Communication method and related apparatus
By triggering the authentication process after the UE updates the parameters, the problem of errors in the UE performing services is solved, and business stability and normal operation are achieved.
Patent Information
- Application Number
- PCT/CN2024/126988
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-29
- Filing Date
- 2024-10-24
- Publication Date
- 2025-05-08
AI Technical Summary
When updating user equipment (UE) parameters in the prior art, errors may occur when the UE performs related services, affecting service stability.
After the UE updates the parameters, a message carrying the authentication indication information is generated and sent to the access and mobility management function network elements to trigger the UE's authentication process to ensure that relevant service operations are performed based on the new parameters.
Effectively avoid or reduce errors in UE when executing services due to parameter updates, and ensure business stability and normal operation.
Smart Images

Figure CN2024126988_08052025_PF_FP_ABST
Abstract
Description
Communication method and related device This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on October 29, 2023, with application number 202311422748.6, and priority to the Chinese patent application with the invention name “Communication Methods and Related Devices”, all contents of which are incorporated by reference in this application. Technical Field The present application relates to the field of communication technology, and in particular to communication methods and related devices. Background Art Nowadays, the Internet brings more and more convenience to people, and people's production and life are increasingly inseparable from the Internet. The network will update the parameters on the user equipment (UE) in some scenarios. For example, after the UE successfully registers to the 5G network, the unified data management (UDM) network element can securely update the parameters on the UE through the UE parameters update (UPU) process. However, these parameters may be related to the services that are running or to be run on the UE, resulting in errors when the UE executes related services. Therefore, it is necessary to study how to reduce the situation where errors occur when the UE executes related services due to the network updating the parameters on the UE. Summary of the invention The embodiments of the present application provide a communication method and related devices, which can avoid or reduce the situation where errors occur when the communication device executes related services due to the network updating parameters on the communication device. In a first aspect, an embodiment of the present application provides a communication method, the method comprising: after updating a first parameter, a communication device supporting a first service generates a first message, the first message comprising authentication indication information for indicating an access and mobility management function network element to trigger a process for authenticating the communication device, and the first parameter is associated with the first service; the communication device sends the first message to the access and mobility management function network element. The first parameter is associated with the first service. The association of the first parameter with the first service may be that the first parameter will be directly or indirectly used in a process related to the first service, or used in the context of a service related to the first service. In the present application, the communication device may be a UE or a chip in the UE. In an embodiment of the present application, after updating the first parameter, the communication device supporting the first service generates a first message and sends the first message to the AMF to trigger a process for authenticating the communication device, and then through the process of authenticating the communication device, performs related operations (i.e., operations related to the communication device executing the first service) based on the new first parameter (i.e., the updated first parameter), thereby avoiding or reducing the situation where errors occur when the communication device executes the first service due to the updating of the first parameter. In one possible implementation, before generating the first message, the method further includes: the communication device receiving a second message from the access and mobility management function network element, wherein the second message includes a new first parameter; and the communication device updating the old first parameter to the new first parameter. In this implementation manner, the communication device may update the old first parameter to the new first parameter. In a possible implementation manner, the method further includes: the communication device determining that it supports the first service. In this implementation, the communication device determines that it supports the first service, so as to send the first message after updating the first parameter, thereby avoiding or reducing the occurrence of errors when the communication device executes the first service due to updating the first parameter. In a possible implementation manner, the generating the first message includes: in response to the communication device supporting the first service and the communication device updating the old first parameter to the new first parameter, the communication device generating the first message carrying the authentication indication information. In this implementation, the communication device generates a first message carrying authentication indication information so that the access and mobility management function network element triggers a process for authenticating the communication device, thereby avoiding or reducing errors that occur when the communication device executes the first service due to updating the first parameter. In one possible implementation, the second message also includes indication information for instructing the communication device to perform a re-registration process, and the generating of the first message includes: when the communication device supports the first service and the communication device updates the old first parameter to the new first parameter, in response to the indication information of the re-registration process, the communication device generates the first message including the authentication indication information, and the first message is a registration request message. In this implementation, the communication device generates a registration request message including authentication indication information so that the access and mobility management function network element triggers a process for authenticating the communication device, thereby avoiding or reducing errors that occur when the communication device executes the first service due to updating the first parameter. In one possible implementation, the second message also includes integrity verification information for verifying all or part of the parameters in the second message; the communication device updates the old first parameter to the new first parameter including: when it is determined, based on the integrity verification information, that the integrity verification of all or part of the parameters in the second message is successful, the communication device updates the old first parameter to the new first parameter. In this implementation, it can be ensured that the new first parameter received by the communication device is correct. In a possible implementation, the first service is an authentication and key management for application (AKMA) service, and the first parameter includes a routing indicator (RID) of the communication device. The first parameter is associated with the first service in that the RID is used to generate an AKMA key identifier corresponding to the AKMA service. In one possible implementation, the first service is an AKMA service, and the first parameter includes the RID of the communication device; after the communication device sends the first message to the access and mobility management function network element, the method also includes: the communication device sends an application session establishment request message to an application function network element supporting the AKMA, and the application session establishment request message includes an AKMA key identifier (AKMA-keyidentifier, A-KID) generated based on the new RID. In this implementation, the communication device sends an application session establishment request message to an application function network element supporting the first service, and can establish an application session with the application function network element. In a possible implementation, the method further includes: the communication device generates an AKMA key and an AKMA key identifier A-KID corresponding to the AKMA key, and generates a key K for the application function network element according to the AKMA key and the identifier of the application function network element. AF . In one possible implementation, the first parameter is a parameter used directly or indirectly by the communication device supporting the first service when using the first service, and the process of authenticating the communication device includes: performing an operation associated with the first service based on a new first parameter, and performing the operation enables the communication device to successfully use the first