Subscription data update method, device, node, and storage medium

The method and device address the issue of AKMA context retention during subscription data updates in 5G networks by deleting the context at a second network function node, enhancing security by preventing traffic exploitation.

JP7762156B2Active Publication Date: 2025-10-29ZTE CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2022555641
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-10-16
Filing Date
2021-09-29
Publication Date
2025-10-29
Estimated Expiration
2041-09-29

AI Technical Summary

Technical Problem

In 5G networks, when user subscription data is updated, the AKMA context is retained by network function nodes, potentially allowing attackers to exploit AKMA traffic.

Method used

A method and device that determine and notify a second network function node to delete the AKMA context during subscription data updates, ensuring the context is not retained, thereby preventing exploitation.

Benefits of technology

Prevents AKMA traffic exploitation by ensuring the context is not retained during subscription data updates, enhancing security in 5G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007762156000001
    Figure 0007762156000001
  • Figure 0007762156000002
    Figure 0007762156000002
  • Figure 0007762156000003
    Figure 0007762156000003
Patent Text Reader

Abstract

A subscription data update method, and an apparatus, a node, and a storage medium are provided, the method including: when a first network function node determines that a user's Authentication and Key Management for Applications (AKMA) subscription data is to be updated, the first network function node determines a second network function node that stores the user's AKMA context; the first network function node sends a subscription data management notification message to the second network function node; and the first network function node receives a subscription data management notification response message sent by the second network function node, wherein after the second network function node deletes the user's AKMA context according to the subscription data management notification message, the subscription data management notification response message is sent.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (Technical field) The present application relates to the technical field of wireless communications, for example, to a subscription data update method, an apparatus, a node, and a storage medium. [Background technology]

[0002] (background) As defined by the 3rd Generation Partnership Project (3GPP®) standards working group, a fifth-generation mobile communications technology (5G) system includes a 5G radio access network (5G RAN) subsystem and a 5G core (5GC) subsystem. As shown in FIG. 1, the 5G system architecture includes multiple network functions (NFs). The 5G RAN subsystem includes a new radio (NR) base station, i.e., a radio access node (AN). The 5G core network subsystem includes a unified data management (UDM), an access management function (AMF), a session management function (SMF), a user plane function (UPF), a policy control function (PCF), a security anchor function (SEAF), an authentication server function (AUSF), and an authentication credential repository and processing function (ARPF). The 5G network includes a subscription privacy identifier (SUCI) and a subscription permanent identifier (SUPI), which may include an international mobile subscriber identity (IMSI) or a network access identifier (NAI).

[0003] Figure 2 is a schematic diagram of the architecture for Authentication and Key Management for Applications (AKMA) based on a service-based architecture. Compared with 5G systems, AKMA introduces a new network function, namely, the AKMA Anchor Function (AAnF). The AAnF is located in the home network and is mainly used to generate session keys between the user equipment (UE) and the application function (AF) and to maintain the security context between the AAnF and the UE. The AAnF is similar to the bootstrapping server function (BSF) in the generic bootstrapping architecture (GBA), and acts as an interface (Ua) between the UE and the AF. * is similar to the Ua interface in the GBA. Nnef, Nausf, Naanf, and Namf in Figure 2 are service-based interfaces for the Network Explosion Function (NF), AUSF, AAnF, and AMF, respectively.

[0004] 3 is a schematic diagram of a key derivation architecture for an authentication and key management system for applications. After a UE accesses a 5G network and 5G authentication and key agreement (AKA), i.e., authentication through 5G-AKA or Extensible Authentication Protocol-AKA' (i.e., EAP-AKA'), is successful, the AUSF and the UE derive a key K AUSF Generate the AKMA anchor key K AKMA But, key K AUSF and the mobile equipment (ME) and AAnF use the key K AKMA From Application Key K AF where AUSF and AAnF are both in the home network. Summary of the Invention [Means for solving the problem]

[0005] (overview) Embodiments of the present application provide a subscription data update method, device, node, and storage medium in which, when user subscription data is updated, the second network function node does not retain a context associated with the AKMA, thereby avoiding a situation in which the AKMA traffic is exploited by an attacker.

[0006] An embodiment of the present application provides a subscription data updating method, including: when a first network function node determines that AKMA subscription data is to be updated, the first network function node determines a second network function node that stores the user's AKMA context; the first network function node sends a subscription data management notification message to the second network function node; and the first network function node receives a subscription data management notification response message sent by the second network function node. After the second network function node deletes the user's AKMA context according to the subscription data management notification message, the subscription data management notification response message is sent.

[0007] An embodiment of the present application provides a subscription data updating method, including: a third network function node receiving a query message sent by a first network function node; the third network function node determining a second network function node according to the query message; and the third network function node sending a query response message to the first network function node, where the query response message carries an identifier or address of the second network function node.

[0008] An embodiment of the present application provides a subscription data update method, including: a fourth network function node determining a second network function node; and the fourth network function node sending a message to the first network function node, where the message carries an identifier or address of the second network function node.

