Communication method and communication device
By generating unique identification information, UEs ensure secure connection establishment with the TNGF keys, addressing the challenge of network registration through trusted non-3GPP access networks by uniquely identifying UEs in communication systems.
Patent Information
- Application Number
- JP2025546367
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-02-12
- Filing Date
- 2024-02-04
- Publication Date
- 2026-02-25
AI Technical Summary
In existing communication systems, a Trusted Non-3GPP Gateway Function (TNGF) cannot accurately determine the TNGF keys corresponding to different User Equipments (UEs) due to the use of anonymous Subscription Concealed Identifiers (SUCIs) that are not unique, preventing secure connections and network registration via trusted non-3GPP access networks.
The UE generates identification information that uniquely represents itself and sends it to the TNGF, allowing the TNGF to associate this information with the corresponding TNGF key, ensuring secure connection establishment even when different UEs use the same anonymous SUCI.
This approach enables the TNGF to identify and establish secure connections with the correct TNGF keys for each UE, facilitating successful network registration and enhancing communication security performance.
Smart Images

Figure 2026506634000001_ABST
Abstract
Description
[Technical Field]
[0001] [Technical field] The present application relates to the field of communication technologies, and in particular to communication methods and devices. [Background technology]
[0002] User equipment (UE) may register with the core network via a 3rd Generation Partnership Project (3GPP) access network or a trusted non-3GPP access network (TNAN), which may include one or more trusted non-3GPP access points (TNAPs) and one or more trusted non-3GPP gateway functions (TNGFs).
[0003] When a UE accesses a network through a trusted non-3GPP gateway function (TNGF) network element, a secure connection, such as an Internet Protocol Security (IPsec) tunnel, needs to be established between the UE and the TNGF for communication security. A TNGF key shared between the UE and the TNGF needs to be used to establish the secure connection. The TNGF keys shared between different UEs and TNGFs are different. In the prior art, the anonymous Subscription Concealed Identifiers (SUCIs) of different UEs may be the same. In this case, the TNGF cannot distinguish between different UEs by using these anonymous SUCIs. As a result, the TNGF cannot accurately obtain the TNGF key corresponding to the UE, and therefore cannot establish an IPsec tunnel between the UE and the TNGF. As a result, the UE cannot register to the network through the trusted non-3GPP access network.
[0004] Therefore, how the TNGF determines the TNGF keys corresponding to different UEs to establish a secure tunnel between the UE and the TNGF is a technical problem that needs to be urgently solved. Summary of the Invention
[0005] The embodiments of the present application provide a communication method and a communication device for solving the problem that a UE cannot register to a network via a trusted non-3GPP access network, thereby improving communication security performance.
[0006] To achieve the above objectives, the present application uses the following technical solutions:
[0007] According to a first aspect, there is provided a communication method applicable to a scenario in which a terminal device registers to a network via a trusted non-3GPP access network. The trusted non-3GPP access network includes a trusted non-3GPP gateway function (TNGF), and the communication method includes: the terminal device receives an authentication request message from the TNGF; the terminal device sends an authentication response message to the TNGF in response to the authentication request message, where the authentication response message includes a registration request message and identification information that can uniquely represent the terminal device; the registration request message is used to request registration to the network and carries an anonymous subscription hiding identifier (SUCI) corresponding to the terminal device; the terminal device sends a secure connection establishment request message, where the secure connection establishment request is used to trigger the establishment of a secure connection between the terminal device and the TNGF, where the secure connection establishment request message includes the identification information and first authentication parameters; the first authentication parameters are a TNGF key (K TNGF ) and K TNGF is the shared key between the terminal device and the TNGF.
[0008] In the present application, it may be understood that the terminal apparatus in the first aspect and the following aspects may be a terminal device (e.g., a mobile phone) or a chip (system) that may be disposed in the terminal device. In other words, the communication method according to the first aspect may be performed by the terminal device or by a chip (system) in the terminal device.
[0009] According to the communication method provided in the first aspect, when a terminal device carries an anonymous SUCI in a registration request message, the terminal device generates an identification information that can uniquely represent the terminal device and sends the identification information to the TNGF, so that the TNGF receives the TNGF key (K TNGF) and store them in association with each other. Thereafter, when the terminal device requests to establish a secure connection between the terminal device and the TNGF, the secure connection establishment request message carries the identification information, so that the TNGF identifies the TNGF key corresponding to the terminal device based on the identification information, and continues the subsequent secure connection establishment procedure based on the TNGF key. In this way, even when different terminal devices using the same anonymous SUCI register to the network via the trusted non-3GPP access network, the TNGF in the trusted non-3GPP access network can still identify the TNGF keys corresponding to different terminal devices, and can establish a secure connection between the corresponding terminal device and the TNGF based on the corresponding TNGF key.
[0010] In a possible design solution, the method further includes: TNGF Based on the security tunnel key (K TIPSec ), and the terminal device generates K TIPSec The terminal device generates a first authentication parameter based on K TNGF Based on the security tunnel key K TIPSec For information on how to generate K, please refer to the notes in Section A.22 of TS33.501 V18.0.0. TIPSec is a key used to establish a secure connection (IPSec SA) between the terminal device and the TNGF. Correspondingly, the TNGF continues the subsequent secure connection establishment procedure based on the TNGF key, which may specifically include: the TNGF uses the K TIPSec and then K TIPSec If the verification of the first authentication parameter is successful (i.e., the TNGF has successfully authenticated the terminal device), the TNGF verifies the first authentication parameter by using K TIPSec and transmits the second authentication parameter to the terminal device. TIPSecIf the verification of the second authentication parameter is also successful (i.e., the terminal device successfully authenticates the TNGF), the terminal device and the TNGF complete mutual authentication, and a secure connection is thereby established.
[0011] In a possible implementation, the anonymous SUCI is a SUCI in a network access identifier (NAI) format, and the username portion of the SUCI in the NAI format is null or a fixed string. When a terminal device accesses a network for the first time and is not configured with a public key of the network, the terminal device carries the SUCI in the NAI format in the registration request when sending the registration request. In this case, considering that the anonymous SUCI cannot uniquely represent the terminal device, the terminal device generates an identification information and carries the identification information in the authentication response message to represent the terminal device.
[0012] In a possible implementation, the identification information is one or a combination of a random number generated by the terminal device, a hash value of a parameter that can uniquely represent the terminal device, or a modified SUCI, where the username part of the modified SUCI is determined based on the random number or the hash value, and the domain name part of the modified SUCI is the same as the domain name part of the anonymous SUCI. It should be noted that when a random number generated by a terminal device is used as identification information, there is still a possibility of collision, i.e., random numbers generated by different terminal devices may be the same. To sufficiently reduce the collision probability, a random number with a long length, for example, a 64-bit random number, may be agreed upon in the standard. The parameter that can uniquely represent the terminal device may be, for example, the username part of the modified SUCI based on the random number or the hash value, and the domain name part of the modified SUCI is the same as the domain name part of the anonymous SUCI. TNGF If the anonymous SUCI is of the format anonymous@realm or @realm, the modified SUCI may be of the format RAND@realm, HASH(RAND)@realm, or HASH(K TNGF)@realm is also acceptable.
[0013] In a possible implementation, the authentication response message includes the access network parameters and the registration request message, and the identification information is carried in a user identifier field of the access network parameters, i.e., in the prior art, the value of the user identifier field of the access network parameters is replaced with the identification information from the anonymous SUCI, thereby minimizing changes to the existing authentication response message format and ensuring system compatibility.
[0014] According to a second aspect, there is provided a communication method applicable to a scenario in which a terminal device registers to a network via a trusted non-3GPP access network. The communication method includes: a TNGF in the trusted non-3GPP access network sends an authentication request message to the terminal device, and then the TNGF receives an authentication response message from the terminal device, where the authentication response message includes indication information; in response to the indication information, the TNGF obtains an identifier for uniquely identifying the terminal device (i.e., association information of the terminal device); and then the TNGF obtains an authentication request message from the terminal device, where the authentication response message includes indication information. TNGF Then, when a secure connection establishment request message is received from the terminal device, the TNGF associates the K TNGF Get K TNGF Continue with the subsequent steps to establish a secure connection based on K. TNGF The process of continuing the subsequent steps of establishing a secure connection based on the above is similar to the process in the first embodiment, and the details will not be described again herein.
[0015] According to the communication method provided in the second aspect, the TNGF determines, based on the indication information from the terminal device, that association information that can uniquely identify the terminal device needs to be obtained, and then the K of the terminal device TNGFand association information and store the association information, so that when a secure connection establishment request message is subsequently received from the terminal device, the TNGF can associate K based on the association information carried in the secure connection establishment request message. TNGF Get K TNGF Based on this, the subsequent steps of establishing a secure connection can continue.
[0016] In a possible implementation, the terminal device cannot generate the association information by itself based on a preset processing logic. For example, the association information may be a random number generated by the TNGF. In this case, before the secure connection establishment request message is received, the method further includes: the TNGF sends the association information to the terminal device.
