Communication methods, devices, and storage media

CN122122958APending Publication Date: 2026-05-29BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING XIAOMI MOBILE SOFTWARE CO LTD
Filing Date
2024-09-27
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

In wireless communication systems, non-access stratum messages that access nodes do not process need to be routed to other network elements through the access network, leading to complexity and efficiency issues in communication security protection.

Method used

Security protection for communication between the terminal and the network element is achieved through security context updates between the first network element and the second network element, including the exchange and updating of information such as key set identifier (KSI), terminal identifier, and serial number (SQN).

Benefits of technology

Secure communication under a multi-NAS architecture has been achieved, improving the security and efficiency of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122122958A_ABST
    Figure CN122122958A_ABST
Patent Text Reader

Abstract

The present disclosure relates to a communication method, device and storage medium. The method comprises: sending a first message to a second network element, the first message being used to update a first security context, the first security context being used to secure communications between the terminal and the first network element and between the terminal and the second network element, or to secure communications between the terminal and the second network element; and updating the first security context. That is, when the first security context is used to secure communications between the terminal and the second network element, the first security context can be updated through the first network element, thereby realizing secure communication under a multi-NAS architecture.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, device and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and particularly relates to a communication method, device and storage medium. BACKGROUND

[0002] In a wireless communication system, a message not processed by an access node is referred to as a non-access stratum message. Except for a mobility management (MM) non-access stratum message, other types of non-access stratum messages are sent by a terminal device to an access and mobility management function (AMF) through an access network, and then routed to other network functions (NFs) by the AMF.

[0003] SUMMARY

[0004] Embodiments of the present disclosure provide a communication method, device and storage medium.

[0005] According to a first aspect of embodiments of the present disclosure, a communication method is provided, performed by a first network element, and the method comprises:

[0006] sending, to a second network element, a first message, the first message being used to update a first security context, the first security context being used to secure communications between a terminal and the first network element and communications between the terminal and the second network element, or to secure communications between the terminal and the second network element;

[0007] updating the first security context.

[0008] According to a second aspect of embodiments of the present disclosure, a communication method is provided, performed by a second network element, and the method comprises:

[0009] receiving a first message sent by a first network element, the first message being used to update a first security context, the first security context being used to secure communications between a terminal and the first network element and communications between the terminal and the second network element, or to secure communications between the terminal and the second network element.

[0010] According to a third aspect of embodiments of the present disclosure, a communication method is provided, performed by a terminal, and the method comprises:

[0011] sending, to a first network element or a second network element, a first signaling;

[0012] The first signaling is used for the terminal to establish a connection with the second network element, and is used for the first network element to send a first message to the second network element, where the first message is used to update a first security context, and the first security context is used to secure communication between the terminal and the first network element and communication between the terminal and the second network element, or to secure communication between the terminal and the second network element. The first signaling includes at least one of a key set identifier KSI, an identifier of the terminal, a sequence number SQN, an instance identifier of the second network element, a type of the second network element, and the KSI is an identifier of the first security context.

[0013] According to a fourth aspect of the embodiments of the present disclosure, a first network element is provided, including:

[0014] The transceiver is configured to send a first message to a second network element, where the first message is used to update a first security context, and the first security context is used to secure communication between a terminal and the first network element and communication between the terminal and the second network element, or to secure communication between the terminal and the second network element.

[0015] The processing module is configured to update the first security context.

[0016] According to a fifth aspect of the embodiments of the present disclosure, a second network element is provided, including:

[0017] The transceiver is configured to receive a first message sent by a first network element, where the first message is used to update a first security context, and the first security context is used to secure communication between a terminal and the first network element and communication between the terminal and the second network element, or to secure communication between the terminal and the second network element.

[0018] According to a sixth aspect of the embodiments of the present disclosure, a terminal is provided, including:

[0019] The transceiver is configured to send a first signaling to a first network element or a second network element.

[0020] The first signaling is used for the terminal to establish a connection with the second network element, and is used for the first network element to send a first message to the second network element, where the first message is used to update a first security context, and the first security context is used to secure communication between the terminal and the first network element and communication between the terminal and the second network element, or is used to secure communication between the terminal and the second network element. The first signaling includes at least one of a key set identifier KSI, an identifier of the terminal, a sequence number SQN, an instance identifier of the second network element, a type of the second network element, and the KSI is an identifier of the first security context.

[0021] According to a seventh aspect of the embodiments of the present disclosure, a communication device is provided, the communication device includes a first network element, a second network element, or a terminal, and the communication device can be used to execute the first aspect or the second aspect or the optional implementation manner of the third aspect.

[0022] According to an eighth aspect of the embodiments of the present disclosure, a communication system is provided, including a first network element, a second network element, and a terminal, wherein the first network element is configured to execute the method described in the optional implementation manner of the first aspect, the second network element is configured to execute the method described in the optional implementation manner of the second aspect, and the terminal is configured to execute the method described in the optional implementation manner of the third aspect.

[0023] According to a ninth aspect of the embodiments of the present disclosure, a storage medium is provided, the storage medium stores instructions, when the instructions are executed on a communication device, the communication device executes the method described in the first aspect or the second aspect or the optional implementation manner of the third aspect.

[0024] According to a tenth aspect of the embodiments of the present disclosure, a computer program product is provided, including a computer program and / or instructions, when the computer program and / or instructions are executed by a communication device, the communication method described in any one of the first aspect of the present disclosure is implemented, or the computer program and / or instructions are executed by a communication device, the communication method described in any one of the second aspect of the present disclosure is implemented, or the computer program and / or instructions are executed by a communication device, the communication method described in any one of the third aspect of the present disclosure is implemented.

[0025] The technical scheme provided by the embodiments of the present disclosure can produce the following beneficial effects: a first message is sent to a second network element, the first message is used to update a first security context, the first security context is used to protect the communication between a terminal and the first network element and the communication between the terminal and the second network element, or to protect the communication between the terminal and the second network element; and the first security context is updated. That is, when the communication between the terminal and the second network element is protected by the first security context, the first security context can be updated through the first network element, so as to realize secure communication under a multi-NAS architecture.

[0026] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0027] In order to more clearly illustrate the technical scheme in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.

[0028] FIG. 1A is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.

[0029] FIG. 1B is a schematic diagram of information transmission according to an embodiment of the present disclosure.

[0030] FIG. 1C is a schematic diagram of a 6G architecture with multiple NAS instances according to an embodiment of the present disclosure.

[0031] FIG. 1D is a schematic diagram of an encryption protection algorithm according to an embodiment of the present disclosure.

[0032] FIG. 1E is a schematic diagram of an integrity protection algorithm according to an embodiment of the present disclosure.

[0033] FIG. 2A is a schematic diagram of interactions of a communication method according to an embodiment of the present disclosure.

[0034] FIG. 2B is a schematic diagram of interactions of a communication method according to an embodiment of the present disclosure.

[0035] FIG. 2C is a schematic diagram of interactions of a communication method according to an embodiment of the present disclosure.

[0036] FIG. 2D is a schematic diagram of interactions of a communication method according to an embodiment of the present disclosure.

[0037] FIG. 3A is a schematic diagram of interactions of a communication method according to an embodiment of the present disclosure.

[0038] FIG. 3B is a schematic diagram of interactions of a communication method according to an embodiment of the present disclosure.

[0039] FIG. 4A is a structural schematic diagram of a first network element according to an embodiment of the present disclosure.

[0040] FIG. 4B is a structural schematic diagram of a second network element according to an embodiment of the present disclosure.

[0041] FIG. 4C is a structural schematic diagram of a terminal according to an embodiment of the present disclosure.

[0042] FIG. 5A is a structural schematic diagram of a communication device according to an embodiment of the present disclosure.

[0043] FIG. 5B is a structural schematic diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0044] The present disclosure provides a communication method, device and storage medium.

[0045] In a first aspect, the present disclosure provides a communication method, performed by a first network element, the method comprising:

[0046] sending, to a second network element, a first message, the first message being used to update a first security context, the first security context being used to secure communications between a terminal and the first network element and between the terminal and the second network element, or to secure communications between the terminal and the second network element;

[0047] updating the first security context.

[0048] In the above embodiment, when the first security context is used to secure communications between the terminal and the second network element, the first security context can be updated by the first network element, thereby realizing secure communications under a multi-NAS architecture.

[0049] In some embodiments of the first aspect, the method further comprises:

[0050] receiving, after the second network element receives a first signaling sent by the terminal, a first request sent by the second network element according to the first signaling, the first signaling being used to establish a connection between the terminal and the second network element, and the first request being used to request the first network element to send a first key of the second network element;

[0051] determining the first key of the second network element according to the first request;

[0052] The first signaling includes at least one of a key set identifier KSI, an identifier of the terminal, a sequence number SQN, an instance identifier of the second network element, a type of the second network element, and the KSI is an identifier of the first security context.

[0053] In the above embodiment, the terminal can send the first signaling to the second network element, and the second network element sends the first request to the first network element after receiving the first signaling, to obtain the first key of the second network element.

[0054] With reference to some embodiments of the first aspect, in some embodiments, the method further includes:

[0055] The first message includes at least one of the first key of the second network element, an identifier of the terminal, an uplink count value, and a downlink count value.

[0056] In the above embodiment, the first network element can send the first key to the second network element.

[0057] With reference to some embodiments of the first aspect, in some embodiments, the method further includes:

[0058] receiving the first signaling sent by the terminal;

[0059] determining the first key of the second network element according to the first signaling;

[0060] The first signaling includes at least one of a KSI, an identifier of the terminal, an SQN, an instance identifier of the second network element, and a type of the second network element, and the KSI is an identifier of the first security context.

[0061] In the above embodiment, the terminal can send the first signaling to the first network element, so that the first network element determines the first key of the second network element according to the first signaling.

[0062] With reference to some embodiments of the first aspect, in some embodiments, the first message includes at least one of the KSI, an identifier of the terminal, the SQN, an instance identifier of the second network element, a type of the second network element, the first key of the second network element, an uplink count value, and a downlink count value.

[0063] In the above embodiment, the first network element can send the first signaling and the first key of the second network element to the second network element.

[0064] With reference to some embodiments of the first aspect, in some embodiments, the updating the first security context includes:

[0065] adding a first label in the first security context, the first label being used to indicate that the terminal is communicating with the second network element.

[0066] In the above embodiment, the first network element can add a first label in the first security context to indicate that the terminal is communicating with the second network element.

[0067] In some embodiments of the first aspect, the method further comprises:

[0068] determining that the first security context includes the first label, and rejecting a request for the first key sent by a network element other than the second network element.

[0069] In the above embodiment, the first network element can reject a key request sent by another network element if the first security context includes the first label.

[0070] In some embodiments of the first aspect, the updating the first security context comprises:

[0071] receiving the second request sent by the second network element, the second request including at least one of the following: the KSI, an identifier of the terminal, an uplink count value, a downlink count value;

[0072] updating at least one of the following in the first security context according to the second request: the uplink count value, the downlink count value.

[0073] In the above embodiment, the second network element can send the second request to the first network element to update the uplink count value and / or the downlink count value in the first security context after the connection between the terminal and the second network element is released.

[0074] In some embodiments of the first aspect, the method further comprises:

[0075] deleting the first label in the first security context, the first label being used to indicate that the terminal is communicating with the second network element.

[0076] In the above embodiment, the first network element can delete the first label in the first security context after the connection between the terminal and the second network element is released.

[0077] In some embodiments of the first aspect, the method further comprises:

[0078] sending a second message to the second network element, the second message being a response message to the second request.

[0079] In the above embodiments, the first network element can send a response message to the second network element after updating the first security context.

[0080] In a second aspect, the embodiments of the present disclosure provide a communication method, performed by a second network element, the method comprising:

[0081] receiving a first message sent by a first network element, the first message being used to update a first security context, the first security context being used to secure communications between a terminal and the first network element and communications between the terminal and the second network element, or to secure communications between the terminal and the second network element.