[0009] An embodiment of the present application provides a subscription data updating device, including: a determination module configured to determine a second network function node that stores the user's AKMA context when it determines that the user's AKMA subscription data is to be updated; a sending module configured to send a subscription data management notification message to the second network function node; and a receiving module configured to receive a subscription data management notification response message sent by the second network function node, wherein the subscription data management notification response message is sent after the second network function node deletes the user's AKMA context according to the subscription data management notification message.

[0010] An embodiment of the present application provides a subscription data updating device, including: a receiving module configured to receive a query message sent by a first network function node; a determining module configured to determine a second network function node according to the query message; and a sending module configured to send a query response message to the first network function node, where the query response message carries an identifier or an address of the second network function node.

[0011] An embodiment of the present application provides a subscription data updating apparatus, including a determination module configured to determine a second network function node and a sending module configured to send a message to the first network function node, the message carrying an identifier or address of the second network function node.

[0012] An embodiment of the present application provides a network function node, which includes a processor that, when a program is executed by the processor, performs a subscription data update method provided by the embodiment of the present application.

[0013] An embodiment of the present application provides a readable / writable storage medium used for computer storage, which may store one or more programs, and the one or more programs may be executed by one or more processors to implement a subscription data update method provided by the embodiment of the present application.

[0014]

[0009] The embodiments of the present application provide a subscription data update method, a device, a node, and a storage medium. The method includes the following steps: when a first network function node determines that a user's AKMA subscription data is to be updated, the first network function node determines a second network function node that stores the user's AKMA context; the first network function node sends a subscription data management notification message to the second network function node; and the first network function node receives a subscription data management notification response message sent by the second network function node. After the second network function node deletes the user's AKMA context according to the subscription data management notification message, the subscription data management notification response message is sent. Through this design, when the user subscription data is updated, the second network function node does not retain the context associated with the AKMA, thereby avoiding a situation in which AKMA traffic is exploited by an attacker. The present invention provides, for example, the following. (Item 1) A method for updating subscription data, comprising: When a first network function node determines that a user's authentication and key management (AKMA) subscription data is to be updated, the first network function node determines a second network function node that stores the user's AKMA context; the first network function node sending a subscription data management notification message to the second network function node; the first network function node receiving a subscription data management notification response message sent by the second network function node; wherein the subscription data management notification response message is sent after the second network function node deletes the AKMA context of the user according to the subscription data management notification message. (Item 2) The first network function node determining the second network function node that stores the AKMA context of the user comprises: the first network function node determining the second network function node according to a local configuration; or The first network function node determines the second network function node according to a third network function node; or the first network function node determines the second network function node according to the fourth network function node; The method according to item 1, comprising: (Item 3) determining, by the first network function node, the second network function node according to the local configuration; the first network function node determining the second network function node according to a partial field of a user identifier; The method described in item 2. (Item 4) The first network function node determining the second network function node according to the third network function node, the first network function node sending a query message to the third network function node; receiving, by the first network function node, a query response message sent by the third network function node according to the query message, wherein the query response message carries an identifier or an address of the second network function node; the first network function node determining the second network function node according to the query response message; The method according to item 2, comprising: (Item 5) The first network function node determining the second network function node according to the fourth network function node, the first network function node sending a subscription change request message to the fourth network function node; receiving, by the first network function node, a subscription change request response message sent by the fourth network function node, the subscription change request response message carrying an identifier or address of the second network function node; the first network function node determining the second network function node according to the subscription change request response message; The method according to item 2, comprising: (Item 6) 5. The method of claim 4, wherein the query message carries at least one of a network function name of the second network function node or a network type of the second network function node, and at least one of a user identifier or location information of the first network function node. (Item 7) Item 6. The method of item 5, wherein the subscription change request message carries at least one of a network function name of the second network function node or a network type of the second network function node, and at least one of a user identifier or location information of the first network function node. (Item 8) The first network function node determining the second network function node according to the fourth network function node, receiving, by the first network function node, a subscription data management subscription message sent by the fourth network function node, the subscription data management subscription message carrying an identifier or address of the second network function node; the first network function node storing the identifier or the address of the second network function node according to the subscription data management subscription message; the first network function node determines the second network function node according to the identifier or the address of the second network function node stored by the first network function node; The method according to item 2, comprising: (Item 9) 9. The method of claim 8, further comprising the first network function node performing a primary authentication process through the fourth network function node before the first network function node receives a subscription data management subscription message sent by the fourth network function node. (Item 10) A method for updating subscription data, comprising: receiving, by a third network function node, the query message sent by the first network function node; The third network function node determines a second network function node according to the query message; the third network function node sending a query response message to the first network function node, the query response message carrying an identifier or address of the second network function node; A method comprising: (Item 11) Item 11. The method of item 10, wherein the query message carries at least one of a network function name of the second network function node or a network type of the second network function node, and at least one of a user identifier or location information of the first network function node. (Item 12) A method for updating subscription data, comprising: the fourth network function node determining the second network function node; the fourth network function node sending a message to the first network function node, the message carrying an identifier or address of the second network function node; A method comprising: (Item 13) The fourth network function node determining the second network function node includes: receiving, by the fourth network function node, a subscription change request message sent by the first network function node, the subscription change request message carrying a user identifier; the fourth network function node querying the second network function node according to the user identifier; Item 13. The method according to item 12, comprising: (Item 14) A subscription data updating device, comprising: a determination module configured to determine a second network function node that stores an Authentication and Key Management for Applications (AKMA) context of a user when determining that the user's AKMA subscription data is updated; a sending module configured to send a subscription data management notification message to the second network function node; a receiving module configured to receive a subscription data management notification response message sent by the second network function node; and after the second network function node deletes the AKMA context of the user according to the subscription data management notification message, the subscription data management notification response message is sent. Subscription data update device. (Item 15) A subscription data updating device, comprising: a receiving module configured to receive a query message sent by the first network function node; a determination module configured to determine a second network function node according to the query message; a sending module configured to send a query response message to the first network function node, the query response message carrying an identifier or address of the second network function node; A subscription data updating device comprising: (Item 16) A subscription data updating device, comprising: a determination module configured to determine a second network function node; a sending module configured to send a message to a first network function node, the message carrying an identifier or address of the second network function node; A subscription data updating device comprising: (Item 17) A network function node comprising a processor, wherein the processor, when executing a computer program, implements the subscription data update method described in any one of items 1 to 9, the subscription data update method described in any one of items 10 to 11, or the subscription data update method described in any one of items 12 to 13. (Item 18) A readable / writable storage medium that stores a computer program, the computer program, when executed by a processor, performs the subscription data update method according to any one of items 1 to 9, the subscription data update method according to any one of items 10 to 11, or the subscription data update method according to any one of items 12 to 13. [Brief explanation of the drawings]

