Key processing methods, communication device, and storage medium
By acquiring and distributing the root key based on capability information during the terminal registration process, the security and efficiency of the terminal obtaining the root key in the ranging/SL positioning service are solved, and the effect that the terminal can use the root key to perform business operations after the registration is completed.
Patent Information
- Application Number
- PCT/CN2023/127983
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-30
- Publication Date
- 2025-05-08
AI Technical Summary
The prior art is difficult to effectively solve the security and efficiency problems that the terminal has in obtaining the root key in the ranging/SL positioning service.
During the terminal registration process, based on the capability information reported by the terminal, the network equipment obtains and distributes the root key for the ranging/SL positioning service to ensure that the terminal can use the root key to perform the ranging/SL positioning service after the registration is completed.
It realizes that the terminal instantly obtains the root key during the registration process, improves the efficiency and security of the ranging/SL positioning service, and avoids additional root key acquisition steps.
Smart Images

Figure CN2023127983_08052025_PF_FP_ABST
Abstract
Description
Key processing method, communication device, and storage medium Technical Field
[0001] The present disclosure relates to the field of communication technology, and in particular to a key processing method, communication equipment, communication system, and storage medium. Background Art
[0002] Ranging / Sidelink (SL) positioning services can be used for positioning and / or ranging between terminals. If a terminal has ranging / SL positioning capabilities and has subscribed to the ranging / SL positioning service, it can obtain ranging / SL positioning service services.
[0003] Summary of the Invention
[0004] Embodiments of the present disclosure provide a key processing method, a communication device, a communication system, and a storage medium.
[0005] According to a first aspect of an embodiment of the present disclosure, a key processing method is provided, which is executed by a first network device, and the method includes: receiving a first message sent by a second network device, the first message including capability information reported by a terminal when requesting registration; obtaining a root key used by the terminal for ranging / SL positioning services based on an indication that the terminal has ranging / sidelink SL positioning capability based on the capability information; and sending the root key to the second network device or the terminal.
[0006] According to the second aspect of an embodiment of the present disclosure, a key processing method is provided, which is executed by a second network device and includes: receiving a fourth message sent by a terminal; the fourth message is used by the terminal to request registration; the fourth message includes the capability information of the terminal; based on the fourth message, a first message is sent to the first network device; the first message includes the capability information; receiving a root key sent by the second network device; the root key is used for the ranging / sidelink SL positioning service of the terminal; and sending the root key to the terminal.
[0007] According to a third aspect of an embodiment of the present disclosure, a key processing method is provided, which is executed by a third network device and includes: receiving a second message sent by a first network device; the second message is used to obtain the root key of the ranging / SL positioning service of the terminal; the second message is sent by the first network device based on the capability information reported by the terminal during the registration request; and the root key of the ranging / SL positioning service is sent to the first network device.
[0008] According to a fourth aspect of an embodiment of the present disclosure, a key processing method is provided, which is executed by a terminal and includes: sending a fourth message to a second network device, the fourth message being used by the terminal to request registration; the fourth message including capability information of the terminal; the capability information being used at least to indicate whether the terminal has ranging / sidelink SL positioning capability; the terminal having ranging / SL positioning capability, and receiving a root key of a ranging / SL positioning service sent by the first network device or the second network device.
[0009] According to the fifth aspect of an embodiment of the present disclosure, a first network device is provided, wherein the first network device includes: a receiving module, configured to receive a second message sent by the first network device; the second message is used to obtain the root key of the ranging / SL positioning service of the terminal; the second message is sent by the first network device based on the capability information reported by the terminal when requesting registration; a processing module, configured to indicate that the terminal has ranging / sidelink SL positioning capability based on the capability information, and obtain the root key of the terminal for ranging / SL positioning service; a sending module, configured to send the root key to the second network device or the terminal.
[0010] According to the sixth aspect of an embodiment of the present disclosure, a second network device is provided, wherein the second network device includes: a receiving module, configured to receive a fourth message sent by a terminal; the fourth message is used by the terminal to request registration; the fourth message includes the capability information of the terminal; a sending module, configured to send a first message to the first network device according to the fourth message; the first message includes the capability information; the receiving module is configured to receive a root key sent by the second network device; the root key is used for the ranging / sidelink SL positioning service of the terminal; the sending module is configured to send the root key to the terminal.
[0011] According to the seventh aspect of an embodiment of the present disclosure, a third network device is provided, wherein the third network device includes: a receiving module, configured to receive a second message sent by the first network device based on capability information reported when the terminal registers a request; the second message is used to obtain a root key for the ranging / SL positioning service of the terminal; and a sending module, configured to send the root key for the ranging / SL positioning service to the first network device.
[0012] According to the eighth aspect of an embodiment of the present disclosure, a terminal is provided, wherein the terminal includes: a sending module, configured to send a fourth message to a second network device, the fourth message being used by the terminal to request registration; the fourth message including capability information of the terminal; the capability information being used at least to indicate whether the terminal has ranging / sidelink SL positioning capability; and a receiving module, configured to receive a root key of a ranging / SL positioning service sent by the first network device or the second network device based on the terminal having ranging / SL positioning capability.
[0013] According to a ninth aspect of an embodiment of the present disclosure, a communication device is provided, wherein the communication device includes:
[0014] one or more processors;
[0015] The processor is used to call instructions to enable the communication device to execute the key processing method provided by any technical solution of the first to fourth aspects.
[0016] According to a tenth aspect of an embodiment of the present disclosure, a storage medium is provided, wherein the storage medium stores instructions, which, when the instructions are executed on a communication device, enable the communication device to execute the key processing method provided by any of the first to fourth aspects.
[0017] According to the technical solution provided by the embodiment of the present disclosure, when a terminal requests registration, the network device will send the root key of the ranging / SL positioning service to the terminal, so that the terminal obtains the root key for subsequent execution of the ranging / SL positioning service during the registration process.
[0018] It should be understood that the foregoing general description and the following detailed description are merely exemplary and explanatory and are not restrictive of the embodiments of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present invention and, together with the description, serve to explain the principles of the embodiments of the present invention.
[0020] FIG1 is a schematic diagram showing an architecture of a communication system according to an exemplary embodiment;
[0021] FIG2A is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0022] FIG2B is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0023] FIG3A is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0024] FIG3B is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0025] FIG4A is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0026] FIG4B is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0027] FIG5 is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0028] FIG6 is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0029] FIG7 is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0030] FIG8A is a schematic structural diagram of a first network device according to an exemplary embodiment;
[0031] FIG8B is a schematic structural diagram of a first network device according to an exemplary embodiment;
[0032] FIG8C is a schematic structural diagram of a first network device according to an exemplary embodiment;
[0033] FIG8D is a schematic structural diagram of a terminal according to an exemplary embodiment;
[0034] FIG9A is a schematic structural diagram of a communication device according to an exemplary embodiment;
[0035] FIG9B is a schematic structural diagram of a chip according to an exemplary embodiment. DETAILED DESCRIPTION
[0036] Embodiments of the present disclosure provide a key processing method, a communication device, a communication system, and a storage medium.
[0037] In a first aspect, an embodiment of the present disclosure provides a key processing method, which is executed by a first network device and includes: receiving a first message sent by a second network device, the first message including capability information reported by the terminal when requesting registration; obtaining a root key used by the terminal for ranging / SL positioning services based on the capability information indicating that the terminal has ranging / sidelink SL positioning capabilities; and sending the root key to the second network device or terminal.
[0038] In the above embodiment, the root key of the ranging / SL positioning service is distributed to the terminal during the registration process, so that the terminal can directly enter the ranging / SL positioning service execution-related process without additionally obtaining the root key after registration.
[0039] In combination with some embodiments of the first aspect, in some embodiments, based on the capability information indicating that the terminal has ranging / sidelink SL positioning capability, obtaining the root key of the terminal for ranging / SL positioning service includes: based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-everything V2X capability, obtaining the root key of the terminal for ranging / SL positioning service; or, based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-proximity ProSe, obtaining the root key of the terminal for ranging / SL positioning service.
[0040] Based on the above solution, when it is detected that the terminal has ranging / SL positioning capability and V2X capability, or when the terminal has ranging / SL positioning capability and the vehicle is adjacent to ProSe, the root key for the ranging / SL positioning service is obtained and distributed to the terminal.
[0041] In combination with some embodiments of the first aspect, in some embodiments, based on the capability information indicating that the terminal has ranging / sidelink SL positioning capability, obtaining the root key of the terminal for ranging / SL positioning service includes: based on the capability information indicating that the terminal has ranging / sidelink SL positioning capability, sending a second message to a third network device; the second message is used to obtain the root key of the terminal's ranging / SL positioning service; receiving a third message sent by the third network device; the third message includes the root key of the terminal's ranging / SL positioning service.
[0042] Based on the above solution, the first network device can obtain the root key of the ranging / SL positioning service through interaction with the third network device, which has the characteristic of simple implementation.