[0017] In a possible implementation, the terminal device may generate association information by itself based on a pre-configured processing logic. In this case, the standard must specify that the terminal device and the TNGF each generate the same association information based on the same processing logic in a timely manner. For example, the association information may be TNGF That is, the terminal device and the TNGF each share a parameter, for example, K TNGF In this case, the TNGF does not need to send the association information to the terminal device, thereby saving signaling resources.
[0018] In a possible implementation, the indication information instructs the terminal device to request registration with the network by using an anonymous subscription concealment identifier (SUCI). Based on the indication information, the TNGF determines that the TNGF needs to generate association information for the terminal device. It can be understood that if the authentication response message does not include the indication information, the TNGF may perform processing according to the prior art and does not need to generate identity information for the terminal device. Therefore, this solution can be well compatible with cases where a terminal device in an existing network does not access the network for the first time, and where a terminal device pre-configured with the network's public key accesses the network via the TNGF.
[0019] In a possible implementation, the TNGF is TNGF Continuing with the subsequent steps of establishing a secure connection based on TNGF ) based on the security tunnel key K TIPSec TNGF produces K TIPSec Continue the subsequent steps of establishing a secure connection based on the above. For related descriptions, please refer to the related descriptions in the first aspect, and the details will not be described again in this specification.
[0020] In a possible implementation, the authentication response message includes access network parameters and the registration request message, and the indication information is carried in the access network parameters. Specifically, the indication information may be carried in the access network parameters as a newly added IE or represented by a user identifier (UE ID) field in the access network parameters. According to the prior art, the registration request message includes an anonymous subscription concealment identifier (SUCI) corresponding to the terminal device, and the access network parameters include a UE ID field. In a possible implementation, unlike the prior art, the access network parameters may further include the indication information in addition to the UE ID field, i.e., the indication information is used as a newly added independent IE in the access network parameters. In another possible implementation, the indication information may be represented by setting the UE ID in the access network parameters to an empty value (i.e., the anonymous SUCI is not carried). In yet another possible implementation, the UE ID field in the access network parameters may be set to the anonymous SUCI. In yet another possible implementation, the UE ID field in the access network parameters may be set to the modified SUCI. If the format of the anonymous SUCI is anonymous@realm or @realm, the modified SUCI may be the reference information @realm, that is, the reference information is expressed by using the username part of the anonymous SUCI.
[0021] According to a third aspect, there is provided a communication method applicable to a scenario in which a terminal device registers to a network via a trusted non-3GPP access network. The trusted non-3GPP access network includes a trusted non-3GPP gateway function (TNGF), and the communication method includes: the terminal device receives an authentication request message from the TNGF; the terminal device sends an authentication response message to the TNGF in response to the authentication request message, the authentication response message including a registration request message and instruction information, the registration request message is used to request registration to the network, and the instruction information instructs the TNGF to generate association information for uniquely identifying the terminal device; the terminal device obtains the association information; the terminal device sends a secure connection establishment request message, the secure connection establishment request is used to trigger the establishment of a secure connection between the terminal device and the TNGF, the secure connection establishment request message including the association information and first authentication parameters; the first authentication parameters are a TNGF key (K TNGF ) and K TNGF is the shared key between the terminal device and the TNGF.
[0022] In the present application, it can be understood that the terminal apparatus in the first aspect may be a terminal device (e.g., a mobile phone) or a chip (system) that can be disposed in the terminal device. In other words, the communication method according to the first aspect may be performed by the terminal device or a chip (system) in the terminal device.
[0023] According to the communication method provided in the first aspect, when a terminal device carries an anonymous SUCI in a registration request message, the terminal device generates an identification information that can uniquely represent the terminal device and sends the identification information to the TNGF, so that the TNGF receives the TNGF key (K TNGF) and store them in association with each other. Thereafter, when the terminal device requests to establish a secure connection between the terminal device and the TNGF, the secure connection establishment request message carries the identification information, so that the TNGF identifies the TNGF key corresponding to the terminal device based on the identification information, and continues the subsequent secure connection establishment procedure based on the TNGF key. In this way, even when different terminal devices using the same anonymous SUCI register to the network via the trusted non-3GPP access network, the TNGF in the trusted non-3GPP access network can still identify the TNGF keys corresponding to different terminal devices, and can establish a secure connection between the corresponding terminal device and the TNGF based on the corresponding TNGF key.
[0024] According to the communication method provided in the second aspect, the terminal device sends instruction information to the TNGF to instruct the TNGF to generate association information that can uniquely identify the terminal device, and then the K of the terminal device TNGF Therefore, when the terminal device subsequently requests to establish a secure connection between the terminal device and the TNGF, the terminal device may send a secure connection establishment request message carrying the association information to the TNGF, whereby the TNGF stores the K corresponding to the terminal device. TNGF and then K TNGF A secure connection can be established based on:
[0025] In a possible implementation, the terminal device may generate association information by itself based on a pre-configured processing logic. In this case, the standard must specify that the terminal device and the TNGF each generate the same association information based on the same processing logic in a timely manner. For example, the association information may be TNGF That is, the terminal device and the TNGF each share a parameter, for example, K TNGFIn this case, the TNGF does not need to send the association information to the terminal device, thereby saving signaling resources.
[0026] In another possible implementation, the terminal device cannot generate the association information by itself based on a pre-configured processing logic. For example, the association information may be a random number generated by the TNGF. The terminal device obtaining the association information includes: The terminal device receives the association information from the TNGF.
[0027] In a possible design solution, the method further includes: TNGF Based on the security tunnel key (K TIPSec ), and the terminal device generates K TIPSec Generate a first authentication parameter based on the following: For related descriptions, please refer to the related contents in the first aspect, and the details will not be described again in this specification.
[0028] In a possible implementation, the authentication response message includes an access network parameter and a registration request message, and the indication information is carried in the access network parameter. For related descriptions, please refer to the related content in the second aspect, and the details will not be described again in this specification.
[0029] In a possible implementation, before the terminal device sends the authentication response message to the TNGF, the method further includes: the terminal device determines that it is the first time the terminal device accesses the network and that it has not been configured with a network public key; the terminal device carries indication information in the authentication response message only when it is determined that it is the first time the terminal device accesses the network and that it has not been configured with a network public key; if it is not the first time the terminal device accesses the network or if it has been configured with a network public key, the indication information does not need to be carried in the authentication response message; therefore, this solution may be well compatible with cases where a terminal device in an existing network accesses the network for the first time or where a terminal device pre-configured with a network public key accesses the network via the TNGF.
[0030] According to a fourth aspect, there is provided a communication device, the communication device including modules such as a transceiver module and a processing module configured to perform any of the communication methods performed by the terminal device in the preceding description, the transceiver module being configured to perform corresponding message receiving and transmitting actions, and the processing module being configured to perform all actions except for receiving and transmitting information.
[0031] Optionally, the communication device according to the fourth aspect may further include a storage module, and the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device can perform any communication method performed by the terminal device in the foregoing description.
[0032] According to a fifth aspect, there is provided a Trusted Non-3GPP Gateway Function (TNGF). The Trusted Non-3GPP Gateway Function includes modules, such as a transceiver module and a processing module, configured to perform any communication method performed by the TNGF in the preceding description. The transceiver module may be configured to perform corresponding message receiving and transmitting actions, and the processing module may be configured to perform all actions except receiving and transmitting information.
[0033] Optionally, the TNGF according to the fifth aspect may further include a storage module, and the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device can perform any communication method performed by the TNGF in the preceding description.
[0034] According to a sixth aspect, there is provided a communications device, the communications device including a processor configured to execute instructions stored in a memory, such that the communications device performs any of the communications methods performed by the terminal device in the preceding description.
[0035] In a possible design solution, the communication device may further include a memory, which may be integrated with the processor or located separately.
[0036] According to a seventh aspect, there is provided a Trusted Non-3GPP Gateway Function (TNGF), the TNGF including a processor, the processor configured to execute instructions stored in a memory, such that a communication device performs any communication method performed by the TNGF in the preceding description.
[0037] According to an eighth aspect, there is provided a computer-readable storage medium containing a computer program or instructions which, when executed on a computer, cause the computer to perform a communication method according to any possible implementation.
[0038] According to a twelfth aspect, there is provided a computer program product comprising a computer program or instructions which, when executed on a computer, cause the computer to perform a communication method according to any possible implementation. [Brief explanation of the drawings]
[0039] [Figure 1] FIG. 1 is a diagram of the architecture of a core network according to an embodiment of the present application; [Figure 2] 1 is a schematic flowchart of a communication method according to an embodiment of the present application; [Figure 3] 4 is a schematic flowchart of another communication method according to an embodiment of the present application; [Figure 4] 4 is a schematic flowchart of yet another communication method according to an embodiment of the present application; [Figure 5] 1 is a structural diagram of an apparatus according to an embodiment of the present application; [Figure 6] FIG. 2 is a structural diagram of another device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE INVENTION
[0040] In order to better understand the technical solutions provided in the embodiments of the present application, technical terms involved in the embodiments of the present application will be explained first.
[0041] 1. 5th generation (5G) mobile communication system (abbreviated as 5G system (5GS)):
[0042] 1 is a diagram of the architecture of 5GS. As shown in FIG. 1, 5GS includes an access network (AN) and a core network (CN), and may further include a UE.