[0015] [Figure 1] FIG. 1 is a schematic diagram of the architecture of a 5G system in the related art. [Figure 2] FIG. 2 is a schematic diagram of an architecture for an authentication and key management system for applications in the related art. [Figure 3] FIG. 3 is a schematic diagram of a key derivation architecture for an authentication and key management system for applications in the related art. [Figure 4] FIG. 4 is a flowchart of an AKMA anchor key generation method in the related art. [Figure 5] FIG. 5 is a flowchart of a subscription data updating method according to an embodiment of the present application. [Figure 6] FIG. 6 is a diagram illustrating signaling interactions of a subscription data update method according to an embodiment of the present application. [Figure 7] FIG. 7 illustrates a signaling interaction diagram of another subscription data update method according to an embodiment of the present application. [Figure 8] FIG. 8 illustrates a signaling interaction diagram of another subscription data update method according to an embodiment of the present application. [Figure 9] FIG. 9 illustrates a signaling interaction diagram of another subscription data update method according to an embodiment of the present application. [Figure 10] FIG. 10 is a flowchart of another subscription data updating method according to an embodiment of the present application. [Figure 11] FIG. 11 is a flowchart of another subscription data updating method according to an embodiment of the present application. [Figure 12] FIG. 12 is a structural diagram of a subscription data updating device according to an embodiment of the present application. [Figure 13] FIG. 13 is a structural diagram of another subscription data updating device according to an embodiment of the present application. [Figure 14] FIG. 14 is a structural diagram of another subscription data updating device according to an embodiment of the present application. [Figure 15] FIG. 15 is a network function node structural diagram according to an embodiment of the present application. DETAILED DESCRIPTION OF THE INVENTION

[0016] (Detailed explanation) Hereinafter, embodiments of the present application will be described in detail in conjunction with the drawings. It should be noted that the embodiments and their features described herein can be combined with each other if not contradictory.

[0017] Additionally, in the present embodiments, the words "optionally" or "for example" are used herein to mean serving as an example, instance, or illustration. Any embodiment or design scheme described in the present embodiments as "optionally" or "example" should not be construed as preferred or advantageous over other embodiments or design schemes. Use of the words "optionally" or "for example" is intended to present concepts in a concrete manner.

[0018] In the related art, the key K AKMA is typically generated by reusing the 5G primary authentication procedure (i.e., 5G-AKA or EAP-AKA' described above). After successful authentication, the UE and AUSF share the key K AUSF From AKMA Anchor Key K AKMA while deriving the key K AKMA Thus, an AKMA-Key Identifier (A-KID) associated with the key K is generated. AKMAmay be updated only through the 5G primary authentication procedure. AKMA technology provides end-to-end security protection from the user to the 5G network user application. When user subscription data is updated, the use of AKMA traffic is affected. If the AAnF continues to retain the context security associated with AKMA, an attacker may use AKMA traffic, which leads to the possibility that AKMA traffic can be exploited by an attacker.