[0043] According to the second aspect, a key processing method is provided, which is executed by a second network device and includes: receiving a fourth message sent by a terminal; the fourth message is used for the terminal to request registration; the fourth message includes the capability information of the terminal; according to the fourth message, a first message is sent to the first network device; the first message includes the capability information; receiving a root key sent by the second network device; the root key is used for the ranging / sidelink SL positioning service of the terminal; and sending the root key to the terminal.
[0044] Based on the above scheme, when the second network device receives the fourth message requesting registration from the terminal, it will return the terminal's capability information to the first network device. In this way, the first network device will obtain the terminal's capability information and distribute the corresponding root key to the terminal based on the terminal's capability information when the terminal supports ranging / SL positioning services.
[0045] In combination with some embodiments of the second aspect, in some embodiments, sending the root key to the terminal includes: the terminal has subscribed to the ranging / sidelink SL positioning service, and sending the root key to the terminal.
[0046] Based on the above solution, when the terminal has subscribed to the ranging / SL positioning service, the root key is sent to the terminal, thereby achieving the distribution of the root key to the terminal authorized to perform the ranging / SL positioning service.
[0047] In combination with some embodiments of the second aspect, in some embodiments, sending the root key to the terminal includes: sending the root key carried in a fifth message to the terminal; the fifth message is used to indicate acceptance of registration of the terminal.
[0048] In the above solution, the root key is carried in the fifth message indicating to the terminal that registration is accepted, so that the root key can be sent to the terminal without additional message signaling.
[0049] In a third aspect, an embodiment of the present disclosure provides a key processing method, which is performed by a third network device, and the method includes: receiving a second message sent by a first network device; the second message is used to obtain a root key for a ranging / SL positioning service of a terminal; the second message is sent by the first network device based on capability information reported by the terminal during a registration request;
[0050] The root key of the ranging / SL positioning service is sent to the first network device.
[0051] In combination with some embodiments of the third aspect, in some embodiments, the root key of the ranging / SL positioning service is obtained according to the subscription information of the terminal.
[0052] In a fourth aspect, an embodiment of the present disclosure provides a key processing method, which is executed by a terminal and includes: sending a fourth message to a second network device, the fourth message being used for the terminal to request registration; the fourth message including capability information of the terminal; the capability information being used at least to indicate whether the terminal has ranging / sidelink SL positioning capability; the terminal having ranging / SL positioning capability, and receiving the root key of the ranging / SL positioning service sent by the first network device or the second network device.
[0053] In combination with some embodiments of the fourth aspect, in some embodiments, the root key sent by the second network device is carried in a fifth message; the fifth message is used to indicate the registration of the receiving terminal.
[0054] In combination with some embodiments of the fourth aspect, in some embodiments, the root key is configured as a long-term credential, which is used to establish a secure direct connection for ranging / SL positioning services.
[0055] In a fifth aspect, an embodiment of the present disclosure provides a first network device, wherein the first network device includes: a receiving module, configured to receive a first message sent by a second network device, the first message including capability information reported when the terminal requests registration; a processing module, configured to indicate, based on the capability information, that the terminal has ranging / sidelink SL positioning capability, and obtain a root key used by the terminal for ranging / SL positioning services; and a sending module, configured to send the root key to the second network device or terminal.
[0056] In the sixth aspect, an embodiment of the present disclosure provides a second network device, wherein the second network device includes: a receiving module, configured to receive a fourth message sent by a terminal; the fourth message is used for the terminal to request registration; the fourth message includes the capability information of the terminal; a sending module, configured to send a first message to the first network device according to the fourth message; the first message includes the capability information; the receiving module, configured to receive a root key sent by the second network device; the root key is used for the ranging / sidelink SL positioning service of the terminal; the sending module, configured to send the root key to the terminal.
[0057] In a seventh aspect, an embodiment of the present disclosure provides a third network device, wherein the third network device includes: a receiving module configured to receive a second message sent by a first network device; the second message is used to obtain a root key for a ranging / SL positioning service of a terminal; the second message is sent by the first network device based on capability information reported by the terminal during a registration request;
[0058] The sending module is configured to send the root key of the ranging / SL positioning service to the first network device.
[0059] In the eighth aspect, an embodiment of the present disclosure provides a terminal, wherein the terminal includes: a sending module, configured to send a fourth message to the second network device, the fourth message being used for the terminal to request registration; the fourth message includes capability information of the terminal; the capability information is at least used to indicate whether the terminal has ranging / sidelink SL positioning capability; a receiving module, configured to receive the root key of the ranging / SL positioning service sent by the first network device or the second network device based on the terminal having ranging / SL positioning capability.
[0060] In a ninth aspect, an embodiment of the present disclosure provides a communication device, the communication device including: one or more processors;
[0061] The processor is used to call instructions to enable the communication device to execute the key processing method described in the optional implementation of the first to fourth aspects.
[0062] In the tenth aspect, an embodiment of the present disclosure provides a storage medium, wherein the storage medium stores instructions, which, when the instructions are executed on a communication device, enable the communication device to execute the key processing method described in the optional implementation methods of the first to fourth aspects.
[0063] In an eleventh aspect, an embodiment of the present disclosure provides a program product. When the program product is executed by a communication device, the communication device executes the key processing method described in the optional implementation of the first to fourth aspects.
[0064] In a twelfth aspect, an embodiment of the present disclosure provides a computer program, which, when executed on a computer, enables the computer to execute the key processing method described in the optional implementation of the first to fourth aspects.
[0065] It is understandable that the above-mentioned terminals, network devices, communication systems, program products, and computer programs are all used to execute the methods provided by the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding methods and will not be repeated here.
[0066] The present disclosure provides a key processing method, communication device, communication system, and storage medium. In some embodiments, the terms "key processing method" and "key processing method" are interchangeable; the terms "information indicating device" and "information processing device" are interchangeable; and the terms "communication system" and "information processing system" are interchangeable.
[0067] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0068] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.
[0069] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.
[0070] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when articles such as "a", "an", "the" in English are used in translation, the noun following the article may be understood as a singular expression or a plural expression.
[0071] In the embodiments of the present disclosure, “plurality” refers to two or more.
[0072] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.
[0073] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "in one case A, in another case B," or "in one case A, in another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, and C.
[0074] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.
[0075] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.
[0076] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0077] In some embodiments, terms such as "...", "determine...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.
[0078] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.
[0079] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.
[0080] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).
[0081] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.
[0082] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.
[0083] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it is also possible to set the structure in which the terminal has all or part of the functions of the access network device. In addition, terms such as "uplink" and "downlink" can also be replaced by terms corresponding to communication between terminals (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels, and uplinks, downlinks, etc. can be replaced by side links.
[0084] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the terminal.
[0085] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
[0086] In some embodiments, data, information, etc. may be obtained with the user's consent.
[0087] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.
[0088] FIG1 is a schematic diagram showing the architecture of a communication system according to an embodiment of the present disclosure.
[0089] As shown in Figure 1, a communication system 100 includes a terminal 101 and a network device 102. The network device 102 may include an access network device and a core network device.
[0090] In some embodiments, the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.
[0091] In some embodiments, the terminal is also referred to as User Equipment (UE).
[0092] In some embodiments, the access network device may be, for example, a node or device that accesses a terminal to a wireless network. The access network device may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a Wi-Fi system, but is not limited thereto.
[0093] In some embodiments, the technical solution of the present disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can be transformed into internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.
[0094] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.
[0095] In some embodiments, the core network device may be a single device including a first network element, or may be a plurality of devices or a group of devices, each including a first network element. The network element may be virtual or physical. The core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).
[0096] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution provided by the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution provided by the embodiment of the present disclosure is also applicable to similar technical problems.
[0097] The following embodiments of the present disclosure may be applied to the communication system 100 shown in Figure 1, or a portion thereof, but are not limited thereto. The entities shown in Figure 1 are illustrative only. The communication system may include all or part of the entities shown in Figure 1, or may include other entities outside of Figure 1. The number and form of the entities may be arbitrary. The connection relationship between the entities is illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.
[0098] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other key processing methods, and next-generation systems based on these. Furthermore, multiple systems may be combined (e.g., LTE, NR, etc.).
[0099] For ranging / SL positioning services provided by network devices, direct communication between terminals is secured by reusing and slightly modifying the security process defined for ProSe user-to-network relay communication. For example, the network device provides a root key to the terminal. This root key can be used to establish secure communication between terminals. However, this approach is not applicable to providing root keys to V2X terminals. As shown in FIG2A , an embodiment of the present disclosure provides a key processing method, which is applied to the communication system shown in FIG1 . The method may include:
[0100] S2101: The terminal sends a fourth message.
[0101] In some embodiments, the terminal sends a fourth message to the second network device.
[0102] In some embodiments, the fourth message is a registration request message of the terminal.
[0103] In some embodiments, the fourth message is used by the terminal to request registration.