[0043] The CN may include a user plane function (UPF) network element (for short referred to as a user plane network element), a core access and mobility management function (AMF) network element, a session management function (SMF) network element (for short referred to as a session management network element), an authentication server function (AUSF) network element, a network data analytics function (NWDAF) network element (for short referred to as a network data analytics network element), a network exposure function (NEF) network element, a network exposure function Repository Function (NRF) network element, a policy control function (PCF) network element (for short referred to as a policy control network element), a unified data management (UDM) network element (for short referred to as a data management network element), an application function (AF) network element, a service communication proxy (SCP) network element, etc.
[0044] The AN may include a 3GPP access network (i.e., a radio access network) and a trusted non-3GPP access network. The 3GPP access network may include several access devices, such as base stations, that provide air interface access to the UE. The trusted non-3GPP access network may include a trusted non-3GPP access point (TNAP) network element and a trusted non-3GPP gateway function (TNGF) network element.
[0045] It should be noted that Figure 1 only provides some examples of network elements or entities in a 5G network. The 5G network may further include some network elements or entities not shown in Figure 1, such as a unified data repository (UDR) network element, a network slice selection function (NSSF) network element, and a charging function (CHF) network element, which is not particularly limited in this embodiment of the present application.
[0046] As shown in FIG. 1, a UE accesses a 5G network through an AN device, and the UE communicates with an AMF network element through an N1 interface (abbreviated as N1). A RAN device communicates with an AMF network element through an N2 interface (abbreviated as N2). A UE communicates with a TNAP through a Yt interface, and the TNAP communicates with a TNGF network element through a Ta interface. The TNGF network element communicates with an AMF network element through an N2 interface. The TNGF network element further communicates with a UPF network element through an N3 interface. A RAN device communicates with a UPF network element through an N3 interface (abbreviated as N3). An SMF network element communicates with a UPF network element through an N4 interface (abbreviated as N4), and the UPF network element accesses a data network (DN) through an N6 interface (abbreviated as N6). In addition, control plane functions such as the AUSF network element, AMF network element, SMF network element, NEF network element, NRF network element, PCF network element, UDM network element, UDR network element, AF network element, NWDAF network element, or SCP network element shown in Figure 1 interact with each other via service-based interfaces.For example, the service-based interface provided by an AUSF network element to the outside is Nausf, the service-based interface provided by an AMF network element to the outside is Namf, the service-based interface provided by an SMF network element to the outside is Nsmf, the service-based interface provided by an NEF network element to the outside is Nnef, the service-based interface provided by an NRF network element to the outside is Nnrf, the service-based interface provided by a PCF network element to the outside is Npcf, the service-based interface provided by a UDM network element to the outside is Nudm, and the service-based interface provided by an AF network element to the outside is Naf. In addition, the service-based interface provided by a UDR network element to the outside is Nudr, the service-based interface provided by an NSSF network element to the outside is Nnssf, and the service-based interface provided by a CHF network element to the outside is Nchf. For a description of the relevant functions and interfaces, please refer to the 5G system architecture figure in the 23501 standard. Details will not be described herein.
[0047] In the following, by using examples, the functions of various parts or network elements involved in the network architecture in a 5G network are described separately.
[0048] (1) A terminal device may be a terminal having receiving and transmitting capabilities, or may be a chip or chip system that can be disposed in a terminal. A terminal may also be called a user equipment (UE), access terminal, subscriber unit, subscriber station, vehicle-mounted terminal, industrial control terminal, mobile station (MS), remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, etc. A terminal device may be fixed or mobile, indoors or outdoors, handheld, wearable, or deployed on land, including on a vehicle, on water (e.g., on a ship), or in the air (e.g., on an airplane, balloon, or satellite). For example, the terminal device may be a gateway station, a mobile phone, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, an in-vehicle terminal device, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, an in-vehicle terminal, a road side unit (RSU) with terminal function, etc. For ease of later description, in this application, a UE is used as an example to describe related solutions.
[0049] (2) The AN is configured to implement access-related functions and may provide network access functions for authorized terminals in a specific area, and may use transmission tunnels with different qualities based on the terminal's level, service requirements, etc. The AN transfers control signals and user data between a network element (terminal) and a CN. The AN in this application may be a radio access network (RAN) or TNAN. The RAN may manage radio resources, provide access services to terminal devices, and transfer control signals and terminal data between terminals and a core network. The RAN may be understood as a base station in a conventional network. For example, the RAN may be responsible for functions such as radio resource management, quality of service (QoS) management, and data compression and encryption on the air interface side. The TNAN is configured to provide reliable non-3GPP access capabilities to terminal devices, and the terminal devices may access the network through the TNAN.
[0050] (3) The TNAP network element is configured to provide UE access functionality. The TNAP may be referred to as a trusted non-3GPP access point, which may be an access node deployed by an operator. The TNAP may be configured to send authentication, authorization, and accounting (AAA) messages, for example, encapsulate extensible authentication protocol (EAP) data packets into AAA messages, and interact with the TNGF to forward NAS messages.
[0051] (4) The TNGF network element is configured to act as a gateway for trusted non-3GPP access networks. The TNGF may be configured to support the N2 and N3 interfaces, may be configured to terminate EAP-5G signaling, and may implement functions such as AMF selection, processing of N2 signaling with the SMF (relayed by the AMF) to support session and QoS, and transparent relay PDUs between terminal devices and user plane devices. In addition, for descriptions of the functions of other network elements, please refer to the descriptions of the functions of the corresponding network elements in Figure 1. Details will not be described again in this specification. N1, N2, N3, N4, N6, and N11 are interface sequence numbers. For the meanings of these interface sequence numbers, please refer to the meanings defined in the 3GPP standard protocol. This is not limited in this specification.
[0052] (5) The mobility management network element is a core network element and is mainly responsible for functions such as signaling processing, e.g., access control, mobility management, attach and detach, and gateway selection. When serving a session of a terminal, the mobility management network element provides control plane storage resources for the session to store a session identifier, an SMF network element identifier associated with the session identifier, etc. In a 5G communication system, the mobility management network element may be an access and mobility management function (AMF) network element. In future communication systems, the mobility management network element may still be an AMF network element or may have another name, which is not limited in this application.
[0053] (6) The session management network element is configured to perform session management in a mobile network, and is responsible for, for example, user plane network element selection, user plane network element redirection, internet protocol (IP) address allocation, bearer establishment, modification, and release, QoS control, session management, terminal IP address allocation and management, endpoint selection that can manage user plane function and policy control and charging function interfaces, downlink data notification, etc. In a 5G communication system, the session management network element may be an SMF network element. In future communication systems, the session management network element may still be an SMF network element or may have another name. This is not limited in the present application.
[0054] (7) The user plane network element is configured to perform packet routing and forwarding, quality of service (QoS) processing of user plane data, etc. In a 5G communication system, a network element or an entity corresponding to a user plane network element may be a user plane function (UPF) network element in a 5G network architecture. In future communication systems, the user plane network element may still be a UPF network element, or the user plane network element may have another name. This is not limited in the embodiments of the present application.
[0055] (8) The authentication server function network element mainly provides authentication functions and supports authentication for 3rd generation partnership project (3GPP) access and non-3GPP access. For details, refer to 3GPP TS 33.501. In a 5G communication system, the authentication server function network element may be an authentication server function (AUSF) network element. In future communication systems, the authentication server function network element may still be an AUSF network element, or the authentication server function network element may have a different name. This is not limited in the embodiments of the present application.
[0056] (9) The data management network element is configured to perform user identity processing, access authentication, registration, mobility management, etc. In a 5G communication system, a network element or entity corresponding to the data management network element may be a unified data management (UDM) network element in a 5G network architecture, where Nudm is a service-based interface provided by the UDM network element, and the UDM network element may communicate with another network function through Nudm. In future communication systems, the data management network element may still be a UDM network element, or the data management network element may have a different name. This is not limited in the embodiments of the present application.
[0057] (10) The network exposure function network element mainly provides services to enable a 3rd Generation Partnership Project (3GPP) network to securely provide network service capabilities to third-party service providers, i.e., application function network elements 207. In a 5G communication system, the network exposure function network element may be a network exposure function (NEF) network element, where Nnef is a service-based interface provided by the NEF network element, and the NEF network element may communicate with another network function through Nnef. In future communication systems, the network exposure function network element may still be an NEF network element or may have a different name. This is not limited in the embodiments of the present application.
[0058] (11) The policy control network element includes a user subscription data management function, a policy control function, a charging policy control function, a QoS control function, etc., and is a unified policy framework for guiding network behavior and provides policy rule information to a network element of a control plane function (e.g., an AMF network element, etc.). In a 5G communication system, the policy control network element may be a PCF network element. In future communication systems, the policy control function network element may still be a PCF network element or may have a different name. This is not limited in the embodiments of the present application.
[0059] (12) The application function network element is mainly configured to provide application layer information for a 3GPP network. In a 5G communication system, the application function network element 207 may be an application function (AF) network element, where Naf is a service-based interface provided by the AF network element, and the AF network element may communicate with another network function through Naf. In future communication systems, the application function network element may still be an AF network element or may have a different name. This is not limited in the embodiments of the present application. For example, the AF network element may include a services capability server (SCS) or an application server (AS).