[0019] For ease of understanding of the methods provided by the embodiments of the present application, the relevant concepts of network function node functions related to the embodiments and drawings of the present application are further explained below.

[0020] The UDM is used to permanently store user subscription data and is located in the home network subscribed by the user. The ARPF stores long-term key credentials for authentication and uses the long-term key credentials as input to perform key operations. The UDM and ARPF are located within the secure environment of the operator or third-party system and are not exposed to unauthorized physical access. In addition, the ARPF and AUSF can interact with each other.

[0021] The AMF is used to manage user demand for network access and is responsible for terminal-to-network non-access stratum (NAS) signaling management, user mobility management, and other functions. The AMF includes the Security Authentication Function (SEAF), which interacts with the AUSF and the UE to receive intermediate keys established for the UE authentication procedure. Based on the authentication method of the Universal Subscriber Identity Module (USIM), the AMF obtains security-related data from the AUSF.

[0022] The AUSF has authentication capabilities for interacting with the ARPF and can terminate requests from the SEAF. The AUSF is located within the secure environment of the operator or third-party system and is not exposed to unauthorized physical access.

[0023] The SMF is used to manage packet data unit (PDU) sessions and user quality of service (QoS) flows, formulate packet detection, and forwarding rules for the UPF.

[0024] The UPF is responsible for functions such as routing and forwarding of Internet Protocol (IP) and non-IP data, usage reporting, and the like.

[0025] The PCF is responsible for providing policy rules at all levels for the AMF and SMF.

[0026] The data network (DN) includes networks such as operator services, network access, and third party services.

[0027] The AF is used to manage the AF session.

[0028] SUCI consists of six parts:

[0029] (1) SUPI type has a value of 0 to 7, where value 0 is IMSI, value 1 is Network Access Identifier (NAI), and others should also be used.

[0030] (2) The home network identifier identifies the user in the home network. If the SUPI is the IMSI, the home network identifier consists of the mobile country code (MCC) and the mobile network code (MNC). If the SUPI is the NAI, the NAI is defined by section 2.2 of IETF RFC7542.

[0031] (3) A routing indicator (RID) is assigned by the home network operator and configured in the USIM with the home network identifier to indicate that network signaling is being routed to the serving user's AUSF and UDM.

[0032] (4) The protection scheme identifier refers to one of the null scheme or a non-null scheme.

[0033] (5) The home network public key identifier represents the identifier of the public key provided by the home network for protecting the SUPI, and in the case of the null scheme, the value of the home network public key identifier is 0.

[0034] (6) The scheme output is the Mobile Subscriber Identification Number (MSIN) of the NAI or IMSI in the case of a null scheme, and the scheme output is the value of the MSIN and NAI using Elliptic Curve Cryptography (EEC) in the case of a non-null scheme.

[0035] For example, when the IMSI is 234150999999999, i.e., MCC=234, MNC=15, and MSIN=099999999, the routing indicator is 678, and the home network public key identifier is 27, the SUCI for the null scheme consists of 0, 234, 15, 678, 0, 0, and 0999999999, and the SUCI for the non-null scheme consists of 0, 234, 15, 678, 1, 27, <Elliptic Curve Cryptography (EEC) ephemeral public key value>, <encryption 09999999>, and <Message Authentication Code (MAC) value (MAC tag value)>.

[0036] As shown in FIG. 4, the 5G primary authentication procedure includes S401, S402, S403, S404, and S405.

[0037] In S401, the AUSF interacts with the UDM to obtain authentication information such as authentication credentials (e.g., AKA authentication vector (AV)), and the authentication type is Nudm_UEAuthentication_Get Request service operation.

[0038] At S402, in the response message, the UDM may indicate to the AUSF whether an AKMA key needs to be generated for the UE.

[0039] In S403, if the AUSF receives an AKMA indication from the UDM, the AUSF AUSF Remember, K AUSF Based on AKMA anchor key K AKMA Before the UE starts communication with the AKMA application server, the UE generates the K AUSF Based on AKMA anchor key K AKMA and generate A-KID.

[0040] In S404, after the AUSF generates the AKMA key material, the user's SUPI and the generated A-KID and K AKMA is sent to the AAnF using the Naanf_AKMA_KeyRegistration Request service operation. The AAnF stores the most recent key material sent by the AUSF.

[0041] In S405, the AAnF sends a response to the AUSF using the Naanf_AKMA_KeyRegistration Response service operation.

[0042] Based on the above concept, an embodiment of the present application provides a subscription data update method, the flowchart of which is shown in Figure 5, including but not limited to S501, S502 and S503.

[0043] In S501, if the first network function node determines that the user's AKMA subscription data is to be updated, the first network function node determines the second network function node that stores the user's AKMA context.

[0044] In this embodiment of the present application, in S501, the first network function node may be understood as a UDM, and the second network function node may be understood as an AAnF.

