the method further includes:
[0139] After the re-authentication process in which the third network element participates is completed, the terminal removes the stored NAS context associated with the first network element.
[0140] In combination with the embodiment of the fourth aspect, in some embodiments, the method further includes:
[0141] After the SMC process with the first network element is completed, the terminal re-generates the NAS context associated with the first network element and sets the NAS count to an initial value.
[0142] In combination with the embodiment of the fourth aspect, in some embodiments, the method further includes:
[0143] In the process of establishing a new NAS connection with the first network element, the terminal generates a second key and a new NAS context, and the second key is used to protect the NAS signaling between the terminal and the first network element.
[0144] After the second key is generated, the NAS count is set to an initial value.
[0145] In the fifth aspect, the embodiments of the present disclosure provide a communication method, wherein the method includes:
[0146] The first network element sends first information to the second network element or the third network element, the first information is used to request triggering a re-authentication process, the first network element independently maintains a NAS context for communication with the terminal, the second network element is used to determine whether the re-authentication process can be re-triggered, and the third network element is used to determine whether the re-authentication process is performed.
[0147] In the sixth aspect, the embodiments of the present disclosure provide a first network element, which includes:
[0148] The transceiver module is configured to send first information, and the first information is used to request triggering a re-authentication process, wherein the first network element independently maintains a NAS context for communication with the terminal.
[0149] In the seventh aspect, the embodiments of the present disclosure provide a second network element, which includes:
[0150] a transceiver configured to receive first information sent by the first network element, the first information being used to request triggering of the re-authentication procedure, wherein the first network element independently maintains a NAS context for communication with the terminal.
[0151] In an eighth aspect, an embodiment of the present disclosure provides a third network element, comprising:
[0152] a transceiver configured to receive the first information or fourth information, the first information being used to request triggering of the re-authentication procedure, and the fourth information being used to request triggering of the re-authentication procedure; and
[0153] In a ninth aspect, an embodiment of the present disclosure provides a terminal, comprising:
[0154] a processing module configured to re-establish a NAS connection between the terminal and the first network element after the re-authentication procedure in which the third network element participates is completed, wherein the first network element triggers the re-authentication procedure by sending the first information, and wherein the first network element independently maintains a NAS context for communication with the terminal.
[0155] In a tenth aspect, an embodiment of the present disclosure provides a core network device, comprising:
[0156] a transceiver configured to send or receive the first information, or configured to receive the fourth information, the first information being used to request triggering of the re-authentication procedure, and the fourth information being used to request triggering of the re-authentication procedure; and
[0157] In an eleventh aspect, an embodiment of the present disclosure provides a first network element, comprising:
[0158] one or more processors;
[0159] The first network element is configured to perform the method in the first aspect.
[0160] In a twelfth aspect, an embodiment of the present disclosure provides a second network element, comprising:
[0161] one or more processors,
[0162] The second network element is configured to perform the method in the second aspect.
[0163] In a thirteenth aspect, an embodiment of the present disclosure provides a third network element, comprising:
[0164] one or more processors,
[0165] The third network element is configured to perform the method in the third aspect.
[0166] In a fourteenth aspect, an embodiment of the present disclosure provides a terminal, comprising:
[0167] one or more processors,
[0168] The terminal is configured to perform the method of the fourth aspect.
[0169] In a fifteenth aspect, an embodiment of the present disclosure provides a communication device, wherein the communication device is configured to perform the method of the first aspect, or the method of the second aspect, or the method of the third aspect, or the method of the fourth aspect.
[0170] The communication device can be a first network element, a second network element, a third network element, a terminal, or a core network device.
[0171] In a sixteenth aspect, an embodiment of the present disclosure provides a communication system, comprising a first network element, a second network element, a third network element, and a terminal, wherein the first network element is configured to perform the method of the first aspect, the second network element is configured to perform the method of the second aspect, the third network element is configured to perform the method of the third aspect, and the terminal is configured to perform the method of the fourth aspect.
[0172] In a seventeenth aspect, an embodiment of the present disclosure provides a storage medium, which stores instructions, when the instructions are executed on a communication device, causing the communication device to perform the method of the first aspect, or the method of the second aspect, or the method of the third aspect, or the method of the fourth aspect.
[0173] In an eighteenth aspect, an embodiment of the present disclosure provides a program product, wherein,
[0174] When the program product is executed by a communication device, causing the communication device to perform the method of the first aspect, or the method of the second aspect, or the method of the third aspect, or the method of the fourth aspect.
[0175] In a nineteenth aspect, an embodiment of the present disclosure provides a computer program, when executed on a computer, causing the computer to perform the method described in the optional implementation manner of the first aspect, the second aspect, or the third aspect.
[0176] In a twentieth aspect, an embodiment of the present disclosure provides a chip or a chip system. The chip or the chip system comprises processing circuitry configured to perform the method described in the first aspect, the second aspect, or the third aspect.
[0177] It can be understood that the above network element, terminal, device, communication system, storage medium, program product, computer program, chip, or chip system are all configured to perform the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved thereby can refer to the beneficial effects in the corresponding method, which will not be described here again.
[0178] This disclosure provides embodiments of a communication method, a network element, a terminal, a device, and a storage medium. In some embodiments, terms such as communication method and information processing method can be used interchangeably, as can terms such as communication device and information processing device, and terms such as information processing system and communication system. A communication device can perform the functions of one or more devices.
[0179] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0180] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0181] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0182] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0183] In the embodiments of this disclosure, "multiple" refers to two or more.
[0184] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0185] In some embodiments, the description of "at least one of A, B", "A and / or B", "in a case A, in another case B", "in response to a case A, in response to a case B", and the like, can include the following technical solutions according to the case: in some embodiments, A (A is executed regardless of B); in some embodiments, B (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selected from A and B); in some embodiments, A and B (A and B are executed). When there are more branches such as A, B, C, and the like, the above is similar.
[0186] In some embodiments, the description of "A or B" and the like can include the following technical solutions according to the case: in some embodiments, A (A is executed regardless of B); in some embodiments, B (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selected from A and B). When there are more branches such as A, B, C, and the like, the above is similar.
[0187] In some embodiments, the prefix words "first", "second", and the like in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute a limitation on the position, order, priority, quantity, or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute an additional limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different; for another example, the description object is "information", and "first information" and "second information" can be the same information or different information, and the content thereof can be the same or different.
[0188] In some embodiments, "including A", "containing A", "for indicating A", "carrying A", can be interpreted as directly carrying A, or indirectly indicating A.
[0189] In some embodiments, the terms "time / frequency", "time / frequency domain", and the like refer to the time domain and / or the frequency domain.
[0190] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "if", "if" and the like can be replaced with each other.
[0191] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.
[0192] In some embodiments, the apparatuses and devices can be interpreted as physical or virtual, and their names are not limited to the names described in the embodiments, and in some cases can also be understood as "equipment", "Device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like.
[0193] In some embodiments, "network" can be interpreted as an apparatus included in the network, such as an access network device, a core network device, and the like.
[0194] In some embodiments, an “access network device (AN Device)” can also be referred to as a “radio access network device (RAN Device),” a “base station (BS),” a “radio base station,” a “fixed station,” and in some embodiments can also be understood as a “node,” an “access point,” a “transmission point (TP),” a “reception point (RP),” a “transmission / reception point (TRP),” a “panel,” an “antenna panel,” an “antenna array,” a “cell,” a “macro cell,” a “small cell,” a “femto cell,” a “pico cell,” a “sector,” a “cell group,” a “serving cell,” a “carrier,” a “component carrier,” a “bandwidth part (BWP),” and the like.
[0195] In some embodiments, a "terminal" or "terminal device" can be referred to as a "user equipment" (UE), a "user terminal," a "mobile station" (MS), a "mobile terminal" (MT), a subscriber station, a mobile unit, a subscriber unit, a wireless unit, a remote unit, a mobile device, a wireless device, a wireless communication device, a remote device, a mobile subscriber station, an access terminal, a mobile terminal, a wireless terminal, a remote terminal, a handset, a user agent, a mobile client, a client, and the like.
[0196] In some embodiments, data, information, and the like can be acquired in compliance with laws and regulations of a country where a location is situated.
[0197] In some embodiments, data, information, and the like can be acquired after consent of a user is obtained.
[0198] In addition, each element, each row, or each column in a table of embodiments of the present disclosure can be implemented as an independent embodiment, and a combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0199] FIG. 1a is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0200] As shown in FIG. 1a, a communication system 100 at least includes a terminal 101, a core network device 102, and an access network device 103.
[0201] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a tablet (Pad), a wireless transceiver-equipped computer, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, a wireless terminal device in a smart home, and the like, but is not limited thereto.
[0202] In some embodiments, the core network device 102 can be one device including the first network element 1021, the second network element 1022, and the third network element 1023, or can be multiple devices or device groups including all or part of the first network element 1021, the second network element 1022, and the third network element 1023. The network element can be virtual or physical. The core network includes at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), a 6G Core Network (6GCN), and a Next Generation Core (NGC), for example.
[0203] In some embodiments, the first network element 1021 is a Network Function (NF) network element, for example, and refers to any network element in the core network device or any network element other than the second network element 1022 and the third network element 1023.
[0204] In some embodiments, the first network element 1021 can implement a corresponding function when it corresponds to different network functions.
[0205] In some embodiments, the second network element 1022 is a Unified Data Management (UDM) function, for example.