service. In this possible implementation, after updating the first parameter, the communication device supporting the first service can successfully use the first service by executing a process to authenticate the communication device to perform operations associated with the first service based on the new first parameter. On the second aspect, an embodiment of the present application provides another communication method, which includes: an access and mobility management function network element executes a registration process for registering the communication device to a network in response to a first registration request message from a communication device, and the registration process includes: the access and mobility management function network element sends a message including a key identifier to the communication device; the access and mobility management function network element receives a second registration request message from the communication device, the second registration request message includes authentication indication information for instructing the access and mobility management function network element to trigger a process for authenticating the communication device and the key identifier; in response to the authentication indication information, the access and mobility management function network element triggers the process for authenticating the communication device. In the embodiment of the present application, the second registration request message includes authentication indication information and a key identifier, and the second registration request message is decoded and integrity protection verified by using a key corresponding to the cryptographic identifier, so that the security of the second registration request message can be improved. In response to the authentication indication information, the access and mobility management function network element triggers a process for authenticating the communication device; it can be known that the communication device is authenticated during the registration process. In a possible implementation manner, before the access and mobility management function network element triggers a process for authenticating the communication device, the method further includes: The access and mobility management function network element performs integrity protection verification on the second registration request message according to the key corresponding to the key identifier. In one possible implementation, before the access and mobility management function network element receives a second registration request message from the communication device, the method also includes: the access and mobility management function network element sends a second message to the communication device, and the second message includes indication information for instructing the communication device to perform a re-registration process. In this implementation, the access and mobility management function network element sends a second message to the communication device, which may instruct the communication device to perform a re-registration process. In a possible implementation, the second message further includes integrity check information and new parameters of the communication device, the integrity check information is used to check all or part of the parameters in the second message, and the second message is used to update the parameters of the communication device. In this implementation, the communication device can more accurately update the old parameters to the new parameters carried by the second message. In one possible implementation, the access and mobility management function network element sending the second message to the communication device includes: the access and mobility management function network element sending the second message to the communication device in response to a message from a unified data management network element including the indication information, the integrity check information and new parameters of the communication device. In a third aspect, an embodiment of the present application provides another communication method, the method comprising: when determining that a first parameter of a communication device supporting a first service needs to be updated, a unified data management network element generates a third message, the third message comprising at least one of first indication information for instructing the communication device to trigger a main authentication process and second indication information for instructing the communication device to perform a re-registration process, and a new first parameter of the communication device, the first parameter being associated with the first service; the unified data management network element sends the third message to an access and mobility management function network element. In an embodiment of the present application, the unified data management network element generates a third message and sends the third message to the access and mobility management function network element when determining that the first parameter of the communication device supporting the first service needs to be updated. When the third message includes the first indication information, the first indication information instructs the communication device to trigger the main authentication process, and then the relevant operations are performed based on the new first parameter through the process of authenticating the communication device, which can avoid or reduce the situation where an error occurs when the communication device executes the first service due to the update of the first parameter. When the third message includes the second indication information, the second indication information is used to instruct the communication device to perform a re-registration process, so that the communication device supporting the first service sends a re-registration request message including the authentication indication information for indicating the process of triggering the authentication of the communication device after updating the old first parameter to the new first parameter, thereby avoiding or reducing the situation where an error occurs when the communication device executes the first service due to the update of the first parameter. In a possible implementation manner, before generating the third message, the method further includes: the unified data management network element determining that the first parameter of the communication device needs to be updated. In this implementation, the unified data management network element determines that the first parameter of the communication device needs to be updated, so as to generate a third message including at least one of the first indication information and the second indication information. In a possible implementation manner, the method further includes: the unified data management network element determining that the communication device supports the first service. In this implementation, the unified data management network element determines that the communication device supports the first service, so as to generate a third message including at least one of the first indication information and the second indication information when determining that the first parameter of the communication device supporting the first service needs to be updated. In one possible implementation, the generating of the third message includes: in response to the communication device supporting the first service and the unified data management network element determining that the first parameter of the communication device needs to be updated, the unified data management network element generates the third message carrying at least one of the first indication information and the second indication information. In this implementation, the unified data management network element generates a third message carrying at least one of the first indication information and the second indication information, so as to subsequently trigger the process of authenticating the communication device to perform related operations based on the new first parameter, thereby avoiding or reducing the situation where errors occur when the communication device executes the first service due to updating the first parameter. In a possible implementation manner, the unified data management network element determines that the first parameter of the communication device needs to be updated, including: the unified data management network element decides to execute a user equipment parameter update UPU process for updating the first parameter of the communication device. In a possible implementation manner, the third message further includes integrity verification information for verifying all or part of the parameters in the third message. In this implementation manner, the access and mobility management function network element may verify the integrity of the third message. In a possible implementation manner, the first service is an AKMA service, and the first parameter includes a RID of the communication device. In a possible implementation manner, the first indication information and the second indication information are the same indication information. In a fourth aspect, an embodiment of the present application provides another communication method, which includes: a communication device supporting a first service receives a fourth message from an access and mobility management function network element, the fourth message including indication information for instructing the communication