[0045] In S501, updating of the user's AKMA subscription data may include, but is not limited to, the following cases: in the first case, the user cancels and deletes the user's subscription message in the UDM from the network; in the second case, the user does not use AKMA traffic and deletes the AKMA subscription information; and in the third case, the user cannot use the service due to various reasons such as non-payment.

[0046] That is, S501 can be understood as the need for the UDM to check the AAnF that stores the user's AKMA context when the user's AKMA subscription data is updated.

[0047] At S502, the first network function node sends a subscription data management notification message to the second network function node.

[0048] When the first network function node determines the second network function node and sends a subscription data management notification message to the second network function node, the user identifier SUPI may be carried in the subscription data management notification message. Optionally, the user's AKMA subscription indication may be carried in the subscription data management notification message.

[0049] At S503, the first network function node receives a subscription data management notification response message sent by the second network function node.

[0050] After the second network function node receives the subscription data management notification message sent by the first network function node, the second network function node obtains the SUPI, A-KID, and K according to the user identifier SUPI carried in the subscription data management notification message. AKMA etc., and then send a subscription data management notification response message to the first network function node.

[0051] This embodiment of the present application provides a subscription data update method, the method including: when a first network function node determines that a user's AKMA subscription data is to be updated, the first network function node determines a second network function node that stores the user's AKMA context; the first network function node sends a subscription data management notification message to the second network function node; and the first network function node receives a subscription data management notification response message sent by the second network function node. After the second network function node deletes the user's AKMA context according to the subscription data management notification message, the subscription data management notification response message is sent. Through such a design manner, when user subscription data is updated, the second network function node does not retain a context associated with the AKMA, thereby avoiding a situation in which AKMA traffic is exploited by an attacker.

[0052] In an embodiment, the implementation of the above S501 may include, but is not limited to, the following cases: in the first case, the first network function node determines the second network function node according to a local configuration, in the second case, the first network function node determines the second network function node through a third network function node, and in the third case, the first network function node determines the second network function node through a fourth network function node.

[0053] As shown in FIG. 6, an implementation form of the first case described above may include the first network function node determining the second network function node according to a partial field of the user identifier.

[0054] For example, the subfields may include MCC, MNC, and the like.

[0055] As shown in Figure 7, an implementation form of the second case may include the following processes: a process in which a first network function node sends a query message to a third network function node; a process in which the first network function node receives a query response message sent by the third network function node according to the query message, where the query response message carries an identifier or an address of the second network function node; and a process in which the first network function node determines the second network function node according to the query response message.

[0056] For example, the query message may carry a network function name (such as AAnF) and / or a network type (such as AAnF type), and a user identifier SUPI and / or location information of the first network function node. The third network function node is a network repository function (NRF), i.e., the NRF may query the AAnF that stores the user's AKMA context according to the SUPI and / or UDM location information and the AAnF network function name and / or AAnF network type in the query message, and then send a query response message to the UDM.

[0057] As shown in Figure 8, in an embodiment, the implementation form of the third case may include the following processes: a process in which a first network function node sends a subscription change request message to a fourth network function node; a process in which the first network function node receives a subscription change request response message sent by the fourth network function node, where the subscription change request response message carries an identifier or address of the second network function node; and a process in which the first network function node determines a subscription to the second network function node according to the change request response message.

[0058] For example, the fourth network function node may be an AUSF, and the subscription change request may carry a network function name (e.g., AAnF) and / or a network type (e.g., AAnF type), and a user identifier SUPI and / or location information of the first network function node, i.e., the AUSF queries the AAnF that stores the user's AKMA context according to the SUPI and / or UDM location information and the AAnF network function name and / or AAnF network type, and sends the query result to the UDM in the form of a subscription change request response message.

[0059] 9 , in an embodiment, an implementation form of the third case may include the following processes: a process in which a first network function node receives a subscription data management subscription message sent by a fourth network function node, where the subscription data management subscription message carries an identifier or an address of a second network function node; a process in which the first network function node stores the identifier or address of the second network function node according to the subscription data management subscription message; and a process in which the first network function node determines the second network function node according to the stored identifier or address of the second network function node.

[0060] Optionally, after the first network function node receives the subscription data management subscription message sent by the fourth network function node, the first network function node may further send a subscription data management subscription response message to the fourth network function node.

[0061] It should be noted that before the first network function node receives the subscription data management subscription message sent by the fourth network function node, the first network function node may further perform a primary authentication procedure through the fourth network function node. Here, the primary authentication procedure is an implementation form provided in Figure 4 of the present application. As can be seen from Figure 4, after the AUSF generates the AKMA key material, the AUSF sends the AKMA key material to the AAnF, and the AAnF stores the AKMA key material. In this way, when the user's AKMA subscription data is updated, the UDM may send a subscription data management notification message to the AAnF according to the AAnF's stored identifier or address.

[0062] 10 is a flowchart of another subscription data update method according to an embodiment of the present application. As shown in FIG. 10, the method may include, but is not limited to, S1001, S1002, and S1003.

[0063] In S1001, the third network function node receives a query message sent by the first network function node.