[0206] In some embodiments, the second network element 1022 is configured to store user data or to be responsible for unified processing of data, including user identification, user subscription data, and authentication data.
[0207] In some embodiments, the third network element 1023 is, for example, an Access and Mobility Management Function (AMF).
[0208] In some embodiments, the third network element 1023 is used for mobility management, and can implement registration management, connection management, mobility management, and user accessibility management of a user, participate in management of an authentication and authorization related control plane, and the like.
[0209] In some embodiments, the third network element 1023 is, for example, a Security Anchor Function (SEAF).
[0210] In some embodiments, the third network element 1023 is used to implement a function of a security anchor point.
[0211] In some embodiments, the core network device 102 can further include other functional network elements, or the first network element 1021 can be replaced with a network element other than the AMF or the UDM.
[0212] In some embodiments, the access network device 103, for example, is a node or device that accesses the terminal 101 to a wireless network, and the access network device 103 can be based on a radio access network (RAN) or a next generation radio access network (NG-RAN). The access network device 103 can include at least one of an evolved node B (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation node B (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a wireless fidelity (WiFi) system, but is not limited thereto.
[0213] In some embodiments, the technical solutions of the present disclosure can be applicable to an Open RAN architecture, at this time, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be realized through software or programs.
[0214] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit (control unit). The CU-DU structure can split the protocol layers of the access network device, and part of the functions of the protocol layers are controlled by the CU, and the remaining part or all of the functions of the protocol layers are distributed in the DU and controlled by the CU, but are not limited thereto.
[0215] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art can know that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.
[0216] The embodiments of the present disclosure described below can be applied to the communication system 100 shown in FIG. 1a or part of the subjects, but are not limited thereto.
[0217] The subjects shown in FIG. 1a are examples. The communication system can include all or part of the subjects in FIG. 1a, or other subjects other than FIG. 1a. The number and form of each subject is arbitrary. The connection relationship between the subjects is an example. The subjects can not be connected or can be connected. The connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.
[0218] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication processing methods, next-generation system expanded based on them, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, and the like).
[0219] In embodiments of the present disclosure, with the development of communication architecture, for example, the new 6G architecture (6G Architecture) supports streamlined network functions (NFs) in order to be more efficient in terms of capacity, coverage, signaling overhead, scalability, and energy consumption, etc. The dependency between different NFs can cause unnecessary complexity and even delay. By redesigning network functions, the dependency between NFs and the number of processing points can be reduced. For example, in the 6G architecture, potential bottlenecks can be eliminated by increasing the possibility of direct signal transmission between NFs.
[0220] In some possible ways, many services need to transfer information from one NG-RAN node to another NG-RAN node through the 5GC, and the information generally needs to be relayed through the AMF in the 5GC, such as the information between the terminal and different NFs or nodes needs to be relayed through the AMF. Among them, the NG-RAN can be regarded as a NF. By introducing SBI, as shown in the Nran path in FIG. 1b, it can allow direct information exchange between NFs, such as between different NG-RANs, without going through the AMF.
[0221] Among them, FIG. 1b exemplarily shows that the communication system can further include various nodes or network elements, such as a location management function (Location Management Function, LMF), a network repository function (Network Repository Function, NRF), a policy and charging function (Policy and Charging Function, PCF), a UE radio capability management function (Capability Management Function, UCMF), a session management function (Session Management Function, SMF), a network data analytics function (Network Data Analytics Function, NWDAF), a network exposure function (Network Exposure Function, NEF), a user plane function (User Plane Function, UPF), and a data network (Data Network, DN), wherein N1, N2, Nran, etc. represent the interface or interface path between the corresponding two nodes.
[0222] In embodiments of the present disclosure, in the service-based scenario of RAN evolution, the RAN node can be a consumer or producer of other network function services in addition to the AMF.
[0223] In some communication systems, such as 5G systems, NAS signaling (transmitted transparently through RAN nodes) is only supported between a UE and an AMF in the core network. When the RAN can evolve to communicate directly with other NFs without going through the AMF, such as in scenarios where information can be exchanged directly between NFs, NAS signaling will need to be supported between the terminal and other NFs in addition to the AMF. As shown in the multi-NAS architecture of FIG. 1c, the RAN node can communicate directly with the NFs through the SBI, and the terminal can communicate directly with multiple NFs using NAS signaling, such as between the terminal and the following nodes or functions: NFa, NFb, NFc, or NFx. The protocol stack for NAS between different functions can be seen in FIG. 1d.
[0224] In the embodiments of the present disclosure, in NAS communication, the NAS COUNT is one of the inputs of the integrity algorithm and the ciphering algorithm for each NAS signaling. The NAS COUNT can include the values of the following two parts: an 8-bit NAS SQN, corresponding to the lowest 8 bits of the NAS COUNT, which needs to be included in the NAS message; and a 16-bit NAS OVERFLOW, corresponding to the highest 16 bits of the NAS COUNT, which needs to be kept synchronized between the terminal and the AMF.
[0225] As shown in FIG. 1e, for the ciphering algorithm of the NAS signaling, at the sender of the NAS signaling, the key, the COUNT, the bearer, the direction, and the length, etc. can be taken as inputs, the KeyStreamBlock is obtained based on the ciphering algorithm, the plaintext is encrypted using the KeyStreamBlock to obtain the ciphertext, and the ciphertext is sent to the receiver of the NAS signaling. The receiver obtains the KeyStreamBlock in the same way, and decrypts the ciphertext using the KeyStreamBlock.
[0226] As shown in FIG. 1f, for the integrity algorithm of the NAS signaling, at the sender of the NAS signaling, the key, the COUNT, and the message, etc. can be taken as inputs, the MAC-I / NAS-MAC is obtained based on the integrity algorithm, and is sent to the receiver of the NAS signaling. The receiver obtains the expected value (XMAC-I / XNAS-MAC) based on the same operation, compares the expected value with the encrypted information value, and determines the integrity.
[0227] wherein the NAS count includes an Uplink (UL) NAS count and a Downlink (DL) NAS count, and the update of the corresponding NAS count is involved in the NAS communication between the two parties when there is an UL message or a DL message. For example, in the NAS communication between the terminal and the NF, for an UL message, the terminal increments the UL NAS count by 1, and the NF updates the UL NAS count accordingly based on the received UL message. For a DL message, the NF increments the DL NAS count by 1, and the terminal updates the DL NAS count accordingly.
[0228] In the scenario of multi-NAS architecture, since there can be multiple NFs that can have NAS communication with the terminal, when the NAS count corresponding to one of the NFs is about to wrap around, the use of the original key to protect the NAS signaling by other NFs can break the NAS security mechanism. It is necessary to provide a way to trigger the re-authentication procedure, or in other words, to provide a way to trigger the re-authentication procedure to refresh the NF key and the NAS count.
[0229] FIG. 2a is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2a, the embodiment of the present disclosure relates to a communication method, and the method comprises:
[0230] In step S2101, the first network element 1021 sends first information to the second network element 1022.
[0231] In some embodiments, the first network element 1021 can include one or more NFs, such as NF1 and NF2. Wherein the NF can be a core network element or node other than AMF or UDM, or a RAN node.
[0232] Optionally, in the embodiment, when the first network element 1021 includes multiple NFs, the multiple NFs can be located in a home network. For example, the home network is a Home Public Land Mobile Network (HPLMN), or a local network, which refers to the home PLMN of the terminal.
[0233] Optionally, in the embodiment, it is assumed that the first network element 1021 independently maintains the NAS context (UE NAS context) for communication with the terminal, for example, multiple NFs such as NF1 and NF2 maintain the NAS context respectively.
[0234] In some embodiments, the first information is used to request triggering of the re-authentication procedure (re-authentication procedure or primary authentication).
[0235] In some embodiments, the first information can be a request information, such as a first request information Nudm_UECM_AuthTrigger Request.
[0236] In some embodiments, the first information comprises at least one of:
[0237] a terminal identifier;
[0238] network element information of the first network element;
[0239] indication information.
[0240] For example, the first information comprises the terminal identifier to indicate the corresponding terminal. The terminal identifier can be a Subscription Permanent Identifier (SUPI) or a Generic Public Subscription Identifier (GPSI) of the terminal. The terminal identifier can be a terminal identifier of a target UE of the NAS communication.
[0241] For example, the first information comprises the network element information to indicate the first network element.
[0242] For example, the first information comprises the indication information, which can be used to indicate the reason why the first network element 1021 initiates the re-authentication request.
[0243] For another example, the first information comprises the terminal identifier and the network element information. Alternatively, the first information comprises the terminal identifier and the indication information. Alternatively, the first information comprises the network element information and the indication information. Alternatively, the first information comprises the terminal identifier, the network element information and the indication information.
[0244] In some examples, the terminal identifier is carried in the first information, and the network element information and the indication information are optional.
[0245] Optionally, the network element information comprises at least one of:
[0246] an NF instance ID of the first network element;
[0247] an IP address of the first network element.
[0248] In some embodiments, the first network element 1021 can send the first information when a NAS counter stored in the first network element 1021 is to be rolled over to an initial value, such as performing step S2101. The NAS counter can have a value in a range. As described in the foregoing embodiments, the NAS counter will be incremented in the communication, and can be rolled over to the initial value after being incremented to the maximum value of the range. The initial value is, for example, 0.
[0249] In some embodiments, the second network element 1022 receives the first information.