[0104] In some embodiments, the fourth message includes capability information of the terminal.
[0105] In some embodiments, the capability information includes at least the capabilities of the terminal.
[0106] In some embodiments, the capability information is used to indicate the capabilities possessed by the terminal.
[0107] In some embodiments, the capability information may be used to indicate whether the terminal has ranging / SL positioning capability. If the terminal has ranging / SL positioning capability, it may be considered that the terminal supports ranging / SL positioning services.
[0108] In some embodiments, the capability information is also used to indicate whether the terminal has V2X capability or ProSe capability. If the terminal has V2X capability or ProSe capability.
[0109] In some embodiments, the fourth message may include a first indicator requesting the network device to issue a root key or long-term credential to the terminal during the terminal's registration process. In some embodiments, the fourth message may not include the first indicator. The network device will determine whether to issue a root key or long-term credential to the terminal during the terminal's registration process based on the capability information carried in the fourth message.
[0110] In some embodiments, the fourth message may be a Non Access Stratum (NAS) message.
[0111] In some embodiments, the fourth message is sent after the terminal is powered on.
[0112] In some embodiments, the terminal sends the fourth message when entering an area with a network from an area without a network.
[0113] In some embodiments, the fourth message is sent after the terminal exits the airplane mode.
[0114] The terminal sends the fourth message to the second network device, and the second network device receives the fourth message.
[0115] In some embodiments, the second network device may be any core network device. For example, the second network device may be an Access Management Function (AMF).
[0116] In some embodiments, the fourth message may further include identification information of the terminal.
[0117] The terminal identification information may include but is not limited to at least one of the following:
[0118] 5G Globally Unique Temporary UE Identity (5G-GUTI) for fifth-generation mobile communications;
[0119] Subscriber Permanent Identifier (SUPI);
[0120] Subscriber Concealed Identifier (SUPI)
[0121] S2102: The second network device sends a first message.
[0122] In some embodiments, the second network device sends the first message to the first network device.
[0123] In some embodiments, the first message includes capability information reported by the terminal when requesting registration.
[0124] The first message includes the capability information carried by the fourth message.
[0125] In some embodiments, before sending the first message to the first network device, the second network device further obtains the contract information of the terminal and determines whether the terminal has a service corresponding to the capabilities of the contracted terminal based on the contract information of the terminal.
[0126] Exemplarily, if the terminal has ranging / SL positioning capabilities, it can be determined based on the subscription information whether the terminal has subscribed to the ranging / SL positioning service.
[0127] Exemplarily, the second network device may obtain subscription data from a user data management function (UDM) and / or a unified data repository (UDR) to verify whether the terminal has subscribed to the ranging / SL positioning service when it has ranging / SL positioning capability.
[0128] In some embodiments, when it is verified that the terminal has subscribed to the ranging / SL positioning service, the capability information carried in the first message will indicate that the terminal has ranging / SL positioning capability; otherwise, the capability information carried in the first message will not indicate that the terminal has ranging / SL positioning capability. If the second network device determines, based on the verification result, whether the capability information carried in the first message indicates that the terminal has ranging / SL positioning capability, the first network device does not need to obtain the root key for the terminal that has not subscribed to the ranging / SL positioning service.
[0129] In some embodiments, regardless of whether the terminal has subscribed to the ranging / SL positioning service, the first message will include the capability information carried by the fourth message and will be sent by the second network device to the first network device.
[0130] In some embodiments, the second network device may also be a core network device. The core network device may include but is not limited to a Policy Control Function (PCF).
[0131] In some embodiments, the first message may include, but is not limited to, a policy association establishment request message.
[0132] S2103: The first network device obtains a root key of the first service;
[0133] In some embodiments, the first service may include but is not limited to ranging / SL positioning services, ProSe services and / or V2X services.
[0134] In some embodiments, based on the capability information indicating that the terminal has ranging / sidelink SL positioning capability, a root key used by the terminal for ranging / SL positioning services is obtained.
[0135] In some embodiments, based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-everything V2X capability, the root key of the terminal for ranging / SL positioning services is obtained.
[0136] In some embodiments, based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-proximity ProSe, a root key used by the terminal for ranging / SL positioning services is obtained.
[0137] In some embodiments, the root key of the ranging / SL positioning service has a unified root key. In this way, all terminals that have signed up for the ranging / SL positioning service use the same root key. In this case, the first network device may have already obtained the root key of the ranging / SL positioning service when other terminals request the root key of the ranging / SL positioning service. Therefore, the first network device locally caches the root key of the ranging / SL positioning service. At this time, the first network device reads the locally cached root key of the ranging / SL positioning service.
[0138] In some embodiments, the root key may be used by the terminal to generate a first key for use in communications related to ranging / SL positioning services based on the root key and other key generation parameters. Exemplarily, the first key may include, but is not limited to, at least one of the following: an integrity key, a confidentiality key, a key for preventing replay attacks, and / or a scrambling key.
[0139] Exemplarily, S2103 may include:
[0140] S2103 - 1 : The first network device sends a second message to the third network device.
[0141] In some embodiments, the second message is used to obtain a root key of the first service of the terminal.
[0142] In some embodiments, the second message is used to obtain a root key for a ranging / SL positioning service of the terminal.
[0143] Exemplarily, after receiving the second message, the third network device determines the root key of the first service such as the ranging / SL positioning service according to the subscription information of the terminal.
[0144] S2103 - 2 : The third network device sends a third message to the first network device.
[0145] In some embodiments, the third message includes the root key of the first service. For example, the third message may include: the root key of the terminal's ranging / SL positioning service, ProSe service and / or V2X service.
[0146] S2104: The first network device sends the acquired root key to the second network device.
[0147] Exemplarily, the first network device may carry the root key of the ranging / SL positioning service in a ranging association establishment response message and send it to the second network device.
[0148] S2105: The second network device sends a fifth message.
[0149] In some embodiments, the second network device sends a fifth message to the terminal.
[0150] Exemplarily, the fifth message may also be a NAS message.
[0151] In some embodiments, the fifth message is used to indicate registration of the receiving terminal.
[0152] In some embodiments, the fifth message may be a registration acceptance message.
[0153] In some embodiments, the fifth message may include a root key of the first service.
[0154] In some embodiments, the fifth message may include a root key for ranging / SL positioning services.
[0155] In some embodiments, the second network device determines that the terminal has subscribed to the ranging / SL positioning service based on the subscription information of the terminal, and then sends a fifth message carrying the root key of the ranging / SL positioning service to the terminal.
[0156] In some embodiments, the second network device determines that the terminal has not subscribed to the ranging / SL positioning service based on the subscription information of the terminal, and then sends a fifth message that does not carry the root key of the ranging / SL positioning service to the terminal.
[0157] In this way, upon receiving the fifth message, the terminal obtains the root key of the ranging / SL positioning service issued by the network device.
[0158] In some embodiments, the terminal receives the root key during the network registration phase.
[0159] In some embodiments, the terminal uses the root key as a long-term credential for establishing a secure direct connection for a first service such as a ranging / SL positioning service.
[0160] In some embodiments, after receiving the root key, the terminal configures the root key to be used as or serves as a long-term credential.
[0161] In some embodiments, if the second network device rejects the terminal's registration, the second network device sends a sixth message to the terminal. The sixth message indicates the rejection of the terminal's registration. The sixth message does not carry a root key for the first service, such as the ranging / SL positioning service.
[0162] As shown in FIG2B , an embodiment of the present disclosure provides a key processing method, which is applied to the communication system shown in FIG1 . The method may include:
[0163] S2201: The terminal sends a fourth message.
[0164] In some embodiments, the terminal sends a fourth message to the second network device.
[0165] In some embodiments, the fourth message is a registration request message of the terminal.
[0166] In some embodiments, the fourth message is used by the terminal to request registration.
[0167] In some embodiments, the fourth message includes capability information of the terminal.
[0168] In some embodiments, the capability information includes at least the capabilities of the terminal.
[0169] In some embodiments, the capability information may be used to indicate whether the terminal has ranging / SL positioning capability. If the terminal has ranging / SL positioning capability, it may be considered that the terminal supports ranging / SL positioning services.
[0170] In some embodiments, the capability information is also used to indicate whether the terminal has V2X capability or ProSe capability. If the terminal has V2X capability or ProSe capability.
[0171] In some embodiments, the fourth message may include a first indicator requesting the network device to issue a root key or long-term credential to the terminal during the terminal's registration process. In some embodiments, the fourth message may not include the first indicator. The network device will determine whether to issue a root key or long-term credential to the terminal during the terminal's registration process based on the capability information carried in the fourth message.
[0172] In some embodiments, the fourth message may further include identification information of the terminal.
[0173] The terminal identification information may include but is not limited to at least one of the following:
[0174] 5G Globally Unique Temporary UE Identity (5G-GUTI) for fifth-generation mobile communications;
[0175] Subscriber Permanent Identifier (SUPI);
[0176] Subscriber Concealed Identifier (SUPI)
[0177] In some embodiments, the fourth message may be a Non Access Stratum (NAS) message.