[0064] In this embodiment of the present application, the third network function node may be an NRF, the first network function node may be a UDM, and the query message sent by the first network function node may carry a network function name and / or a network type, and a user identifier and / or location information of the first network function node.

[0065] In S1002, the third network function node determines the second network function node according to the query message.

[0066] The third network function node queries the second network function node according to the network function name and / or network type and the user identifier and / or location information of the first network function node in the query message.

[0067] The second network function node may be an AAnF, which is used to store the user's AKMA context.

[0068] At S1003, the third network function node sends a query response message to the first network function node.

[0069] The query response message sent by the third network function node carries an identifier or address of the second network function node.

[0070] This embodiment of the present application provides a subscription data update method, including: a third network function node receiving a query message sent by a first network function node; the third network function node determining a second network function node according to the query message; and the third network function node sending a query response message to the first network function node, where the query response message carries an identifier or address of the second network function node. Through the solution described above, the second network function node is effectively determined so that when user subscription data is updated, the first network function node may send a subscription data management notification message to the second network function node, and the second network function node does not retain a context associated with the AKMA, thereby avoiding a situation in which the AKMA traffic is exploited by an attacker.

[0071] 11 is a flowchart of another subscription data update method according to an embodiment of the present application. As shown in FIG. 11, the method may include, but is not limited to, S1101 and S1102.

[0072] In S1101, the fourth network function node determines the second network function node.

[0073] In this embodiment of the present application, the fourth network function node may be an AUSF, and the second network function node may be an AAnF, which is used to store the user's AKMA context.

[0074] For example, an implementation of S1101 may include the following: a fourth network function node receiving a subscription change request message sent by the first network function node, where the subscription change request message carries a user identifier; and the fourth network function node querying the second network function node according to the user identifier.

[0075] The first network function node may be a UDM, i.e., after the AUSF receives the subscription change request message sent by the UDM, the AUSF queries the AAnF that stores the user's AKMA context according to the user identifier in the message.

[0076] In S1102, the fourth network function node transmits a message to the first network function node.

[0077] The message sent by the fourth network function node may carry an identifier or address of the second network function node.

[0078] This embodiment of the present application provides a subscription data update method, including: a fourth network function node determining a second network function node; and the fourth network function node sending a message to a first network function node, the message carrying an identifier or address of the second network function node. Through the solution described above, when user subscription data is updated, the first network function node can determine a second network function node to send a subscription data management notification message to the second network function node, and the second network function node does not retain a context associated with the AKMA, thereby avoiding a situation in which the AKMA traffic is exploited by an attacker.

[0079] 12 is a structural diagram of a subscription data updating device according to an embodiment of the present application. As shown in FIG. 12, the device may include a determining module 1201, a sending module 1202, and a receiving module 1203. The determining module is configured to determine a second network function node that stores the user's AKMA context when it determines that the user's AKMA subscription data is updated. The sending module is configured to send a subscription data management notification message to the second network function node. The receiving module is configured to receive a subscription data management notification response message sent by the second network function node. After the second network function node deletes the user's AKMA context according to the subscription data management notification message, the subscription data management notification response message is sent.

[0080] In an embodiment, the determination module is configured to determine the second network function node according to a local configuration, determine the second network function node through a third network function node, and determine the second network function node through a fourth network function node.

[0081] In an embodiment, the determination module is configured to determine the second network function node according to a partial field of the user identifier.

[0082] In an embodiment, the determination module may include a communication unit and a determination unit. The communication unit is configured to send a query message to a third network function node and receive a query response message sent by the third network function node according to the query message, where the query response message carries an identifier or an address of the second network function node. The determination unit is configured to determine the second network function node according to the query response message.

[0083] In an embodiment, the determination module may include a communication unit and a determination unit. The communication unit is configured to send a subscription change request message to a fourth network function node and receive a subscription change request response message sent by the fourth network function node, where the subscription change request response message carries an identifier or address of the second network function node. The determination unit is configured to determine the second network function node according to the subscription change request response message.

[0084] The query message may carry a network function name and / or a network type, and a user identifier and / or location information of the first network function node. The subscription change request message may carry a network function name and / or a network type, and a user identifier and / or location information of the first network function node.

[0085] In one embodiment, the determination module may include a communication unit, a storage unit, and a determination unit. The communication unit is configured to receive a subscription data management subscription message sent by the fourth network function node, where the subscription data management subscription message carries an identifier or an address of the second network function node. The storage unit is configured to store the identifier or address of the second network function node according to the subscription data management subscription message. The determination unit is configured to determine the second network function node according to the stored identifier or address of the second network function node.

[0086] In an embodiment, the apparatus may further include an authentication module configured to perform a primary authentication procedure through a fourth network function node.

[0087] The subscription data updating apparatus provided by this embodiment is used to implement the subscription data updating method of the embodiments shown in Figures 5, 6, 7, 8, and 9. The implementation principles and technical effects of the apparatus are similar to those of the method, and the details will not be repeated in this specification.