[0060] (13) Data network refers to a network that provides data transmission services to terminals, such as IMS (IP Multimedia Service) and the Internet.
[0061] A terminal accesses a data network by establishing a session from the terminal to a RAN network element, a UPF network element, and a DN network element.
[0062] (14) The network data analysis function network element is configured to provide network data collection and analysis functions based on technologies such as big data and artificial intelligence. In a 5G system, the network data analysis function network element may be an NWDAF network element. In future communication systems, the network data analysis function network element may still be an NWDAF network element or may have a different name. This is not limited in this application.
[0063] (15) The slice selection function network element is configured to select a network slice for a terminal. In a 5G communication system, the slice selection function network element may be an NSSF network element. In future communication systems, the network slice selection function network element may still be an NSSF network element or may have a different name. This is not limited in the embodiments of the present application.
[0064] (16) The integrated data repository network element is mainly responsible for storing structured data, and the stored content includes subscription data and policy data, publicly disclosed structured data, and application-related data. In a 5G communication system, the integrated data repository network element may be a UDR network element. In future communication systems, the integrated data repository network element may still be a UDR network element or may have a different name. This is not limited in the present application.
[0065] It should be noted that in the following embodiments, the TNAP network element is abbreviated as TNAP, the TNGF network element is abbreviated as TNGF, the AMF network element is abbreviated as AMF, the AUSF network element is abbreviated as AUSF, and the terminal device is described by using UE. Details will not be described subsequently.
[0066] A UE may register with the core network via a 3rd Generation Partnership Project (3GPP) access network or a trusted non-3GPP access network (TNAN).
[0067] It should be understood that 3GPP access refers to accessing a mobile network by using a 3GPP access technology. 3GPP access technologies include, but are not limited to, technologies such as 5G, LTE, and UMTS. In general, 3GPP access technologies can be understood to use access provided by base stations of types such as gNBs and eNBs. Non-3GPP access refers to accessing a network by using a technology other than a 3GPP access technology. Non-3GPP access technologies include, but are not limited to, technologies such as wireless fidelity (Wi-Fi), Bluetooth, and zigBee. Types of non-3GPP access include untrusted non-3GPP access technologies and trusted non-3GPP access technologies. For example, in untrusted non-3GPP access technologies, the core network is accessed via radio access nodes deployed by non-operators, and in trusted non-3GPP access technologies, the core network is accessed via radio access nodes and wired access technologies deployed by operators.
[0068] The non-3GPP access network devices may include, but are not limited to, a non-3GPP interworking function (N3IWF), a trusted non-3GPP gateway function (TNGF), a trusted non-3GPP access point (TNAP), a trusted wireless local area network interworking function (TWIF), and a wireline access gateway function (W-AGF). The W-AGF may also be referred to as an AGF.
[0069] For example, if the access technology is an untrusted non-3GPP access technology, the non-3GPP access network device corresponding to the untrusted non-3GPP access technology may include an N3IWF. The network topology structure of the N3IWF is equivalent to that of a radio access network (RAN) in a 3GPP access network, and an N2 interface and an N3 interface may be supported. If the access technology is a trusted non-3GPP access technology, the non-3GPP access network device corresponding to the trusted non-3GPP access technology may include a TNGF. The network topology structure of the TNGF is equivalent to that of a RAN in a 3GPP access network, and an N2 interface and an N3 interface may be supported.
[0070] 2.UE Identifier:
[0071] In the 3GPP system, UE identifiers are classified into two types: a persistent identifier of the UE and an anonymous identifier. A persistent identifier is stored in a Universal Subscriber Identity Module (USIM). Because the 3GPP system has privacy protection requirements, a persistent identifier of the UE cannot be transmitted over the air interface because transmission over the air interface may cause the persistent identifier to be leaked, resulting in user tracking. Therefore, only anonymous identifiers can be transmitted over the air interface.
[0072] Typical anonymous identifiers include a Subscription Concealed Identifier (SUCI) and a 5G globally unique temporary identity (5G-GUTI). The SUCI can be calculated by the UE by using the SUPI. For example, the UE encrypts the SUPI by using a public key in the USIM card. The SUCI may be in Network Access Identifier (NAI) format, i.e., username@realm format, or in International Mobile Subscriber Identity (IMSI) format. From the network's perspective, an SUCI in NAI format may not uniquely identify the UE. For an SUCI in NAI format, username is the username part of the SUCI, and @realm is the domain name part of the SUCI.
[0073] When the UE accesses the network for the first time, the UE attempts to access the network by using the SUCI. When the UE accesses the network, the AMF generates a 5G-GUTI and sends the 5G-GUTI to the UE. After that, when the UE accesses the network again, the UE may attempt to access the network by using the 5G-GUTI.
[0074] When a UE accesses the network for the first time and the UE's USIM card does not have a public key, an anonymous SUCI is introduced to prevent the SUPI from being exposed. When the anonymous SUCI is in NAI format, the format of the anonymous SUCI may be (1) one in which the username part is omitted, i.e., the format is @realm, or (2) one in which the username is a fixed string, i.e., the format is anonymous@realm. Because the username in the anonymous SUCI sent by all UEs is omitted or the username value is the same, the anonymous SUCI has the function of hiding user identity.
[0075] In a possible implementation, the embodiments of the present application provide the following technical solution to avoid the problem that the TNGF cannot determine the TNGF key corresponding to different UEs when the UE registers with the network by using an anonymous SUCI, thereby improving communication security performance. The following briefly describes the solution in the embodiments of the present application. In the embodiments of the present application, the UE generates identification information that can uniquely represent the UE and sends the identification information to the TNGF. The TNGF associates the identification information with the TNGF key corresponding to the UE. In this way, after subsequently receiving the identification information sent by the UE, the TNGF can determine the TNGF key corresponding to the UE based on the identification information.
[0076] Hereinafter, implementations of the embodiments of the present application will be described in detail with reference to the accompanying drawings herein.
[0077] The communication method provided in the embodiments of the present application may be applied to any communication system. The communication system may be a third generation partnership project (3GPP) communication system, such as a non-terrestrial network (NTN) system or an LTE communication system, or may be a 5G mobile communication system, an NR communication system, or a new wireless vehicle-to-everything (NR V2X) system. The communication method may be applied to a system in LTE and 5G hybrid networking, a device-to-device (D2D) communication system, a machine-to-machine (M2M) communication system, the Internet of Things (IoT), and another next-generation communication system, such as future communication systems such as 6G, or may be a non-3GPP communication system. This is not limited. It should be noted that the solutions in the embodiments of the present application may also be applied to other communication systems, and corresponding names may be replaced with names of corresponding functions in other communication systems.
[0078] All aspects, embodiments, or features are presented in this application by describing systems that may include multiple devices, components, modules, etc. It is to be appreciated and understood that each system may include different devices, components, modules, etc. and / or may not include all of the devices, components, modules, etc. discussed with reference to the accompanying drawings. Additionally, combinations of these solutions may be used.
[0079] Additionally, in the embodiments of this application, terms such as "example" and "for example" are used to mean giving an example, illustrating, or explaining. Any embodiment or design scheme described in this application as an "example" should not be described as preferred or having more advantages than another embodiment or design scheme. Rather, the term "example" is used to present concepts in a concrete way.
[0080] The network architectures and service scenarios described in the embodiments of the present application are intended to more clearly explain the technical solutions in the embodiments of the present application, and do not constitute limitations on the technical solutions provided in the embodiments of the present application. Those skilled in the art can know the following: With the evolution of network architectures and the emergence of new service scenarios, the technical solutions provided in the embodiments of the present application can also be applied to similar technical problems.
[0081] For ease of understanding of the embodiments of the present application, the embodiment of Figure 2 illustrates a procedure for a UE to access a network via a trusted non-3GPP. For detailed procedures, please refer to Section 7A.2.1 of TS 33.501 Release 18.0.0.
[0082] It should be noted that the procedure includes two authentication procedures, each of which includes a first authentication procedure, i.e., a primary authentication procedure (hereinafter referred to as the primary authentication procedure unless otherwise specified), and a second authentication procedure. In the primary authentication procedure, the authentication server is the AUSF, the authenticator is the AMF, and the authentication target is the UE. The method used in the primary authentication procedure is the extensible authentication protocol (EAP)-authentication and key management (AKA), i.e., the EAP-AKA' method or the 5G-AKA method. Details will not be described in this specification. In the second authentication procedure, the authentication server is the TNGF, the authenticator is the TNAP, and the authentication target is the UE. The relationship between the time when the primary authentication procedure is performed and the time when the second authentication procedure is performed is as follows: The UE first triggers the second authentication procedure (corresponding to steps 201 to 205). In the process of executing the second authentication procedure, the AMF triggers the first authentication procedure (corresponding to steps 207 to 209). After the first authentication procedure is successfully completed, the execution of the second authentication procedure continues (corresponding to step 210), and the end of step 210 indicates the completion of the second authentication procedure.
[0083] Step 201: Establish a Layer 2 connection between a UE and a Trusted Non-3GPP Access Point (TNAP).