[0178] In some embodiments, the fourth message is sent after the terminal is powered on.
[0179] In some embodiments, the terminal sends the fourth message when entering an area with a network from an area without a network.
[0180] In some embodiments, the fourth message is sent after the terminal exits the airplane mode.
[0181] The terminal sends the fourth message to the second network device, and the second network device receives the fourth message.
[0182] In some embodiments, the second network device may be any core network device. For example, the second network device may be an Access Management Function (AMF).
[0183] S2202: The second network device sends a first message.
[0184] In some embodiments, the second network device sends the first message to the first network device.
[0185] In some embodiments, the first message includes capability information reported by the terminal when requesting registration.
[0186] The first message includes the capability information carried by the fourth message.
[0187] In some embodiments, before sending the first message to the first network device, the second network device further obtains the contract information of the terminal and determines whether the terminal has a service corresponding to the capabilities of the contracted terminal based on the contract information of the terminal.
[0188] Exemplarily, if the terminal has ranging / SL positioning capabilities, it can be determined based on the subscription information whether the terminal has subscribed to the ranging / SL positioning service.
[0189] Exemplarily, the second network device may obtain subscription data from a user data management function (UDM) and / or a unified data repository (UDR) to verify whether the terminal has subscribed to the ranging / SL positioning service when it has ranging / SL positioning capability.
[0190] In some embodiments, when it is verified that the terminal has subscribed to the ranging / SL positioning service, the capability information carried in the first message will indicate that the terminal has ranging / SL positioning capability; otherwise, the capability information carried in the first message will not indicate that the terminal has ranging / SL positioning capability. If the second network device determines, based on the verification result, whether the capability information carried in the first message indicates that the terminal has ranging / SL positioning capability, the first network device does not need to obtain the root key for the terminal that has not subscribed to the ranging / SL positioning service.
[0191] In some embodiments, regardless of whether the terminal has subscribed to the ranging / SL positioning service, the first message will include the capability information carried by the fourth message and will be sent by the second network device to the first network device.
[0192] In some embodiments, the second network device may also be a core network device. The core network device may include but is not limited to a Policy Control Function (PCF).
[0193] In some embodiments, the first message may include, but is not limited to, a policy association establishment request message.
[0194] S2203: The first network device obtains a root key of the first service.
[0195] In some embodiments, the first service may include but is not limited to ranging / SL positioning service, V2X service and / or ProSe service. In short, the first network device may issue root keys for various services to the terminal during the terminal registration process.
[0196] In some embodiments, based on the capability information indicating that the terminal has ranging / sidelink SL positioning capability, a root key used by the terminal for ranging / SL positioning services is obtained.
[0197] In some embodiments, based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-everything V2X capability, the root key of the terminal for ranging / SL positioning services is obtained.
[0198] In some embodiments, based on the capability information indicating that the terminal has ranging / SL positioning capability and the vehicle is in proximity to ProSe, a root key used by the terminal for ranging / SL positioning services is obtained.
[0199] In some embodiments, the root key of the first service has a unified root key. In this case, all terminals subscribed to the ranging / SL positioning service use the same root key. In this case, the first network device may have already obtained the root key of the first service when other terminals request the root key of the first service. Therefore, the first network device locally caches the root key of the first service. In this case, the first network device reads the locally cached root key of the first service without having to request the root key of the first service from a third network device.
[0200] In some embodiments, the root key for the ranging / SL positioning service may be used by a terminal to generate a first key for use in communications related to the ranging / SL positioning service based on the root key and other key generation parameters. Exemplarily, the first key may include, but is not limited to, at least one of the following: an integrity key, a confidentiality key, a key for preventing replay attacks, and / or a scrambling key.
[0201] Illustratively, S2203 may include:
[0202] S2203-1: The first network device sends a second message to the third network device.
[0203] In some embodiments, the second message is used to obtain a root key of the first service.
[0204] In some embodiments, the second message is used to obtain a root key for a ranging / SL positioning service of the terminal.
[0205] Exemplarily, after receiving the second message, the third network device determines the root key of the first service according to the subscription information of the terminal.
[0206] Exemplarily, after receiving the second message, the third network device determines the root key of the ranging / SL positioning service according to the subscription information of the terminal.
[0207] S2203-2: The third network device sends a third message to the first network device.
[0208] In some embodiments, the third message includes a root key of the first service of the terminal.
[0209] In some embodiments, the third message includes a root key for the ranging / SL positioning service of the terminal.
[0210] S2204: The first network device sends the root key to the terminal.
[0211] In some embodiments, the first network device sends the root key of the first service to the terminal.
[0212] In this embodiment, the first network device directly sends the root key of the ranging / SL positioning service to the terminal, so that the terminal receives the root key during the network registration phase.
[0213] S2205: The second network device sends a fifth message.
[0214] In some embodiments, the fifth message is used to indicate registration of the receiving terminal.
[0215] In some embodiments, the fifth message may be a registration acceptance message.
[0216] In some embodiments, the second network device sends a fifth message to the terminal based on whether to accept the terminal's registration. For example, if the terminal's registration is accepted, the second network device sends the fifth message to the terminal; otherwise, the second network device sends a sixth message indicating rejection of the registration or does not send the fifth message.
[0217] In some embodiments, the terminal uses the root key as a long-term credential for establishing a secure direct connection for ranging / SL positioning services.
[0218] In some embodiments, after receiving the root key, the terminal configures the root key as a long-term credential for use.
[0219] In this embodiment, there is no specific order or association between the terminal receiving the root key sent by the first network device and receiving the fifth message. In short, the terminal will not receive the root key in the response message of the registration request.
[0220] As shown in FIG3A , an embodiment of the present disclosure provides a key processing method, which is executed by a first network device. The method may include:
[0221] S3101: Receive the first message.
[0222] In some embodiments, the first network device may be any network device that participates in processing a terminal registration request.
[0223] Exemplarily, the first network device may be a core network device such as a PCF or other device that can provide a key.
[0224] Exemplarily, the first message may be sent by the second network device when receiving the fourth message from the terminal.
[0225] The fourth message may include capability information and / or identification information of the terminal.
[0226] The capability information of the terminal may indicate the capability of the terminal.
[0227] The terminal identification information may include but is not limited to at least one of the following:
[0228] 5G Globally Unique Temporary UE Identity (5G-GUTI) for fifth-generation mobile communications;
[0229] Subscriber Permanent Identifier (SUPI);
[0230] Subscriber Concealed Identifier (SUPI)
[0231] In some embodiments, the first network device receives a first message sent by the second network device.
[0232] In some embodiments, the second network device may be a device that performs mobility management on the terminal, such as AMF or MME.
[0233] In some embodiments, the first message includes capability information reported by the terminal when requesting registration.
[0234] The first message includes capability information requested by the terminal for registration.
[0235] For example, the capability information of the terminal may indicate whether the terminal has ranging / SL positioning capability. If the terminal has ranging / SL positioning capability, the terminal supports the subscription ranging / SL positioning service.
[0236] In some embodiments, the first message may include, but is not limited to, a policy association establishment request message.
[0237] S3102: The first network device obtains a root key of the first service.
[0238] In some embodiments, the first service may include but is not limited to ranging / SL positioning services, ProSe services and / or V2X services.
[0239] In some embodiments, based on the capability information indicating that the terminal has ranging / sidelink SL positioning capability, a root key used by the terminal for ranging / SL positioning services is obtained.
[0240] In some embodiments, based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-everything V2X capability, the root key of the terminal for ranging / SL positioning services is obtained.
[0241] In some embodiments, based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-proximity ProSe, a root key used by the terminal for ranging / SL positioning services is obtained.
[0242] In some embodiments, the root key of the ranging / SL positioning service has a unified root key. In this way, all terminals that have signed up for the ranging / SL positioning service use the same root key. In this case, the first network device may have already obtained the root key of the ranging / SL positioning service when other terminals request the root key of the ranging / SL positioning service. Therefore, the first network device locally caches the root key of the ranging / SL positioning service. At this time, the first network device reads the locally cached root key of the ranging / SL positioning service.
[0243] In some embodiments, the root key may be used by the terminal to generate a first key for use in communications related to ranging / SL positioning services based on the root key and other key generation parameters. Exemplarily, the first key may include, but is not limited to, at least one of the following: an integrity key, a confidentiality key, a key for preventing replay attacks, and / or a scrambling key.
[0244] For example, S3102 may include:
[0245] The first network device sends a second message;
[0246] The first network device receives the third message.
[0247] In some embodiments, the second message is used to obtain a root key of the first service of the terminal.
[0248] In some embodiments, the second message is used to obtain a root key for a ranging / SL positioning service of the terminal.
[0249] Exemplarily, after receiving the second message, the third network device determines the root key of the first service such as the ranging / SL positioning service according to the subscription information of the terminal.