[0088] 13 is a structural diagram of another subscription data updating device according to an embodiment of the present application. As shown in FIG. 13, the device may include a receiving module 1301, a determining module 1302, and a sending module 1303. The receiving module is configured to receive a query message sent by a first network function node. The determining module is configured to determine a second network function node according to the query message. The sending module is configured to send a query response message to the first network function node, where the query response message carries an identifier or address of the second network function node.

[0089] The query message carries a network function name and / or a network type, and a user identifier and / or location information of the first network function node.

[0090] The subscription data updating apparatus provided by this embodiment is used to implement the subscription data updating method of the embodiment shown in Figure 10. The implementation principle and technical effect of the apparatus are similar to those of the method, and the details will not be repeated in this specification.

[0091] 14 is a structural diagram of another subscription data updating device according to an embodiment of the present application. As shown in FIG. 14, the device may include a determining module 1401 and a sending module 1402. The determining module is configured to determine a second network function node. The sending module is configured to send a message to the first network function node, where the message carries an identifier or address of the second network function node.

[0092] Optionally, the determination module may include a communication unit and a query unit, where the communication unit is configured to receive a subscription change request message sent by the first network function node, where the subscription change request message carries a user identifier, and the query unit is configured to query the second network function node according to the user identifier.

[0093] The subscription data updating apparatus provided by this embodiment is used to implement the subscription data updating method of the embodiment shown in Figure 11. The implementation principle and technical effect of the apparatus are similar to those of the method, and the details will not be repeated in this specification.

[0094] Figure 15 is a structural diagram of a network function node according to an embodiment of the present application. As shown in Figure 15, the network function node includes a processor 1501 and a memory 1502. The number of processors 1501 in the network function node may be one or more, and Figure 15 illustrates one processor 1501 as an example. The processor 1501 and the memory 702 in the network function node may be connected via a bus or in other manners, and Figure 15 illustrates connection via a bus as an example.

[0095] As a computer-readable storage medium, the memory 1502 may be configured to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the methods in any of the embodiments of the present application shown in Figures 5 to 11. The processor 1501 executes the software programs, instructions, or modules stored in the memory 1502 to perform the methods in the embodiments shown in Figures 5 to 11.

[0096] The memory 1502 may primarily include a program storage area and a data storage area, where the program storage area may store an operating system and application programs required by at least one function, while the data storage area may store data created in response to use of the set-top box. Additionally, the memory 1502 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk memory, flash memory, or other non-volatile solid-state memory.

[0097] In some embodiments, if possible, a processor in a node may implement the subscription data update method through its internal logic circuits, gate circuits, and other hardware circuits.

[0098] An embodiment of the present application further provides a readable / writable storage medium used for computer storage, the storage medium storing one or more programs, which, when executed by one or more processors, may perform the method provided by any of the embodiments shown in Figures 5-11.

[0099] It should be understood by those skilled in the art that the steps of the methods and the functional modules / units in all or part of the devices disclosed in the foregoing description can be implemented as software, firmware, hardware, or any suitable combination thereof.

[0100] In a hardware implementation, boundaries between functional modules / units may not correspond to boundaries between physical components. For example, one physical component may have several functions, or one function or step may be performed by several physical components together. Some or all of the physical components may be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, may be implemented as hardware, or may be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed across computer-readable media. Computer-readable media may include computer storage media (or non-transitory media) and communication media (or transitory media). As known to those skilled in the art, the term “computer storage media” includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, disk storage or other magnetic storage devices, or any other medium accessible by a computer used to store the desired information. Additionally, as known to those skilled in the art, communication media generally include computer-readable instructions, data structures, program modules, or other data in a modulated data signal transported on a carrier or other transport mechanism and may include any information delivery media.

[0101] Preferred embodiments of the present application are illustrated herein with reference to the drawings, and are not intended to limit the scope of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and spirit of the present application should fall within the scope of the present application.

Claims

1. A method for wireless communication, comprising: a first network function node determining a second network function node that stores an authentication and key management (AKMA) context for an application of the user; the first network function node sending a subscription data management notification message to the second network function node; receiving, by the first network function node, a subscription data management notification response message sent by the second network function node; wherein the subscription data management notification response message is sent after the second network function node deletes the AKMA context of the user in accordance with the subscription data management notification message.

2. The first network function node determining the second network function node that stores the AKMA context of the user comprises: the first network function node determining the second network function node according to a local configuration; or the first network function node determines the second network function node according to a third network function node; The method of claim 1 , comprising:

3. 3. The method of claim 2, wherein the first network function node determining the second network function node according to the local configuration comprises the first network function node determining the second network function node according to a partial field of a user identifier.