device to trigger a main authentication process and a new first parameter of the communication device, the first parameter being associated with the first service; in response to the indication information, the communication device sends a first message to the access and mobility management function network element, the first message including authentication indication information for instructing the access and mobility management function network element to trigger a process for authenticating the communication device. In an embodiment of the present application, in response to indication information, the communication device sends a first message to the access and mobility management function network element to instruct the access and mobility management function network element to trigger a process for authenticating the communication device, and then performs related operations based on the new first parameter through the process of authenticating the communication device, which can avoid or reduce the situation where errors occur when the communication device executes the first service due to updating the first parameter. In one possible implementation, after a communication device supporting a first service receives a fourth message from an access and mobility management functional network element, and before the communication device sends a first message to the access and mobility management functional network element, the method further includes: the communication device updating an old first parameter to the new first parameter. In a possible implementation, the fourth message further includes integrity check information; the communication device updates the old first parameter The new first parameter includes: when it is determined based on the integrity check information that the integrity check of the new first parameter is successful, the communication device updates the old first parameter to the new first parameter. In this implementation manner, the integrity of the fourth message can be guaranteed. In a possible implementation manner, the first service is an AKMA service, and the first parameter includes a RID of the communication device. In one possible implementation, the first service is an AKMA service, and the first parameter includes the RID of the communication device; after the communication device sends the first message to the access and mobility management function network element, the method also includes: the communication device sends an application session establishment request message to an application function network element supporting the first service, and the application session establishment request message includes an AKMA key identifier A-KID generated based on the new first parameter. In a possible implementation, the method further includes: in response to the AKMA service of the communication device, the communication device generates an AKMA key and an AKMA key identifier A-KID corresponding to the AKMA key, and generates a key K for the application function network element according to the AKMA key and the identifier of the application function network element. AF . In a fifth aspect, an embodiment of the present application provides another communication method, the method comprising: after the unified data management network element sends a third message to the access and mobility management function network element, the fifth message is generated, the third message is used to update the first parameter of the communication device supporting the first service, the fifth message is used to request the access and mobility management function network element to trigger the main authentication process of the communication device, the first parameter is associated with the first service; the unified data management network element sends the fifth message to the access and mobility management function network element. The third message is used to update the first parameter of the communication device supporting the first service, which can be understood as: the third message is used to update the first parameter of the communication device, and the communication device supports the first service. In an embodiment of the present application, after sending a third message for updating the first parameter of the communication device supporting the first service, UDM sends a fifth message to AMF, which can request AMF to trigger the main authentication process, and then perform related operations based on the new first parameter through the process of authenticating the communication device, thereby avoiding or reducing the situation where errors occur when the communication device executes the first service due to updating the first parameter. In a possible implementation manner, the method further includes: the unified data management network element sending the third message to the access and mobility management function network element. In a possible implementation manner, the third message includes first integrity check information for verifying all or part of the parameters in the third message and a new first parameter of the communication device. In a possible implementation manner, before generating the fifth message, the method further includes: the unified data management network element determining that the communication device supports the first service. In a possible implementation, the generating the fifth message includes: in response to the communication device supporting the first service and the unified data management network element determining that the third message for updating the first parameter of the communication device has been sent, the unified data management network element generates the fifth message. In a possible implementation, the third message includes communication device update data and response indication information for instructing the communication device to respond to the request of the unified data management network element. Exemplarily, the response indication information is used to instruct the communication device to respond to the received new first parameter. In this implementation, the third message includes communication device update data and response indication information to verify whether the communication device correctly receives the new first parameter. In one possible implementation, the unified data management network element receives a sixth message from the access and mobility management function network element, and the sixth message includes second integrity verification information generated in response to the response indication information, and the second integrity verification information is used by the unified data management network element to verify the sixth message; the generating of the fifth message includes: when it is determined that the integrity verification of all or part of the parameters in the sixth message is successful based on the second integrity verification information, in response to the communication device supporting the first service and the unified data management network element having sent the third message for updating the first parameter of the communication device, the unified data management network element generates the fifth message. In this implementation, when it is determined based on the second integrity check information that the integrity check of all or part of the parameters in the sixth message is successful, in response to the communication device supporting the first service and the unified data management network element having sent a third message for updating the first parameters of the communication device, the unified data management network element generates a fifth message; this can avoid triggering the process of authenticating the communication device when the communication device does not correctly receive the new first parameter, thereby saving signaling overhead. In a possible implementation manner, the method further includes: when the unified data management network element determines that the first parameter of the communication device needs to be updated, generating the third message including the communication device update data and the response indication information. In this implementation, when determining that the first parameter of the communication device needs to be updated, the unified data management network element generates a third message including communication device update data and indication information, so that the communication device updates the old first parameter to the new first parameter and provides feedback. In a possible implementation manner, the first service is an AKMA service, and the first parameter includes a RID of the communication device. In a sixth aspect, an embodiment of the present application provides a communication device, which has the function of implementing the behavior in the method embodiment of the first aspect above. The communication device (terminal device) may be a communication device, or a component of a communication device (such as a processor, a chip, or a chip system, etc.), or a logic module or software that can implement all or part of the functions of the communication device. The functions of the communication device may be implemented by hardware, or may be implemented by hardware executing corresponding software, and the hardware or software includes one or more modules or units corresponding to the above functions. In a possible implementation, the communication device includes a processing module and a transceiver module, wherein: after updating a first parameter of a communication