[0250] In some embodiments, the first network device receives a third message sent by the third network device.
[0251] In some embodiments, the third message includes a root key for the ranging / SL positioning service of the terminal.
[0252] S3103: The first network device sends the root key of the ranging / SL positioning service to the second network device.
[0253] In some embodiments, the third message includes the root key of the first service. For example, the third message may include: the root key of the terminal's ranging / SL positioning service, ProSe service and / or V2X service.
[0254] As shown in FIG3B , an embodiment of the present disclosure provides a key processing method, which is executed by a first network device. The method may include:
[0255] S3201: Receive the first message.
[0256] In some embodiments, the first network device may be any network device that participates in processing a terminal registration request.
[0257] Exemplarily, the first network device may be a core network device such as a PCF or other device that can provide a key.
[0258] In some embodiments, the first network device receives a first message sent by the second network device.
[0259] In some embodiments, the second network device may be a device that performs mobility management on the terminal, such as AMF or MME.
[0260] In some embodiments, the first message includes capability information reported by the terminal when requesting registration.
[0261] The first message includes capability information requested by the terminal for registration.
[0262] For example, the capability information of the terminal may indicate whether the terminal has ranging / SL positioning capability. If the terminal has ranging / SL positioning capability, the terminal supports the subscription ranging / SL positioning service.
[0263] In some embodiments, the first message may include, but is not limited to, a policy association establishment request message.
[0264] S3202: The first network device obtains a root key of the first service.
[0265] In some embodiments, the first service may include but is not limited to ranging / SL positioning service, V2X service and / or ProSe service. In short, the first network device may issue root keys for various services to the terminal during the terminal registration process.
[0266] In some embodiments, based on the capability information indicating that the terminal has ranging / sidelink SL positioning capability, a root key used by the terminal for ranging / SL positioning services is obtained.
[0267] In some embodiments, based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-everything V2X capability, the root key of the terminal for ranging / SL positioning services is obtained.
[0268] In some embodiments, based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-proximity ProSe, a root key used by the terminal for ranging / SL positioning services is obtained.
[0269] In some embodiments, the root key of the first service has a unified root key. In this case, all terminals subscribed to the ranging / SL positioning service use the same root key. In this case, the first network device may have already obtained the root key of the first service when other terminals request the root key of the first service. Therefore, the first network device locally caches the root key of the first service. In this case, the first network device reads the locally cached root key of the first service without having to request the root key of the first service from a third network device.
[0270] In some embodiments, the root key for the ranging / SL positioning service may be used by a terminal to generate a first key for use in communications related to the ranging / SL positioning service based on the root key and other key generation parameters. Exemplarily, the first key may include, but is not limited to, at least one of the following: an integrity key, a confidentiality key, a key for preventing replay attacks, and / or a scrambling key.
[0271] Exemplarily, S3202 may include:
[0272] The first network device sends a second message to the third network device.
[0273] In some embodiments, the second message is used to obtain a root key of the first service.
[0274] In some embodiments, the second message is used to obtain a root key for a ranging / SL positioning service of the terminal.
[0275] Exemplarily, after receiving the second message, the third network device determines the root key of the first service according to the subscription information of the terminal.
[0276] Exemplarily, after receiving the second message, the third network device determines the root key of the ranging / SL positioning service according to the subscription information of the terminal.
[0277] The first network device receives the third message.
[0278] In some embodiments, the second message is used to obtain a root key of the first service.
[0279] In some embodiments, the second message is used to obtain a root key for a ranging / SL positioning service of the terminal.
[0280] Exemplarily, after receiving the second message, the third network device determines the root key of the first service according to the subscription information of the terminal.
[0281] Exemplarily, after receiving the second message, the third network device determines the root key of the ranging / SL positioning service according to the subscription information of the terminal.
[0282] S3203: The first network device sends the root key to the terminal.
[0283] In some embodiments, the first network device sends the root key of the first service to the terminal.
[0284] In this embodiment, the first network device directly sends the root key of the ranging / SL positioning service to the terminal, so that the terminal receives the root key during the network registration phase.
[0285] As shown in FIG4A , an embodiment of the present disclosure provides a key processing method, which is executed by a second network device. The method may include:
[0286] S4101: Receive the fourth message.
[0287] In some embodiments, the second network device receives a fourth message sent by the terminal.
[0288] In some embodiments, the fourth message is used by the terminal to request registration.
[0289] In some embodiments, the fourth message includes capability information of the terminal.
[0290] In some embodiments, the capability information includes at least the capabilities of the terminal.
[0291] In some embodiments, the capability information may be used to indicate whether the terminal has ranging / SL positioning capability. If the terminal has ranging / SL positioning capability, it may be considered that the terminal supports ranging / SL positioning services.
[0292] In some embodiments, the capability information is also used to indicate whether the terminal has V2X capability or ProSe capability. If the terminal has V2X capability or ProSe capability.
[0293] In some embodiments, the fourth message may include a first indicator requesting the network device to issue a root key or long-term credential to the terminal during the terminal's registration process. In some embodiments, the fourth message may not include the first indicator. The network device will determine whether to issue a root key or long-term credential to the terminal during the terminal's registration process based on the capability information carried in the fourth message.
[0294] In some embodiments, the fourth message may be a Non Access Stratum (NAS) message.
[0295] In some embodiments, the fourth message is sent after the terminal is powered on.
[0296] In some embodiments, the terminal sends the fourth message when entering an area with a network from an area without a network.
[0297] In some embodiments, the fourth message is sent after the terminal exits the airplane mode.
[0298] The terminal sends the fourth message to the second network device, and the second network device receives the fourth message.
[0299] In some embodiments, the second network device may be any core network device. For example, the second network device may be an Access Management Function (AMF).
[0300] S4102: The second network device sends a first message.
[0301] In some embodiments, the second network device sends the first message to the first network device.
[0302] In some embodiments, the first message includes capability information reported by the terminal when requesting registration.
[0303] The first message includes the capability information carried by the fourth message.
[0304] The capability information is used to indicate the capabilities of the terminal.
[0305] In some embodiments, before sending the first message to the first network device, the second network device further obtains the contract information of the terminal and determines whether the terminal has a service corresponding to the capabilities of the contracted terminal based on the contract information of the terminal.
[0306] Exemplarily, if the terminal has ranging / SL positioning capabilities, it can be determined based on the subscription information whether the terminal has subscribed to the ranging / SL positioning service.
[0307] Exemplarily, the second network device may obtain subscription data from a user data management function (UDM) and / or a unified data repository (UDR) to verify whether the terminal has subscribed to the ranging / SL positioning service when it has ranging / SL positioning capability.
[0308] In some embodiments, when it is verified that the terminal has subscribed to the ranging / SL positioning service, the capability information carried in the first message will indicate that the terminal has ranging / SL positioning capability; otherwise, the capability information carried in the first message will not indicate that the terminal has ranging / SL positioning capability. If the second network device determines, based on the verification result, whether the capability information carried in the first message indicates that the terminal has ranging / SL positioning capability, the first network device does not need to obtain the root key for the terminal that has not subscribed to the ranging / SL positioning service.
[0309] In some embodiments, regardless of whether the terminal has subscribed to the ranging / SL positioning service, the first message will include the capability information carried by the fourth message and will be sent by the second network device to the first network device.
[0310] In some embodiments, the second network device may also be a core network device. The core network device may include but is not limited to a Policy Control Function (PCF).
[0311] In some embodiments, the first message may include, but is not limited to, a policy association establishment request message.
[0312] S4103: The second network device receives the root key of the first service.
[0313] Exemplarily, the first service may include but is not limited to ranging / SL positioning service, V2X service and / or ProSe service.
[0314] S4104: The second network device sends a fifth message.
[0315] In some embodiments, the second network device sends a fifth message to the terminal.
[0316] Exemplarily, the fifth message may also be a NAS message.
[0317] In some embodiments, the fifth message is used to indicate registration of the receiving terminal.
[0318] In some embodiments, the fifth message may be a registration acceptance message.
[0319] In some embodiments, the fifth message includes a root key of the first service.
[0320] In some embodiments, the fifth message may include a root key for ranging / SL positioning services.
[0321] In some embodiments, the second network device determines that the terminal has subscribed to the ranging / SL positioning service based on the subscription information of the terminal, and then sends a fifth message carrying the root key of the ranging / SL positioning service to the terminal.
[0322] In some embodiments, the second network device determines that the terminal has not subscribed to the ranging / SL positioning service based on the subscription information of the terminal, and then sends a fifth message that does not carry the root key of the ranging / SL positioning service to the terminal.
[0323] In this way, upon receiving the fifth message, the terminal obtains the root key of the ranging / SL positioning service issued by the network device.
[0324] In some embodiments, the terminal receives the root key during the network registration phase.
[0325] In some embodiments, the terminal uses the root key as a long-term credential for establishing a secure direct connection for ranging / SL positioning services.