[0084] For other types of non-3GPP access (eg Ethernet type), it may not be necessary to perform this step.
[0085] Step 202: The TNAP sends an EAP Identity Request (EAP-Req / Identity) message to the UE to request to obtain the identity information of the UE.
[0086] Step 203: The UE returns an EAP Identity Response (EAP-Res / Identity) message to the TNAP.
[0087] For example, an EAP authentication procedure is triggered in steps 202 and 203. These EAP messages (EAP Identity Request / EAP Identity Response) are encapsulated in Layer 2 data packets and sent over the Layer 2 connection established in step 201.
[0088] The EAP Identity Response message includes the UE's NAI-formatted identifier, which may be in username@realm format. The NAI carries information for selecting a TNGF, such as the TNGF's full qualified domain name (FQDN). The NAI-formatted identifier triggers the TANP to send authentication, authorization, and accounting (AAA) requests to the TNGF. EAP data packets between the TNAP and the TNGF are encapsulated by using AAA messages.
[0089] Step 204: The TNGF sends an authentication request (EAP Request / 5G-Start) message to the UE.
[0090] For example, the authentication request message is used to initiate an EAP-5G authentication procedure.
[0091] Step 205: The UE returns an authentication response (EAP-Response / 5G-NAS) message to the TNGF.
[0092] The authentication response message includes an access network parameter (AN-Params) portion and a non-access stratum-protocol data unit (NAS-PDU) portion. The NAS-PDU portion carries a Registration Request message, and the AN-Params portion carries a user identifier field (UE ID). The UE ID may be a 5G-globally unique temporary UE identity (5G-GUTI) or a subscription concealed identifier (SUCI). The parameters carried in the AN-Params portion can be viewed and used by the TNGF. For example, the UE ID and / or other parameters (e.g., PLMN ID, etc.) in the AN-Params can be used by the TNGF to select an AMF. The Registration Request message included in the NAS-PDU carries the UE's identity information, and the value of the identity information is the same as the value of the UE ID in the AN-Params. For example, if AN-Params carries a SUCI, the registration request message also carries the SUCI, if AN-Params carries an anonymous SUCI, the registration request message also carries the anonymous SUCI, or if AN-Params carries a 5G-GUTI, the registration request message also carries the 5G-GUTI. The SUCI or anonymous SUCI is generated by the UE, and the 5G-GUTI is generated by the core network element AMF and sent to the UE when the UE accesses the network for the first time.
[0093] Specifically, when a UE registers with a network for the first time, AN-Params carries SUCI. When the UE's USIM card does not have a public key and the operator has requirements to protect user privacy, AN-Params carries anonymous SUCI. When it is not the first time that a UE accesses a network, i.e., if the UE has accessed the network before, AN-Params carries 5G-GUTI. Initial registration / access to a network means that the UE registers / accesses the network without an available 5G NAS security context.
[0094] Step 206: The TNGF performs AMF selection, and the TNGF sends a registration request message to the selected AMF.
[0095] Step 207 (optional): When the registration request message in step 206 carries the 5G-GUTI and the AMF cannot determine the UE's true identity SUPI based on the 5G-GUTI, the AMF sends a NAS Identity Request message to the UE, which is used to obtain the UE's identity information. The UE returns a NAS Identity Response message to the AMF, and the NAS Identity Response message includes the SUCI.
[0096] Step 208: The AMF decides to authenticate the UE, and performs step 208a.
[0097] If the SUCI is received, the AMF may decide to authenticate the UE. Alternatively, if the 5G-GUTI is received, the AMF may decide not to perform authentication. In this case, a bidirectional authentication procedure between the UE and the AMF may not be performed. Alternatively, after receiving the 5G-GUTI, the AMF decides to authenticate the UE according to a local policy or by using the SUCI in the registration request message received in step 206.
[0098] When the AMF decides to perform authentication on the UE and the authentication is successful, the UE and the AMF share the same TNGF key (K TNGF Optionally, the UE generates the TNAP key (K TNAP ) can be further generated. TNGF is generated by the UE based on the long-term key, and K TNAP is K TNGF Optionally, the UE may alternatively derive K in a subsequent step S209a. TNGF and / or K TNAP Optionally, the procedure in which the AMF performs authentication on the UE is divided into steps 208a, 208b, and 208c, as shown below.
[0099] Step 208a: The AMF sends a Nausf_UEAuthentication_Authenticate request message to the AUSF, where the Nausf_UEAuthentication_Authenticate request message includes the UE identity information carried in the registration request message.
[0100] Step 208b: The AUSF initiates an Authentication and Key Agreement (AKA) procedure for the UE, such as a 5G-AKA procedure or an EAP-AKA' procedure. After the agreement is completed, the AUSF returns step 208c to the AMF.
[0101] Step 208c: The AUSF returns a Nausf_UEAuthentication_Authenticate response message to the AMF, and the Nausf_UEAuthentication_Authenticate response message includes the SEAF key.
[0102] Specifically, the AMF uses the SEAF key to derive the NAS key (e.g., the NAS confidentiality protection key and / or the NAS integrity protection key) and K TNGFThe SEAF key is also generated based on the long-term key corresponding to the UE.
[0103] Step 209: Perform an NAS security activation procedure between the AMF and the UE. After the procedure is completed, the UE and the AMF start to perform confidentiality and / or integrity protection on NAS messages by using an NAS confidentiality protection key and / or an NAS integrity protection key. Specifically, step 209 is divided into steps 209a and 209b as follows:
[0104] Step 209a: The AMF sends a security activation request message (e.g., a NAS Security Mode Command) to the UE. When the EAP-AKA authentication procedure is used, the security activation request message may further include an EAP-Success message indicating that the AMF has successfully authenticated the UE. The EAP-Success message is generated by the AUSF and indicates that the AUSF has successfully authenticated the UE.
[0105] Step 209b: The UE returns a security activation complete (NAS Security Mode Complete) message to the AMF.
[0106] Step 210: The TNGF and the UE complete authentication. Specifically, step 210 is divided into steps 210a, 210b, 210c, 210d, and 210e, as shown below.
[0107] Step 210a: After the AMF receives a security activation complete message from the UE, the AMF sends an initial context setup request (NGAP Initial Context Setup Request) message to the TNGF, and the initial context setup request message is TNGF Includes:
[0108] In this case, the UE and TNGF share the same key K TNGF It has.
[0109] Step 210b: The TNGF sends an EAP-Request / 5G-Notification message to the UE, where the EAP-Notification request message includes the address of the TNGF (e.g., the IP address of the TNGF), which is used by the UE to subsequently establish a secure connection (e.g., an IP security tunnel IPSec) with the TNGF.
[0110] Step 210c: The UE sends an EAP-Response / 5G-Notification message to the TNGF.
[0111] Step 210d: After receiving the authentication response message from the UE, the TNGF sends an AAA message to the TNAP, which includes an authentication complete (EAP-Success) message and a K TNAP Includes:
[0112] For example, the authentication complete message is generated by the TNGF, and the sending of this message indicates that the EAP-5G procedure has been successfully completed.
[0113] Step 210e: TNAP TNAP and sends an authentication completion message (EAP-Success) to the UE. In response, the UE receives an authentication completion message from the TNAP, and the EAP-5G authentication session is completed.
[0114] Step 211 (optional): An L2 security (Layer 2 security) link is established between the UE and the TNAP, and the UE and the TNAP TNAP and a security association is established to protect subsequent messages exchanged between the UE and the TNAP, i.e., all subsequent messages between the UE and the TNAP are encrypted and / or integrity protected.
[0115] Step 212: The UE receives an IP configuration of a trusted non-3GPP access network (TNAN). For example, the UE obtains an address (e.g., an IP address) of the UE by using a dynamic host configuration protocol (DHCP).
[0116] Step 213: The UE initiates a procedure to establish a secure connection with the TNGF.
[0117] Specifically, step 213 is divided into steps 213a, 213b, and 213c as follows:
[0118] Step 213a: The UE initiates an initial key exchange (IKE_INIT) with the TNGF by using the received address of the TNGF to negotiate a session key.
[0119] After the IKE_INIT exchange is completed, the UE and TNGF generate a session key and negotiate a security algorithm. The UE and TNGF use the session key and the negotiated security algorithm to perform confidentiality and / or integrity protection on subsequent exchanged messages.
[0120] Step 213b: The UE sends a secure connection establishment request (IKE_AUTH) message to the TNGF.
[0121] The secure connection establishment request message includes an initiator identifier (IDi) of the UE and a first authentication parameter AUTH, where the value of IDi is the same as the value of the UE ID provided in step 205 .
[0122] In a possible implementation, before sending the establishment request (IKE_AUTH) message, the UE TNGF Based on the check key K TIPSec Calculate K TIPSec The first authentication parameter AUTH is calculated by using:
[0123] Step 213c: The TNGF returns a secure connection establishment response (IKE_AUTH) message to the UE.