device supporting a first service, the processing module generates a first message, the first message includes authentication indication information for indicating that an access and mobility management function network element triggers a process for authenticating the communication device, and the first parameter is associated with the first service; the transceiver module is used to send the first message to the access and mobility management function network element. The first parameter is associated with the first service. The association of the first parameter with the first service may be that the first parameter is directly or indirectly used in a process related to the first service, or is used in the context of a service related to the first service. In a possible implementation, the transceiver module is further used to receive a second message from the access and mobility management function network element, wherein the second message includes a new first parameter; and the processing module is further used to update the old first parameter to the new first parameter. In a possible implementation manner, the processing module is further configured to determine whether the communication device supports the first service. In a possible implementation manner, the processing module is specifically configured to generate the first message carrying the authentication indication information in response to the communication device supporting the first service and updating the old first parameter to the new first parameter. In one possible implementation, the second message also includes indication information for instructing the communication device to perform a re-registration process; the processing module is specifically used to generate the first message including the authentication indication information in response to the indication information of the re-registration process when the communication device supports the first service and updates the old first parameter to the new first parameter, and the first message is a registration request message. In one possible implementation, the second message also includes integrity verification information for verifying all or part of the parameters in the second message; the processing module is specifically used to update the old first parameter to the new first parameter when it is determined that the integrity verification of all or part of the parameters in the second message is successful based on the integrity verification information. In a possible implementation, the first service is an AKMA service, and the first parameter includes the RID of the communication device; the transceiver module is further used to send an application session establishment request message to an application function network element supporting the first service, and the application session establishment request message includes an A-KID generated based on the new first parameter. In a possible implementation, the processing module is further configured to generate an AKMA key and an AKMA key identifier A-KID corresponding to the AKMA key in response to the AKMA service of the communication device, and generate a key K for the application function network element according to the AKMA key and the identifier of the application function network element. AF . Possible implementations of the communication device of the sixth aspect may refer to various possible implementations of the first aspect. For the technical effects brought about by various possible implementation methods of the sixth aspect, reference may be made to the introduction to the technical effects of the first aspect or various possible implementation methods of the first aspect. In a seventh aspect, an embodiment of the present application provides a communication device, which has the function of implementing the behavior in the method embodiment of the second aspect above. The communication device may be a communication device, or a component of a communication device (such as a processor, a chip, or a chip system, etc.), or a logic module or software that can implement all or part of the functions of the communication device. The function of the communication device may be implemented by hardware, or may be implemented by hardware executing corresponding software, and the hardware or software includes one or more modules or units corresponding to the above functions. In a possible implementation, the communication device includes a processing module and a transceiver module, wherein: the processing module is used to respond to a first registration request message from a communication device, and execute a registration process for registering the communication device to a network, and the registration process includes: an access and mobility management function network element sends a message including a key identifier to the communication device; the transceiver module is used to receive a second registration request message from the communication device, and the second registration request message includes authentication indication information for indicating that the access and mobility management function network element triggers a process for authenticating the communication device and the key identifier; in response to the authentication indication information, the access and mobility management function network element triggers a process for authenticating the communication device. In a possible implementation manner, the processing module is further configured to perform integrity protection verification on the second registration request message according to the key corresponding to the key identifier. In a possible implementation, the transceiver module is further used to send a second message to the communication device, where the second message includes instruction information for instructing the communication device to perform a re-registration process. In a possible implementation, the second message further includes integrity check information and new parameters of the communication device, the integrity check information is used to check all or part of the parameters in the second message, and the second message is used to update the parameters of the communication device; the processing module is further used to respond to the instruction information, the integrity check information and the new parameters of the communication device from the unified data management network element. The second message is sent to the communication device through the transceiver module. Possible implementations of the communication device of the seventh aspect may refer to various possible implementations of the second aspect. For the technical effects brought about by various possible implementation methods of the seventh aspect, reference may be made to the introduction to the technical effects of the second aspect or various possible implementation methods of the second aspect. In an eighth aspect, an embodiment of the present application provides a communication device, which has the function of implementing the behavior in the method embodiment of the third aspect above. The communication device may be a communication device, or a component of a communication device (such as a processor, a chip, or a chip system, etc.), or a logic module or software that can implement all or part of the functions of the communication device. The function of the communication device may be implemented by hardware, or may be implemented by hardware executing corresponding software, and the hardware or software includes one or more modules or units corresponding to the above functions. In a possible implementation, the communication device includes a processing module and a transceiver module, wherein: the processing module is used to generate a third message when determining that a first parameter of a communication device supporting a first service needs to be updated, and the third message includes at least one of the first indication information for instructing the communication device to trigger a main authentication process and the second indication information for instructing the communication device to perform a re-registration process and a new first parameter of the communication device, and the first parameter is associated with the first service; the transceiver module is used to send the third message to an access and mobility management function network element. In a possible implementation manner, the processing module is further configured to determine whether the first parameter of the communication device needs to be updated. In a possible implementation manner, the processing module is further configured to determine whether the communication device supports the first service. In one possible implementation, the processing module is specifically used to generate the third message carrying at least one of the first indication information and the second indication information in response to the communication device supporting the first service and the unified data management network element determining that the first parameter of the communication device needs to be updated. In a possible implementation manner, the processing module is specifically configured to determine to execute a user equipment parameter update UPU procedure for updating the first parameter of the communication device. Possible implementations of the communication device of the eighth aspect may refer to various possible implementations of the third aspect. Regarding the technical effects brought about by various possible implementation