[0326] In some embodiments, if the second network device rejects the registration of the terminal, the second network device sends a sixth message to the terminal. The sixth message indicates the rejection of the registration of the terminal. The sixth message does not carry the root key of the ranging / SL positioning service.
[0327] In some embodiments, the root key may be used by the terminal to generate a first key for use in communications related to ranging / SL positioning services based on the root key and other key generation parameters. Exemplarily, the first key may include, but is not limited to, at least one of the following: an integrity key, a confidentiality key, a key for preventing replay attacks, and / or a scrambling key.
[0328] As shown in FIG4B , an embodiment of the present disclosure provides a key processing method, which is performed by a second network device. The method may include:
[0329] S4201: Receive the fourth message.
[0330] In some embodiments, the second network device receives a fourth message sent by the terminal.
[0331] In some embodiments, the fourth message is used by the terminal to request registration.
[0332] In some embodiments, the fourth message includes capability information of the terminal.
[0333] In some embodiments, the capability information includes at least the capabilities of the terminal.
[0334] In some embodiments, the capability information may be used to indicate whether the terminal has ranging / SL positioning capability. If the terminal has ranging / SL positioning capability, it may be considered that the terminal supports ranging / SL positioning services.
[0335] In some embodiments, the capability information is also used to indicate whether the terminal has V2X capability or ProSe capability. If the terminal has V2X capability or ProSe capability.
[0336] In some embodiments, the fourth message may include a first indicator requesting the network device to issue a root key or long-term credential to the terminal during the terminal's registration process. In some embodiments, the fourth message may not include the first indicator. The network device will determine whether to issue a root key or long-term credential to the terminal during the terminal's registration process based on the capability information carried in the fourth message.
[0337] In some embodiments, the fourth message may be a Non Access Stratum (NAS) message.
[0338] In some embodiments, the fourth message is sent after the terminal is powered on.
[0339] In some embodiments, the terminal sends the fourth message when entering an area with a network from an area without a network.
[0340] In some embodiments, the fourth message is sent after the terminal exits the airplane mode.
[0341] The terminal sends the fourth message to the second network device, and the second network device receives the fourth message.
[0342] In some embodiments, the second network device may be any core network device. For example, the second network device may be an Access Management Function (AMF).
[0343] S4202: The second network device sends a first message.
[0344] In some embodiments, the second network device sends the first message to the first network device.
[0345] In some embodiments, the first message includes capability information reported by the terminal when requesting registration.
[0346] The first message includes the capability information carried by the fourth message.
[0347] In some embodiments, before sending the first message to the first network device, the second network device further obtains the contract information of the terminal and determines whether the terminal has a service corresponding to the capabilities of the contracted terminal based on the contract information of the terminal.
[0348] Exemplarily, if the terminal has ranging / SL positioning capabilities, it can be determined based on the subscription information whether the terminal has subscribed to the ranging / SL positioning service.
[0349] Exemplarily, the second network device may obtain subscription data from a user data management function (UDM) and / or a unified data repository (UDR) to verify whether the terminal has subscribed to the ranging / SL positioning service when it has ranging / SL positioning capability.
[0350] In some embodiments, when it is verified that the terminal has subscribed to the ranging / SL positioning service, the capability information carried in the first message will indicate that the terminal has ranging / SL positioning capability; otherwise, the capability information carried in the first message will not indicate that the terminal has ranging / SL positioning capability. If the second network device determines, based on the verification result, whether the capability information carried in the first message indicates that the terminal has ranging / SL positioning capability, the first network device does not need to obtain the root key for the terminal that has not subscribed to the ranging / SL positioning service.
[0351] In some embodiments, regardless of whether the terminal has subscribed to the ranging / SL positioning service, the first message will include the capability information carried by the fourth message and will be sent by the second network device to the first network device.
[0352] In some embodiments, the second network device may also be a core network device. The core network device may include but is not limited to a Policy Control Function (PCF).
[0353] In some embodiments, the first message may include, but is not limited to, a policy association establishment request message.
[0354] S4203: The second network device sends a fifth message.
[0355] In some embodiments, the fifth message is used to indicate registration of the receiving terminal.
[0356] In some embodiments, the fifth message may be a registration acceptance message.
[0357] In some embodiments, the fifth message includes a root key of the first service.
[0358] In some embodiments, the first service may include but is not limited to ranging / SL positioning service, V2X service and / or ProSe service.
[0359] In some embodiments, the second network device sends a fifth message to the terminal based on whether to accept the terminal's registration. For example, if the terminal's registration is accepted, the second network device sends the fifth message to the terminal; otherwise, the second network device sends a sixth message indicating rejection of the registration or does not send the fifth message.
[0360] In some embodiments, the root key of the first service is directly sent to the terminal by the first network device. For example, the second network device may transparently transmit the root key of the first service provided by the first device to the terminal.
[0361] In some embodiments, the terminal uses the root key as a long-term credential for establishing a secure direct connection for the first service.
[0362] In this embodiment, there is no specific order or association between the terminal receiving the root key sent by the first network device and receiving the fifth message. In short, the terminal will not receive the root key in the response message of the registration request.
[0363] As shown in FIG5 , an embodiment of the present disclosure provides a key processing method, which is performed by a third network device and includes:
[0364] S5101: Receive the second message.
[0365] In some embodiments, the third network device receives a second message sent by the first network device based on capability information reported during a terminal registration request.
[0366] In some embodiments, the second message is used to obtain a root key of the first service of the terminal.
[0367] Exemplarily, the first service may include but is not limited to ranging / SL positioning service, V2X service and / or ProSe service.
[0368] In some embodiments, the second message is used to obtain a root key for a ranging / SL positioning service of the terminal.
[0369] S5102: Obtain the root key of the first service.
[0370] In some embodiments, the root key of the first service is obtained based on the contract information of the terminal.
[0371] S5103: Send the root key of the first service.
[0372] In some embodiments, the root key of the ranging / SL positioning service is sent to the first network device.
[0373] As shown in FIG6 , an embodiment of the present disclosure provides a key processing method, which is executed by a terminal and includes:
[0374] S6101: Send the fourth message.
[0375] In some embodiments, the terminal sends a fourth message to the second network device.
[0376] In some embodiments, the terminal sends a fourth message to the second network device.
[0377] In some embodiments, the fourth message is a registration request message of the terminal.
[0378] In some embodiments, the fourth message is used by the terminal to request registration.
[0379] In some embodiments, the fourth message includes capability information of the terminal.
[0380] In some embodiments, the capability information includes at least the capabilities of the terminal.
[0381] In some embodiments, the capability information is used to indicate the capabilities possessed by the terminal.
[0382] In some embodiments, the capability information is used to indicate that the terminal has the capability of the first service. If the capability information is used to indicate that the terminal has the capability of the first service, it means that the terminal supports the first service.
[0383] In some embodiments, the capability information may be used to indicate whether the terminal has ranging / SL positioning capability. If the terminal has ranging / SL positioning capability, it may be considered that the terminal supports ranging / SL positioning services.
[0384] In some embodiments, the capability information is also used to indicate whether the terminal has V2X capability or ProSe capability. If the terminal has V2X capability or ProSe capability.
[0385] In some embodiments, the fourth message may include a first indicator requesting the network device to issue a root key or long-term credential to the terminal during the terminal's registration process. In some embodiments, the fourth message may not include the first indicator. The network device will determine whether to issue a root key or long-term credential to the terminal during the terminal's registration process based on the capability information carried in the fourth message.
[0386] In some embodiments, the fourth message may be a Non Access Stratum (NAS) message.
[0387] In some embodiments, the fourth message is sent after the terminal is powered on.
[0388] In some embodiments, the terminal sends the fourth message when entering an area with a network from an area without a network.
[0389] In some embodiments, the fourth message is sent after the terminal exits the airplane mode.
[0390] The terminal sends the fourth message to the second network device, and the second network device receives the fourth message.
[0391] In some embodiments, the second network device may be any core network device. For example, the second network device may be an Access Management Function (AMF).
[0392] S6102: Receive the root key of the first service.
[0393] In some embodiments, the terminal receives a root key of the first service sent by the second network device.
[0394] In some embodiments, the first service may include but is not limited to ranging / SL positioning services, ProSe services and / or V2X services.
[0395] In some embodiments, the terminal receives a fifth message sent by the second network device.
[0396] Exemplarily, the fifth message may be a NAS message.
[0397] In some embodiments, the fifth message is used to indicate registration of the receiving terminal.
[0398] In some embodiments, the fifth message may be a registration acceptance message.
[0399] In some embodiments, the fifth message may include a root key of the first service.
[0400] In some embodiments, the fifth message may include a root key for ranging / SL positioning services.
[0401] In some embodiments, the terminal receives the root key during the network registration phase.
[0402] In some embodiments, the terminal uses the root key as a long-term credential for establishing a secure direct connection for a first service such as a ranging / SL positioning service.