[0124] The secure connection establishment response message includes a responder identifier (IDr) and a second authentication parameter AUTH, and the second authentication parameter is a K TNGF Optionally, before the TNGF sends the secure connection establishment response (IKE_AUTH) message, the TNGF TNGF Based on K TIPSec Calculate K TIPSec The correctness of the first authentication parameter AUTH is verified by using K, and after the verification is successful, step 213c is performed. TIPSec Calculated by TNGF based on
[0125] After receiving the secure connection establishment response message, the UE TIPSec After the verification by the UE is successful, the two-way verification between the UE and the TNGF is completed.
[0126] It should be noted that after step 213c, a secure connection is established between the UE and the TNGF, which is used for sending all subsequent NAS messages.
[0127] Step 214: The TNGF returns an initial context setup response message to the AMF.
[0128] For example, the initial context setup response message is used to notify the AMF that the UE context has been created.
[0129] Step 215: The AMF sends a NAS Registration Accept message to the UE, and the UE completes the process of registering with the network via a trusted non-3GPP network.
[0130] For example, a NAS Registration Accept message is forwarded to the UE via the secure connection established in step 213 .
[0131] In the above procedure, the TNGF stores the value of the UE ID in the AN parameter, i.e., in the SUCI or 5G-GUTI, in step 205, and then stores the value of the UE ID in the SUCI or 5G-GUTI in step 210a. TNGF After receiving the UE ID value and K TNGF Then, after receiving the same SUCI or 5G-GUTI in step 213b, the TNGF stores the K corresponding to the UE. TNGF It can be seen that the TNGF does not need to know whether the UE ID carries SUCI or 5G-GUTI, and the TNGF only needs to store the relevant content for subsequent key association.
[0132] In addition, in the above procedure, the UE identity carried in the AN parameter and the UE identity carried in the NAS-PDU in step 205 are the same, i.e., both are 5G-GUTI or both are SUCIs.
[0133] In the above-mentioned prior art solution in which a UE accesses a network via a trusted non-3GPP channel, when the UE's USIM card does not have a public key and the operator has a requirement to protect user privacy, the UE uses an anonymous SUCI to protect privacy. However, when an anonymous SUCI is used, how the TNGF determines the UE's key becomes problematic because the anonymous SUCI of different UEs may be the same. Specifically, this is because the anonymous SUCI has a fixed structure, i.e., either @realm or anonymous@realm. As a result, when the realm is the same, the anonymous SUCI is necessarily the same between different UEs. Therefore, regardless of whether the AN parameter carries an anonymous SUCI, the TNGF cannot obtain the TNGF key corresponding to the UE. As a result, a problem occurs when a secure connection is established between the TNGF and the UE in step 213.
[0134] In order to solve the above problem, this embodiment provides the following solution: The flowchart of the communication method is shown in Figure 3. The procedure includes the following steps:
[0135] Step 301: For specific steps, please refer to steps 201-204, and the details will not be described again in this specification.
[0136] Step 302: The UE generates identification information.
[0137] The identification information can uniquely represent the UE. The identification information may be generated at any opportunity before step 303 is performed. For example, the UE may generate the identification information after receiving an authentication request from the TNGF (step 204), or after receiving an EAP Identity Request from the TNAP (step 202), or before or after establishing a Layer 2 connection to the TNAP (step 201), or when the UE determines that the USIM card does not have a public key and the operator has privacy requirements, or after the UE generates an anonymous SUCI. This embodiment does not limit the specific opportunity for generating the identification information.
[0138] In this embodiment of the present application, the UE may generate the identification information in any one of the following ways:
[0139] Method 1: The identification information is a first random number, and the first random number is any random number that can uniquely represent the UE.
[0140] For example, the UE randomly generates a first random number, and the length of the first random number may be any length within 64 bits. For example, the length of the first random number is 64 bits. The length and unit of the generated random number and the manner of generating the random number are not limited in this embodiment.
[0141] In a possible implementation, the UE generates the first random number by using the registration request message or some content of the registration request message as an input parameter to ensure the uniqueness of the random number. For example, the UE generates the first random number by using an encrypted part in the registration request message. Scheme 2: The identification information is a first hash value, and the first hash value is an arbitrary hash value of parameters that can uniquely represent the UE.
[0142] For example, the parameters that can uniquely represent a UE are the random number in Method 1, the SUPI of the UE, and K TNGF, and the UE's long-term key K(K TNGF is generated based on the long-term key), or a combination thereof. The specific method for generating the first hash value is not limited in this embodiment.
[0143] Method 3: The identity is the modified SUCI.
[0144] The username portion of the modified SUCI can uniquely represent the UE and may be, for example, the first random number determined in Method 1 or the first hash value determined in Method 2, or may be a parameter further derived based on the first random number or the first hash value. The domain name portion of the modified SUCI is the same as the domain name portion of the UE's anonymous SUCI.
[0145] For example, if the UE's anonymous SUCI is anonymous@realm, the modified SUCI may be rand1@realm, where rand1 may be the first random number generated in scheme 1.
[0146] Step 303: The UE sends an authentication response message to the TNGF, where the authentication response message includes identification information. Correspondingly, the TNGF receives the authentication response message from the UE and stores the identification information.
[0147] The identification information may be carried in the UE ID portion within the AN parameter, and the registration request message includes an anonymous SUCI.
[0148] Step 304: For specific steps, please refer to steps 206 to 210, and the details will not be described again in this specification.
[0149] Step 305: The TNGF uses the initial context setup request message sent by the AMF (step 210a) to TNGF After receiving the ID and K TNGF Remember it by associating it with the following.
[0150] For example, associative storage is the process by which TNGF organizes K TNGF For example, the identification information and K TNGF Alternatively, the association storage may store the identification information and K TNGF and are stored separately, and the identification information and K TNGF The TNGF then calculates the K based on the identification information and the index. TNGF The identification information is stored after the TNGF receives the authentication response message from the UE (step 303), and the index is K TNGF The time may be any time between when the index is received (step 210a) and when the index is generated (step 307). The specific time when the index is generated is not limited in this embodiment.
[0151] Step 306: For specific steps, please refer to steps 211-213a, and the details will not be described again in this specification.
[0152] Step 307: The UE sends a secure connection establishment request (IKE_AUTH) message to the TNGF.
[0153] The difference between step 307 and step 213b is that the value of IDi carried in the secure connection establishment request (IKE_AUTH) message is set to the identification information, i.e., the value of IDi is no longer the same as the value of the UE ID provided in step 205.
[0154] For other contents, please refer to the relevant description in step 213b, and the details will not be described again here.
[0155] Step 308: The TNGF selects the corresponding K based on the identification information. TNGF Determine.
[0156] Step 309: For specific steps, please refer to steps 213c to 215, and the details will not be described again in this specification.
[0157] According to the communication method provided in this embodiment of the present application, when the UE uses an anonymous SUCI, it generates an identity that can uniquely identify the UE. Although the UE identity carried in the AN parameter (identity) and the registration request message (anonymous SUCI) is different, this is a solution that does not change the existing logic of the TNGF. Therefore, the problem that the TNGF cannot distinguish different keys of different UEs caused by the use of anonymous SUCI is avoided, and only the UE needs to be changed, thereby reducing the network upgrade cost.
[0158] To solve the problem that the TNGF cannot distinguish different UEs that use the same anonymous SUCI, this embodiment provides another solution. The UE still uses the anonymous SUCI for access. When the UE determines that it will use the anonymous SUCI, the TNGF generates association information that can be associated with the UE. The association information may be sent to the UE by the TNGF or may be generated by the UE. A flowchart of the communication method is shown in Figure 4. This procedure includes the following steps:
[0159] Step 401: For specific steps, please refer to steps 201-204, and the details will not be described again in this specification.
[0160] Step 402: The UE sends an authentication response message to the TNGF. In response, the TNGF receives an authentication response message from the UE.
[0161] For related descriptions, please refer to step 205. Different from step 205, AN-Params further includes indication information, which indicates that the UE accesses the network by using an anonymous SUCI.
[0162] In this embodiment of the present application, the indication information may be any one of the following:
[0163] Method 1: The UE fills the UE ID in the AN parameter part with an anonymous SUCI. That is, if the UE ID in the AN parameter part is in the format of an anonymous SUCI, it indicates that the UE accesses the network by using an anonymous SUCI. This method is sometimes called an implicit indication method.
[0164] Method 2: The UE sets the UE ID in the AN parameter section to a null value, a meaningless value, or does not carry the UE ID parameter. This method is also an implicit indication method.
[0165] Method 3: The indication information is a newly added IE, which indicates whether the UE uses an anonymous SUCI for access. This IE may use bit indication information or counting information to indicate whether the anonymous SUCI is used for access. For example, a bit value of 0 indicates that the UE uses a non-anonymous SUCI or 5G-GUTI for access, and a bit value of 1 indicates that the UE uses an anonymous SUCI for access. This method may also be called an explicit indication method.
[0166] Alternatively, the indication information is a newly added IE, the presence of which indicates that the UE uses an anonymous SUCI for access. The absence of this IE indicates that the UE uses a non-anonymous SUCI or 5G-GUTI for access. This method may also be referred to as an explicit indication method.
[0167] Step 403: The TNGF determines a specific method for associating the keys.