[0250] In some embodiments, the second network element 1022 can be a UDM in a home network.
[0251] In some embodiments, the second network element 1022 is configured to determine whether the re-authentication procedure can be triggered, as described in step S2102.
[0252] In step S2102, the second network element 1022 determines whether to trigger the re-authentication procedure according to the first information and a local policy.
[0253] In some embodiments, after receiving the first information, the second network element 1022 can determine whether to trigger the re-authentication procedure based on the first information and the local policy.
[0254] In some embodiments, after receiving the first information and making a decision, the second network element 1022 can perform step S2103 to respond.
[0255] In some embodiments, if the second network element 1022 determines that the re-authentication procedure cannot be triggered, it can carry the reason in the response to the first network element 1021; if the second network element 1022 determines that the re-authentication procedure can be triggered, it can confirm the request of the first network element 1021 in the response, as shown in step S2102.
[0256] In step S2103, the second network element 1022 sends second information to the first network element 1021.
[0257] In some embodiments, the first network element 1021 receives the second information.
[0258] In some embodiments, the second information is used to respond to the first information.
[0259] In some embodiments, the second information can be response information, such as first response information Nudm_UECM_AuthTrigger Response.
[0260] In some embodiments, when the second network element 1022 determines that the re-authentication procedure can be triggered, the second information such as Nudm_UECM_AuthTrigger Response can be used to confirm the first information.
[0261] Optionally, the second information is used to indicate that the re-authentication procedure is triggered, so that the first network element 1021 can wait for key update after receiving the second information.
[0262] In some embodiments, when the second network element 1022 determines that the re-authentication procedure cannot be triggered, the second information, such as the Nudm_UECM_AuthTrigger response, can be used to carry the cause.
[0263] Optionally, the second information is used to indicate the cause that the re-authentication procedure cannot be triggered, so that the first network element 1021 learns that the re-authentication procedure will not be performed this time after receiving the second information.
[0264] In step S2104, the second network element 1022 sends fourth information to the third network element 1023.
[0265] In some embodiments, the third network element 1023 receives the fourth information.
[0266] In some embodiments, the third network element 1023 can be an AMF or an SEAF.
[0267] In some embodiments, the network element information of one or more first network elements connected with the terminal is maintained in the NAS context of the terminal stored in the third network element.
[0268] In some embodiments, the fourth information is used to request triggering of the re-authentication procedure.
[0269] Optionally, after receiving the first information, if the second network element 1022 determines that the re-authentication procedure can be triggered, the fourth information can be sent to the third network element 1023 to request the re-authentication procedure.
[0270] In some embodiments, the fourth information can be a request information, such as the second request information Nudm_UECM_Re-AuthenticationNotification request.
[0271] In some embodiments, the fourth information includes at least one of the following:
[0272] The terminal identifier;
[0273] The network element information of the first network element.
[0274] The terminal identifier or the network element information can refer to the description of the foregoing embodiments.
[0275] Optionally, the terminal identifier can be included in the fourth information, and the network element information is optional. The network element information can include the ID and / or IP address of the first network element.
[0276] In step S2105, the third network element 1023 determines whether to perform the re-authentication procedure according to the local policy and the terminal state.
[0277] In some embodiments, after receiving the fourth information, the third network element 1023 can make a decision based on the local policy and the terminal state to determine whether to perform the re-authentication procedure.
[0278] In some embodiments, the terminal state can be a moving state or an authentication state of the terminal.
[0279] In some embodiments, if the terminal is in handover or has been under the authentication of the third network element 1023 such as an AMF before receiving the fourth information from the second network element 1022, the third network element 1023 can determine not to perform the re-authentication procedure.
[0280] Alternatively, if the third network element 1023 determines that it cannot run the authentication based on the local policy, it can determine not to perform the re-authentication procedure.
[0281] In some embodiments, if the third network element 1023 determines that the re-authentication procedure can be performed based on the local policy and the terminal state, the fourth information can be confirmed.
[0282] Step S2106, the third network element 1023 sends fifth information to the second network element 1022.
[0283] In some embodiments, the second network element 1022 receives the fifth information.
[0284] In some embodiments, the fifth information is used to respond to the fourth information.
[0285] In some embodiments, the fifth information can be response information such as second response information Nudm_UECM_Re-AuthenticationNotification response.
[0286] In some embodiments, in combination with the description of the foregoing embodiments, if the third network element 1023 determines not to perform the re-authentication procedure, the fifth information can carry the reason why the re-authentication procedure cannot be performed.
[0287] In some embodiments, in combination with the description of the foregoing embodiments, if the third network element 1023 determines to perform the re-authentication procedure, the fifth information can be used to indicate the confirmation of performing the re-authentication procedure to confirm the request of the fourth information.
[0288] Step S2107, the third network element 1023 stores the network element information of the first network element.
[0289] In some embodiments, the third network element 1023 can perform this step S2107 when confirming to perform the re-authentication procedure.
[0290] In some embodiments, the network element information can refer to the description of the foregoing embodiments, for example, the network element information comprises the ID and / or IP address of the first network element.
[0291] In some embodiments, after sending the fifth information or storing the network element information, the third network element 1023 can initiate or start a re-authentication process. In the re-authentication process, the terminal 101 and the third network element 1023 can perform the re-authentication process. The nodes participating in the re-authentication process can at least comprise the terminal 101, the second network element 1022 and the third network element 1023.
[0292] In step S2108, the terminal 101 removes the stored NAS context associated with the first network element 1021.
[0293] In some embodiments, if the re-authentication process is completed, for example, after the re-authentication process initiated or participated by the third network element 1023 is completed, the terminal 101 can remove the original stored NAS context, and can re-establish a connection with the first network element 1021 based on step S2111 or step S2112.
[0294] In step S2109, the third network element 1023 generates a first key after update according to the network element information.
[0295] In some embodiments, step S2109 can be that the third network element 1023 generates a new first key in the case that the re-authentication process is successful.
[0296] In some embodiments, the third network element 1023 can regenerate the first key based on the stored ID and / or IP address of the first network element.
[0297] In some embodiments, the first key can be denoted as K NF .
[0298] In some embodiments, in the re-authentication process, the third network element 1023 can first generate a new root key (denoted as K AMF ); and in this step, a new first key can be further generated based on the new root key to realize key update.
[0299] It is worth noting that the terminal 101 can generate the root key and the first key in the same way as the third network element 1023.
[0300] In step S2110, the third network element 1023 sends third information to the first network element 1021.
[0301] In some embodiments, the third information can be notification information, for example, a key refresh notification.
[0302] In some embodiments, the third information includes the first key after the update, such as K NF .
[0303] In some embodiments, the first network element 1021 receives the third information.
[0304] In some embodiments, after receiving the third information, the first network element 1021 can replace the original key or the old key with the new first key in the third information, such as K NF .
[0305] In some embodiments, the third network element 1023 can only send the updated key to the first network element 1021 (such as NF1) that initiates the re-authentication request. Whether the key needs to be updated to other first network elements 1021 (such as NF2) is determined by the terminal 101 based on subsequent communication conditions.
[0306] In some embodiments, the third network element 1023 can send the third information to multiple first network elements 1021.
[0307] Optionally, when the third network element 1023 maintains the network element information of multiple first network elements, in addition to sending the first key after the update to the first network element (such as NF1) that requests to trigger the re-authentication, the third network element 1023 can also send the first key corresponding to the other first network element (such as NF2) to the other first network element. For example, for different first network elements 1021, the third network element 1023 can generate the first key corresponding to the first network element 1021 based on the network element information of the first network element 1021. For example, the third network element 1023 generates K NF corresponding to NF1 for NF1, and can send it to NF1 through the third information. For another example, the third network element 1023 generates K NF corresponding to NF2 for NF2, and can send it to NF2 through the third information.
[0308] In this case, the third network element 1023 can store the corresponding NF key record when generating the first keys corresponding to multiple NFs.
[0309] Optionally, the original key of NF2 can be generated by the third network element 1023, so that the third network element 1023 can update the key for NF2 when it involves key update.
[0310] Optionally, the multiple first network elements can be multiple first network elements connected to the terminal.
[0311] Optionally, the multiple first network elements can include the first network element (such as NF1) that requests to trigger the re-authentication, and the other first network element (such as NF2) that does not actively request to trigger the re-authentication.
[0312] In this embodiment, if the network element information of the plurality of first network elements is stored locally in the terminal NAS context, the third network element 1023 can send the new K NF .
[0313] This embodiment is optional, for example, if all the first network elements maintain the terminal NAS context respectively, the third network element does not need to maintain the network element information of the first network elements connected to the terminal, and the third network element sends the third information to the requested first network element.
[0314] In step S2111, the first network element 1021 generates a second key according to the third information.
[0315] In some embodiments, the second key is used to protect the NAS signaling between the first network element and the terminal. The second key is updated or generated by the first network element 1021 according to the new first key. The terminal 101 can generate the second key by itself.
[0316] In some embodiments, in combination with FIGS. 1e and 1f, the second key can be used as an input key in an encryption algorithm or an integrity algorithm.
[0317] In some embodiments, the second key can be denoted as K NF_INT and K NF_ENC .
[0318] In some embodiments, if the first network element 1021 supports the SMC process, the SMC process can be initiated based on the second key, and the security of the new NAS connection with the terminal is activated. After this embodiment, step S2112 can be performed. The SMC process can activate a new key, and the process can ensure that the subsequent NAS communication with the terminal is based on the updated key.