[0082] In some embodiments of the second aspect, the method further comprises:

[0083] receiving first signaling sent by the terminal, the first signaling being used to establish a connection between the terminal and the second network element;

[0084] sending, to the first network element, a first request according to the first signaling, the first request being used to request the first network element to send a first key of the second network element;

[0085] In some embodiments of the second aspect, the first signaling comprises at least one of the following: a key set identifier KSI, an identifier of the terminal, a sequence number SQN, an instance identifier of the second network element, a type of the second network element, the KSI being an identifier of the first security context; and the first request comprises at least one of the following: the KSI, the identifier of the terminal, the instance identifier of the second network element, the type of the second network element, and the SQN.

[0086] In some embodiments of the second aspect, the first message is determined by the first network element according to the first request, and the first message comprises at least one of the following: a first key of the second network element, an identifier of the terminal, an uplink count value, and a downlink count value.

[0087] In some embodiments of the second aspect, the method further comprises:

[0088] The first message is determined according to first signaling received by the first network element, the first signaling is used for the terminal to establish a connection with the second network element, and the first signaling includes at least one of the following: KSI, an identifier of the terminal, SQN, an instance identifier of the second network element, a type of the second network element, and the KSI is an identifier of the first security context; and the first message includes at least one of the following: the KSI, the identifier of the terminal, the SQN, the instance identifier of the second network element, the type of the second network element, a first key of the second network element, an uplink count value, and a downlink count value.

[0089] In some embodiments in combination with the second aspect, in some embodiments, the first signaling is not secured by the first security context, and the method further includes:

[0090] sending, to the terminal, a third message according to a second key of the second network element, the third message being used for activating the first security context to secure communication between the terminal and the second network element, and the second key of the second network element being determined according to the first key;

[0091] The third message includes at least one of the following: the KSI, a security algorithm selected by the second network element, the instance identifier of the second network element, the type of the second network element, and first indication information, the first indication information being used for indicating that the terminal does not reset an uplink count value and a downlink count value in the first security context.

[0092] In the above embodiments, if the first signaling is not secured by the first security context, the second network element can send the third message to the terminal to request to activate security protection between the terminal and the second network element.

[0093] In some embodiments in combination with the second aspect, in some embodiments, the method further includes:

[0094] receiving a fourth message sent by the terminal, the fourth message being used for indicating that the first security context is successfully activated to secure communication between the terminal and the second network element.

[0095] In the above embodiments, after the terminal determines that the fourth message is verified, the terminal can send the fourth message to the second network element to indicate that security between the second network element and the terminal is successfully activated.

[0096] In some embodiments in combination with the second aspect, in some embodiments, the method further includes:

[0097] performing security verification on the first signaling according to a second key of the second network element, wherein the second key of the second network element is determined according to the first key of the second network element, and the first signaling is securely protected by the first security context.

[0098] In the above embodiment, if the first signaling is securely protected by the first security context, the second network element can directly perform security verification on the first signaling.

[0099] In combination with some embodiments of the second aspect, in some embodiments, the method further includes:

[0100] storing first information, the first information including at least one of the following: an identifier of the terminal, the KSI, a second key of the second network element, a security algorithm selected by the second network element, an uplink count value, and a downlink count value, the second key of the second network element being determined according to the first key of the second network element.

[0101] In the above embodiment, the second network element can store the first information.

[0102] In combination with some embodiments of the second aspect, in some embodiments, the method further includes:

[0103] determining that a connection between the terminal and the second network element is released, and sending the second request to the first network element.

[0104] The second request includes at least one of the following: the KSI, the identifier of the terminal, the uplink count value, and the downlink count value.

[0105] In combination with some embodiments of the second aspect, in some embodiments, the method further includes:

[0106] receiving a second message sent by the first network element, the second message being a response message of the second request.

[0107] In combination with some embodiments of the second aspect, in some embodiments, the method further includes:

[0108] deleting a stored second security context of the second network element, the second security context being used for securely protecting communication between the second network element and the terminal.

[0109] In the above embodiment, the second network element can delete the stored second security context.

[0110] In a third aspect, the embodiments of the present disclosure provide a communication method, performed by a terminal, the method including:

[0111] sending first signaling to a first network element or a second network element;

[0112] The first signaling is used for the terminal to establish a connection with the second network element, and is used for the first network element to send a first message to the second network element, where the first message is used to update a first security context, and the first security context is used to secure communication between the terminal and the first network element and communication between the terminal and the second network element, or is used to secure communication between the terminal and the second network element. The first signaling includes at least one of a key set identifier KSI, an identifier of the terminal, a sequence number SQN, an instance identifier of the second network element, a type of the second network element, and the KSI is an identifier of the first security context.

[0113] In some embodiments in combination with the third aspect, in some embodiments, the first signaling is not secured by the first security context, and the method further includes:

[0114] receiving a third message sent by the second network element, where the third message is used to activate security protection between the terminal and the second network element;

[0115] performing security verification on the third message according to the first security context;

[0116] determining that the third message passes the security verification, and sending a fourth message to the second network element, where the fourth message is used to indicate that security protection between the terminal and the second network element by the first security context is successfully activated;

[0117] The third message includes at least one of the KSI, a security algorithm selected by the second network element, an instance identifier of the second network element, a type of the second network element, and first indication information, where the first indication information is used to indicate that the terminal does not reset uplink and downlink count values in the first security context.

[0118] In some embodiments in combination with the third aspect, in some embodiments, the first signaling is secured by the first security context.

[0119] In some embodiments in combination with the third aspect, in some embodiments, the method further includes:

[0120] determining that the connection between the terminal and the second network element is released, and updating the first security context.

[0121] In the above embodiments, if the connection between the terminal and the second network element is released, the terminal can update the stored first security context.

[0122] In a fourth aspect, the embodiments of the present disclosure provide a first network element, which can include at least one of a transceiver module, a processing module; wherein the first network element can be configured to perform the optional implementation manners of the first aspect.

[0123] In a fifth aspect, the embodiments of the present disclosure provide a second network element, which can include at least one of a transceiver module, a processing module; wherein the second network element can be configured to perform the optional implementation manners of the second aspect.

[0124] In a sixth aspect, the embodiments of the present disclosure provide a terminal, which can include at least one of a transceiver module, a processing module; wherein the terminal can be configured to perform the optional implementation manners of the third aspect.

[0125] In a seventh aspect, the embodiments of the present disclosure provide a first network element, which can include one or more processors; wherein the first network element can be configured to perform the optional implementation manners of the first aspect.

[0126] In an eighth aspect, the embodiments of the present disclosure provide a second network element, which can include one or more processors; wherein the second network element can be configured to perform the optional implementation manners of the second aspect.

[0127] In a ninth aspect, the embodiments of the present disclosure provide a terminal, which can include one or more processors; wherein the terminal can be configured to perform the optional implementation manners of the third aspect.

[0128] In a tenth aspect, the embodiments of the present disclosure provide a communication system, which can include a first network element, a second network element and a terminal; wherein the first network element is configured to perform the method described in the optional implementation manners of the first aspect, the second network element is configured to perform the method described in the optional implementation manners of the second aspect, and the terminal is configured to perform the method described in the optional implementation manners of the third aspect.

[0129] In an eleventh aspect, the embodiments of the present disclosure provide a storage medium, which stores instructions, when the instructions are run on a communication device, cause the communication device to perform the method described in the optional implementation manners of the first aspect or the second aspect or the third aspect.

[0130] In a twelfth aspect, the embodiments of the present disclosure provide a program product, which, when executed by a communication device, causes the communication device to perform the method described in the optional implementation manners of the first aspect or the second aspect or the third aspect.

[0131] In a thirteenth aspect, the embodiments of the present disclosure provide a computer program, which, when run on a computer, causes the computer to perform the method described in the optional implementation manners of the first aspect or the second aspect or the third aspect.

[0132] In a fourteenth aspect, an embodiment of the present disclosure provides a chip or chip system. The chip or chip system includes processing circuitry configured to perform the method described in the first aspect or the optional implementation of the second aspect or the third aspect.

[0133] In a fifteenth aspect, an embodiment of the present disclosure provides a communication device, which can be used to perform the method described in the optional implementation of the first aspect when the communication device is a first network element, the method described in the optional implementation of the second aspect when the communication device is a second network element, and the method described in the optional implementation of the third aspect when the communication device is a terminal.

[0134] It can be understood that the first network element, the second network element, the terminal, the communication device, the communication system, the storage medium, the program product, the computer program, the chip or the chip system can be used to perform the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved are referred to the beneficial effects in the corresponding method, which will not be described here.

[0135] The embodiments of the present disclosure propose a communication method, device and storage medium. In some embodiments, the terms of information transmission method, information processing method and communication method can be replaced with each other; the terms of information transmission device, information processing device, communication device and communication equipment can be replaced with each other; the terms of information processing system and communication system can be replaced with each other.

[0136] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments or some or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation of other embodiments.

[0137] In each embodiment of the present disclosure, the terms and / or descriptions between the embodiments are consistent if there is no special description and logical conflict, and can be referred to each other, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0138] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.

[0139] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as “one”, “a”, “the”, “above”, “said”, “preceding”, “this”, etc., can represent “one and only one”, and can also represent “one or more”, “at least one”, etc. For example, in the case of using articles such as “a”, “an”, “the” in English in translation, the noun after the article can be understood as singular expression, and can also be understood as plural expression.

[0140] In some embodiments, “plurality” can refer to two or more.

[0141] In some embodiments, the terms “at least one of”, “one or more of”, “a plurality of”, “multiple”, etc. can be replaced with each other.

[0142] In some embodiments, the writing manner of “at least one of A, B”, “A and / or B”, “A in one case, B in another case”, “responding to a case A, responding to another case B”, etc. can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments, A and B are selected to be executed (A and B are selectively executed); in some embodiments, A and B (A and B are both executed). When there are more branches of A, B, C, etc., it is similar to the above.

[0143] In some embodiments, the writing manner of “A or B” and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments, A and B are selected to be executed (A and B are selectively executed). When there are more branches of A, B, C, etc., it is similar to the above.

[0144] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments, and should not be construed as redundant limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different. For another example, the description object is "information", and "first information" and "second information" can be the same information or different information, and the contents thereof can be the same or different.

[0145] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0146] In some embodiments, the terms of "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.

[0147] In some embodiments, the terms of "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms of "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.

[0148] In some embodiments, an apparatus or the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments. The terms "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.

[0149] In some embodiments, a "network" can be interpreted as an apparatus (for example, an access network device, a core network device, and the like) included in the network.

[0150] In some embodiments, the terms "Access Network Device (AN Device)", "Radio Access Network Device (RAN Device)", "Base Station (BS)", "Radio Base Station", "Fixed Station", "Node", "Access Point", "Transmission Point (TP)", "Reception Point (RP)", "Transmission / Reception Point (TRP)", "Panel", "Antenna Panel", "Antenna Array", "Cell", "Macro Cell", "Small Cell", "Femto Cell", "Pico Cell", "Sector", "Cell Group", "Serving Cell", "Carrier", "Component Carrier", "Bandwidth Part (BWP)" and the like can be replaced with each other.

[0151] In some embodiments, the terms "terminal," "terminal device," "user equipment" (UE), "user terminal," "mobile station" (MS), "mobile terminal" (MT), subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, and the like can be used interchangeably.

[0152] In some embodiments, an access network device, a core network device, or a network device can be replaced with a terminal. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between an access network device, a core network device, or a network device and a terminal is replaced with communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), or the like). In this case, the structure in which the terminal has all or part of the functions of the access network device can also be provided. In addition, the terms "uplink," "downlink," and the like can be replaced with terms corresponding to the inter-terminal communication (e.g., "side"). For example, an uplink channel, a downlink channel, and the like can be replaced with a side channel or a direct connection channel, and an uplink, a downlink, and the like can be replaced with a side link or a direct connection link.

[0153] In some embodiments, a terminal can be replaced with an access network device, a core network device, or a network device. In this case, the structure in which the access network device, the core network device, or the network device has all or part of the functions of the terminal can also be provided.

[0154] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country where the location is situated.

[0155] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.

[0156] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0157] FIG. 1A is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure. As shown in FIG. 1A, the communication system 100 can include a first network element 101, a second network element 102, and a terminal device 103.

[0158] In some embodiments, the terminal device 103 can include at least one of a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a Pad, a computer with wireless transceiver function, a Virtual Reality (VR) terminal device, an Augmented Reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, but is not limited thereto.