4. The first network function node determining the second network function node according to the third network function node, the first network function node sending a query message to the third network function node; receiving, by the first network function node, a query response message sent by the third network function node according to the query message, the query response message carrying an identifier or an address of the second network function node; the first network function node determining the second network function node according to the query response message; The method of claim 2 , comprising:

5. The first network function node determining the second network function node according to the third network function node, the first network function node sending a subscription change request message to the third network function node; receiving, by the first network function node, a subscription change request response message sent by the third network function node, the subscription change request response message carrying an identifier or address of the second network function node; the first network function node determining the second network function node according to the subscription change request response message; The method of claim 2 , comprising:

6. 5. The method of claim 4, wherein the query message carries at least one of a network function name of the second network function node, a network type of the second network function node, a user identifier, or location information of the first network function node.

7. 6. The method of claim 5, wherein the subscription change request message carries at least one of a network function name of the second network function node or a network type of the second network function node, and at least one of a user identifier or location information of the first network function node.

8. The first network function node determining the second network function node according to the third network function node, receiving, by the first network function node, a subscription data management subscription message sent by the third network function node, the subscription data management subscription message carrying an identifier or address of the second network function node; the first network function node storing the identifier or the address of the second network function node according to the subscription data management subscription message; the first network function node determining the second network function node according to the identifier or the address of the second network function node stored by the first network function node; The method of claim 2 , comprising:

9. 9. The method of claim 8, further comprising the first network function node performing a primary authentication process through the third network function node before the first network function node receives the subscription data management subscription message sent by the third network function node.

10. A first network function node, the first network function node comprising: a memory for storing computer instructions; and a processor in communication with the memory, wherein when the processor executes the computer instructions, the processor: determining a second network function node that stores an authentication and key management (AKMA) context for an application of the user; sending a subscription data management notification message to the second network function node; receiving a subscription data management notification response message sent by the second network function node; the first network function node; The first network function node, wherein the subscription data management notification response message is sent after the second network function node deletes the AKMA context of the user in accordance with the subscription data management notification message.

11. When the processor is configured to cause the first network function node to determine a second network function node that stores the AKMA context of the user, the processor: determining the second network function node according to a local configuration; or determining the second network function node according to a third network function node; The first network function node of claim 10 , configured to cause the first network function node to implement one of:

12. A first network function node as described in claim 11, wherein when the processor is configured to cause the first network function node to determine the second network function node according to the local configuration, the processor is configured to cause the first network function node to determine the second network function node according to a partial field of a user identifier.

13. When the processor is configured to cause the first network function node to determine the second network function node according to the third network function node, the processor: sending a query message to the third network function node; receiving a query response message sent by the third network function node according to the query message, the query response message carrying an identifier or address of the second network function node; determining the second network function node according to the query response message; The first network function node according to claim 11 , configured to cause the first network function node to perform the following:

14. When the processor is configured to cause the first network function node to determine the second network function node according to the third network function node, the processor: sending a subscription change request message to the third network function node; receiving a subscription modification request response message sent by the third network function node, the subscription modification request response message carrying an identifier or address of the second network function node; determining the second network function node according to the subscription change request response message; The first network function node according to claim 11 , configured to cause the first network function node to perform the following:

15. The first network function node described in claim 13, wherein the query message carries at least one of a network function name of the second network function node, a network type of the second network function node, a user identifier, or location information of the first network function node.

16. A non-transitory storage medium for storing computer-readable instructions, the computer-readable instructions, when executed by a processor within a first network function node, determining a second network function node that stores an authentication and key management (AKMA) context for an application of the user; sending a subscription data management notification message to the second network function node; receiving a subscription data management notification response message sent by the second network function node; causing the processor to perform A non-transitory storage medium, wherein the subscription data management notification response message is transmitted after the second network function node deletes the AKMA context of the user in accordance with the subscription data management notification message.

17. When the computer-readable instructions cause the processor to determine a second network function node that stores the AKMA context for the user, the computer-readable instructions further comprise: determining the second network function node according to a local configuration; or determining the second network function node according to a third network function node; 17. The non-transitory storage medium of claim 16, which causes the processor to perform one of:

18. A non-transitory storage medium as described in claim 17, wherein when the computer-readable instructions cause the processor to determine the second network function node according to the local configuration, the computer-readable instructions cause the processor to determine the second network function node according to a partial field of a user identifier.

19. When the computer-readable instructions cause the processor to determine the second network function node according to the third network function node, the computer-readable instructions further comprise: sending a query message to the third network function node; receiving a query response message sent by the third network function node according to the query message, the query response message carrying an identifier or address of the second network function node; determining the second network function node according to the query response message; The non-transitory storage medium of claim 17 , which causes the processor to perform the following:

20. The non-transitory storage medium of claim 19, wherein the query message carries at least one of a network function name of the second network function node, a network type of the second network function node, a user identifier, or location information of the first network function node.

Citation Information

Patent Citations

  • Method and apparatus for network function selection scheme in service based architecture of communication network

    WO2020031157A1

  • Methods for authentication and key management in a wireless communications network and related apparatuses

    WO2020152140A1

  • Non-public network authentication in 5g

    WO2020173863A1