[0319] In some embodiments, if the first network element 1021 does not support the SMC process, the first network element 1021 can generate the second key during or in the process of establishing a new NAS with the terminal, as in step S2113.
[0320] In step S2112, after the SMC process is successfully completed, the first network element 1021 and the terminal 101 set the NAS count to an initial value.
[0321] In some embodiments, if the first network element 1021 supports the SMC process, the first network element 1021 and the terminal 101 can update the NAS count, such as setting it to an initial value, during the initiation and completion of the SMC process. The initial value can be 0. It can be understood that based on the verification of the SMC process, the security of the NAS communication can be ensured, and therefore the NAS count can be set to zero.
[0322] In some embodiments, after the SMC procedure between the terminal 101 and the first network element 1021 is completed, the terminal 101 can re-generate the NAS context associated with the first network element and set the NAS count to 0.
[0323] At step S2113, the terminal 101 re-establishes the NAS connection with the first network element 1021.
[0324] In some embodiments, the terminal 101 can trigger or initiate the re-establishment of the NAS connection.
[0325] For example, after the re-authentication is completed, the terminal 101 can trigger the re-establishment of the NAS connection with the first network element 1021.
[0326] In some embodiments, during or in the process of re-establishing the NAS connection with the first network element 1021, the terminal 101 can also generate a second key and a new NAS context.
[0327] In some embodiments, if the SMC procedure is not supported, after the second key is generated, the first network element 1021 and the terminal 101 can set the NAS count to an initial value, such as 0.
[0328] In some embodiments, the new NAS connection between the terminal 101 and the first network element 1021 is protected by the new key, such as the second key.
[0329] In some embodiments, the terminal 101 can actively trigger the NAS connection with different first network elements 1021 according to the communication needs.
[0330] For example, in combination with the foregoing embodiment descriptions, if the third network element 1023 only updates the key to the first network element 1021, such as NF1, which requests re-authentication. Assuming that the terminal 101 still needs to communicate with other first network elements 1021, such as NF2, the terminal 101 can actively trigger a new NAS connection with NF2 and can update the key and the context in the process of the new NAS connection.
[0331] In some embodiments, the names of signals and the like are not limited to the names described in the embodiments, and the terms "information", "message", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", and the like can be replaced with each other.
[0332] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectionally transmit", "send and / or receive" can be replaced with each other, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and various meanings.
[0333] In some embodiments, the terms "send", "transmit", "report", "issue", "transmit", "bidirectionally transmit", "send and / or receive" can be replaced with each other.
[0334] In some embodiments, the terms "radio", "wireless", "radio access network (RAN)", "access network (AN)", "RAN-based" and the like can be replaced with each other.
[0335] In some embodiments, the terms "certain", "preset", "preset", "set", "indicated", "certain", "arbitrary", "first" and the like can be replaced with each other, "certain A", "preset A", "preset A", "set A", "indicated A", "certain A", "arbitrary A", "first A" can be interpreted as A specified in advance in protocols and the like, or A obtained by setting, configuration, or indication, or A specific, certain, arbitrary, or first A, but not limited thereto.
[0336] In some embodiments, the determination or judgment can be made by a value represented by 1 bit (0 or 1), or by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values (for example, comparison with a predetermined value), but not limited thereto.
[0337] The method related to the embodiments of the present disclosure can include at least one of steps S2101-S2113. For example, step S2101 can be an independent embodiment, steps S2101 and S2104 can be independent embodiments, and steps S2101, S2104 and S2110 can be independent embodiments, but not limited thereto.
[0338] In some embodiments, step S2102 is optional, and in different embodiments, it can be replaced by one or more steps.
[0339] In some embodiments, step S2103 is optional, and in different embodiments, it can be replaced by one or more steps.
[0340] In some embodiments, step S2105 is optional, and in different embodiments can be replaced by one or more steps.
[0341] In some embodiments, step S2106 is optional, and in different embodiments can be replaced by one or more steps.
[0342] In some embodiments, step S2107 is optional, and in different embodiments can be replaced by one or more steps.
[0343] In some embodiments, step S2112 or S2113 is optional, and in different embodiments can be replaced by one or more steps.
[0344] In some embodiments, other optional implementations can be described before or after the description of the corresponding embodiments in FIG. 2a.
[0345] FIG. 2b is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2a, the embodiments of the present disclosure relate to a communication method, and the above method comprises:
[0346] Step S2201, the first network element 1021 sends first information to the third network element 1023.
[0347] In some embodiments, the third network element 1023 receives the first information.
[0348] In some embodiments, the descriptions of the first network element 1021, the third network element 1023 and the first information can be referred to the descriptions of the embodiments in FIG. 2a, which will not be described here.
[0349] In some embodiments, when the first network element 1021 comprises multiple NFs, the multiple NFs can be located in a service network. For example, the service network can be a visited PLMN (VPLMN), which is a PLMN visited by the terminal.
[0350] Optionally, it is assumed that the first network element 1021 independently maintains the NAS context for communication with the terminal, for example, multiple NFs such as NF1 and NF2 respectively maintain the NAS context.
[0351] Optionally, in the terminal NAS context stored by the third network element 1023, the network element information of the first network element connected to the terminal can also be maintained.
[0352] In this embodiment, the first network element 1021 can directly initiate a request to the third network element 1023 without going through the second network element 1022.
[0353] Step S2202, the third network element 1023 determines whether to perform the re-authentication procedure according to the local policy and the terminal state.
[0354] In some embodiments, the implementation of step S2202 can refer to the implementation of step S2105 in FIG. 2a, which will not be repeated here.
[0355] Step S2203, the third network element 1023 sends second information to the first network element 1021.
[0356] In some embodiments, the second information can refer to the description of step S2103 in FIG. 2a, or the second information is a response information re-authentication response.
[0357] Optionally, when the third network element 1023 determines that the re-authentication procedure can be performed, the second information is used to indicate that the re-authentication procedure is confirmed to be performed, and the first information is confirmed.
[0358] Optionally, when the third network element 1023 determines that the re-authentication procedure cannot be performed, the second information includes a reason why the re-authentication procedure cannot be performed.
[0359] Step S2204, the third network element 1023 stores the network element information of the first network element.
[0360] In some embodiments, the implementation of step S2204 can refer to the implementation of step S2107 in FIG. 2a, which will not be repeated here.
[0361] Step S2205, the terminal 101 removes the stored NAS context associated with the first network element 1021.
[0362] In some embodiments, the implementation of step S2205 can refer to the implementation of step S2108 in FIG. 2a, which will not be repeated here.
[0363] Step S2206, the third network element 1023 generates an updated first key according to the network element information.
[0364] In some embodiments, the implementation of step S2206 can refer to the implementation of step S2108 in FIG. 2a, which will not be repeated here.
[0365] Step S2207, the third network element 1023 sends third information to the first network element 1021.
[0366] In some embodiments, the implementation of step S2207 can refer to the implementation of step S2109 in FIG. 2a, which will not be repeated here.
[0367] Step S2208. The first network element 1021 generates a second key according to the third information.
[0368] In some embodiments, the implementation of step S2207 can refer to the implementation of step S2110 in FIG. 2a, which will not be repeated here.
[0369] Step S2209. After the SMC procedure is successfully completed, the first network element 1021 and the terminal 101 set the NAS count to an initial value.
[0370] In some embodiments, the implementation of step S2208 can refer to the implementation of step S2111 in FIG. 2a, which will not be repeated here.
[0371] Step S2210. The terminal 101 reestablishes the NAS connection with the first network element 1021.
[0372] In some embodiments, the implementation of step S2210 can refer to the implementation of step S2112 in FIG. 2a, which will not be repeated here.
[0373] The method related to the embodiments of the present disclosure can include at least one of steps S2201-S2210. For example, step S2201 can be an independent embodiment, and steps S2201 and S2207 can be independent embodiments, but are not limited thereto.
[0374] In some embodiments, step S2202 is optional, and in different embodiments, it can be replaced by one or more steps.
[0375] In some embodiments, step S2203 is optional, and in different embodiments, it can be replaced by one or more steps.
[0376] In some embodiments, step S2204 is optional, and in different embodiments, it can be replaced by one or more steps.
[0377] In some embodiments, step S2205 is optional, and in different embodiments, it can be replaced by one or more steps.
[0378] In some embodiments, step S2209 is optional, and in different embodiments, it can be replaced by one or more steps.
[0379] In some embodiments, step S2210 is optional, and in different embodiments, it can be replaced by one or more steps.
[0380] In some embodiments, other optional implementations can be described before or after the corresponding description of FIG. 2b.
[0381] FIG. 3a is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3a, the embodiment of the present disclosure relates to a communication method, which is performed by the first network element 1021, and the above method comprises the following steps:
[0382] In step S3101, first information is sent.
[0383] In some embodiments, the implementation of step S3101 can refer to the implementation of step S2101 in FIG. 2a, which will not be described here.
[0384] In some embodiments, the implementation of step S3101 can refer to the implementation of step S2201 in FIG. 2b, which will not be described here.
[0385] In step S3102, second information is received.
[0386] In some embodiments, the implementation of step S3102 can refer to the implementation of step S2103 in FIG. 2a, which will not be described here.
[0387] In some embodiments, the implementation of step S3102 can refer to the implementation of step S2203 in FIG. 2b, which will not be described here.
[0388] In step S3103, third information is received.