[0159] In some embodiments, the technical solutions of the present disclosure can be applicable to the Open RAN architecture, at this time, the interfaces between the access network devices or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be realized through software or programs.

[0160] In some embodiments, the first network element 101 is a network element with a management access and mobility function, for example, is an Access and Mobility Management Function (AMF), or is a network element with an authentication function, for example, is an Authentication Server Function (AUSF) or a Security Anchor Functionality (SEAF), the name is not limited thereto, and it can also be other network elements that implement similar functions.

[0161] In some embodiments, the second network element 102 includes other network elements in addition to the first network element 101.

[0162] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed by the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new business scenarios appear, the technical solutions proposed by the embodiments of the present disclosure are also applicable to similar technical problems.

[0163] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1A or part of the subject, but are not limited thereto. The subjects shown in FIG. 1A are examples, and the communication system can include all or part of the subjects in FIG. 1A, or other subjects other than FIG. 1A. The number and form of each subject is arbitrary, each subject can be physical or virtual, the connection relationship between each subject is an example, each subject can not be connected or can be connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.

[0164] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio Access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based on them, or the like. Further, a plurality of systems can be combined (for example, combination of LTE or LTE-A and 5G, or the like).

[0165] In some embodiments of the present disclosure, in order to understand the embodiments of the present disclosure, the basic concepts related to the present disclosure are described.

[0166] 1、Non-Access Stratum message: refers to a message sent by a terminal to a core network element through a radio access node. Since the access node does not process it, it is called a Non-Access Stratum message. In the embodiments of the present disclosure, the message not processed by the access node is called a NAS (Non-Access Stratum) message or NAS signaling. It should be understood that the name of the message in the present disclosure is not limited, and the message not processed by the access node can also have other names (such as other possible names defined in future communication protocols).

[0167] 2、NAS message classification: According to the target core network element and function of the NAS message, the NAS message can be divided into MM NAS message, Session Management (SM) NAS message, Short Messaging Service (SMS) NAS message, and Call Control (CC) NAS message. In the 5G system, in addition to MM NAS, other types of NAS messages are first sent to the AMF by the UE through the access network, and then routed to other NFs by the AMF.

[0168] In some embodiments of the present disclosure, according to the description of the white paper “6G Architecture Scenarios” published by 5GPPP [1], the new 6G architecture should support streamlined network functions (NFs) to improve efficiency in terms of capacity, coverage, signaling overhead, scalability, and energy consumption. The dependencies between network functions can lead to unnecessary complexity and even cause delays. By redesigning network functions, the number of dependencies and processing points can be reduced. One way to improve the 6G architecture is to enhance the possibility of direct signaling between network functions to eliminate potential bottlenecks. Currently, many services require information to be transmitted from one Nextgeneration Radio Access Network (NG-RAN) node to another through the 5th Generation Core (5GC). In the 5GC, these information are relayed through the AMF, while in fact, only limited or even no AMF involvement can be required. FIG. IB is a schematic diagram of information transmission according to an embodiment of the present disclosure. As shown in FIG. IB, in order to simplify this transmission process, the introduction of Service Based Interface (SBI) will allow these information to be exchanged directly between NG-RAN network functions without going through the AMF. In FIG. IB, the Location Management Function (LMF), Network Repository Function (NRF), Policy Control Function (PCF), Unified Data Management (UDM), UE Radio Capability Management Function (UCMF), Session Management Function (SMF), Network Data Analytics Function (NWDAF), Network Exposure Function (NEF), User Plane Function (UPF), and Data Network (DN) are network elements in the Core Network (CN) for implementing different functions. Nlmf, Nnrf, Namf, Npcf, Nsmf, Nudm, Nnwdaf, Nucmf, Nnef, Nran, Nl, N2, N3, N4, and N6 are interface sequence numbers.

[0169] In some embodiments, if the RAN evolves to a service-based architecture, it means that the RAN node can act as a consumer to accept services from other network functions or as a producer to provide services to other network functions in addition to the AMF. In the current 5G system, NAS signaling (transmitted transparently through the RAN node) only supports communication between a user equipment (UE) and the AMF in the core network. If the RAN can evolve to communicate directly with other core network functions (NFs) without going through the AMF, it means that NAS signaling needs to be supported between the UE and other core NFs in addition to the AMF. FIG. 1C is a schematic diagram of a 6G architecture with multiple NAS instances, according to an embodiment of the present disclosure. As shown in FIG. 1C, a 6G architecture with multiple NAS instances can be enabled, such that the RAN node is able to communicate directly with any core NFs over service-based interfaces, and the UE is able to communicate directly with any core NFs using NAS signaling. For example, the UE can communicate with NFa over NAS-a and with NFb over NAS-b.

[0170] In some embodiments, the existing NAS COUNT mechanism defined in 3GPP TS 33.501 [2] cannot support the multi-NAS architecture. FIG. 1D is a schematic diagram of an encryption protection algorithm, according to an embodiment of the present disclosure. As shown in FIG. 1D, the count (NAS COUNT) is one of the inputs of the encryption protection algorithm (NEA) for each NAS signaling. FIG. 1E is a schematic diagram of an integrity protection algorithm, according to an embodiment of the present disclosure. As shown in FIG. 1E, the count (NAS COUNT) is one of the inputs of the integrity protection algorithm (NIA) for each NAS signaling. The NAS COUNT includes the values of two parts:

[0171] (1) The NAS sequence number (NAS SQN) of 8 bits, which is explicitly contained in the NAS message. This corresponds to the least significant 8 bits of the NAS COUNT.

[0172] (2) The NAS overflow value (NAS OVERFLOW) of 16 bits, which is maintained and synchronized as much as possible between the UE and the AMF. This corresponds to the most significant 16 bits of the NAS COUNT.

[0173] In some embodiments, the steps of the receiving entity handling the NAS OVERFLOW and the NAS COUNT when receiving a message are as follows:

[0174] (1) If the entity receives a message with a RECEIVED NAS SQN higher than the STORED NAS SQN, the entity shall assume that the sender used a NAS COUNT of (STORED NAS OVERFLOW)‖(RECEIVED NAS SQN) and verify the message integrity protection based on this assumption. If the integrity verification is successful, the receiving entity shall accept the message and update the STORED NAS SQN to the RECEIVED NAS SQN; otherwise, it shall reject the message.

[0175] (2) If the entity receives a message with a RECEIVED NAS SQN lower than the STORED NAS SQN, the entity shall assume that the sender used a NAS COUNT of (STORED NAS OVERFLOW + 1)‖(RECEIVED NAS SQN) and verify the message integrity protection based on this assumption. If the integrity verification is successful, the receiving entity shall accept the message, update its stored NAS SQN to the received NAS SQN, and increment its stored NAS OVERFLOW; otherwise, it shall reject the message.

[0176] In some embodiments, as defined in 3GPP TS 33.501 [2], the NAS COUNT is only maintained in the AMF and the UE, i.e. other network functions (NFs) do not store the respective NAS COUNT for sending / receiving NAS signaling. Without the correct NAS COUNT, the NAS signaling will be rejected by the receiver. This will impact the communication traffic over the NAS connection between the UE and other network functions. Therefore, how to enhance the NAS COUNT mechanism to support the multi-NAS architecture in 6G is a problem to be solved urgently.

[0177] FIG. 2A is an interaction schematic diagram of a communication method according to an embodiment of the disclosure. The method can be performed by the communication system described above. As shown in FIG. 2A, the method can include:

[0178] In step S2101, the terminal sends first signaling to the second network element.

[0179] In some embodiments, the second network element can receive the first signaling. For example, the second network element can receive the first signaling sent by the terminal. For another example, the second network element can also receive the first signaling sent by other entities.

[0180] In some embodiments, the first signaling is used to establish a connection, such as a NAS connection, between the terminal and the second network element.

[0181] In some embodiments, the first signaling is used to update the first security context.

[0182] In some embodiments, the first network element can comprise at least one of: an AUSF, an SEAF, an AMF.

[0183] In some embodiments, the second network element is any network element other than the first network element.

[0184] In some embodiments, the second network element can be referred to as an NF.

[0185] In some embodiments, the security context can be a NAS security context. For example, the first security context can be a first NAS security context, and the second security context can be a second NAS security context.

[0186] In some embodiments, the first signaling can be used to establish a NAS connection between the terminal and the second network element.

[0187] In some embodiments, the first signaling can be referred to as NAS signaling.

[0188] In some embodiments, the first signaling comprises at least one of: a Key Set Identifier (KSI), an identifier of the terminal, a Sequence Number (SQN), an instance identity of the second network element, a type of the second network element, the KSI being an identifier of the first security context.

[0189] In some embodiments, the identifier of the terminal can comprise at least one of: an International Mobile Subscriber Identity (IMSI), a Network Access Identifier (NAI), a Global Cable Identifier (GCI), a Global Line Identifier (GLI), a Subscription Concealed Identifier (SUCI), a Subscription Permanent Identifier (SUPI), a Globally Unique Temporary Identity (GUTI), a Generic Public Subscription Identifier (GPSI).

[0190] In some embodiments, if the terminal does not store the second security context of the second network element, the NAS signaling sent by the terminal to the second network element is not protected by security, and the value of the KSI included in the NAS signaling indicates that there is no available security context, for example, the value is 111.

[0191] In some embodiments, the first security context is stored in the terminal, and the first security context is used to protect the communication between the terminal and the first network element and the communication between the terminal and the second network element, or is used to protect the communication between the terminal and the second network element. The first security context is stored in the first network element, and the first security context is used to protect the communication between the terminal and the first network element. The second security context is stored in the second network element, and the second security context is used to protect the communication between the second network element and the terminal. The first security context and the second security context correspond to each other, for example, when the terminal sends NAS signaling to the second network element, the first security context can be used to protect the NAS signaling, and correspondingly, when the second network element sends NAS signaling to the terminal, the second security context can be used to protect the NAS signaling. The first security context and the second security context can have at least one same content. For example, the first security context and the second security context have the same NAS connection identifier (the connection identifier includes 3GPP access and non-3GPP access). For another example, the first security context and the second security context have the same selection algorithm. For another example, the first security context and the second security context have the same key for encryption protection and / or the same key for integrity protection.

[0192] In some embodiments, the first security context stored in the terminal can include the second security context.

[0193] In some embodiments, the first security context stored in the terminal is as shown in Table 1:

[0194] Table 1

[0195] In some embodiments, the first security context stored in the first network element is as shown in Table 2:

[0196] Table 2

[0197] As shown in Table 1, the first security context stored in the terminal includes a connection identifier, a KSI, an uplink count value, a downlink count value, a security context of the first network element, and a second security context of the second network element. The second security context of the second network element in Table 1 is the same as the second security context stored in the second network element.

[0198] As shown in Table 1, the first security context stored by the terminal also contains the security context of the first network element, which is used to protect the communication between the terminal and the first network element.

[0199] It should be noted that the first security context stored in Table 2 corresponds to the first security context stored in Table 1. For example, the KSI in Table 1 is the same as the KSI in Table 2, the uplink count value in Table 1 is the same as the uplink count value in Table 2, and the connection identifier in Table 1 is the same as the connection identifier in Table 2.

[0200] In step S2102, the second network element sends a first request to the first network element according to the first signaling.

[0201] In some embodiments, the first network element can receive the first request. For example, the first network element can receive the first request sent by the second network element. For another example, the first network element can also receive the first request sent by other entities.

[0202] In some embodiments, the first request can be used to obtain the first key of the second network element.

[0203] In some embodiments, the first key of the second network element is a root key of the communication between the terminal and the second network element.

[0204] In some embodiments, the first request can include at least one of the following: KSI, identifier of the terminal, SQN, instance identifier of the second network element, type of the second network element.

[0205] In some embodiments, the instance identifier and the type of the second network element are used to distinguish different network elements, for example, the instance identifiers and the types corresponding to different network elements are different.

[0206] In some embodiments, the instance identifier can also be referred to as instance ID.

[0207] In some embodiments, the first request can also be referred to as a key request.

[0208] In some embodiments, after the second network element receives the first signaling sent by the terminal, the second network element sends the first request to the first network element according to the first signaling.

[0209] In step S2103, the first network element determines the first key of the second network element according to the first request.