methods of the eighth aspect, reference may be made to the introduction to the technical effects of the third aspect or various possible implementation methods of the third aspect. In the ninth aspect, an embodiment of the present application provides a communication device, which has the function of implementing the behavior in the method embodiment of the fourth aspect above. The communication device may be a communication device, or a component of a communication device (such as a processor, a chip, or a chip system, etc.), or a logic module or software that can implement all or part of the functions of the communication device. The function of the communication device may be implemented by hardware, or may be implemented by hardware executing corresponding software, and the hardware or software includes one or more modules or units corresponding to the above functions. In a possible implementation, the communication device includes a processing module and a transceiver module, wherein: the transceiver module is used to receive a fourth message from an access and mobility management function network element, the fourth message includes indication information for indicating that the communication device triggers a main authentication process and a new first parameter of the communication device, the first parameter being associated with the first service; the processing module is used to respond to the indication information, and send a first message to the access and mobility management function network element through the transceiver module, the first message including authentication indication information for indicating that the access and mobility management function network element triggers a process for authenticating the communication device. In a possible implementation manner, the processing module is further configured to update the old first parameter to the new first parameter. In one possible implementation, the fourth message also includes integrity verification information; the processing module is specifically used to, when it is determined that the integrity verification of the new first parameter is successful based on the integrity verification information, the communication device updates the old first parameter to the new first parameter. In one possible implementation, the first service is an AKMA service, and the first parameter includes the RID of the communication device; the transceiver module is also used to send an application session establishment request message to an application function network element supporting the first service, and the application session establishment request message includes an AKMA key identifier A-KID generated based on the new first parameter. In a possible implementation, the processing module is further configured to generate, in response to an AKMA service of the communication device, an AKMA key and an AKMA key identifier A-KID corresponding to the AKMA key by the communication device, and generate, according to the AKMA key and the identifier of the application function network element, a key K for the application function network element. AF . Possible implementations of the communication device of the ninth aspect may refer to various possible implementations of the fourth aspect. Regarding the technical effects brought about by various possible implementation methods of the ninth aspect, reference may be made to the introduction to the technical effects of the fourth aspect or various possible implementation methods of the fourth aspect. In a tenth aspect, an embodiment of the present application provides a communication device, which has the function of implementing the behavior in the method embodiment of the fifth aspect. The communication device can be a communication device, or a component of a communication device (such as a processor, a chip, or a chip system, etc.), or a logic module or software that can implement all or part of the functions of the communication device. The functions of the communication device can be implemented by hardware, The corresponding software implementation can also be executed by hardware, and the hardware or software includes one or more modules or units corresponding to the above functions. In a possible implementation, the communication device includes a processing module and a transceiver module, wherein: the processing module is used to generate a fifth message after the transceiver module sends a third message to the access and mobility management function network element, the third message is used to update the first parameter of the communication device supporting the first service, the fifth message is used to request the access and mobility management function network element to trigger the main authentication process of the communication device, and the first parameter is associated with the first service; the transceiver module is used to send the fifth message to the access and mobility management function network element. The third message is used to update the first parameter of the communication device supporting the first service, which can be understood as: the third message is used to update the first parameter of the communication device, and the communication device supports the first service. In a possible implementation manner, the transceiver module is further configured to send the third message to the access and mobility management function network element. In a possible implementation, the processing module is specifically configured to generate the fifth message in response to the communication device supporting the first service and the unified data management network element determining that the third message for updating the first parameter of the communication device has been sent. In one possible implementation, the third message includes communication device update data and response indication information for instructing the communication device to respond to the request of the unified data management network element; the transceiver module is also used to receive a sixth message from the access and mobility management function network element, the sixth message including second integrity verification information generated in response to the response indication information, the second integrity verification information being used by the unified data management network element to verify the sixth message; the processing module is specifically used to generate the fifth message in response to the communication device supporting the first service and the unified data management network element having sent the third message for updating the first parameters of the communication device, when it is determined based on the second integrity verification information that the integrity verification of all or part of the parameters in the sixth message is successful. In a possible implementation manner, the processing module is further configured to generate the third message including the communication device update data and the response indication information when it is determined that the first parameter of the communication device needs to be updated. Possible implementations of the communication device of the tenth aspect may refer to various possible implementations of the fifth aspect. Regarding the technical effects brought about by various possible implementation methods of the tenth aspect, reference may be made to the introduction to the technical effects of the fifth aspect or various possible implementation methods of the fifth aspect. In the eleventh aspect, an embodiment of the present application provides another communication device, which includes a processor, the processor is coupled to a memory, the memory is used to store programs or instructions, when the program or instructions are executed by the processor, the communication device executes the method shown in any possible implementation of the first to fifth aspects above. In the embodiment of the present application, in the process of executing the above method, the process of sending information (or signal) in the above method can be understood as the process of outputting information based on the instructions of the processor. When outputting information, the processor outputs the information to the transceiver so that it can be transmitted by the transceiver. After the information is output by the processor, it may also need to be processed in other ways before it reaches the transceiver. Similarly, when the processor receives input information, the transceiver receives the information and inputs it into the processor. Furthermore, after the transceiver receives the information, the information may need to be processed in other ways before it is input into the processor. For operations such as sending and / or receiving involved by the processor, unless otherwise specified or unless they conflict with the actual function or internal logic in the relevant description, they can be generally understood as instructions output based on the processor. During the implementation process, the processor may be a processor specifically used to execute these methods, or may be a processor that executes computer instructions in a memory to execute these methods, such as a general-purpose processor, etc. For example, the processor may also be used to execute a program stored in the memory, and when the program is executed, the communication device executes the method as shown in the first aspect or any possible implementation of the first aspect. In a possible implementation, the memory is located outside the