[0389] In some embodiments, the implementation of step S3103 can refer to the implementation of step S2110 in FIG. 2a, which will not be described here.
[0390] In some embodiments, the implementation of step S3103 can refer to the implementation of step S2207 in FIG. 2b, which will not be described here.
[0391] In step S3104, a second key is generated.
[0392] In some embodiments, the implementation of step S3104 can refer to the implementation of step S2111 in FIG. 2a, which will not be described here.
[0393] In some embodiments, the implementation of step S3104 can refer to the implementation of step S2208 in FIG. 2b, which will not be described here.
[0394] In step S3105, a NAS count is set to an initial value.
[0395] In some embodiments, the implementation of step S3105 can refer to the implementation of step S2112 in FIG. 2a, which will not be described here.
[0396] In some embodiments, the implementation of step S3105 can refer to the implementation of step S2209 in FIG. 2b, and details are not described herein again.
[0397] Step S3106, reestablishing the NAS connection.
[0398] In some embodiments, the implementation of step S3106 can refer to the implementation of step S2113 in FIG. 2a, and details are not described herein again.
[0399] In some embodiments, the implementation of step S3106 can refer to the implementation of step S2210 in FIG. 2b, and details are not described herein again.
[0400] The method related to the embodiments of the present disclosure can include at least one of steps S3101-S3106.
[0401] In some embodiments, the other optional implementations described before or after the corresponding description of FIG. 3a can be referred to.
[0402] FIG. 3b is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3b, the embodiments of the present disclosure relate to a communication method, which is performed by a first network element 1021, and the above method includes:
[0403] Step S3201, sending first information.
[0404] In some embodiments, the implementation of step S3201 can refer to the implementation of step S2101 in FIG. 2a, and details are not described herein again.
[0405] In some embodiments, the implementation of step S3201 can refer to the implementation of step S2201 in FIG. 2b, and details are not described herein again.
[0406] Step S3202, receiving second information.
[0407] In some embodiments, the implementation of step S3202 can refer to the implementation of step S2103 in FIG. 2a, and details are not described herein again.
[0408] In some embodiments, the implementation of step S3202 can refer to the implementation of step S2203 in FIG. 2b, and details are not described herein again.
[0409] Step S3203, receiving third information.
[0410] In some embodiments, the implementation of step S3203 can refer to the implementation of step S2110 in FIG. 2a, and details are not described herein again.
[0411] In some embodiments, the implementation of step S3203 can refer to the implementation of step S2207 in FIG. 2b, which will not be repeated here.
[0412] In some embodiments, other optional implementations can be referred to before or after the description corresponding to FIG. 3b.
[0413] FIG. 3c is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3c, the embodiment of the present disclosure relates to a communication method, which is performed by a first network element 1021, and the above method comprises the following steps:
[0414] Step S3301: transmitting first information.
[0415] In some embodiments, the implementation of step S3301 can refer to the implementation of step S2101 in FIG. 2a, which will not be repeated here.
[0416] In some embodiments, the implementation of step S3301 can refer to the implementation of step S2201 in FIG. 2b, which will not be repeated here.
[0417] In some embodiments, other optional implementations can be referred to before or after the description corresponding to FIG. 3c.
[0418] FIG. 4a is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 4a, the embodiment of the present disclosure relates to a communication method, which is performed by a second network element 1022, and the above method comprises the following steps:
[0419] Step S4101: receiving first information.
[0420] In some embodiments, the implementation of step S4101 can refer to the implementation of step S2101 in FIG. 2a, which will not be repeated here.
[0421] Step S4102: determining whether to trigger a re-authentication process.
[0422] In some embodiments, the implementation of step S4102 can refer to the implementation of step S2102 in FIG. 2a, which will not be repeated here.
[0423] Step S4103: transmitting second information.
[0424] In some embodiments, the implementation of step S4103 can refer to the implementation of step S2103 in FIG. 2a, which will not be repeated here.
[0425] Step S4104: transmitting fourth information.
[0426] In some embodiments, the implementation of step S4104 can be referred to the implementation of step S2104 in FIG. 2a, and details are not described herein.
[0427] Step S4105, receiving fifth information.
[0428] In some embodiments, the implementation of step S4105 can be referred to the implementation of step S2105 in FIG. 2a, and details are not described herein.
[0429] The method involved in the embodiments of the present disclosure can include at least one of steps S4101-S4105.
[0430] In some embodiments, other optional implementations can be referred to the description before or after FIG. 4a.
[0431] FIG. 4b is a flow diagram of a communication method according to the embodiments of the present disclosure. As shown in FIG. 4b, the embodiments of the present disclosure involve a communication method, which is performed by the second network element 1022, and the above method includes the following steps:
[0432] Step S4201, receiving first information.
[0433] In some embodiments, the implementation of step S4201 can be referred to the implementation of step S2101 in FIG. 2a, and details are not described herein.
[0434] Step S4202, sending second information.
[0435] In some embodiments, the implementation of step S4202 can be referred to the implementation of step S2103 in FIG. 2a, and details are not described herein.
[0436] Step S4203, sending fourth information.
[0437] In some embodiments, the implementation of step S4203 can be referred to the implementation of step S2104 in FIG. 2a, and details are not described herein.
[0438] The method involved in the embodiments of the present disclosure can include at least one of steps S4201-S4203.
[0439] In some embodiments, other optional implementations can be referred to the description before or after FIG. 4b.
[0440] FIG. 4c is a flow diagram of a communication method according to the embodiments of the present disclosure. As shown in FIG. 4c, the embodiments of the present disclosure involve a communication method, which is performed by the second network element 1022, and the above method includes the following steps:
[0441] Step S4301, receiving first information.
[0442] In some embodiments, the implementation of step S4301 can refer to the implementation of step S2101 in FIG. 2a, which will not be repeated here.
[0443] In some embodiments, the implementation of step S4301 can refer to the implementation of step S2101 in FIG. 2a, which will not be repeated here.
[0444] FIG. 5a is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 5a, the embodiment of the present disclosure relates to a communication method, which is performed by the third network element 1023, and the above method comprises:
[0445] Step S5101, receiving fourth information or first information.
[0446] In some embodiments, the implementation of step S5101 can refer to the implementation of step S2104 in FIG. 2a, which will not be repeated here.
[0447] In some embodiments, the implementation of step S5101 can refer to the implementation of step S2201 in FIG. 2b, which will not be repeated here.
[0448] Step S5102, determining whether to perform a re-authentication process.
[0449] In some embodiments, the implementation of step S5102 can refer to the implementation of step S2105 in FIG. 2a or step S2202 in FIG. 2b, which will not be repeated here.
[0450] Step S5103, sending fifth information or second information.
[0451] In some embodiments, the implementation of step S5103 can refer to the implementation of step S2106 in FIG. 2a, which will not be repeated here.
[0452] In some embodiments, the implementation of step S5103 can refer to the implementation of step S2203 in FIG. 2b, which will not be repeated here.
[0453] Step S5104, storing network element information of the first network element.
[0454] In some embodiments, the implementation of step S5104 can refer to the implementation of step S2107 in FIG. 2a or step S2204 in FIG. 2b, which will not be repeated here.
[0455] Step S5105, generating an updated first key.
[0456] In some embodiments, the implementation of step S5105 can refer to the implementation of step S2109 in FIG. 2a or step S2206 in FIG. 2b, which will not be repeated here.
[0457] Step S5106, transmitting the third information.
[0458] In some embodiments, the implementation of step S5106 can refer to the implementation of step S2110 in FIG. 2a or step S2207 in FIG. 2b, which will not be repeated here.
[0459] The method involved in the embodiments of the present disclosure can include at least one of steps S5101-S5106.
[0460] In some embodiments, other optional implementations can be referred to before or after the corresponding description of FIG. 5a.
[0461] FIG. 5b is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 5b, the embodiments of the present disclosure involve a communication method, which is performed by a third network element 1023, and the above method includes:
[0462] Step S5201, receiving fourth information or first information.
[0463] In some embodiments, the implementation of step S5201 can refer to the implementation of step S2104 in FIG. 2a, which will not be repeated here.
[0464] In some embodiments, the implementation of step S5201 can refer to the implementation of step S2201 in FIG. 2b, which will not be repeated here.
[0465] Step S5202, transmitting fifth information or second information.
[0466] In some embodiments, the implementation of step S5202 can refer to the implementation of step S2106 in FIG. 2a, which will not be repeated here.
[0467] In some embodiments, the implementation of step S5202 can refer to the implementation of step S2203 in FIG. 2b, which will not be repeated here.
[0468] Step S5203, transmitting the third information.
[0469] In some embodiments, the implementation of step S5203 can refer to the implementation of step S2110 in FIG. 2a or step S2207 in FIG. 2b, which will not be repeated here.
[0470] The method involved in the embodiments of the present disclosure can include at least one of steps S5201-S5203.
[0471] In some embodiments, other optional implementations can be referred to before or after the corresponding description of FIG. 5b.
[0472] FIG. 5c is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 5c, the embodiment of the present disclosure relates to a communication method, which is performed by the third network element 1023, and the above method comprises the following steps:
[0473] In step S5301, the fourth information or the first information is received.
[0474] In some embodiments, the implementation of step S5301 can refer to the implementation of step S2104 in FIG. 2a, which will not be repeated here.
[0475] In some embodiments, the implementation of step S5301 can refer to the implementation of step S2201 in FIG. 2b, which will not be repeated here.