[0210] In some embodiments, after the first network element receives the first request sent by the second network element, the first network element can retrieve the first security context corresponding to the terminal according to the KSI and / or the identifier of the terminal contained in the first request, and obtain the first key of the second network element through vertical derivation.

[0211] In some embodiments, the first key of different network elements is associated with the terminal, for example, the first key of the first network element is associated with the terminal, and the first key of the second network element is also associated with the terminal. For the terminal side, the first keys corresponding to different network elements are different.

[0212] In some embodiments, the first network element can perform vertical derivation through a key derivation function (KDF) to obtain the first key of the second network element.

[0213] In some embodiments, the first key of the second network element can be represented as K NF .

[0214] Optionally, the input of the KDF can include the identifier of the terminal, an Anti-Bidding down Between Architectures (ABBA) parameter, an instance identifier or type of the second network element, and the first key of the first network element.

[0215] Optionally, the input of the KDF can include the identifier of the terminal, the ABBA parameter, the instance identifier or type of the second network element, a count value, and the first key of the first network element.

[0216] In some embodiments, the count value can include an uplink count value or a downlink count value.

[0217] In some embodiments, if the first signaling is NAS signaling, the count value can be a NAS count value, which can include an uplink NAS count value (UL NAS COUNT) or a downlink NAS count value (DL NAS COUNT).

[0218] In some embodiments, the first key of the first network element can be obtained in the network access process, and the specific obtaining method can refer to the existing protocol, which will not be described here.

[0219] Optionally, if the first network element is an AUSF, the first key of the first network element can be represented as K AUSF , if the first network element can be represented as SEAF, the first key of the first network element can be represented as K SEAF , and if the first network element is an AMF, the first key of the first network element can be represented as K AMF . For example, taking the first network element as an AMF, the identifier of the terminal, the ABBA parameter, the instance identifier or type of the second network element, the NAS count value, and K AMF are input into the KDF, and the KDF outputs K NF .

[0220] In some embodiments, if the NAS COUNT value inputted into the KDF is the UL NAS COUNT, the second network element can provide the SQN in the received first signaling to the first network element, i.e. include the SQN in the first request; if the NAS COUNT value inputted into the KDF is the DL NAS COUNT, the first network element can use the stored DL NAS COUNT to derive the K NF .

[0221] Step S2104, the first network element sends a first message to the second network element.

[0222] In some embodiments, the second network element can receive the first message. For example, the second network element can receive the first message sent by the first network element. For another example, the second network element can also receive the first message sent by other entities.

[0223] In some embodiments, the first message is a response message of the first request.

[0224] In some embodiments, the first message can be referred to as a key response message, a key response, etc.

[0225] In some embodiments, the first message can include at least one of the following: the first key of the second network element, the identifier of the terminal, the uplink count value, the downlink count value.

[0226] In some embodiments, the first message is used to update the first security context.

[0227] It should be understood that the second network element does not store the first security context, and the updated first security context includes the first key of the second network element, which is used by the second network element to determine the second key, which is used by the second network element to activate the security protection between the terminal and the second network element. After the security protection between the terminal and the second network element is activated, the communication between the terminal and the second network element can be secured by the first security context.

[0228] Step S2105, the first network element adds a first label in the first security context.

[0229] In some embodiments, the first label is used to indicate that the terminal is communicating with the second network element.

[0230] In some embodiments, if the communication between the terminal and different NFs cannot be parallel, i.e. during the communication between the terminal and the second network element, other network elements except the second network element cannot establish a NAS connection with the terminal.

[0231] In some embodiments, after the first network element receives the first request sent by the second network element, the first network element can add the first label in the stored first security context, indicating that the terminal is communicating with the second network element.

[0232] In some embodiments, if the first network element determines that the first label is included in the first security context, the first network element can reject a request for obtaining the first key sent by a network element other than the second network element.

[0233] For example, if the second network element is an NF A During the communication between the terminal and the NF A , the first network element can reject a key request sent by the NF B .

[0234] It should be noted that the execution order of step S2105 is not limited in the embodiments of the present disclosure, and step S2105 can be exchanged with any one of steps S2106-S2109 or executed simultaneously.

[0235] In step S2106, the second network element sends a third message to the terminal according to the second key of the second network element.

[0236] In some embodiments, the terminal can receive the third message. For example, the terminal can receive the third message sent by the second network element. For another example, the terminal can also receive the third message sent by another entity.

[0237] In some embodiments, the third message is used to activate security protection between the terminal and the second network element.

[0238] It should be understood that after the security protection between the terminal and the second network element is activated, the communication between the terminal and the second network element can be secured by the first security context.

[0239] In some embodiments, the third message is used to activate the first security context to secure the communication between the terminal and the second network element.

[0240] In some embodiments, the third message includes at least one of the following: the KSI, the security algorithm selected by the second network element, the instance identifier of the second network element, the type of the second network element, and the first indication information indicating that the terminal does not reset the uplink count value and the downlink count value in the first security context.

[0241] In some embodiments, the first indication information can also be referred to as no_change_count indication.

[0242] In some embodiments, the third message can be referred to as a security mode command (SMC) message.

[0243] In some embodiments, after the second network element receives the first key sent by the first network element, the second network element can derive the second key according to the first key.

[0244] Optionally, the second key can comprise a key for ciphering protection and / or a key for integrity protection. The key for ciphering protection can be denoted as K NF_ENC , and the key for integrity protection can be denoted as K NF_INT .

[0245] It should be noted that the specific method of deriving the second key can refer to the description of the existing protocol, which will not be repeated here.

[0246] In some embodiments, the second network element can send the third message to the terminal according to the derived K NF_ENC and / or K NF_INT . It should be understood that the third message is a message that is securely protected by K NF_ENC and / or K NF_INT .

[0247] Step S2107, the terminal performs security verification on the third message according to the first security context.

[0248] In some embodiments, after receiving the third message sent by the second network element, the terminal can derive the first key and the second key of the second network element according to the first security context, and perform security verification on the third message by the second key of the second network element.

[0249] It should be noted that the method of deriving the first key by the terminal can refer to the method of deriving the first key by the first network element in step S2103, which will not be repeated here.

[0250] In some embodiments, the terminal can perform decryption processing on the third message by the derived K NF_ENC , and if successful decryption is performed, it means that the third message passes the security verification.

[0251] In some embodiments, the terminal can verify the integrity of the third message by the derived K NF_INT , and if the integrity of the third message is verified, it means that the third message passes the security verification.

[0252] In some embodiments, the terminal can perform decryption processing on the third message by the derived K NF_ENC , and verify the integrity of the third message by the derived K NF_INT , and if successful decryption and integrity verification are performed, it means that the third message passes the security verification.

[0253] In some embodiments, if the third message comprises first indication information, the terminal will not reset the uplink count value and the downlink count value to 0.

[0254] In some embodiments, the terminal determines that the third message is verified, and the communication between the terminal and the second network element is protected by the first security context and the second security context.

[0255] In some embodiments, during the communication between the terminal and the second network element, for an uplink (UL) message, the terminal increases the UL NAS COUNT by 1, and the second network element synchronously updates the UL NAS COUNT; for a downlink (DL) message, the second network element increases the DL NAS COUNT by 1, and the terminal synchronously updates the DL NAS COUNT.

[0256] Step S2108, the terminal determines that the third message passes the security verification, and sends a fourth message to the second network element.

[0257] In some embodiments, the second network element can receive the fourth message. For example, the second network element can receive the fourth message sent by the terminal. For another example, the second network element can also receive the fourth message sent by another entity.

[0258] In some embodiments, the fourth message is a response message of the third message.

[0259] In some embodiments, the fourth message can also be referred to as a security mode complete message.

[0260] In some embodiments, the fourth message is used to indicate that the security between the second network element and the terminal is successfully activated. It should be understood that the successful activation of the security between the second network element and the terminal means that the communication between the second network element and the terminal is protected by the first security context and the second security context.

[0261] It should be understood that the fourth message sent by the terminal to the second network element is encrypted and integrity protected by the first security context.

[0262] In some embodiments, after the second network element receives the fourth message sent by the terminal, the second network element can send a NAS signaling to the terminal.

[0263] Step S2109, the second network element stores the first information.

[0264] In some embodiments, the first information can include at least one of the following: an identifier of the terminal, the KSI, a second key of the second network element, a security algorithm selected by the second network element, an uplink count value, and a downlink count value.

[0265] In some embodiments, after the second network element receives the fourth message sent by the terminal, the second network element can store the first information.

[0266] It should be noted that step S2109 can be exchanged with step S2108 or performed at the same time.

[0267] Step S2110, the second network element determines that the connection between the terminal and the second network element is released, and sends a second request to the first network element.

[0268] In some embodiments, the first network element can receive the second request. For example, the first network element can receive the second request sent by the second network element. For another example, the first network element can also receive the second request sent by other entities.

[0269] In some embodiments, the second request is used to request the first network element to update the first security context.

[0270] In some embodiments, the second request can also be referred to as a UE security context update request, a UE context update request, etc.

[0271] In some embodiments, the second request can include at least one of the following: KSI, identifier of the terminal, uplink count value, downlink count value.

[0272] In some embodiments, after the NAS connection between the terminal and the second network element is released, the second network element can send the second request to the first network element.

[0273] Step S2111, the first network element updates the first security context according to the second request.

[0274] In some embodiments, after the first network element receives the second request sent by the second network element, the first network element can update the first security context of the terminal according to the KSI and / or the identifier of the terminal in the second request.

[0275] In some embodiments, the first network element can update at least one of the following: uplink count value, downlink count value, in the stored first security context according to the second request.

[0276] For example, the first network element can update the uplink count value in Table 2 to the uplink count value in the second request, and update the downlink count value in Table 2 to the downlink count value in the second request.

[0277] Step S2112, the first network element deletes the first label in the first security context.

[0278] It should be understood that after the first network element receives the second request, the first network element can determine that the connection between the terminal and the second network element has been released, delete the first label in the stored first security context, which means that the first network element can receive the key request sent by other network elements.

[0279] For example, the first network element can delete the first label in Table 2.

[0280] Step S2113, the first network element sends a second message to the second network element.

[0281] In some embodiments, the second network element can receive the second message. For example, the second network element can receive the second message sent by the first network element. For another example, the second network element can also receive the second message sent by other entities.

[0282] In some embodiments, the second message is a response message of the second request.

[0283] In some embodiments, the second message can also be referred to as a UE security context update response, a UE context update response, etc.

[0284] In some embodiments, after the first network element completes the update of the first security context, the first network element can send the second message to the second network element.

[0285] Step S2114, the terminal updates the first security context.

[0286] In some embodiments, after the terminal determines that the connection with the second network element is released, the terminal can delete the second security context of the second network element in the stored first security context. For example, the terminal can delete the second security context of the second network element in Table 1, i.e., the first key of the second network element, the key for integrity protection, the key for encryption protection, and the selected algorithm.

[0287] In some embodiments, the terminal can also update at least one of the following in the stored first security context: the uplink count value and the downlink count value. For example, the terminal can update the uplink count value and / or the downlink count value in Table 1, such as setting the uplink count value and / or the downlink count value in Table 1 to 0.

[0288] Step S2115, the second network element deletes the stored second security context of the second network element.

[0289] In some embodiments, after the second network element determines that the connection with the terminal is released, the second network element can delete the stored second security context of the second network element.

[0290] With the above method, when the communication between the terminal and the second network element is protected by the first security context, the first security context can be updated by the first network element, thereby realizing secure communication under the multi-NAS architecture.

[0291] The method related to the embodiments of the present disclosure can include at least one of the steps S2101-S2115. For example, the step S2101 can be implemented as an independent embodiment, the step S2104 can be implemented as an independent embodiment, the step S2105 can be implemented as an independent embodiment, the step S2106 can be implemented as an independent embodiment, the step S2109 can be implemented as an independent embodiment, the step S2111 can be implemented as an independent embodiment, the step S2112 can be implemented as an independent embodiment, the step S2114 can be implemented as an independent embodiment, the step S2115 can be implemented as an independent embodiment, the step S2101+the step S2102 can be implemented as an independent embodiment, the step S2102+the step S2103 can be implemented as an independent embodiment, the step S2103+the step S2104 can be implemented as an independent embodiment, the step S2106+the step S2108 can be implemented as an independent embodiment, the step S2110+the step S2113 can be implemented as an independent embodiment, the step S2101+the step S2102+the step S2103+the step S2104 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.