communication device. In a possible implementation, the memory is located inside the communication device. In a possible implementation, the processor and the memory may also be integrated into one device, that is, the processor and the memory may also be integrated together. In a possible implementation, the communication device further includes a transceiver, and the transceiver is used to receive a signal or send a signal. In a twelfth aspect, the present application provides another communication device, which includes a processing circuit and an interface circuit, wherein the interface circuit is used to acquire or output data; the processing circuit is used to execute the method shown in any possible implementation of the first to fifth aspects above. In the thirteenth aspect, the present application provides a computer-readable storage medium, in which a computer program is stored. The computer program includes program instructions, which, when executed, enable the computer to execute the method shown in any possible implementation of the first to fifth aspects above. In a fourteenth aspect, the present application provides a computer program product, which includes a computer program, and the computer program includes program instructions, which, when executed, enable a computer to execute a method as shown in any possible implementation of the first to fifth aspects above. In a fifteenth aspect, the present application provides a chip comprising a processor and a communication interface, wherein the processor reads instructions stored in a memory through the communication interface to execute a method as shown in any one of the first to fifth aspects above. In a sixteenth aspect, the present application provides a communication system, comprising the communication device described in the sixth aspect or any possible implementation of the sixth aspect, and the communication device described in the seventh aspect or any possible implementation of the seventh aspect. In the seventeenth aspect, the present application provides another communication system, comprising the communication device described in the eighth aspect or any possible implementation of the eighth aspect, and the communication device described in the ninth aspect or any possible implementation of the ninth aspect. BRIEF DESCRIPTION OF THE DRAWINGS Figure 1 is a schematic diagram of a 5G network architecture based on a service-oriented architecture; Figure 2 is a schematic diagram of the AKMA network architecture; FIG3 is a flow chart of a method for deducing an AKMA anchor key after primary authentication provided in an embodiment of the present application; FIG. 4( a) shows a K deduction for a specific AF after the master authentication provided in an embodiment of the present application. AF Schematic diagram of the process; FIG. 4( b) shows a K deduction for a specific AF after the master authentication provided in an embodiment of the present application. AF Another flow chart of FIG5 is a flowchart of a method for triggering a primary authentication process by a UE's home network according to an embodiment of the present application; FIG6 is a schematic diagram of a UPU process provided in an embodiment of the present application; FIG7 is a schematic diagram of the format of a UPU message header; FIG8 is a method flow diagram of combining an AKMA process and a UPU process provided in an embodiment of the present application; FIG9 is a flow chart of a communication method provided in an embodiment of the present application; FIG10 is a flow chart of another communication method provided in an embodiment of the present application; FIG11 is a flow chart of another communication method provided in an embodiment of the present application; FIG12 is a flow chart of another communication method provided in an embodiment of the present application; FIG13 is a flow chart of another communication method provided in an embodiment of the present application; FIG14 is a flow chart of another communication method provided in an embodiment of the present application; FIG15 is a flow chart of another communication method provided in an embodiment of the present application; FIG16 is a flow chart of another communication method provided in an embodiment of the present application; FIG17 is a flow chart of another communication method provided in an embodiment of the present application; FIG18 is a schematic diagram of the structure of a communication device 1800 provided in an embodiment of the present application; FIG. 19 is a schematic diagram of the structure of another device 190 provided in an embodiment of the present application. DETAILED DESCRIPTION The terms "first" and "second" in the specification, claims and drawings of the present application are only used to distinguish different objects, rather than to describe a specific order. It is understood that the various digital numbers involved in the embodiments of the present application are only for the convenience of description and are not used to limit the scope of the embodiments of the present application. The size of the sequence number of the above-mentioned processes does not mean the order of execution, and the execution order of each process should be determined by its function and inherent logic. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices. In the present application, the naming of the message is only used to distinguish different messages and should not be understood as a limitation. In other words, the name of any message in the present application can be replaced by other naming, and the present application is not limited. The "embodiment" mentioned in this article means that the specific features, structures or characteristics described in conjunction with the embodiment can be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It can be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments. The terms used in the following embodiments of the present application are only for the purpose of describing specific embodiments and are not intended to be limiting of the present application. As used in the specification and appended claims of the present application, the singular expressions "one", "a kind", "said", "above", "the" and "this" are intended to include plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in the present application refers to and includes any or all possible combinations of one or more of the listed items. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The term "plurality" used in the present application refers to two or more. In the textual description of the present application, the character " / " generally indicates that the objects associated before and after are an "or" relationship. Tie. It can be understood that in each embodiment of the present application, "A corresponds to B" means that there is a corresponding relationship between A and B, and B can be determined according to A. However, it should also be understood that determining (or generating) B according to (or based on) A does not mean that B is determined (or generated) only according to (or based on) A, and B can also be determined (or generated) according to (or based on) A and / or other information. It should be understood that in the present application, indication includes direct indication (also called explicit indication) and implicit indication. Wherein, direct indication of information A means including the information A; implicit indication of information A means indicating information A through the correspondence between information A and information B and direct indication of information B. Wherein, the correspondence between information A and information B can be predefined, pre-stored, pre-burned, or pre-configured. It should be understood that in the present application, information C is used to determine information D, which includes information D being determined based only on information C, and information D being determined based on information C and other information. In addition, information C is used to determine information D, and it can also be indirectly determined, for example, information D is determined based on information E, and information E is determined based on information C. In addition, "network element A sends information A to network element B" in each embodiment of the present application can be understood as the destination end of the information A or the intermediate network element in the transmission path between the destination end and the network element B, which may include directly or indirectly sending information to network element B. "Network element B receives information A from network element A" can be understood as the source end of the information A or the intermediate network element in the transmission path between the source end and the network element A, which may include directly or indirectly receiving information from network element A. The information may be processed as necessary between the source end and the destination end of the information transmission, such as format changes, etc., but the destination end can understand the valid information from the source end. Similar expressions in the present application can be understood similarly and will not be repeated here. Figure 1 is a schematic diagram of a 5G network architecture based on a service-oriented architecture. The 5G network architecture shown in Figure 1 may include terminal devices, (radio) access networks ((R)AN) and core networks. Terminal devices access data networks (DN) through access networks and core networks. In one possible