[0403] In some embodiments, if the second network device rejects the terminal's registration, the second network device sends a sixth message to the terminal. The sixth message indicates the rejection of the terminal's registration. The sixth message does not carry a root key for the first service, such as the ranging / SL positioning service.
[0404] In some embodiments, the terminal receives a root key of the first service sent by the first network device.
[0405] In some embodiments, the terminal receives a root key of a first service transparently transmitted by the first network device based on the second network device.
[0406] The root key distribution procedure in related technologies is not applicable to V2X terminals. For ranging / SL positioning services provided by the network, there is no secure establishment mechanism for obtaining the root key between V2X terminals. V2X terminals can be terminals with V2X capabilities.
[0407] An embodiment of the present disclosure provides a key processing method, which may include: allowing a V2X terminal to obtain a root key for secure establishment between terminals and for ranging / SL positioning services provided by the network.
[0408] This disclosed embodiment proposes that during the V2X terminal registration process, the network provides a root key to ensure the security of direct communication.
[0409] For V2X terminals that can serve the ranging / distance measurement / SL positioning services provided by the network.
[0410] The contract information of the terminal should include information on whether the V2X terminal has signed a contract for ranging / SL positioning services.
[0411] As shown in FIG7 , an embodiment of the present disclosure provides a key processing method, which may include:
[0412] 1. The terminal sends a registration request message to the AMF. The registration request message includes the terminal ID. The registration request message also includes capability information. The terminal ID may include an identifier such as SUCI or 5G-GUTI. This capability information may indicate the capabilities of the terminal. For example, the capability information may indicate that the terminal has V2X and ranging capabilities, or it may indicate that the terminal has ProSe and ranging capabilities.
[0413] 2.AMF retrieves the terminal's contract information from UDM through the Nudm_SDM_Get service.
[0414] 3.AMF verifies whether the terminal has signed up for ranging / SL positioning services, for example, determines whether the terminal is subscribed / authorized as a positioning terminal based on the terminal's contract information.
[0415] 4. The AMF initiates the establishment of a terminal policy association with the PCF by including the terminal capabilities. In this way, the AMF sends a terminal policy control related message to the UDR / UDM. This message may include the terminal's SUPI and terminal capability information.
[0416] 5. PCF obtains terminal policy information from UDR based on terminal capabilities. The terminal policy information may include the root key.
[0417] If the terminal's capability information indicates that the terminal has V2X and ranging capabilities, the PCF retrieves the root key from the UDR. This root key is used to ensure the security of direct communication.
[0418] If the terminal's capability information indicates that the terminal does not have V2X capability or ranging capability, the PCF may not obtain the root key for direct communication security from the UDR.
[0419] A root key may be generated for a terminal based on the terminal's subscription information. For example, the terminal may have subscribed to ranging / SL positioning services, or the terminal may have subscribed to both V2X services and ranging / SL positioning services.
[0420] 6. The PCF may pass the root key used for direct communication security to the AMF. The root key may also be transparently passed to the terminal through the AMF.
[0421] 7.AMF sends a registration acceptance message to the terminal.
[0422] When the PCF sends the root key for direct communication security to the AMF, the root key may be carried in the registration accept message and sent to the terminal.
[0423] When the terminal capability changes, the AMF shall transmit the terminal capability information to the PCF so that the PCF can obtain the root key of the corresponding capability of the terminal. After receiving the capability information, the PCF determines that the terminal has the capability of ranging / SL positioning, and then obtains the root key of the ranging / SL positioning service. For example, after receiving the capability information, the PCF determines that the terminal has the capability of ranging / SL positioning and V2X, and then obtains the root key of the ranging / SL positioning service. For another example, after receiving the capability information, the PCF determines that the terminal has the capability of ranging / SL positioning and ProSe, and then obtains the root key of the ranging / SL positioning service.
[0424] After receiving the root key during the registration process, the terminal uses the root key as a long-term credential to establish a secure direct communication link between terminals.
[0425] The terminal should be able to receive and understand the root key for the ranging / SL positioning service provided by the network.
[0426] The endpoint should be able to use the root key as a long-term credential to establish direct connection security.
[0427] The AMF should be able to verify whether the user has signed up for the ranging / SL positioning service based on the user's contract information.
[0428] The AMF shall be able to include the root key for ranging / SL positioning services in the Registration Accept message.
[0429] The PCF should be able to obtain the root key used by the ranging / SL positioning service provided by the network from the UDR.
[0430] The PCF should be able to process the terminal's capability information and determine the root key.
[0431] The PCF should be able to provide the terminal with the root key for the ranging / SL positioning services provided by the network.
[0432] In the embodiments of the present disclosure, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations of other embodiments.
[0433] In the embodiments of the present disclosure, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations of other embodiments.
[0434] The embodiments of the present disclosure also provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device or a core network device) in any of the above methods.
[0435] It should be understood that the division of the various units or modules in the above devices is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above devices, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units or modules by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.
[0436] In the embodiments of the present disclosure, a processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of a hardware circuit. The logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.
[0437] FIG8A is a first network device provided by an embodiment of the present disclosure, wherein the first network device includes:
[0438] The receiving module 110 is configured to receive a first message sent by the second network device, where the first message includes capability information reported by the terminal when requesting registration;
[0439] The processing module 120 is configured to obtain a root key used by the terminal for ranging / SL positioning services based on the capability information indicating that the terminal has ranging / sidelink SL positioning capabilities;
[0440] The sending module 130 is configured to send the root key to the second network device or terminal.
[0441] In some embodiments, the receiving module and / or the sending module may correspond to specific structures such as a network interface of a network device.
[0442] In some embodiments, the processing module may correspond to various types of processors.
[0443] It is worth noting that the processing module can execute any steps related to information processing in the key processing method executed by the first network device.
[0444] The sending module can be used for any step related to sending in the key processing method executed by the first network device.
[0445] The receiving module can be used in any step related to reception in the key processing method executed by the first network device.
[0446] In some embodiments, the processing module is configured to obtain the root key of the terminal for ranging / SL positioning services based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-everything V2X capability; or to obtain the root key of the terminal for ranging / SL positioning services based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-proximity ProSe.
[0447] In some embodiments, the sending module is configured to send a second message to a third network device based on the capability information indicating that the terminal has ranging / sidelink SL positioning capability; the second message is used to obtain the root key of the terminal's ranging / SL positioning service; the receiving module is configured to receive a third message sent by the third network device; the third message includes the root key of the terminal's ranging / SL positioning service.
[0448] FIG8B is a diagram of a second network device provided in an embodiment of the present disclosure, wherein the second network device includes:
[0449] The receiving module 210 is configured to receive a fourth message sent by the terminal; the fourth message is used by the terminal to request registration; the fourth message includes capability information of the terminal;
[0450] The sending module 220 is configured to send a first message to the first network device according to the fourth message; the first message includes capability information;
[0451] The receiving module 210 is configured to receive a root key sent by the second network device; the root key is used for ranging / sidelink SL positioning services of the terminal;
[0452] The sending module 220 is configured to send the root key to the terminal.
[0453] In some embodiments, the receiving module and the sending module may correspond to specific structures such as a network interface of the second network device.
[0454] Optionally, the network device further comprises a storage module and / or a processing module, wherein the storage module may be configured to store information. The processing module may be configured to execute steps related to information processing in the key processing method executed by the second network device.
[0455] In some embodiments, the sending module is configured to send the root key to the terminal when the terminal has subscribed to the ranging / sidelink SL positioning service.
[0456] In some embodiments, the sending module is configured to send the root key carried in the fifth message to the terminal; the fifth message is used to indicate acceptance of registration of the terminal.
[0457] FIG8C is a third network device provided by an embodiment of the present disclosure, wherein the third network device includes:
[0458] The receiving module 310 is configured to receive a second message sent by the first network device based on the capability information reported when the terminal registers the request; the second message is used to obtain a root key for the ranging / SL positioning service of the terminal;
[0459] The sending module 320 is configured to send the root key of the ranging / SL positioning service to the first network device.
[0460] In some embodiments, the third network device further includes a processing module.
[0461] The sending module can execute any operation related to the sending step in the key processing method executed by the third network device.
[0462] The receiving module can execute any operation related to the receiving step in the key processing method executed by the third network device.
[0463] In some embodiments, the third network device may further include a processing module.
[0464] The processing module can execute any operation related to information processing in the key processing method executed by the third network device.
[0465] In some embodiments, the processing module is configured to obtain a root key for the ranging / SL positioning service based on the subscription information of the terminal.
[0466] FIG8D is a terminal provided by an embodiment of the present disclosure, wherein the terminal includes:
[0467] The sending module 410 is configured to send a fourth message to the second network device, where the fourth message is used by the terminal to request registration; the fourth message includes capability information of the terminal; the capability information is used to indicate at least whether the terminal has ranging / sidelink (SL) positioning capability;
[0468] The receiving module 420 is configured to receive the root key of the ranging / SL positioning service sent by the first network device or the second network device when the terminal has the ranging / SL positioning capability.