[0292] In some embodiments, any two steps among the steps S2101-S2115 can be exchanged in order or executed simultaneously. For example, the step S2111 and the step S2112 can be exchanged in order or executed simultaneously, the step S2113 and any one of the steps S2111, the step S2112 or the step S2114 can be exchanged in order or executed simultaneously, the step S2115 and any one of the steps S2111-S2114 can be exchanged in order or executed simultaneously.

[0293] In some embodiments, the steps S2101-S2115 are optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0294] In some embodiments, other optional implementations described before or after the description corresponding to FIG. 2A can be referred to.

[0295] FIG. 2B is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure. The method can be performed by the communication system described above. As shown in FIG. 2B, the method can include:

[0296] The step S2201, the terminal sends first signaling to the second network element.

[0297] It should be noted that the definition of the first signaling in the step S2201 can refer to the description of the step S2101, which will not be repeated here.

[0298] In some embodiments, the first signaling is security protected by the first security context.

[0299] For example, the terminal can derive the first key of the second network element through the existing first security context, and derive the second key of the second network element according to the first key, and security protect the first signaling through the second key.

[0300] It should be noted that the method for the terminal to derive the first key can refer to the method for the first network element to derive the first key in step S2103, which will not be repeated here.

[0301] In step S2202, the second network element sends a first request to the first network element according to the first signaling.

[0302] The optional implementation of step S2202 can refer to the optional implementation of step S2102 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0303] In step S2203, the first network element determines the first key of the second network element according to the first request.

[0304] The optional implementation of step S2203 can refer to the optional implementation of step S2103 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0305] In step S2204, the first network element sends a first message to the second network element.

[0306] The optional implementation of step S2204 can refer to the optional implementation of step S2104 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0307] In step S2205, the first network element adds a first label in the first security context.

[0308] The optional implementation of step S2205 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0309] In step S2206, the second network element security verifies the first signaling according to the second key of the second network element.

[0310] In some embodiments, after the second network element receives the first key sent by the first network element, the second network element can derive the second key according to the first key, and security verify the first signaling through the second key.

[0311] In some embodiments, the second network element can security verify the first signaling through the derived KNF_ENC decrypting the first signaling, if the first signaling is successfully decrypted, indicating that the first signaling passes the security verification.

[0312] In some embodiments, the second network element can derive the K NF_INT verifying the integrity of the first signaling, if the first signaling is verified to be complete, indicating that the first signaling passes the security verification.

[0313] In some embodiments, the second network element can derive the K NF_ENC decrypting the first signaling by using the derived K NF_INT verifying the integrity of the first signaling, if the first signaling is successfully decrypted and verified to be complete, indicating that the first signaling passes the security verification.

[0314] In some embodiments, the second network element determines that the first signaling passes the verification, indicating that the terminal and the second network element can perform secure communication.

[0315] It should be understood that the communication between the terminal and the second network element can be securely protected by the first security context and the second security context.

[0316] In some embodiments, during the communication between the terminal and the second network element, for uplink (UL) messages, the terminal increases the UL NAS COUNT by 1, and the second network element synchronously updates the UL NAS COUNT; for downlink (DL) messages, the second network element increases the DL NAS COUNT by 1, and the terminal synchronously updates the DL NAS COUNT.

[0317] In some embodiments, if the first signaling passes the verification, step S2207 is performed.

[0318] In step S2207, the second network element stores the first information.

[0319] The optional implementation of step S2207 can refer to the optional implementation of step S2109 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0320] In step S2208, the second network element determines to release the connection between the terminal and the second network element, and sends a second request to the first network element.

[0321] The optional implementation of step S2208 can refer to the optional implementation of step S2110 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0322] In step S2209, the first network element updates the first security context according to the second request.

[0323] The optional implementation of step S2209 can refer to the optional implementation of step S2111 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0324] In step S2210, the first network element deletes the first label in the first security context.

[0325] The optional implementation of step S2210 can refer to the optional implementation of step S2112 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0326] In step S2211, the first network element sends a second message to the second network element.

[0327] The optional implementation of step S2211 can refer to the optional implementation of step S2113 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0328] In step S2212, the terminal updates the first security context.

[0329] The optional implementation of step S2212 can refer to the optional implementation of step S2114 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0330] In step S2213, the second network element deletes the stored second security context of the second network element.

[0331] The optional implementation of step S2213 can refer to the optional implementation of step S2115 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0332] By using the above method, when the communication between the terminal and the second network element is protected by the first security context, the first network element can update the first security context, thereby realizing secure communication under the multi-NAS architecture; and when the first signaling is protected, the second network element can directly perform security verification on the first signaling, without the need to send an SMC message, thereby saving signaling.

[0333] The method related to the embodiments of the present disclosure can include at least one of the steps S2201-S2213. For example, the step S2201 can be implemented as an independent embodiment, the step S2204 can be implemented as an independent embodiment, the step S2205 can be implemented as an independent embodiment, the step S2206 can be implemented as an independent embodiment, the step S2207 can be implemented as an independent embodiment, the step S2208 can be implemented as an independent embodiment, the step S2209 can be implemented as an independent embodiment, the step S2210 can be implemented as an independent embodiment, the step S2212 can be implemented as an independent embodiment, the step S2213 can be implemented as an independent embodiment, the step S2201+the step S2202 can be implemented as an independent embodiment, the step S2202+the step S2203 can be implemented as an independent embodiment, the step S2203+the step S2204 can be implemented as an independent embodiment, the step S2208+the step S2211 can be implemented as an independent embodiment, the step S2201+the step S2202+the step S2203+the step S2204 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.

[0334] In some embodiments, any two steps among the steps S2201-S2213 can be exchanged in order or performed simultaneously. For example, the step S2204 and the step S2205 can be exchanged in order or performed simultaneously, the step S2209 and the step S2210 can be exchanged in order or performed simultaneously, the step S2211 and the step S2209, the step S2210, or the step S2212 can be exchanged in order or performed simultaneously, the step S2213 and any one of the steps S2209-S2212 can be exchanged in order or performed simultaneously.

[0335] In some embodiments, the steps S2201-S2213 are optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0336] FIG. 2C is an interaction diagram of a communication method according to an embodiment of the present disclosure. The method can be performed by the communication system described above. As shown in FIG. 2C, the method can include:

[0337] In step S2301, the terminal sends first signaling to the first network element.

[0338] In some embodiments, the first network element can receive the first signaling. For example, the first network element can receive the first signaling sent by the terminal. For another example, the first network element can also receive the first signaling sent by another entity.

[0339] In some embodiments, the first signaling is used for the terminal to establish a connection, such as a NAS connection, with the second network element.

[0340] In some embodiments, the first signaling is used for updating the first security context.

[0341] In some embodiments, the second network element comprises at least one of: the first network element, the second network element.

[0342] In some embodiments, the first network element can comprise at least one of: an AUSF, an SEAF, an AMF.

[0343] In some embodiments, the second network element is any network element other than the first network element.

[0344] In some embodiments, the second network element can be referred to as an NF.

[0345] In some embodiments, the security context can be a NAS security context.

[0346] In some embodiments, the first security context can be a NAS security context of the terminal. For example, the first security context can be a first NAS security context, and the second security context can be a second NAS security context.

[0347] In some embodiments, the first signaling can be used for establishing a NAS connection between the terminal and the second network element.

[0348] In some embodiments, the first signaling can be referred to as a NAS signaling.

[0349] In some embodiments, the first signaling comprises at least one of: a KSI, an identifier of the terminal, an SQN, an instance identity of the second network element, a type of the second network element.

[0350] In some embodiments, the identifier of the terminal can comprise at least one of: an IMSI, an NAI, a GCI, a GLI, a SUCI, a SUPI, a GUTI, a GPSI.

[0351] In some embodiments, if the terminal does not store the second security context of the second network element, the NAS signaling sent by the terminal to the second network element is not protected by security, and the value of the KSI contained in the NAS signaling indicates that there is currently no available security context, for example, the value.

[0352] In some embodiments, the first security context is stored in the terminal, and is used for security protection of the communication between the terminal and the first network element, and the communication between the terminal and the second network element, or is used for security protection of the communication between the terminal and the second network element. The first security context is stored in the first network element, and is used for security protection of the communication between the terminal and the first network element. The second security context is stored in the second network element, and is used for security protection of the communication between the second network element and the terminal. The first security context and the second security context correspond to each other, for example, when the terminal sends NAS signaling to the second network element, the first security context can be used to protect the NAS signaling, and correspondingly, when the second network element sends NAS signaling to the terminal, the second security context can be used to protect the NAS signaling. The first security context and the second security context can have at least one same content. For example, the first security context and the second security context have the same NAS connection identifier (the connection identifier includes 3GPP access and non-3GPP access). For another example, the first security context and the second security context have the same selection algorithm. For yet another example, the first security context and the second security context have the same key for encryption protection and / or the key for integrity protection.

[0353] In some embodiments, the first security context stored in the terminal is shown in Table 1, and the first security context stored in the first network element is shown in Table 2.

[0354] As shown in Table 1, the first security context stored in the terminal includes a connection identifier, a KSI, an uplink count value, a downlink count value, a security context of the first network element, and a second security context of the second network element. The second security context of the second network element in Table 1 is the same as the second security context stored in the second network element.

[0355] As shown in Table 1, the first security context stored in the terminal also includes the security context of the first network element, which is used for security protection of the communication between the terminal and the first network element.

[0356] In step S2302, the first network element determines the first key of the second network element according to the first signaling.

[0357] In some embodiments, after the first network element receives the first signaling sent by the terminal, the first network element can perform security verification on the first signaling.

[0358] In some embodiments, the first network element can perform decryption processing on the first signaling, and if the decryption is successful, it indicates that the first signaling passes the security verification.

[0359] In some embodiments, the first network element can verify the integrity of the first signaling, and if the first signaling is verified to be complete, it means that the first signaling passes the security verification.

[0360] In some embodiments, the first network element can decrypt the first signaling and verify the integrity of the first signaling, and if the first signaling is successfully decrypted and verified to be complete, it means that the first signaling passes the security verification.

[0361] In some embodiments, if the first signaling fails the verification, a failure indication message is sent to the terminal.

[0362] In some embodiments, after the first signaling passes the security verification, the first security context of the terminal can be retrieved according to the KSI contained in the first signaling and / or the identifier of the terminal, and the first key of the second network element can be derived by vertical derivation.

[0363] It should be noted that the method for the first network element to derive the first key can refer to step S2103, which will not be described here.

[0364] Step S2303, the first network element sends a first message to the second network element.

[0365] In some embodiments, the second network element can receive the first message. For example, the second network element can receive the first message sent by the first network element. For another example, the second network element can also receive the first message sent by other entities.

[0366] In some embodiments, the first message can include at least one of the following: KSI, identifier of the terminal, SQN, instance identifier of the second network element, type of the second network element, first key of the second network element, uplink count value, downlink count value.

[0367] In some embodiments, the first network element can transparently transmit the first signaling sent by the terminal to the second network element, and carry the first key of the second network element.

[0368] In some embodiments, the first message is used to update the first security context.

[0369] It should be understood that the second network element does not store the first security context, and the updated first security context contains the first key of the second network element, which is used by the second network element to determine the second key, which is used by the second network element to activate the security protection between the terminal and the second network element. After the security protection between the terminal and the second network element is activated, the communication between the terminal and the second network element can be secured by the first security context, and the first security context can be updated.

[0370] Step S2304, the first network element adds a first label in the first security context.

[0371] The optional implementation of step S2304 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0372] In step S2305, the second network element sends a third message to the terminal according to the second key of the second network element.

[0373] The optional implementation of step S2305 can refer to the optional implementation of step S2106 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0374] In step S2306, the terminal performs security verification on the third message according to the first security context.

[0375] The optional implementation of step S2306 can refer to the optional implementation of step S2107 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0376] In step S2307, the terminal determines that the third message passes the security verification, and sends a fourth message to the second network element.