[0168] TNGF is the key to UE TNGF There are two ways to associate it with
[0169] Method 1 is the method described in steps 206 to 215 and steps 301 to 309. In this method, the TNGF performs the association by using the UE ID carried in the AN part.
[0170] Method 2 is a method using association information, which will be described later in this embodiment.
[0171] Specifically, if the TNGF determines that the AN-Params carries the SUCI or 5G-GUTI, or carries the UE ID but does not carry indication information, the TNGF performs Method 1. If the TNGF determines that the UE has registered with the network by using an anonymous SUCI, Method 2 is used.
[0172] After receiving the authentication response message from the UE, the TNGF determines whether the UE uses SUCI, 5G-GUTI, or anonymous SUCI during registration according to the AN-Params in the authentication response message. For the three indication methods in step 402, the corresponding determination methods are as follows:
[0173] For Scheme 1: The TNGF determines whether the UE uses a SUCI, an anonymous SUCI, or a 5G-GUTI for access based on the pre-configured method #1. For example, the format information of the anonymous SUCI is pre-configured in the TNGF. When the format information is not satisfied, it is determined that the UE uses a SUCI or a 5G-GUTI for access. When the format of the UE ID is the same as the format of the anonymous SUCI, it is determined that the UE uses the anonymous SUCI for access, and the subsequent procedures in this embodiment are continued. When the format of the UE ID is the same as the format of the SUCI or the format of the 5G-GUTI, steps 206 to 215 are executed. For the format information of the anonymous SUCI, please refer to the above description. Optionally, the TNGF may further distinguish whether the UE uses a SUCI or a 5G-GUTI based on the pre-configured format information.
[0174] For Scheme 2: The TNGF determines whether the AN parameter part carries a null value or a meaningless value, or whether the AN parameter part does not carry a UE ID part, based on the pre-configured Scheme #2. If one of the aforementioned conditions is met, the TNGF determines that the UE uses anonymous SUCI, and the subsequent procedures in this embodiment are continued; otherwise, steps 206 to 215 are executed.
[0175] For Scheme 3: The TNGF determines whether the UE uses an anonymous SUCI by checking whether a newly added IE appears or by checking the value of the newly added IE. If it is determined that an anonymous SUCI is used for access, the subsequent procedures in this embodiment are continued. If it is determined that an anonymous SUCI or 5G-GUTI is used, or an anonymous SUCI is not used, steps 206 to 215 are executed.
[0176] Step 404: After determining that the UE's identifier is an anonymous SUCI, the TNGF obtains association information.
[0177] The association information may be a newly generated value or an existing value. The association information may uniquely identify one terminal device, and the unique identification may be unique only within the scope of the TNGF, or may be unique throughout the network. The scope of the unique identification is not limited in this embodiment. For example, the association information may be a hash value obtained through calculation, an assigned identifier that can be uniquely associated with the UE side, or a TNGF key (K TNGF ), or a KTIPsec key identifier. Note that step 404 may be performed immediately after step 403, or at any time between step 403 and step 406. This means that after the UE decides to use an anonymous SUCI, the TNGF does not need to obtain the association information immediately, i.e., the opportunity for decision and the opportunity for obtaining the association information may be separated, since the association information may not be immediately available. For example, after the TNGF decides in step 404 that the UE will use an anonymous SUCI for access, the TNGF may obtain the KTIPsec key identifier in step 210a. TNGF After obtaining the TNGF, the pre-configured method and K TNGF The hash value is the association information. That is, only after step 210a, the TNGF obtains the association information and calculates the hash value by using the association information and K TNGF Correspondingly, the same K TNGF After generating K, the UE uses the preconfigured method and TNGFIn another example, after the TNGF assigns the UE's address to the UE in step 212, the TNGF has determined that the UE will use an anonymous SUCI for access, so the TNGF uses the UE's address as association information and calculates the association information and K TNGF After receiving the UE address, the UE uses the UE address as association information.
[0178] Step 405: For specific steps, please refer to steps 206 to 213a, and the details will not be described again in this specification.
[0179] It should be noted that the UE side also needs to obtain the association information. There are two ways for the UE side to obtain the association information:
[0180] Method a: The UE side may generate association information by using the same generation method as the TNGF side.
[0181] For example, the UE side may register with the network by using an anonymous SUCI and then determine that association information needs to be generated. The UE may generate the association information immediately after obtaining the relevant parameters, or may generate the association information before transmitting in step 406. For example, in the above-mentioned hash value generation method, K TNGF After obtaining the association parameter, the UE may generate the association information immediately, or may generate the association information before step 406 is performed. This embodiment does not limit the specific occasion when the UE generates the association parameters.
[0182] Method b: Alternatively, the UE side may obtain association information by using a message sent by the TNGF.
[0183] For example, in the above method of using the UE address as association information, the UE address is sent to the UE in step 212. Therefore, after obtaining the UE address information in step 212, the UE uses the UE address as association information.
[0184] Step 406: The UE sends a secure connection establishment request (IKE_AUTH) message to the TNGF, where the secure connection establishment request message includes IDi and a first authentication parameter AUTH.
[0185] IDi is the association information. For other contents, please refer to the related description in step 213b, and the details will not be described again in this specification.
[0186] Step 407: After receiving a secure connection establishment request message from the UE, the TNGF establishes a corresponding K TNGF For other contents, please refer to the related description in step 213b, and the details will not be described again in this specification.
[0187] Step 408: For specific steps, please refer to steps 213c to 215, and the details will not be described again in this specification.
[0188]
[0023] Based on the communication method provided in this embodiment of the present application, when the UE performs registration by using the anonymous SUCI, indication information is implicitly or explicitly transferred to the TNGF, so that the TNGF determines that the UE has registered with the network by using the anonymous SUCI, and further, the TNGF recognizes that it needs to obtain association information. Then, when establishing a secure connection, the UE carries the association information in the IDi payload, so that the TNGF can uniquely identify the UE based on the association information.
[0024] Above, the communication method provided in the embodiment of the present application has been described in detail with reference to Figures 2 to 4.
[0189] Based on the same inventive concept as the method embodiments, the embodiments of the present application further provide an apparatus 500 and an apparatus 600 configured to perform the methods performed by a terminal device or a TNGF in the method embodiments shown in Figures 2 to 4. For related features, please refer to the aforementioned method embodiments, and the details will not be described again herein.
[0190] 5, the device 500 includes a transceiver module 501 and a processing module 502. The transceiver module 501 is configured to perform corresponding message receiving and transmitting actions, and the processing module 502 can be configured to perform all actions except for receiving and transmitting information. For specific functions of the transceiver module 801 and the processing module 802, please refer to the description in the above method embodiment. The details will not be described again in this specification.
[0191] For example, Figure 6 is a diagram of a second structure of a communication device according to an embodiment of the present application. The communication device may be a terminal device or a TNGF. As shown in Figure 6, the communication device 600 may include a processor 601. Optionally, the communication device 600 may further include a memory 602 and / or a transceiver 603. The processor 601 is coupled to the memory 602 and the transceiver 603. For example, the processor may be connected to the memory and the transceiver via a communication bus.
[0192] Each component of the communication device 600 will be described in detail below with reference to FIG.
[0193] Processor 601 is the control center of communication device 600 and may be a processor or a collective term for multiple processing elements. For example, processor 601 may be one or more central processing units (CPUs), or application-specific integrated circuits (ASICs), or may be configured as one or more integrated circuits implementing embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).
[0194] Optionally, the processor 601 may perform various functions of the communication device 600 by executing software programs stored in the memory 602 and accessing data stored in the memory 602 .
[0195] In a specific implementation, in one embodiment, the processor 601 may include one or more CPUs, for example, CPU0 and CPU1 shown in FIG.
[0196] In a specific implementation, in one embodiment, the communications device 600 may alternatively include multiple processors, such as the processor 601 and processor 604 shown in FIG. 6. Each of the processors may be a single-core processor (single CPU) or a multi-core processor (multiple CPUs). A processor herein may be one or more devices, circuits, and / or processing cores configured to process data (e.g., computer program instructions).
[0197] The memory 602 is configured to store a software program for implementing the solution in the present application, and the processor 601 controls the execution. For specific implementation, please refer to the aforementioned method embodiment. The details will not be described again in this specification.
[0198] Optionally, memory 602 may be a read-only memory (ROM) or another type of static storage device capable of storing static information and instructions, or a random access memory (RAM) or another type of dynamic storage device capable of storing information and instructions, or may be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or another compact disc storage device, an optical disc storage device (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disc storage medium or another magnetic storage device, or any other medium that can be used to carry or store expected program code in the form of instructions or data structures and that can be accessed by a computer. However, memory is not limited thereto. Memory 602 may be integrated with processor 601 or may exist independently, and is coupled to processor 601 via an interface circuit (not shown in FIG. 6 ) in communication device 600. This is not particularly limited in this embodiment of the present application.
[0199] The transceiver 603 is configured to communicate with another communication device. For example, the communication device 600 is a terminal device, and the transceiver 603 may be configured to communicate with a network device or another terminal device. In another example, the communication device 600 is a network device, and the transceiver 603 may be configured to communicate with a terminal device or another network device.