scenario, a key (e.g., a long-term key) and related functions are stored in the terminal device. When the terminal device performs two-way authentication with a core network element (e.g., an access and mobility management function (AMF) network element, an authentication server function (AUSF) network element), the stored key and related functions are used to verify the authenticity of the network. The terminal device may be a device that provides a wireless communication function, for example, a handheld device or a vehicle-mounted device with a wireless connection function. At present, some examples of terminal devices are: mobile phones, satellite mobile terminals, cellular phones, smart phones, tablet computers, laptop computers, PDAs, mobile internet devices (MID), wearable devices (such as smart watches, smart bracelets, pedometers, smart glasses, etc.), vehicle-mounted devices (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed railways, etc.), satellite terminals, virtual reality (VR) devices, augmented reality (AR) devices, smart point of sale (POS) machines, customer-premises equipment (CPE), wireless terminals in industrial control, wireless terminals in self driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, and wireless terminals in smart homes. The present invention relates to wireless terminals in a home (e.g., refrigerators, televisions, air conditioners, electric meters, etc.), intelligent robots, robotic arms, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication functions, computing devices or other processing devices connected to wireless modems, flying devices (e.g., intelligent robots, hot air balloons, drones, airplanes), terminal devices in 5G networks, or terminal devices in future-evolved public land mobile communication networks (PLMNs), etc., which are not limited in the embodiments of the present application. As an example and not a limitation, in the embodiments of the present application, the terminal device may also be a mobile terminal (mobile termination, MT) in an IAB node. When an IAB node faces its parent node, it may be regarded as a terminal device, in which case the IAB node plays the role of an MT.The following description uses UE as an example of a terminal device, and UE appearing anywhere subsequently may be replaced by a terminal device or other examples of a terminal device. In the embodiment of the present application, the device for realizing the function of the terminal device may be a terminal device, or a device capable of supporting the terminal device to realize the function, such as a chip system, which may be installed in the terminal device or used in combination with the terminal device. In the embodiment of the present application, the chip system may be composed of a chip, or may include a chip and other discrete devices. In the embodiment of the present application, only the device for realizing the function of the terminal device is used as an example for explanation, and the scheme of the embodiment of the present application is not limited. The access network (AN) can be an access network that uses different access technologies. There are two types of wireless access technologies: 3rd generation partnership project (3GPP) access technology (such as the wireless access technology used in 3G, 4G or 5G systems) and non-3rd generation partnership project (non-3GPP) access technology. 3GPP access technology refers to access technology that complies with 3GPP standards and specifications. Access networks that use 3GPP access technology are called radio access networks. Non-3GPP access technology refers to access technology that does not comply with 3GPP standards, for example, air interface technology represented by wireless fidelity (WiFi). The access network is used to implement access-related functions, and can provide network access functions for authorized users in a specific area, and can determine transmission links of different qualities to transmit user data according to the user level, business requirements, etc. The access network forwards control signals and user data between the UE and the core network. The access network may include access network equipment, which may be equipment that provides access to the UE, and may include radio access network (RAN) equipment and wired access network (FAN) equipment. The access network equipment in the embodiment of the present application may refer to a RAN node (or device) that connects the terminal device to the wireless network. RAN equipment is mainly responsible for wireless resource management, quality of service (QoS) management, data compression and encryption and other functions on the air interface side. RAN equipment may include various forms of base stations, such as macro base stations, micro base stations (also called small stations), relay stations, access points, balloon stations, etc. In systems using different wireless access technologies, the names of devices with base station functions may be different. For example, in 5G systems, they are called RAN or next-generation Node basestation (gNB), and in long term evolution (LTE) systems, they are called evolved Node B (eNB or eNodeB). The core network is responsible for maintaining the subscription data of the mobile network and providing UE with functions such as session management, mobility management, policy management, and security authentication. The core network includes but is not limited to the following network elements: application function (AF) network element, unified data management (UDM) network element, unified data repository (UDR) network element, policy control function (PCF) network element, session management function (SMF) network element, access and mobility management function (AMF) network element, network repository function (NRF) network element, authentication server function (AUSF) network element, network exposure function (NEF) network element, and user plane function (UPF) network element. The following introduces some network elements in the core network. AMF network element is mainly responsible for mobility management. For example, AMF is responsible for user location update, user registration network, user switching, etc. The SMF network element is mainly responsible for session management in the mobile network, such as session establishment, modification, and release. Specific functions include allocating Internet Protocol (IP) addresses to users and selecting UPF network elements that provide message forwarding functions. The UPF network element is mainly responsible for forwarding and receiving user data. It can receive user data from the data network and transmit it to the UE through the access network equipment; it can also receive user data from the UE through the access network equipment and forward it to the data network. AUSF network element, the functional entity of the network (i.e. core network) to authenticate the UE, is used by the network to verify whether the UE is authentic. The PCF network element mainly supports providing a unified policy framework to control network behavior, provides policy rules for control plane functions, and is responsible for obtaining user subscription information related to policy decisions. The PCF network element can provide policies to the AMF network element and SMF network element, such as QoS policy, slice selection policy, UE policy, etc. AF network elements (or application functional entities) interact with the 3GPP core network to provide application layer services. AF network elements can convey the requirements of the application side to the network side, such as QoS requirements or user status event subscriptions. AF can be a third-party functional entity or an application service deployed by an operator. UDM network element includes functions such as execution and management of contract data, user access authentication, and authorization. The UDR network element includes the storage and access functions of contract data, policy data, application data and other types of data. NEF network element is mainly used to support the opening of capabilities and events. NRF network elements can be used to provide network element discovery functions and provide network element information corresponding to the network element type based on requests from other network elements. NRF also provides network element management services, such as network element registration, update, deregistration, and network element status subscription and push. DN, on which various services can be deployed, can provide data and / or voice services for UE. Among them, AF network element, UDM network element, UDR network element, PCF network element, SMF network element, AMF network element, NRF network element, AUSF network element, NEF network element, UPF network element can also be referred to as AF, UDM, UDR, PCF, SMF, AMF, NRF, AUSF, NEF, UPF respectively. In Figure 1, Nausf, Nnef, Nnfr, Namf, Npcf, Nsmf, Nudm, Nudr, and Naf are service-oriented interfaces provided by the above AUSF, NEF, NRF, AMF, PCF, SMF, UDM, UDR, and AF, respectively, and are used to call corresponding service-oriented operations. N1, N2, N3, N4, and N6 are interface serial numbers, and the meanings of these interface serial numbers are as follows: 1) N1: The interface between AMF and UE, which can be used to deliver non-access stratum (NAS) signaling (such as QoS rules from AMF) to UE. 2) N2: The interface between AMF and access network equipment, which can be used to transmit wireless bearer control information from the core network side to the access network equipment. 