[0377] The optional implementation of step S2307 can refer to the optional implementation of step S2108 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0378] In step S2308, the second network element stores the first information.

[0379] The optional implementation of step S2308 can refer to the optional implementation of step S2109 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0380] In step S2309, the second network element determines that the connection between the terminal and the second network element is released, and sends a second request to the first network element.

[0381] The optional implementation of step S2309 can refer to the optional implementation of step S2110 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0382] In step S2310, the first network element updates the first security context according to the second request.

[0383] The optional implementation of step S2310 can refer to the optional implementation of step S2111 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0384] The first network element deletes the first label in the first security context in step S2311.

[0385] The optional implementation of step S2311 can refer to the optional implementation of step S2112 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0386] The first network element sends a second message to the second network element in step S2312.

[0387] The optional implementation of step S2312 can refer to the optional implementation of step S2113 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0388] The terminal updates the first security context in step S2313.

[0389] The optional implementation of step S2313 can refer to the optional implementation of step S2114 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0390] The second network element deletes the stored second security context of the second network element in step S2314.

[0391] The optional implementation of step S2314 can refer to the optional implementation of step S2115 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0392] With the above method, when the communication between the terminal and the second network element is protected by the first security context, the first security context can be updated by the first network element, thereby realizing secure communication under the multi-NAS architecture.

[0393] The method related to the embodiments of the present disclosure can include at least one of the steps S2301-S2314. For example, the step S2301 can be implemented as an independent embodiment, the step S2304 can be implemented as an independent embodiment, the step S2305 can be implemented as an independent embodiment, the step S2308 can be implemented as an independent embodiment, the step S2310 can be implemented as an independent embodiment, the step S2311 can be implemented as an independent embodiment, the step S2313 can be implemented as an independent embodiment, the step S2314 can be implemented as an independent embodiment, the step S2301+the step S2302 can be implemented as an independent embodiment, the step S2302+the step S2303 can be implemented as an independent embodiment, the step S2305+the step S2307 can be implemented as an independent embodiment, the step S2309+the step S2312 can be implemented as an independent embodiment, the step S2301+the step S2302+the step S2303 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.

[0394] In some embodiments, any two steps among the steps S2301-S2314 can be exchanged in order or performed simultaneously. For example, the step S2303 and the step S2304 can be exchanged in order or performed simultaneously, the step S2310 and the step S2311 can be exchanged in order or performed simultaneously, the step S2312 and any one of the steps S2310, S2311 or S2313 can be exchanged in order or performed simultaneously, the step S2314 and any one of the steps S2310-S2313 can be exchanged in order or performed simultaneously.

[0395] In some embodiments, the steps S2301-S2314 are optional, and one or more of the steps can be omitted or replaced in different embodiments.

[0396] FIG. 2D is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure. The method can be performed by the communication system described above. As shown in FIG. 2D, the method can include:

[0397] In step S2401, the terminal sends first signaling to the first network element.

[0398] It should be noted that the definition of the first signaling in the step S2401 can refer to the description of the step S2101, which will not be repeated here.

[0399] In some embodiments, the first signaling is securely protected by the first security context.

[0400] For example, the terminal can derive the first key of the second network element through the existing first security context, and derive the second key of the second network element according to the first key, through which the first signaling is securely protected.

[0401] It should be noted that the method for the terminal to derive the first key can refer to the method for the first network element to derive the first key in step S2103, which will not be repeated here.

[0402] Step S2402, the first network element determines the first key of the second network element according to the first signaling.

[0403] In some embodiments, the first network element can derive the first key of the second network element.

[0404] It should be noted that the method for the first network element to derive the first key can refer to step S2103, which will not be repeated here.

[0405] Step S2403, the first network element sends a first message to the second network element.

[0406] In some embodiments, the second network element can receive the first message. For example, the second network element can receive the first message sent by the first network element. For another example, the second network element can also receive the first message sent by other entities.

[0407] In some embodiments, the first message includes at least one of the following: KSI, identifier of the terminal, SQN, instance identifier of the second network element, type of the second network element, first key of the second network element, uplink count value, downlink count value.

[0408] In some embodiments, the first network element can transparently transmit the first signaling sent by the terminal to the second network element, and carry the first key of the second network element.

[0409] It should be noted that the derivation method of the first key of the second network element is described in step S2103, which will not be repeated here.

[0410] In some embodiments, steps S2402-S2403 can also be omitted. After the first network element receives the first signaling sent by the terminal, it can also transparently transmit the first signaling to the second network element. After the second network element receives the first signaling, it can refer to steps S2102-S2104 to send a first request to the first network element. After the first network element receives the first request, it determines the first key of the second network element, and sends a first message to the second network element. After the second network element receives the first message, it executes step S2405.

[0411] Step S2404, the first network element adds a first label in the first security context.

[0412] The optional implementation of step S2404 can refer to the optional implementation of step S2105 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0413] In step S2405, the second network element performs security verification on the first signaling according to the second key of the second network element.

[0414] The optional implementation of step S2405 can refer to the optional implementation of step S2206 in FIG. 2B and other associated parts in the embodiments related to FIG. 2B, which will not be repeated here.

[0415] In step S2406, the second network element stores the first information.

[0416] The optional implementation of step S2406 can refer to the optional implementation of step S2109 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0417] In step S2407, the second network element determines to release the connection between the terminal and the second network element, and sends a second request to the first network element.

[0418] The optional implementation of step S2407 can refer to the optional implementation of step S2110 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0419] In step S2408, the first network element updates the first security context according to the second request.

[0420] The optional implementation of step S2408 can refer to the optional implementation of step S2111 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0421] In step S2409, the first network element deletes the first label in the first security context.

[0422] The optional implementation of step S2409 can refer to the optional implementation of step S2112 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0423] In step S2410, the first network element sends a second message to the second network element.

[0424] The optional implementation of step S2410 can refer to the optional implementation of step S2113 in FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.

[0425] In step S2411, the terminal updates the first security context.

[0426] The optional implementation of step S2411 can refer to the optional implementation of step S2114 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0427] In step S2412, the second network element deletes the stored second security context of the second network element.

[0428] The optional implementation of step S2412 can refer to the optional implementation of step S2115 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.

[0429] With the above method, when the communication between the terminal and the second network element is protected by the first security context, the first security context can be updated by the first network element, thereby realizing secure communication under the multi-NAS architecture; and when the first signaling is protected, the second network element can directly perform security verification on the first signaling, without the need to send an SMC message, thereby saving signaling.

[0430] The method involved in the embodiments of the present disclosure can include at least one of the above steps S2401-S2412. For example, step S2401 can be implemented as an independent embodiment, step S2404 can be implemented as an independent embodiment, step S2406 can be implemented as an independent embodiment, step S2408 can be implemented as an independent embodiment, step S2409 can be implemented as an independent embodiment, step S2411 can be implemented as an independent embodiment, step S2412 can be implemented as an independent embodiment, step S2401+step S2402 can be implemented as an independent embodiment, step S2402+step S2403 can be implemented as an independent embodiment, step S2407+step S2410 can be implemented as an independent embodiment, step S2401+step S2402+step S2403 can be implemented as an independent embodiment, but not limited thereto.

[0431] In some embodiments, the order of any two steps among steps S2401-S2412 can be exchanged or executed simultaneously. For example, step S2404 and step S2405 can be exchanged or executed simultaneously, step S2409 and step S2408 can be exchanged or executed simultaneously, step S2411 and step S2408, step S2409 or step S2410 can be exchanged or executed simultaneously, and step S2412 and any one of steps S2408-S2411 can be exchanged or executed simultaneously.

[0432] In some embodiments, steps S2401-S2412 are optional, and one or more of these steps can be omitted or replaced in different embodiments.

[0433] In some embodiments, the name of information and the like is not limited to the name described in the embodiments, and the terms of "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", "chip", and the like can be replaced with each other.

[0434] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be replaced with each other, and can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and the like.

[0435] In some embodiments, the terms of "send", "transmit", "report", "issue", "transmit", "bidirectional transmission", "send and / or receive" can be replaced with each other.

[0436] In some embodiments, the terms of "certain", "preset", "preset", "set", "indicated", "certain", "arbitrary", "first", and the like can be replaced with each other, and "certain A", "preset A", "preset A", "set A", "indicated A", "certain A", "arbitrary A", "first A" can be interpreted as A specified in advance in protocols and the like, can be interpreted as A obtained by setting, configuring, or indicating, and can be interpreted as certain A, certain A, arbitrary A, or first A, but is not limited thereto.

[0437] In some embodiments, the purpose of the embodiments of the present disclosure is to ensure that the AUSF / AMF / SEAF can maintain the NAS COUNT in the communication under the multi-NAS architecture.

[0438] In some embodiments, an object of the embodiments of the present disclosure is to provide a NAS COUNT synchronization method between NF and AUSF / AMF / SEAF.

[0439] In some embodiments, the AUSF / SEAF / AMF and the UE can maintain the UE NAS context identified by KSI. When the NAS connection between the NF and the UE is released, no information is stored in the NF and the UE.

[0440] In some embodiments, the NAS context structure stored in the UE is shown in Table 3:

[0441] Table 3

[0442] In some embodiments, the NAS context structure stored in the AUSF / SEAF / AMF is shown in Table 4:

[0443] Table 4

[0444] FIG. 3A is an interaction diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 3A, the embodiments of the present disclosure relate to a communication method, which can be performed by a communication system. The method can include:

[0445] Step S3101, the UE sends NAS signaling to the NF.

[0446] In some embodiments, the UE sends the NAS signaling to initiate a request to establish a NAS connection with the NF.

[0447] In some embodiments, the initial NAS signaling for NAS connection establishment can be forwarded by the AMF.

[0448] In some embodiments, if the NAS signaling is forwarded by the AMF, the NAS signaling can be protected by the NAS security context of the AMF. The NAS signaling contains KSI (i.e., the identifier of the UE NAS security context) and the UE identifier.

[0449] In some embodiments, if the NAS signaling is sent directly to the NF and no existing NAS security context of the NF is stored, the NAS signaling is not protected. The NAS signaling contains KSI (value 111) and the UE identifier.

[0450] In some embodiments, the AMF / SEAF / AUSF can provide the K NF and KSI / KSI NF to the NF after receiving the NAS signaling from the UE. In this case, no key request / response needs to be performed between the AMF / SEAF / AUSF and the NF.

[0451] Step S3102, the NF sends a key request to the AUSF / AMF / SEAF and receives a key response sent by the AUSF / AMF / SEAF.

[0452] In some embodiments, the key request can include KSI, UE identifier, NF instance ID / NF type and SQN in received NAS signaling.

[0453] In some embodiments, the AUSF / AMF / SEAF retrieves the UE's NAS security context based on KSI and / or UE identifier and derives K NF by vertical derivation. The SEAF / AMF / AUSF can maintain a flag in the UE NAS security context indicating that the UE is communicating with the NF.

[0454] In some embodiments, the key response message includes K NF , UL NAS COUNT and DL NAS COUNT, UE identifier and KSI (optional).

[0455] In some embodiments, K NF_INT is the key for integrity protection derived from K NF . N NF_ENC is the key for encryption protection derived from K NF .

[0456] In some embodiments, K NF Vertical derivation: the input S of the Key Derivation Function (KDF) is: UE identifier (such as IMSI, NAI, GCI or GLI), ABBA parameter, NF instance ID. The input key KEY is K AUSF / K SEAF / K AMF .

[0457] In some embodiments, the input S of the KDF is: UE identifier (such as International Mobile Subscriber Identification Number (IMSI), Network Access Identifier (NAI), Global Cell Identity (GCI) or Global Line Identifier (GLI), ABBA parameter, NF instance ID and NAS COUNT. The input key KEY is K AUSF / K SEAF / K AMFIf UL NAS COUNT is used to generate K NF , the NF provides the received SQN to the AMF / SEAF / AUSF. If DL NAS COUNT is used to generate K NF , the AMF / SEAF / AUSF will directly use the stored DL NAS COUNT.

[0458] In some embodiments, it is assumed that the communication between the UE and different NFs cannot be done in parallel, i.e. the NF A cannot initiate the establishment of a NAS connection with the UE during the communication between the UE and the NF B . If a flag is maintained in the UE context, the AMF rejects the key request from other NFs.