[0476] In some embodiments, other optional implementations can be referred to before or after the description of FIG. 5c.
[0477] FIG. 6a is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 6a, the embodiment of the present disclosure relates to a communication method, which is performed by the terminal 101, and the above method comprises the following steps:
[0478] In step S6101, the stored NAS context associated with the first network element is removed.
[0479] In some embodiments, the implementation of step S6101 can refer to the implementation of step S2108 in FIG. 2a or step S2205 in FIG. 2b, which will not be repeated here.
[0480] In step S6102, the NAS connection is re-established.
[0481] In some embodiments, the implementation of step S6102 can refer to the implementation of step S2113 in FIG. 2a, which will not be repeated here.
[0482] In some embodiments, the implementation of step S6102 can refer to the implementation of step S2210 in FIG. 2b, which will not be repeated here.
[0483] In step S6103, the NAS count is set to an initial value.
[0484] In some embodiments, the implementation of step S6103 can refer to the implementation of step S2112 or S2113 in FIG. 2a, which will not be repeated here.
[0485] The method according to the embodiment of the present disclosure can comprise at least one of steps S6101-S6103.
[0486] In some embodiments, one of step S6102 and step S6103 can be performed.
[0487] In some embodiments, other optional implementations can be seen before or after the description corresponding to Figure 6a.
[0488] Figure 6b is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 6b, the embodiment of the present disclosure relates to a communication method, which is executed by the terminal 101, and the above method comprises:
[0489] Step S6201, re-establishing the NAS connection.
[0490] In some embodiments, the implementation of step S6201 can refer to the implementation of step S2113 in Figure 2a, which will not be repeated here.
[0491] In some embodiments, the implementation of step S6201 can refer to the implementation of step S2210 in Figure 2b, which will not be repeated here.
[0492] In some embodiments, other optional implementations can be seen before or after the description corresponding to Figure 6b.
[0493] Figure 7a is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 7a, the embodiment of the present disclosure relates to a communication method, which assumes that all NFs maintain UE NAS context respectively. In the UE NAS context stored in the AMF / SEAF, the NF instance ID / IP address of the NF connected to the UE can also be maintained. NF1 and NF2 are located in the home network.
[0494] Among them, NF, NF1 or NF2 corresponds to the first network element of the preceding embodiments, and AMF / SEAF corresponds to the third network element.
[0495] As shown in Figure 7a, the method of the embodiment of the present disclosure comprises:
[0496] Step S7101, if the stored NAS counter is about to be rotated, the NF such as NF1 can send a request (Nudm_UECM_AuthTrigger request) to the UDM.
[0497] In some embodiments, the request of this step is used to trigger the re-authentication process, which corresponds to the first information of the preceding embodiments. Among them, the SUPI or GPSI of the target UE can be included in the request, and optionally, the NF instance ID can also be included in the request.
[0498] In some embodiments, the UDM corresponds to the second network element.
[0499] Step S7102, the UDM decides by itself based on the request and local policy whether to trigger the home network triggered re-authentication.
[0500] Step S7103, the UDM sends a response (Nudm_UECM_AuthTrigger response) to the NF1.
[0501] In some embodiments, the response in this step corresponds to the second information in the foregoing embodiments, to confirm the request in step S7101.
[0502] Step S7104, the UDM sends a request (Nudm_UECM_Re-AuthenticationNotification request) to the AMF / SEAF.
[0503] In some embodiments, the request in this step corresponds to the fourth information in the foregoing embodiments, to request triggering re-authentication. In the request, the SUPI or GPSI of the UE can be carried, and optionally, the NF instance ID / IP address of the NF can also be carried. The “ / ” represents “or” or “and / or”.
[0504] Step S7105, the AMF / SEAF sends a response (Nudm_UECM_Re-AuthenticationNotification response) to the UDM.
[0505] In some embodiments, after the AMF / SEAF receives the request in step S7104 from the UDM, the AMF / SEAF will decide whether to run the re-authentication process based on its own local policy and the UE state. The UE state includes, for example, that the UE is switching, or the UE has been under the authentication of the AMF before receiving the authentication notification from the UDM.
[0506] In some embodiments, if the AMF / SEAF determines that it cannot run the re-authentication (e.g., based on the local policy), the AMF / SEAF sends an authentication response message to the UDM with a failure cause. If it is determined that the re-authentication can be run, the AMF / SEAF can confirm the request in step S7104.
[0507] In some embodiments, if the AMF confirms the request of the UDM, the AMF will store the NF instance ID / IP address.
[0508] Step S7106, the AMF / SEAF starts the re-authentication process.
[0509] In some embodiments, once the re-authentication process is completed, the UE removes all NAS contexts of the NF.
[0510] Step S7107, the AMF / SEAF re-generates the K NFand sends it to the NF.
[0511] In some embodiments, the AMF / SEAF can re-generate the K NF .
[0512] In some embodiments, upon receiving the new K NF , the NF replaces the old key with the new key.
[0513] In some embodiments, upon receiving the new key, the NF can initiate the SMC procedure and activate the new NAS security with the UE. After the SMC, the NF and the UE can set the NAS count to zero.
[0514] In some embodiments, if the NF does not support the SMC procedure, the UE generates a new K NF and the corresponding NAS security context during the establishment of the new NAS connection with the NF, and the NF generates a new K NF_INT and K NF_ENC respectively during the new NAS connection with the UE. The NAS connection between the UE and the NF is protected by the new keys. Once the new keys are generated, the NF and the UE can set the NAS count to zero.
[0515] Step S7108, the AMF / SEAF sends a refresh notification containing the K NF to the other NFs connected to the UE.
[0516] In some embodiments, the other NFs connected to the UE correspond to the ID / IP addresses stored locally in the UE NAS context.
[0517] Figure 7b is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 7b, the embodiment of the present disclosure relates to a communication method, which assumes that all NFs maintain the UE NAS context respectively. In the UE NAS context stored by the AMF / SEAF, there is no need to maintain the NF instance ID / IP addresses of the NFs connected to the UE. NF1 and NF2 are located in the home network.
[0518] wherein the NF, NF1 or NF2 corresponds to the first network element of the foregoing embodiments, and the AMF / SEAF corresponds to the third network element.
[0519] As shown in Figure 7b, the method of the embodiment of the present disclosure includes:
[0520] Step S7201, if the stored NAS count is about to be rotated, the NF can send a request (Nudm_UECM_AuthTrigger request) to the UDM.
[0521] Step S7202, the UDM decides by itself whether to trigger the home network triggered re- authentication based on the request and local policy.
[0522] Step S7203, the UDM sends a response (Nudm_UECM_AuthTrigger response) to the NF1.
[0523] Step S7204, the UDM sends a request (Nudm_UECM_Re-AuthenticationNotification request) to the AMF / SEAF.
[0524] Step S7205, the AMF / SEAF sends a response (Nudm_UECM_Re-AuthenticationNotification response) to the UDM.
[0525] Step S7206, the AMF / SEAF starts the re-authentication procedure.
[0526] Step S7207, the UE initiates NAS connection re-establishment with the NF.
[0527] In some embodiments, once the re-authentication procedure is completed, the UE removes all NAS contexts of the NF and can initiate a new NAS connection with the NF.
[0528] In some embodiments, the implementation of steps S7201-S7206 can refer to the description of FIG. 7a.
[0529] FIG. 7c is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 7c, the embodiment of the present disclosure relates to a communication method, which assumes that all NFs maintain UE NAS contexts respectively. In the UE NAS context stored by the AMF / SEAF, the NF instance ID / IP address of the NF connected to the UE can also be maintained. The NF1 and the NF2 are located in the serving network.
[0530] Wherein, the NF, the NF1 or the NF2 corresponds to the first network element of the foregoing embodiments, and the AMF / SEAF corresponds to the third network element.
[0531] As shown in FIG. 7c, the method of the embodiment of the present disclosure includes:
[0532] Step S7301, if the stored NAS counter is about to be rotated, the NF can send a request (re-authentication request) to the AMF.
[0533] In some embodiments, the request can correspond to the first information in FIG. 2b to request triggering re-authentication. The request can include the SUPI or GPSI of the target UE, and optionally, the NF instance ID.
[0534] At step S7302, the AMF decides whether to perform the re-authentication procedure based on the local policy and the UE state, and sends a re-authentication response.
[0535] In some embodiments, this step can refer to the description of step S7105.
[0536] At step S7303, the AMF / SEAF starts the re-authentication procedure.
[0537] In some embodiments, once the re-authentication procedure is completed, the UE removes all NAS contexts for the NF.
[0538] At step S7304, the AMF / SEAF re-generates K NF and sends it to the NF.
[0539] In some embodiments, the AMF / SEAF can re-generate K NF based on the stored NF instance ID / IP address.
[0540] In some embodiments, upon receiving K NF , the NF replaces the old key with the new key.
[0541] In some embodiments, upon receiving the new key, the NF can initiate the SMC procedure and activate the new NAS security with the UE. After the SMC, the NF and the UE can set the NAS count to zero.
[0542] In some embodiments, if the NF does not support the SMC procedure, the UE generates a new K NF and the corresponding NAS security context during the establishment of the new NAS connection with the NF, and the NF generates a new K NF_INT and K NF_ENC respectively during the new NAS connection with the UE. The NAS connection between the UE and the NF is protected by the new keys. Once the new keys are generated, the NF and the UE can set the NAS count to zero.