[0200] Optionally, the transceiver 603 may include a receiver and a transmitter (not shown separately in FIG. 6), where the receiver is configured to implement a receiving function and the transmitter is configured to implement a transmitting function.
[0201] Optionally, the transceiver 603 may be integrated with the processor 601 or may exist independently, and is coupled to the processor 601 via an interface circuit (not shown in FIG. 6) in the communication device 600. This is not particularly limited in this embodiment of the present application.
[0202] It should be noted that the configuration of communication device 600 shown in Figure 6 does not constitute a limitation on the communication device. An actual communication device may include more or fewer components than those shown in the figure, may combine some components, or may have a different arrangement of components.
[0203] In addition, for the technical effects of the communication device 600, please refer to the technical effects of the communication method in the above method embodiments, and the details will not be described again in this specification.
[0204] It is understood that the processor in embodiments of the present application may be a central processing unit (CPU), or the processor may be another general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc.
[0205] It may be understood that the memory in the embodiments of the present application may be volatile memory, nonvolatile memory, or both. Nonvolatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM) used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) may be used, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0206] All or part of the foregoing embodiments may be implemented using software, hardware (e.g., circuits), firmware, or any combination thereof. When software is used to implement the foregoing embodiments, the foregoing embodiments may be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded and executed on a computer, the procedures or functions according to the embodiments of the present application are generated entirely or partially. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or another programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from a website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., infrared, radio, microwave, etc.) method. The computer-readable storage medium may be any available medium accessible by a computer, or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, or magnetic tapes), optical media (e.g., DVDs), or semiconductor media, which may be solid-state drives.
[0207] It should be understood that the term "and / or" herein describes only an association relationship between related objects and represents that three relationships may exist. For example, A and / or B may represent the following three cases: only A exists, both A and B exist, and only B exists. Here, A and B may be singular or plural. Furthermore, the character " / " herein usually indicates an "or" relationship between related objects, but may also indicate an "and / or" relationship. For more details, please refer to the context for understanding.
[0208] As used herein, "at least one" means one or more, and "plurality" means two or more. "At least one of the following items (moieties)" or similar expressions means any combination of these items, including a single item (moiety) or any combination of multiple items (moieties). For example, at least one of a, b, or c can refer to a, b, c, ab, ac, bc, or abc, where a, b, and c may be singular or plural.
[0209] It should be understood that the sequence numbers of the above processes do not imply the order of execution in various embodiments of the present application, and the order of execution of the processes should be determined based on the functions and internal logic of the processes, and should not be construed as any limitation on the implementation process of the embodiments of the present application.
[0210] Those skilled in the art may recognize that, in combination with the examples described in the embodiments disclosed herein, the units and algorithm steps may be implemented by electronic hardware or a combination of computer software and electronic hardware. Whether a function is performed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but the implementation form should not be considered to go beyond the scope of this application.
[0211] For the sake of convenient and concise description, it can be clearly understood by those skilled in the art that for the detailed operation processes of the aforementioned systems, devices and units, please refer to the corresponding processes in the aforementioned method embodiments, and the details will not be described again in this specification.
[0212] In some embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods may be implemented in other manners. For example, the described device embodiments are merely examples. For example, the division into units is merely a logical division of function, and other divisions may be used in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not implemented. In addition, the shown or described mutual couplings or direct couplings or communication connections may be implemented by using some interfaces. Indirect couplings or communication connections between devices or units may be implemented in electronic, mechanical, or other forms.
[0213] The units described as separate parts may or may not be physically separate, and the parts shown as units may or may not be physical units, and may be located in one location or distributed over multiple network units. Some or all of the units may be selected based on actual requirements to achieve the objectives of the solutions of the embodiments.
[0214] In addition, the functional units in the embodiments of the present application may be integrated into one processing unit, and each of the units may exist physically alone, or two or more units may be integrated into one unit.
[0215] When a function is implemented in the form of a software functional unit and sold or used as an independent product, the function may be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application may essentially be implemented in the form of a software product, or a portion of the technical solution may be implemented in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for instructing a computer device (which may be a personal computer, a server, a network device, etc.) to perform all or part of the steps of the method described in the embodiments of the present application. The aforementioned storage medium includes any medium capable of storing program code, such as a USB flash drive, a removable hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, etc.
[0216] The above description is merely a specific implementation of the present application and is not intended to limit the scope of protection of the present application. Any variations or replacements that can be easily conceived by those skilled in the art within the technical scope disclosed in the present application shall fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be subject to the scope of protection of the claims.
Claims
1. 1. A communication method applicable to a scenario in which a terminal device registers to a network via a trusted non-3GPP access network, the trusted non-3GPP access network including a trusted non-3GPP gateway function (TNGF), the method comprising: receiving, by the terminal device, an authentication request message from the TNGF; sending, by the terminal device, an authentication response message to the TNGF in response to the authentication request message, the authentication response message including a registration request message and identification information capable of uniquely representing the terminal device, the registration request message being used to request registration with the network and carrying an anonymous subscription concealment identifier (SUCI) corresponding to the terminal device; sending a secure connection establishment request message to the TNGF by the terminal device, the secure connection establishment request message being used to trigger the establishment of a secure connection between the terminal device and the TNGF, the secure connection establishment request message including the identification information and a first authentication parameter, the first authentication parameter being a TNGF key (K TNGF ) is generated based on the K TNGF is a shared key between the terminal device and the TNGF; A method comprising:
2. The identification information is TNGF The method of claim 1, wherein the TNGF is used to associate with
3. The terminal device TNGF Based on the security tunnel key (K TIPSec ) The terminal device TIPSec generating the first authentication parameter based on 3. The method of claim 1 or 2, further comprising:
4. The method of claim 1 , wherein the anonymous SUCI is a SUCI in a Network Access Identifier (NAI) format, and a username portion of the SUCI in the NAI format is a null value or a fixed string.
5. generating, by the terminal device, the identification information if the terminal device is not configured with the network's public key; The method of claim 1 , further comprising:
6. Before transmitting the authentication response message to the TNGF by the terminal device, the method further comprises: determining, by the terminal device, that the terminal device is accessing the network for the first time; 6. The method of claim 1, further comprising:
7. 7. The method of claim 1, wherein the identification information is one or a combination of a random number generated by the terminal device, a hash value of parameters that can uniquely represent the terminal device, or a modified SUCI, and a username portion of the modified SUCI is determined based on the random number or the hash value.
8. The method of claim 7 , wherein the domain name portion of the modified SUCI is the same as the domain name portion of the anonymous SUCI.
9. The method according to claim 1 , wherein the authentication response message includes access network parameters and the registration request message, and the identification information is carried in a user identifier field of the access network parameters.
10. The method of claim 1 , wherein the identification information is a 64-bit random number.
11. A communication method applied to a scenario in which a terminal device registers to a network via a trusted non-3GPP access network, comprising: sending an authentication request message to the terminal device by a Trusted Non-3GPP Gateway Function (TNGF) in the trusted non-3GPP access network; receiving, by the TNGF, an authentication response message from the terminal device, the authentication response message including a registration request message and identification information that can uniquely represent the terminal device, the registration request message being used to request registration with the network and carrying an anonymous Subscription Concealment Identifier (SUCI) corresponding to the terminal device; sending, by the TNGF, the registration request to a mobility management network element; The TNGF receives a TNGF key (K TNGF ), wherein the K TNGF is a shared key between the terminal device and the TNGF; The TNGF induces the TNGF and the identification information in association with each other; receiving, by the TNGF, a secure connection establishment request message from the terminal device, the secure connection establishment request message being used to trigger the establishment of a secure connection between the terminal device and the TNGF, the secure connection establishment request message including the identification information and first authentication parameters; The TNGF induces the K TNGF and obtaining The TNGF is TNGF and continuing, by the TNGF, the procedure for establishing the secure connection if the first authentication parameter is successfully verified based on A method comprising:
12. 12. The method of claim 11, wherein the anonymous SUCI is a SUCI in a network access identifier (NAI) format, and a username portion of the SUCI in the NAI format is a null value or a fixed string.
13. 13. The method according to claim 11 or 12, wherein the identification information is one or a combination of a random number, a hash value of parameters that can uniquely represent the terminal device, or a modified SUCI, and a username portion of the modified SUCI is determined based on the random number or the hash value.
14. The method of claim 13 , wherein the domain name portion of the modified SUCI is the same as the domain name portion of the anonymous SUCI.
15. The method of any one of claims 11 to 14, wherein the identification information is a 64-bit random number.
16. Terminal device, comprising a module adapted to carry out the communication method according to any one of claims 1 to 10.
17. A trusted non-3GPP gateway function, comprising a module configured to implement a communication method according to any one of claims 11 to 15.
18. 16. A computer readable storage medium containing a computer program or instructions which, when run on a computer, cause the computer to perform the communication method of any one of claims 1 to 15.
19. 16. A communications system comprising a terminal device and a trusted non-3GPP gateway function, said terminal device configured to perform a method according to any one of claims 1 to 10, and said trusted non-3GPP gateway function configured to perform a method according to any one of claims 11 to 15.
20. A computer program product comprising a computer program or instructions which, when run on a computer, cause the computer to carry out the communication method of any one of claims 1 to 15.