[0459] Step S3103, the NF sends an SMC message to the UE.

[0460] In some embodiments, the NF initiates the SMC to activate the NAS security between the NF and the UE.

[0461] In some embodiments, the NF derives K NF_INT / K NF_ENC and provides the KSI (received from the UE or SEAF / AUSF / AMF), the selected security algorithm, the NF type / NF instance ID (optional) and the no_change_count indication to the UE. The NF stores the KSI, the key, the selected security algorithm, the UL NAS COUNT and the DL NAS COUNT.

[0462] Step S3104, the UE sends a security mode complete message to the NF.

[0463] In some embodiments, the UE derives K NF and K NF_INT / K NF_ENC to verify the SMC message. If the verification is passed, the UE sends a security mode complete message to the NF.

[0464] In some embodiments, upon receiving the no_change_count indication, the UE does not reset the NAS COUNT to zero and stores the security algorithm and the key selected by the NF in the UE NAS security context.

[0465] Step S3105, the NF sends NAS signaling to the UE.

[0466] In some embodiments, if the security mode complete message is verified, the NF can communicate securely with the UE. All subsequent communications between the UE and the NF will be protected by the NAS security context created for the NF. For UL messages, the UE increments the UL NAS COUNT by 1, and the NF updates the UL NAS COUNT accordingly. For DL messages, the NF increments the DL NAS COUNT by 1, and the UE updates the DL NAS COUNT accordingly.

[0467] In some embodiments, after the NAS connection is released, steps S3106-S3108 are performed.

[0468] Step S3106, the UE removes the NAS security context for the NF.

[0469] Step S3107, the NF sends a UE context update request to the SEAF / AMF / AUSF.

[0470] In some embodiments, the UE context update request includes the latest UL NAS COUNT and DL NAS COUNT.

[0471] Step S3108, the SEAF / AMF / AUSF sends a UE context update response to the NF.

[0472] In some embodiments, the SEAF / AMF / AUSF updates the UL NAS COUNT and DL NAS COUNT, and removes the label in the UE context.

[0473] FIG. 3B is an interaction diagram illustrating a communication method according to embodiments of the present disclosure. As shown in FIG. 3B, embodiments of the present disclosure relate to a communication method, which can be performed by a communication system. The method can include:

[0474] Step S3201, the UE sends NAS signaling to the NF.

[0475] In some embodiments, the UE sends the NAS signaling to initiate a request to establish a NAS connection with the NF.

[0476] In some embodiments, the UE derives K NF and K NF_INT / K NF_ENC .

[0477] In some embodiments, K NF Vertical derivation: input S of KDF: UE identifier (e.g. IMSI, NAI, GCI or GLI), ABBA parameter, NF instance ID. Input key KEY is K AUSF / K SEAF / K AMF .

[0478] In some embodiments, the input S to the KDF: UE identifier (e.g. IMSI, NAI, GCI or GLI), ABBA parameters, NF instance ID and NAS COUNT. The input key KEY is K AUSF / K SEAF / K AMF .

[0479] In some embodiments, the NAS signaling sent by the UE can be protected by K NF_INT and / or K NF_ENC . KSI, UE identifier and SQN are included in the NAS signaling.

[0480] In some embodiments, the initial NAS signaling of the NAS connection establishment can be forwarded by the AMF.

[0481] Step S3202, the NF sends a key request to the AUSF / AMF / SEAF and receives a key response sent by the AUSF / AMF / SEAF.

[0482] In some embodiments, once the NAS signaling is received, the NF sends a key request to the SEAF / AMF / AUSF. The key request includes the UE identifier, KSI, SQN and NF instance ID / NF type.

[0483] In some embodiments, the AUSF / AMF / SEAF retrieves the UE NAS security context according to the received KSI and / or UE identifier and generates K NF using vertical derivation. The SEAF / AMF / AUSF can maintain a flag in the UE NAS security context indicating that the UE is communicating with the NF.

[0484] In some embodiments, the AMF / SEAF / AUSF returns K NF , UL NAS COUNT, DL NAS COUNT, KSI (optional) and the selected algorithm to the NF.

[0485] In some embodiments, it is assumed that the communication between the UE and different NFs cannot proceed in parallel, i.e. during the UE communication with NF A, NF B cannot initiate the establishment of a NAS connection with the UE. If a flag is maintained in the UE security context, the AMF will reject the key request from other NFs.

[0486] In some embodiments, the NF derives K NF_INT / K NF_ENCTo verify the received NAS signaling and store the KSI, key, selected security algorithm, UL NAS COUNT and DL NAS COUNT.

[0487] Step S3203, the NF sends NAS signaling to the UE.

[0488] In some embodiments, if the NAS signaling is verified, the NF can communicate securely with the UE. All subsequent communication between the UE and the NF is protected by the NAS security context created for the NF. For uplink messages, the UE increments the UL NAS COUNT by 1 and the NF updates the UL NAS COUNT accordingly. For downlink messages, the NF increments the DL NAS COUNT by 1 and the UE updates the DL NAS COUNT accordingly.

[0489] In some embodiments, steps S3204-S3206 are performed after the NAS connection is released.

[0490] Step S3204, the UE removes the NAS security context for the NF.

[0491] Step S3205, the NF sends a UE context update request to the SEAF / AMF / AUSF.

[0492] In some embodiments, the UE context update request includes the latest UL NAS COUNT and DL NAS COUNT.

[0493] Step S3206, the SEAF / AMF / AUSF sends a UE context update response to the NF.

[0494] In some embodiments, the SEAF / AMF / AUSF updates the UL NAS COUNT and DL NAS COUNT and removes the tag in the UE context.

[0495] In some embodiments, the SEAF / AMF / AUSF can receive a key request from the NF.

[0496] In some embodiments, the SEAF / AMF / AUSF can reject the key request when a tag is maintained in the UE NAS context.

[0497] In some embodiments, the SEAF / AMF / AUSF can maintain a tag after generating a new K NF .

[0498] In some embodiments, the SEAF / AMF / AUSF can return the K NF and NAS Count to the NF in a key response message.

[0499] In some embodiments, the SEAF / AMF / AUSF can receive a UE context update request from the NF.

[0500] In some embodiments, the SEAF / AMF / AUSF can update the NAS COUNT according to the provided information.

[0501] In some embodiments, the SEAF / AMF / AUSF can return a UE context update response to the NF and remove the flag.

[0502] In some embodiments, the SEAF / AMF / AUSF can maintain the UE NAS context for communication under a multi-NAS architecture.

[0503] In some embodiments, the NF can send a key request to the AMF / SEAF / AUSF.

[0504] In some embodiments, the NF can receive K NF and NAS Count in a key response message from the AMF / AUSF / SEAF.

[0505] In some embodiments, the NF can send a UE context update request to the AMF / AUSF / SEAF.

[0506] In some embodiments, the NF can receive a UE context update response.

[0507] In some embodiments, the UE can maintain the UE NAS context for communication under a multi-NAS architecture.

[0508] In some embodiments, the UE can keep the NAS COUNT after receiving the no_change_count indication contained in the SMC message.

[0509] In some embodiments, the UE can remove the NAS context after the NAS connection between the NF and the UE is released.

[0510] In some embodiments of the present disclosure, a communication system can be provided, which can include a terminal and a network device, wherein the terminal can perform the communication method performed by the terminal in the foregoing embodiments of the present disclosure; the network device can perform the communication method performed by the network device in the foregoing embodiments of the present disclosure.

[0511] The embodiments of the present disclosure further provide a device for implementing any of the above methods, for example, a device comprising units or modules for implementing the steps performed by the terminal in any of the above methods. For another example, another device is further provided, comprising units or modules for implementing the steps performed by the network equipment (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.

[0512] It should be understood that the division of each unit or module in the above device is only a logical function division, and all or part of the units or modules can be integrated into one physical entity or physically separated in actual implementation. In addition, the units or modules in the device can be implemented in the form of processor invoking software: for example, the device comprises a processor connected with a memory, the memory stores instructions, and the processor invokes the instructions stored in the memory to implement any of the above methods or to implement the functions of each unit or module of the device, wherein the processor is, for example, a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be implemented by the design of the hardware circuit, and the hardware circuit can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are implemented by the design of the logical relationship between the elements in the circuit; for another example, in another implementation, the hardware circuit is a programmable logic device (PLD), and taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to implement the functions of part or all of the units or modules. All units or modules of the above device can be implemented in the form of processor invoking software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor invoking software, and the remaining part is implemented in the form of hardware circuit.

[0513] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the hardware circuit configuration. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.

[0514] FIG. 4A is a schematic diagram of a structure of a first network element according to an embodiment of the present disclosure. As shown in FIG. 4A, the first network element 101 can include at least one of a transceiver module 4101, a processing module 4102, and the like. In some embodiments, the transceiver module 4101 is configured to send a first message to a second network element, the first message being used to update a first security context, the first security context being used to secure communications between the terminal and the first network element and communications between the terminal and the second network element, or to secure communications between the terminal and the second network element; and the processing module 4102 is configured to update the first security context. Optionally, the transceiver module 4101 can be used to perform at least one of the communication steps (for example, steps S2102 and S2104, but not limited thereto) of sending and / or receiving performed by the first network element 101 in any of the above methods, and details are not described herein again. Optionally, the processing module 4102 can be used to perform at least one of the other steps (for example, steps S2103, S2105, and S2111, but not limited thereto) performed by the first network element 101 in any of the above methods, and details are not described herein again.

[0515] In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be mutually replaced with a transceiver.

[0516] In some embodiments, the processing module can be one module, or can include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module respectively. Optionally, the processing module can be mutually replaced with a processor.

[0517] FIG. 4B is a schematic diagram of a structure of a second network element according to an embodiment of the present disclosure. As shown in FIG. 4B, the second network element 102 can include at least one of a transceiver module 4201, a processing module 4202, and the like. In some embodiments, the transceiver module 4201 is configured to receive a first message sent by a first network element, the first message being used to update a first security context, the first security context being used to secure communications between the terminal and the first network element and communications between the terminal and the second network element, or to secure communications between the terminal and the second network element. Optionally, the transceiver module 4201 can be used to perform at least one of the communication steps (e.g., steps S2102, S2104, S2106, but not limited to) of the sending and / or receiving performed by the second network element 102 in any of the above methods, which will not be described herein. Optionally, the processing module 4202 can be used to perform at least one of the other steps (e.g., step S2109, but not limited to) of the second network element 102 in any of the above methods, which will not be described herein.

[0518] In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be mutually replaced with a transceiver.

[0519] In some embodiments, the processing module can be one module or can include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module, respectively. Optionally, the processing module can be mutually replaced with a processor.

[0520] FIG. 4C is a structural schematic diagram of a terminal according to an embodiment of the present disclosure. As shown in FIG. 4C, the terminal 103 can include at least one of a transceiver module 4301, a processing module 4302, and the like. In some embodiments, the transceiver module 4301 is configured to send first signaling to a first network element or a second network element; wherein the first signaling is used for the terminal to establish a connection with the second network element, and is used for the first network element to send a first message to the second network element, the first message being used for updating a first security context, the first security context being used for security protection of communication between the terminal and the first network element and communication between the terminal and the second network element, or for security protection of communication between the terminal and the second network element; the first signaling includes at least one of a key set identifier KSI, an identifier of the terminal, a sequence number SQN, an instance identifier of the second network element, a type of the second network element, and the KSI being an identifier of the first security context. Optionally, the transceiver module 4301 can be configured to perform at least one of the communication steps (for example, steps S2101 and S2108, but not limited thereto) of sending and / or receiving performed by the terminal 103 in any of the above methods, details are not described herein again. Optionally, the processing module 4302 can be configured to perform at least one of the other steps (for example, step S2107, but not limited thereto) performed by the terminal 103 in any of the above methods, details are not described herein again.

[0521] In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be mutually replaced with a transceiver.

[0522] In some embodiments, the processing module can be one module, or can include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module. Optionally, the processing module can be mutually replaced with a processor.

[0523] FIG. 5A is a structural schematic diagram of a communication device 5100 according to an embodiment of the present disclosure. The communication device 5100 can be a network device (for example, an access network device, a core network device, and the like), or a terminal (for example, a user equipment, and the like), or a chip, a chip system, or a processor supporting the first device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 5100 can be used to implement the methods described in the above method embodiments, and details can be referred to the descriptions in the above method embodiments.