[0469] In some embodiments, the terminal may further include a processing module.
[0470] The sending module can execute any operation related to the sending step in the key processing method executed by the terminal.
[0471] The receiving module can execute any operation related to the receiving step in the key processing method executed by the terminal.
[0472] The processing module can execute any operation related to information processing in the key processing method executed by the terminal.
[0473] In some embodiments, the root key sent by the second network device is carried in a fifth message; the fifth message is used to indicate the acceptance of the registration of the terminal.
[0474] In some embodiments, the root key is configured as or serves as a long-term credential and is used to establish a secure direct connection for ranging / SL positioning services.
[0475] An embodiment of the present disclosure further provides a communication device, which may include: one or more processors; wherein the processor is used to call instructions to enable the communication device to execute a key processing method that can be implemented in any of the aforementioned embodiments.
[0476] The communication device may be one or more of the aforementioned terminal, the first network device to the third network device.
[0477] 9A and / or 9B , the communication device 8100 further includes one or more memories 8102 for storing instructions. Alternatively, all or part of the memories 8102 may be located outside the communication device 8100.
[0478] The communication device may be the aforementioned terminal and network device. In some embodiments, the network device may be a master node and / or an auxiliary node.
[0479] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps such as sending and receiving in the above method are performed by the transceiver 8103, and the other steps are performed by the processor 8101.
[0480] In some embodiments, a transceiver may include a receiver and a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, and transceiver circuit may be used interchangeably; the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be used interchangeably; and the terms receiver, receiving unit, receiver, and receiving circuit may be used interchangeably.
[0481] Optionally, the communication device 8100 further includes one or more interface circuits 8104, which are connected to the memory 8102. The interface circuits 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuits 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0482] The communication device 8100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 9A . The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: (1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data or programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.
[0483] 9B is a schematic diagram of the structure of the chip 8200 provided in an embodiment of the present disclosure. If the communication device 8100 can be a chip or a chip system, please refer to the schematic diagram of the structure of the chip 8200 shown in FIG9B , but the present disclosure is not limited thereto.
[0484] The chip 8200 includes one or more processors 8201, and the processor 8201 is used to call instructions to enable the chip 8200 to execute any of the above key processing methods.
[0485] In some embodiments, chip 8200 further includes one or more interface circuits 8202, which are connected to memory 8203. Interface circuit 8202 can be used to receive signals from memory 8203 or other devices, and can be used to send signals to memory 8203 or other devices. For example, interface circuit 8202 can read instructions stored in memory 8203 and send the instructions to processor 8201. Optionally, the terms interface circuit, interface, transceiver pin, and transceiver are interchangeable.
[0486] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Alternatively, all or part of the memories 8203 may be outside the chip 8200.
[0487] The present disclosure also provides a storage medium having instructions stored thereon, which, when executed on the communication device 8100, causes the communication device 8100 to execute any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but may also be a transient storage medium.
[0488] The present disclosure further provides a program product, which, when executed by the communication device 8100, enables the communication device 8100 to perform any of the above key processing methods. Optionally, the program product is a computer program product.
[0489] The present disclosure also provides a computer program, which, when executed on a computer, enables the computer to execute any one of the above key processing methods.
[0490] Other embodiments of the present invention will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow from the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the invention being indicated by the following claims.
[0491] It should be understood that the present invention is not limited to the exact construction described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.
Claims
1. A key processing method, wherein: Executed by a first network device, the method includes: receiving a first message sent by a second network device, wherein the first message includes capability information reported by the terminal when requesting registration; Acquire a root key used by the terminal for ranging / SL positioning services based on the capability information indicating that the terminal has ranging / sidelink SL positioning capabilities; The root key is sent to the second network device or the terminal.
2. The method according to claim 1, wherein: The method of obtaining, based on the capability information indicating that the terminal has ranging / sidelink SL positioning capability, a root key used by the terminal for ranging / SL positioning services, includes: Based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-everything (V2X) capability, obtaining a root key for ranging / SL positioning services of the terminal; or, Based on the capability information indicating that the terminal has ranging / SL positioning capability and vehicle-to-proximity ProSe, a root key for the ranging / SL positioning service of the terminal is obtained.
3. The method according to claim 1 or 2, wherein: The method of obtaining, based on the capability information indicating that the terminal has ranging / sidelink SL positioning capability, a root key used by the terminal for ranging / SL positioning services, includes: Based on the capability information indicating that the terminal has ranging / sidelink SL positioning capability, sending a second message to a third network device; the second message is used to obtain the root key of the ranging / SL positioning service of the terminal; Receive a third message sent by the third network device; the third message includes the root key of the ranging / SL positioning service of the terminal.
4. A key processing method, wherein: Executed by the second network device, the method includes: receiving a fourth message sent by a terminal; the fourth message is used by the terminal to request registration; the fourth message includes capability information of the terminal; According to the fourth message, sending a first message to the first network device; the first message includes the capability information; Receiving a root key sent by the second network device; the root key is used for ranging / sidelink SL positioning service of the terminal; The root key is sent to the terminal.
5. The method according to claim 4, wherein: The sending the root key to the terminal includes: The terminal has subscribed to ranging / sidelink SL positioning service, and the root key is sent to the terminal.
6. The method according to claim 4 or 5, wherein: The sending the root key to the terminal includes: The root key carried in a fifth message is sent to the terminal; the fifth message is used to indicate acceptance of registration of the terminal.
7. A key processing method, wherein: Executed by a third network device, the method includes: receiving a second message sent by the first network device; the second message is used to obtain a root key of a ranging / SL positioning service of the terminal; the second message is sent by the first network device based on capability information reported by the terminal during a registration request; The root key of the ranging / SL positioning service is sent to the first network device.
8. The method according to claim 7, wherein: The method further comprises: The root key of the ranging / SL positioning service is obtained according to the subscription information of the terminal.
9. A key processing method, wherein: Executed by a terminal, the method includes: Sending a fourth message to the second network device, the fourth message being used by the terminal to request registration; the fourth message comprising capability information of the terminal; the capability information being used to at least indicate whether the terminal has ranging / sidelink SL positioning capability; The terminal has ranging / SL positioning capability, and receives a root key of a ranging / SL positioning service sent by the first network device or the second network device.
10. The method according to claim 9, wherein: The root key sent by the second network device is carried in a fifth message; the fifth message is used to indicate acceptance of registration of the terminal.
11. The method according to claim 9 or 10, wherein: The root key is configured as a long-term credential, and the root key is used to establish a secure direct connection for the ranging / SL positioning service.
12. A first network device, wherein: The first network device comprises: A receiving module, configured to receive a first message sent by a second network device, wherein the first message includes capability information reported by the terminal when requesting registration; A processing module, configured to indicate that the terminal has ranging / sidelink SL positioning capability based on the capability information, and obtain a root key used by the terminal for ranging / SL positioning services; A sending module is configured to send the root key to the second network device or the terminal.
13. A second network device, wherein: The second network device comprises: A receiving module, configured to receive a fourth message sent by a terminal; the fourth message is used by the terminal to request registration; the fourth message includes capability information of the terminal; a sending module, configured to send a first message to the first network device according to the fourth message; the first message includes the capability information; The receiving module is configured to receive a root key sent by the second network device; the root key is used for ranging / sidelink SL positioning service of the terminal; The sending module is configured to send the root key to the terminal.
14. A third network device, wherein: The third network device comprises: A receiving module, configured to receive a second message sent by a first network device; the second message is used to obtain a root key of a ranging / SL positioning service of a terminal; the second message is sent by the first network device based on capability information reported by the terminal during a registration request; A sending module is configured to send the root key of the ranging / SL positioning service to the first network device.
15. A terminal, wherein: The terminal comprises: A sending module is configured to send a fourth message to the second network device, wherein the fourth message is used by the terminal to request registration; the fourth message includes capability information of the terminal; the capability information is at least used to indicate whether the terminal has ranging / sidelink SL positioning capability; The receiving module is configured to receive the root key of the ranging / SL positioning service sent by the first network device or the second network device based on the terminal having the ranging / SL positioning capability.
16. A communication device, wherein: The communication device comprises: one or more processors; The processor is used to call instructions so that the communication device executes the key processing method described in any one of claims 1 to 3, 4 to 6, 7 to 8, and / or claims 9 to 11.
17. A storage medium, wherein: The storage medium stores instructions, and when the instructions are executed on a communication device, the communication device executes the key processing method described in any one of claims 1 to 3, 4 to 6, 7 to 8, and / or claims 9 to 11.
Citation Information
Patent Citations
Key distribution method and device, communication equipment and storage medium
CN116349267A
Information processing method and device, communication equipment and storage medium
CN116803113A
Security discovery method, device, system and equipment and storage medium
CN116847338A
User equipment anchor capability indication for sidelink-based positioning
US20220394659A1