[0543] At step S7305, the AMF / SEAF sends a refresh notification containing K NF to other NFs connected to the UE.
[0544] In some embodiments, the ID / IP address corresponding to the NFs to which the other UE is connected is locally stored in the UE NAS context.
[0545] Figure 7d is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 7d, the embodiment of the present disclosure relates to a communication method, assuming that all NFs maintain UE NAS contexts respectively. In the UE NAS context stored in the AMF / SEAF, there is no need to maintain the NF instance ID / IP address of the NF connected to the UE. NF1 and NF2 are located in the serving network.
[0546] In some embodiments, the NF, NF1 or NF2 corresponds to the first network element of the preceding embodiments, and the AMF / SEAF corresponds to the third network element.
[0547] As shown in Figure 7d, the method of the embodiment of the present disclosure includes:
[0548] At step S7401, if the stored NAS counter is about to be rolled over, the NF can send a request (re-authentication request) to the AMF.
[0549] At step S7402, the AMF decides whether to perform a re-authentication procedure based on a local policy and a UE state, and sends a response.
[0550] At step S7403, the AMF / SEAF starts the re-authentication procedure.
[0551] In some embodiments, once the re-authentication procedure is completed, the UE removes all NAS contexts of the NF.
[0552] At step S7404, the UE initiates NAS connection re-establishment with the NF.
[0553] In some embodiments, once the re-authentication procedure is completed, the UE removes all NAS contexts of the NF and can initiate a new NAS connection with the NF.
[0554] In some embodiments, the implementation of steps S7401-S7403 can refer to the description of Figure 7c.
[0555] In the embodiment of the present disclosure, when the NAS counter is about to be rolled over, it can be ensured that all NFs can refresh the NAS key and the NAS counter respectively to protect and verify the NAS signaling.
[0556] In some embodiments, for the UE, the UE can perform at least one of the following: once the re-authentication is completed, the UE can trigger NAS connection establishment with the NF; the UE can remove all NAS contexts of the NF.
[0557] In some embodiments, for the NF, the NF can perform at least one of the following:
[0558] Once the stored NAS count is about to rollover, the NF can send a reauthentication request to the AMF / UDM;
[0559] The NF can receive a reauthentication response from the AMF / UDM;
[0560] The NF can receive a refresh notification from the AMF carrying a new K NF ;
[0561] Upon receiving the refresh notification, the NF can generate a new key to protect the NAS signaling;
[0562] Upon receiving a NAS connection setup from the UE, the NF can remove the UE context.
[0563] In some embodiments, for the SEAF / AMF, the SEAF / AMF can perform at least one of the following:
[0564] The SEAF / AMF can receive a reauthentication request from the UDM / NF;
[0565] The SEAF / AMF can store the NF instance ID / IP address and send a refresh notification message to the NF after the primary authentication procedure is completed.
[0566] In some embodiments, for the UDM, the UDM can perform at least one of the following:
[0567] The UDM can receive a reauthentication request from the NF;
[0568] The UDM can send a reauthentication response to the NF;
[0569] The UDM can send an authentication notification message to the AMF / SEAF carrying the NF instance / IP address.
[0570] Embodiments of the present disclosure also propose an apparatus or a communication device for implementing any of the above methods, for example, a communication device including units or modules to implement the steps performed by a terminal in any of the above methods. For another example, another communication device is also proposed, including units or modules to implement the steps performed by a network device (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.
[0571] It should be understood that the division of units or modules in the above communication device is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the communication device can be implemented in the form of processor calling software: for example, the communication device includes a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to realize the functions of any of the above methods or the units or modules of the above device. The processor is, for example, a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the communication device or a memory outside the device. Alternatively, the units or modules in the communication device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of the hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the above units or modules are realized by the design of the logical relationship between the elements in the circuit; for example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the above units or modules. All units or modules of the above communication device can be realized by processor calling software, or all units or modules can be realized by hardware circuit, or part of the units or modules can be realized by processor calling software, and the remaining part can be realized by hardware circuit.
[0572] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuits, and the logical relationship of the hardware circuits is fixed or can be reconfigured. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), or the like.
[0573] FIG. 8a is a structural schematic diagram of a communication device according to an embodiment of the present disclosure. As shown in FIG. 8a, the communication device 8100 can include at least one of a transceiver module 8101, a processing module 8102, and the like. In some embodiments, when the communication device 8100 is configured to implement the functions of the first network element, the transceiver module 8101 is configured to transmit first information used to request triggering of a re-authentication procedure, wherein the first network element independently maintains a NAS context for communication with a terminal.
[0574] Optionally, the transceiver module 8101 is configured to perform at least one of the communication steps of transmitting and / or receiving performed by the first network element in any of the above methods, which will not be described herein. Optionally, the processing module 8102 is configured to perform at least one of the other steps performed by the first network element in any of the above methods, which will not be described herein.
[0575] FIG. 8b is a structural diagram of a communication device according to an embodiment of the present disclosure. As shown in FIG. 8b, the communication device 8200 can include at least one of a transceiver module 8201, a processing module 8202, etc. In some embodiments, when the communication device 8100 is configured to implement a function of a second network element, the transceiver module 8201 is configured to receive first information sent by a first network element, the first information being used to request triggering of a re-authentication procedure, wherein the first network element independently maintains a NAS context for communication with a terminal.
[0576] Optionally, the transceiver module 8201 is configured to perform at least one of the communication steps, such as sending and / or receiving, performed by the second network element in any of the methods described above. Details are not described herein again. Optionally, the processing module 8202 is configured to perform at least one of the other steps performed by the second network element in any of the methods described above. Details are not described herein again.
[0577] FIG. 8c is a structural diagram of a communication device according to an embodiment of the present disclosure. As shown in FIG. 8c, the communication device 8300 can include at least one of a transceiver module 8301, a processing module 8302, etc. In some embodiments, when the communication device 8100 is configured to implement a function of a third network element, the transceiver module 8301 is configured to receive first information or fourth information, the first information and the fourth information being used to request triggering of a re-authentication procedure; and the third network element is configured to determine whether to perform the re-authentication procedure.
[0578] Optionally, the transceiver module 8301 is configured to perform at least one of the communication steps, such as sending and / or receiving, performed by the third network element in any of the methods described above. Details are not described herein again. Optionally, the processing module 8302 is configured to perform at least one of the other steps performed by the third network element in any of the methods described above. Details are not described herein again.
[0579] FIG. 8d is a structural diagram of a communication device according to an embodiment of the present disclosure. As shown in FIG. 8d, the communication device 8400 can include at least one of a transceiver module 8401, a processing module 8402, etc. In some embodiments, when the communication device 8100 is configured to implement a function of a terminal, the processing module 8402 is configured to re-establish a NAS connection between the terminal and a first network element after a re-authentication procedure in which a third network element participates is completed, wherein the first network element triggers the re-authentication procedure by sending first information, and wherein the first network element independently maintains a NAS context for communication with the terminal.
[0580] Optionally, the transceiver module 8401 is configured to perform at least one of the communication steps, such as sending and / or receiving, performed by the terminal in any of the methods described above. Details are not described herein again. Optionally, the processing module 8402 is configured to perform at least one of the other steps performed by the terminal in any of the methods described above. Details are not described herein again.
[0581] In some embodiments, the transceiving module can include a transmitting module and / or a receiving module, which can be separate or integrated together. Alternatively, the transceiving module can be mutually replaced with a transceiver.
[0582] In some embodiments, the processing module can be one module or include multiple sub-modules. Alternatively, the multiple sub-modules perform all or part of the steps required by the processing module. Alternatively, the processing module can be mutually replaced with a processor.
[0583] FIG. 9a is a structural schematic diagram of a communication device 9100 according to an embodiment of the present disclosure. The communication device 9100 can be a network device or a terminal device, or a chip, chip system, or processor supporting the implementation of any of the above methods by the network device or the terminal device. The communication device 9100 can be used to implement the methods described in the above method embodiments, and specific reference can be made to the descriptions in the above method embodiments.
[0584] As shown in FIG. 9a, the communication device 9100 includes one or more processors 9101. The processor 9101 can be a general-purpose processor or a special-purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. Alternatively, the communication device 9100 is configured to perform any of the above methods. Alternatively, the one or more processors 9101 are configured to invoke instructions to cause the communication device 9100 to perform any of the above methods.
[0585] In some embodiments, the communication device 9100 further includes one or more transceivers 9102. When the communication device 9100 includes one or more transceivers 9102, the transceiver 9102 performs at least one of the communication steps such as transmitting and / or receiving in the above methods, and the processor 9101 performs at least one of the other steps. In alternative embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Alternatively, the terms transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc. can be mutually replaced, and the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be mutually replaced, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be mutually replaced.
[0586] In some embodiments, the communication device 9100 further comprises one or more memories 9103 for storing data. Alternatively, all or part of the memories 9103 can also be outside the communication device 9100. In optional embodiments, the communication device 9100 can comprise one or more interface circuits 9104. Alternatively, the interface circuit 9104 is connected with the memory 9103, the interface circuit 9104 can be used to receive data from the memory 9103 or other devices, and can be used to send data to the memory 9103 or other devices. For example, the interface circuit 9104 can read the data stored in the memory 9103 and send the data to the processor 9101.