[0524] As shown in FIG. 5A, the communication device 5100 includes one or more processors 5101. The processor 5101 can be a general processor or a special-purpose processor, etc., for example, can be a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, the central processing unit can be used to control the communication device (such as a base station, a baseband chip, an Internet of Things device, an Internet of Things device chip, a DU or a CU, etc.), execute programs, and process data of programs. The communication device 5100 is configured to perform any of the above methods.

[0525] In some embodiments, the communication device 5100 further includes one or more memories 5102 for storing instructions. Optionally, all or part of the memory 5102 can also be outside the communication device 5100.

[0526] In some embodiments, the communication device 5100 further includes one or more transceivers 5103. When the communication device 5100 includes one or more transceivers 5103, the transceiver 5103 performs at least one of the communication steps (such as steps S2101 and S2102, but not limited to) in the above methods, and the processor 5101 performs at least one of the other steps (such as step S2103, but not limited to).

[0527] In some embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced with each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced with each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced with each other.

[0528] In some embodiments, the communication device 5100 can include one or more interface circuits. Optionally, the interface circuit is connected with the memory 5102, and the interface circuit can be used to receive signals from the memory 5102 or other devices, and can be used to send signals to the memory 5102 or other devices. For example, the interface circuit can read the instructions stored in the memory 5102 and send the instructions to the processor 5101.

[0529] The communication device 5100 described in the above embodiments can be the first device or the IoT device, but the scope of the communication device 5100 described in the present disclosure is not limited thereto, and the structure of the communication device 5100 can not be limited by FIG. 5A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: 1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, an IoT device, a smart IoT device, a cellular phone, a wireless device, a handset, a mobile unit, a car device, a first device, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.

[0530] FIG. 5B is a structural diagram of a chip 5200 according to an embodiment of the present disclosure. For the case where the communication device 5100 is a chip or a chip system, the structural diagram of the chip 5200 shown in FIG. 5B can be referred to, but is not limited thereto.

[0531] The chip 5200 includes one or more processors 5201, and the chip 5200 is configured to execute any of the above methods.

[0532] In some embodiments, the chip 5200 further includes one or more interface circuits 5203. The interface circuit 5203 can be connected to the memory 5202, and the interface circuit 5203 can be configured to receive signals from the memory 5202 or other devices, and the interface circuit 5203 can be configured to send signals to the memory 5202 or other devices. For example, the interface circuit 5203 can read instructions stored in the memory 5202 and send the instructions to the processor 5201.

[0533] In some embodiments, the interface circuit 5203 performs at least one of the communication steps (such as step S2101, step S2102, but not limited thereto) in the above methods, and the processor 5201 performs at least one of the other steps (such as step S2105, but not limited thereto).

[0534] In some embodiments, the terms interface circuit, interface, transceiver pin, and transceiver can be replaced with each other.

[0535] In some embodiments, the chip 5200 further includes one or more memories 5202 for storing instructions. Optionally, all or part of the memory 5202 can be outside the chip 5200.

[0536] The embodiments of the present disclosure further provide a storage medium having instructions stored thereon, which, when executed on the communication device 5100, cause the communication device 5100 to perform any of the above methods. Alternatively, the storage medium is an electronic storage medium. Alternatively, the storage medium is a computer-readable storage medium, but is not limited to this, and it can also be a storage medium readable by other devices. Alternatively, the storage medium can be a non-transitory storage medium, but is not limited to this, and it can also be a transitory storage medium.

[0537] The embodiments of the present disclosure further provide a program product, which, when executed by the communication device 5100, causes the communication device 5100 to perform any of the above methods. Alternatively, the program product can be a computer program product.

[0538] The embodiments of the present disclosure further provide a computer program, which, when executed on a computer, causes the computer to perform any of the above methods.

Claims

1. A communication method characterized by comprising: The method is performed by a first network element, and comprises: sending, to a second network element, a first message, the first message being used to update a first security context, the first security context being used to secure communications between a terminal and the first network element and between the terminal and the second network element, or to secure communications between the terminal and the second network element; updating the first security context.

2. The method of claim 1, wherein, The method further comprises: after the second network element receives first signaling sent by the terminal, the first network element receiving a first request sent by the second network element according to the first signaling, the first signaling being used for the terminal to establish a connection with the second network element, and the first request being used to request the first network element to send a first key of the second network element; determining the first key of the second network element according to the first request; wherein the first signaling comprises at least one of the following: a key set identifier KSI, an identifier of the terminal, a sequence number SQN, an instance identifier of the second network element, and a type of the second network element, the KSI being an identifier of the first security context; and the first request comprises at least one of the following: the KSI, the identifier of the terminal, the instance identifier of the second network element, the type of the second network element, and the SQN.

3. The method of claim 2, wherein, The first message comprises at least one of the following: the first key of the second network element, the identifier of the terminal, an uplink count value, and a downlink count value.

4. The method of claim 1, wherein, The method further comprises: receiving first signaling sent by the terminal, the first signaling being used for the terminal to establish a connection with the second network element; determining the first key of the second network element according to the first signaling; wherein the first signaling comprises at least one of the following: a KSI, an identifier of the terminal, an SQN, an instance identifier of the second network element, and a type of the second network element, the KSI being an identifier of the first security context.

5. The method of claim 4, wherein, The first message comprises at least one of the following: the KSI, the identifier of the terminal, the SQN, the instance identifier of the second network element, the type of the second network element, the first key of the second network element, an uplink count value, and a downlink count value.

6. The method according to any one of claims 2-5, characterized in that, The updating the first security context comprises: adding a first label in the first security context, the first label being used to indicate that the terminal is communicating with the second network element.

7. The method of claim 6, wherein, The method further comprises: determining that the first security context comprises the first label, and rejecting a request for obtaining a first key sent by a network element other than the second network element.

8. The method according to any one of claims 1 to 7, characterized in that, The updating the first security context comprises: receiving a second request sent by the second network element, the second request comprising at least one of the following: a KSI, an identifier of the terminal, an uplink count value, and a downlink count value; updating at least one of the following in the first security context according to the second request: an uplink count value and a downlink count value.

9. The method of claim 8, wherein, The method further comprises: deleting a first label in the first security context, the first label being used to indicate that the terminal is communicating with the second network element.

10. The method according to claim 8 or 9, characterized in that, The method further comprises: sending a second message to the second network element, the second message being a response message of the second request.

11. A communication method characterized by comprising: The method is performed by a second network element, and the method comprises: receiving a first message sent by a first network element, the first message being used to update a first security context, the first security context being used to secure communications between a terminal and the first network element and between the terminal and the second network element, or to secure communications between the terminal and the second network element. The method further comprises:

12. The method of claim 11, wherein, receiving first signaling sent by the terminal, the first signaling being used for the terminal to establish a connection with the second network element; sending a first request to the first network element according to the first signaling, the first request being used to request the first network element to send a first key of the second network element; wherein the first signaling comprises at least one of the following: a key set identifier KSI, an identifier of the terminal, a sequence number SQN, an instance identifier of the second network element, a type of the second network element, the KSI being an identifier of the first security context; and the first request comprises at least one of the following: the KSI, the identifier of the terminal, the instance identifier of the second network element, the type of the second network element, the SQN. The first message is determined by the first network element according to the first request, and the first message comprises at least one of the following: the first key of the second network element, the identifier of the terminal, an uplink count value, a downlink count value.

13. The method of claim 12, wherein, The first message is determined according to first signaling received by the first network element, the first signaling being used for the terminal to establish a connection with the second network element, the first signaling comprising at least one of the following: a key set identifier KSI, an identifier of the terminal, a sequence number SQN, an instance identifier of the second network element, a type of the second network element, the KSI being an identifier of the first security context; and the first message comprising at least one of the following: the KSI, the identifier of the terminal, the SQN, the instance identifier of the second network element, the type of the second network element, the first key of the second network element, an uplink count value, a downlink count value.

14. The method of claim 11, wherein, The first signaling is not secured by the first security context, and the method further comprises:

15. The method according to any one of claims 12-14, characterized in that, sending a third message to the terminal according to a second key of the second network element, the third message being used to activate the first security context to secure communications between the terminal and the second network element, the second key of the second network element being determined according to the first key of the second network element; wherein the third message comprises at least one of the following: the KSI, a security algorithm selected by the second network element, the instance identifier of the second network element, the type of the second network element, first indication information, the first indication information being used to indicate that the terminal does not reset an uplink count value and a downlink count value in the first security context. The method further comprises:

16. The method of claim 15, wherein, receiving a fourth message sent by the terminal, the fourth message being used to indicate that the first security context is successfully activated to secure communications between the terminal and the second network element. ​ 17. The method according to any one of claims 12-14, characterized by, The method further comprises: performing security verification on the first signaling according to a second key of the second network element, wherein the second key of the second network element is determined according to the first key of the second network element, and the first signaling is securely protected by the first security context.

18. The method according to any one of claims 12-17, characterized by, The method further comprises: storing first information, the first information comprising at least one of the following: an identifier of the terminal, the KSI, a second key of the second network element, a security algorithm selected by the second network element, an uplink count value, and a downlink count value, wherein the second key of the second network element is determined according to the first key of the second network element.

19. The method according to any one of claims 11-18, characterized in that, The method further comprises: determining that the connection between the terminal and the second network element is released, and sending a second request to the first network element; wherein the second request comprises at least one of the following: the KSI, an identifier of the terminal, an uplink count value, and a downlink count value.

20. The method of claim 19, wherein, The method further comprises: receiving a second message sent by the first network element, the second message being a response message to the second request.

21. The method according to claim 19 or 20, characterized in that, The method further comprises: deleting a stored second security context of the second network element, the second security context being used for securely protecting communication between the second network element and the terminal. The method is performed by a terminal, and the method comprises:

22. A method of communication, comprising: sending first signaling to a first network element or a second network element; wherein the first signaling is used for the terminal to establish a connection with the second network element, and is used for the first network element to send a first message to the second network element, the first message being used for updating a first security context, the first security context being used for securely protecting communication between the terminal and the first network element, and communication between the terminal and the second network element, or for securely protecting communication between the terminal and the second network element; and the first signaling comprises at least one of the following: a key set identifier KSI, an identifier of the terminal, a sequence number SQN, an instance identifier of the second network element, and a type of the second network element, wherein the KSI is an identifier of the first security context. The first signaling is not securely protected by the first security context, and the method further comprises:

23. The method of claim 22, wherein, receiving a third message sent by the second network element, the third message being used for activating the first security context to securely protect communication between the terminal and the second network element; performing security verification on the third message according to the first security context; determining that the third message passes the security verification, and sending a fourth message to the second network element, the fourth message being used for indicating that the first security context is successfully activated to securely protect communication between the terminal and the second network element; wherein the third message comprises at least one of the following: the KSI, a security algorithm selected by the second network element, the instance identifier of the second network element, the type of the second network element, and first indication information, wherein the first indication information is used for indicating that the terminal does not reset an uplink count value and a downlink count value in the first security context. The first signaling is securely protected by the first security context.

24. The method of claim 22, wherein, The method further comprises:

25. The method of any one of claims 22-24, wherein, ​ determining a release of a connection between the terminal and the second network element, updating the first security context.

26. A communications device, characterized by The communication device is configured to perform the communication method of any one of claims 1 to 10, claims 11 to 21, or claims 22 to 25.

27. A communication system, characterized by The communication system comprises a first network element configured to implement the communication method of any one of claims 1 to 10, a second network element configured to implement the communication method of any one of claims 11 to 21, and a terminal configured to implement the communication method of any one of claims 22 to 25.

28. A storage medium, the storage medium storing instructions, wherein, The instructions, when executed on the communication device, cause the communication device to perform the communication method of any one of claims 1 to 10, or claims 11 to 21, or claims 22 to 25.

29. A computer program product comprising computer programs and / or instructions, characterized in that, The computer program and / or instructions, when executed on the communication device, implement the communication method of any one of claims 1 to 10, or the communication method of any one of claims 11 to 21, or the communication method of any one of claims 22 to 25.