[0587] The communication device 9100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 9100 described in the present disclosure is not limited thereto, and the structure of the communication device 9100 can not be limited by Figure 9a. The communication device can be a stand-alone device or can be part of a larger device. For example, the communication device can be: 1) a stand-alone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally include a storage component for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (9) other devices, etc.
[0588] Figure 9b is a structural schematic diagram of a chip 9200 according to an embodiment of the present disclosure. For the case where the communication device 9100 can be a chip or a chip system, the structural schematic diagram of the chip 9200 shown in Figure 9b can be referred to, but is not limited thereto.
[0589] The chip 9200 comprises one or more processors 9201. The chip 9200 is configured to execute any of the above methods.
[0590] In some embodiments, the chip 9200 further comprises one or more interface circuits 9202. Alternatively, the terms interface circuit, interface, and transceiver pin can be replaced with each other. In some embodiments, the chip 9200 further comprises one or more memories 9203 for storing data. Alternatively, all or part of the memories 9203 can be outside the chip 9200. Alternatively, the interface circuit 9202 is connected with the memory 9203, the interface circuit 9202 can be used to receive data from the memory 9203 or other devices, and the interface circuit 9202 can be used to send data to the memory 9203 or other devices. For example, the interface circuit 9202 can read the data stored in the memory 9203 and send the data to the processor 9201.
[0591] In some embodiments, the interface circuit 9202 performs at least one of the communication steps such as transmitting and / or receiving in the above-described methods. The interface circuit 9202 performing the communication steps such as transmitting and / or receiving in the above-described methods refers to, for example, the interface circuit 9202 performing data interaction between the processor 9201, the chip 9200, the memory 9203, or a transceiver device. In some embodiments, the processor 9201 performs at least one of the other steps.
[0592] The modules and / or devices described in each embodiment of the communication device, chip, etc. can be combined or separated as appropriate. Alternatively, some or all of the steps can be performed by a plurality of modules and / or devices in cooperation, which is not limited here.
[0593] The disclosure further proposes a storage medium having instructions stored thereon, which, when executed on the communication device 9100, cause the communication device 9100 to perform any of the above methods. Alternatively, the storage medium is an electronic storage medium. Alternatively, the storage medium is a computer-readable storage medium, but is not limited to this, and it can also be a storage medium readable by other devices. Alternatively, the storage medium can be a non-transitory storage medium, but is not limited to this, and it can also be a transitory storage medium.
[0594] The disclosure further proposes a program product which, when executed by the communication device 9100, causes the communication device 9100 to perform any of the above methods. Alternatively, the program product is a computer program product.
[0595] The disclosure further proposes a computer program which, when executed on a computer, causes the computer to perform any of the above methods. Industrial applicability
[0596] The re-authentication procedure is triggered by the first network element request, thereby ensuring the security in the NAS communication.
Claims
1. A communication method, wherein, The method comprises: The first network element sends first information, the first information being used for requesting triggering a re-authentication procedure, wherein the first network element independently maintains a non-access stratum (NAS) context for communication with a terminal.
2. The method of claim 1, wherein, The first network element sends the first information, comprising: The first network element is located in a home network, and sends the first information to a second network element, wherein the second network element is used for determining whether the re-authentication procedure can be triggered.
3. The method of claim 1, wherein, The first network element sends the first information, comprising: The first network element is located in a serving network, and sends the first information to a third network element, wherein the third network element is used for determining whether to perform the re-authentication procedure.
4. The method of any one of claims 2 to 3, wherein, The method further comprises: The first network element receives second information sent by the second network element or the third network element, wherein the second information is used for responding to the first information.
5. The method of claim 4, wherein, The second information is used for indicating confirming triggering the re-authentication procedure or confirming performing the re-authentication procedure, wherein the second network element determines triggering the re-authentication procedure or the third network element determines performing the re-authentication procedure.
6. The method of claim 4, wherein, The second information comprises a reason for which the re-authentication procedure cannot be triggered or a reason for which the re-authentication procedure cannot be performed, wherein the second network element determines that the re-authentication procedure cannot be triggered or the third network element determines that the re-authentication procedure cannot be performed.
7. The method of any one of claims 2 to 5, wherein, The method further comprises: The first network element receives third information sent by a third network element, wherein the third information comprises a first key after update.
8. The method of claim 7, wherein, The method further comprises: The first network element generates a second key according to the third information, wherein the second key is used for protecting NAS signaling between the first network element and a terminal.
9. The method of claim 8, wherein, The method further comprises: Initiating a security mode command (SMC) procedure according to the second key; After the SMC procedure is successfully completed, setting the NAS count to an initial value.
10. The method of claim 8, wherein, The method further comprises: After the second key is generated, setting the NAS count to the initial value.
11. The method of claim 8 or 10, wherein, The method further comprises: The first network element re-establishes a NAS connection with the terminal.
12. The method of any one of claims 7 to 11, wherein, The first network element receives third information sent by the third network element, comprising: The third network element maintains network element information of a plurality of first network elements, and the plurality of first network elements receive the third information sent by the third network element. The first information is sent when a non-access stratum (NAS) count stored in the first network element is about to be rotated to an initial value.
13. The method of any one of claims 1 to 12, wherein, The first information comprises at least one of the following:
14. The method of any one of claims 1 to 13, wherein, A terminal identifier; Network element information of the first network element; Indication information. The network element information comprises at least one of the following:
15. The method of claim 14, wherein, An identifier of the first network element; An IP address of the first network element. The method comprises:
16. A communication method, wherein, A second network element receives first information sent by a first network element, wherein the first information is used for requesting triggering a re-authentication procedure, and the first network element independently maintains a non-access stratum (NAS) context for communication with a terminal. The method further comprises:
17. The method of claim 16, wherein, The second network element determines triggering the re-authentication procedure according to the first information and a local policy; The second network element sends second information to the first network element, wherein the second information is used for responding to the first information. 18. The method of claim 16 or 17, wherein, The method further includes: The second network element sends fourth information to a third network element, and the fourth information is used to request triggering of a re-authentication process, and the third network element is used to determine whether to perform the re-authentication process.
19. The method of claim 18, wherein, The method further includes: The second network element receives fifth information sent by the third network element, and the fifth information is used to respond to the fourth information.
20. The method of claim 18 or 19, wherein, The fourth information includes at least one of the following: A terminal identifier; Network element information of the first network element.
21. The method of any one of claims 16 to 20, wherein, The first information includes at least one of the following: A terminal identifier; Network element information of the first network element; Indication information.
22. The method of claim 20 or 21, wherein, The network element information includes at least one of the following: An identifier of the first network element; An IP address of the first network element.
23. A communication method, wherein, The method includes: A third network element receives first information or fourth information, and the first information and the fourth information are used to request triggering of a re-authentication process; and The third network element is used to determine whether to perform the re-authentication process.
24. The method of claim 23, wherein, The third network element receives the first information, including: The third network element receives the first information sent by the first network element, and the first network element is a network function (NF) network element.
25. The method of claim 23, wherein, The third network element receives the fourth information, including: The third network element receives the fourth information sent by the second network element, and the second network element sends the fourth information after receiving the first information, and the second network element is used to determine whether to trigger the re-authentication process.
26. The method of claim 25, wherein: In a NAS context of the terminal stored by the third network element, network element information of one or more first network elements connected with the terminal is maintained.
27. The method of any one of claims 23 to 26, wherein, The method further includes: The third network element determines whether to perform the re-authentication process according to a local policy and a terminal state.
28. The method of claim 27, wherein, The method further includes: The third network element sends second information to the first network element, and the second information is used to respond to the first information; or The third network element sends fifth information to the second network element, and the fifth information is used to respond to the fourth information.
29. The method of claim 28, wherein: The second information or the fourth information includes a reason that the re-authentication process cannot be performed, and the third network element determines that the re-authentication process cannot be performed.
30. The method of claim 28, wherein: The second information or the fourth information is used to indicate confirmation of performing the re-authentication process, and the third network element determines to perform the re-authentication process.
31. The method of claim 28 or 30, wherein, The method further includes: It is determined to perform the re-authentication process, and the third network element stores network element information of the first network element.
32. The method of claim 31, wherein, The method further includes: According to the network element information, a first key after update is generated; Third information is sent to the first network element, and the first key after update is included in the third information.
33. The method of claim 32, wherein, The third information is sent to the first network element, including: The third network element maintains network element information of a plurality of first network elements, and the third information is sent to the plurality of first network elements; and the plurality of first network elements include a first network element triggering the re-authentication and other first network elements.
34. The method of any one of claims 23 to 33, wherein, The first information includes at least one of the following: A terminal identifier; Network element information of the first network element; Indication information.
35. The method of any one of claims 31 to 34, wherein, The network element information comprises at least one of: an identifier of the first network element; an IP address of the first network element.
36. A communication device, wherein the communication device is configured to perform the method of any one of claims 1-15, the method of any one of claims 16-22, or the method of any one of claims 23-35.
37. A communication system, wherein, A communication system comprising a first network element configured to perform the method of any one of claims 1-15, a second network element configured to perform the method of any one of claims 16-22, and a third network element configured to perform the method of any one of claims 23-35.
38. A storage medium having stored thereon instructions which, when executed on a communication device, cause the communication device to perform the method of any one of claims 1-15, or the method of any one of claims 16-22, or the method of any one of claims 23-35.
39. A program product, wherein the program product, when executed on a communication device, causes the communication device to perform the method of any one of claims 1-15, or the method of any one of claims 16-22, or the method of any one of claims 23-35.