3) N3: The interface between the access network equipment and UPF, mainly used to transmit uplink and downlink user plane data between the access network equipment and UPF. 4) N4: The interface between SMF and UPF can be used to transfer information between the control plane and the user plane, including controlling the issuance of forwarding rules, QoS rules, traffic statistics rules, etc. for the user plane and reporting information on the user plane. 5) N6: Interface between UPF and DN, used to transfer uplink and downlink user data flows between UPF and DN. The above network element or function can be a network element in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). As a possible implementation, the above network element or function can be implemented by one device, or by multiple devices, or a functional module in one device, which is not specifically limited in the embodiments of the present application. The following is a schematic diagram of an authentication and key management for applications (AKMA) network architecture based on the above 5G network architecture. The network architecture shown in Figure 2 is based on the network architecture shown in Figure 1, and adds the architecture and network elements involved in the AKMA process. The following introduces part of the network in Figure 2. AKMA anchor function (AAnF) network element (hereinafter referred to as AAnF) can interact with AUSF to obtain the AKMA anchor key K AKMA , and is responsible for generating key materials used between UE and AF, such as AKMA application key (K AF ) and K AFIn one possible implementation, the AKMA anchor key is sent by AUSF to AAnF after the UE completes the primary authentication. AF interacts with 3GPP core network elements. AF can interact with PCF network elements to obtain QoS parameters, or AF network elements provide QoS parameters to PCF network elements, thereby achieving an effect that can affect application data transmission. AKMA In the scenario of AKMA service, the AF supporting AKMA service can initiate a request to obtain the AKMA application key (i.e. K AF ). That is, in the AKMA scenario, AF can interact with AAnF to obtain K AF and K AF The effective time of the AF. The location of the AF can be inside the 5G core network (5G core, 5GC) or outside the 5GC. If the AF is inside the 5GC or the AF is a trusted AF of the operator, then the AF can interact directly with the PCF. If the AF is outside the 5GC or the AF is an untrusted AF of the operator, the NEF forwards the interaction content between the AF and the PCF as an intermediary. NEF acts as an intermediary to provide interactive services between the external AF and the AAnF within the core network. In the AKMA scenario, AUSF can provide AAnF with AKMA key material, namely AKMA key identifier (A-KID) and AKMA anchor key K AKMA , and provide the UE's identification information, such as the user permanent identifier (SUPI), to the AAnF. Among them, A-KID is used to identify the UE's AKMA anchor key K AKMA . The AKMA process can include the UE and AUSF deducing K after the primary authentication AKMA (See Figure 3 below), and AAnF is the AF derivation of K AF (Refer to Figure 4(a) and Figure 4(b)). The following describes the derivation K after the master authentication in conjunction with Figure 3. AKMA The process and Figure 4 (a) and Figure 4 (b) introduce the deduction K after the master authentication AF Figure 4(a) shows the process of deducing K for a specific AF after the master authentication provided in the embodiment of the present application. AF FIG4(b) is a flowchart of the process of deducing K for a specific AF after the master authentication provided in the embodiment of the present application. AFAnother flow chart of the main authentication. The main authentication may be an authentication between the UE and the core network. The main authentication process may include the following steps: the UE sends a request to the core network to request to connect to the core network; the core network sends a random number and a challenge code to the UE; the UE generates a response code using the stored key K and the received random number, and sends the response code to the core network; the core network generates an expected response code using the key K stored in its own database and the random number sent to the UE, and compares the expected response code with the response code from the UE. If the two are the same, the UE is authenticated; the core network sends an encryption key K to the UE. AUSF , K AUSF Used for subsequent secure communications. Referring to FIG3 , FIG3 is a flow chart of a method for deducing an AKMA anchor key after primary authentication provided by an embodiment of the present application. As shown in FIG3 , the method includes: 301. AUSF sends an authentication vector acquisition request (Nudm_UEAuthentication_GetRequest) message to UDM. The authentication vector acquisition request message contains SUPI or subscription concealed identifier (SUCI). Exemplarily, when the AMF provides SUCI to the AUSF, the AUSF carries SUCI in the authentication vector acquisition request message; when the AMF provides SUPI to the AUSF, the AUSF carries SUPI in the authentication vector acquisition request message. The authentication vector acquisition request message is used to request an authentication vector (AV) from the UDM, and the authentication vector is used for primary authentication / primary authentication between the core network element and the UE. In this article, the primary authentication process may also be referred to as the primary authentication process. For details, please refer to the primary authentication process defined in the TS 33.501 specification of 3GPP. 302. UDM sends an authentication vector acquisition response (Nudm_UEAuthentication_GetResponse) message to AUSF. The authentication vector acquisition response message includes an authentication vector. Optionally, the authentication vector includes K AUSF UDM can generate K based on the key K AUSF The authentication vector corresponds to the SUPI / SUCI. The SUPI / SUCI in the authentication vector acquisition request message is used to identify the UE. The UE and AUSF can obtain the same K AUSF. Optionally, the authentication vector acquisition response message also includes AKMA indication information and a routing indicator (RID). RID can be a part of SUCI and is represented by 1 to 4 decimal digits. For example, UDM obtains the UE's contract information based on SUCI / SUPI, and determines whether the UE supports the use of AKMA services based on the UE's contract information, that is, determines whether the UE is authorized to use AKMA services; if the UE supports the use of AKMA services, UDM sends AKMA indication information and RID to AUSF. Step 303: AUSF generates K AKMA and A-KID. In one possible implementation, if AUSF receives an AKMA indication from UDM, AUSF stores K in the authentication vector according to the AKMA indication. AUSF , and after the main authentication process is successfully completed, according to K AUSF Generate K AKMA and AKMA-keyidentifier (A-KID), where A-KID is used to identify K AKMA , or it can be understood that the K corresponding to the A-KID can be obtained according to the A-KID AKMA . Exemplarily, the format of A-KID is username@example. The username part includes RID and AKMA temporary UE identifier (AKMA temporary UE identifier, A-TID), and the example part includes home network identifier (homenetworkidentifier). The home network identifier is used to identify the home network of the UE, which includes the mobile country code (mobile country code, MCC) and the mobile network code (mobile network code, MNC). A-TID can be based on K AUSF A temporary identifier is generated. The format of A-KID is described uniformly here and will not be repeated later. AMF can use RID+home public land mobile network (HPLMN) ID to select AUSF, and AUSF can use RID+HPLMNID to select UDM. AUSF according to K AUSF Generate K AKMA An example is as follows: AUSF uses K AUSF As the key K, and using the following parameters 1 to 5 as the input of the key derivation function, generate K AKMA : Parameter 1: FC = 0x80; that is, parameter 1 is 0x80; Parameter 2: P0 = "AKMA"; that is, parameter 2 is the string "AKMA"; Parameter 3: L0 = length of "AKMA"; (for example, 0x000x04); that is, parameter 3 is the length of the string "AKMA"; Parameter 4: P1 = SUPI; Parameter 5: L1 = length of SUPI. AUSF according to K AUSF An example of generating an A-TID is as follows: AUSF uses K AUSF As the key K, and using the following parameters 1 to 5 as input to the key derivation function, generate the A-TID: Parameter 1: FC = 0x81; that is, parameter 1 is 0x81; Parameter 2: P0 = "A-TID"; that is, parameter 2 is the string "A-TID"; Parameter 3: L0 = length of "A-TID"; (e.g., 0x00 0x05) Parameter 4: P1 = SUPI; Parameter 5: L1 = length of SUPI. After AUSF generates A-TID, it can construct A-KID based on RID, A-TID and home network identifier. 304. AUSF sends an AKMA anchor key registration request (Naanf_AKMA_AnchorKey_Register Request) message to AAnF. The AKMA point key registration request message contains SUPI, A-KID and K AKMA The AAnF is an AAnF selected by the AUSF from one or more AAnFs corresponding to the RID. 305. AAnF sends an AKMA anchor key registration response (Naanf_AKMA_AnchorKey_RegisterResponse) message to AUSF. AAnF can combine A-KID and K AKMA Through A-KID, you can find the K corresponding to this A-KID in AAnF. AKMA In other words, the A-KID is used to find the K corresponding to the A-KID in the AAnF. AKMA For example, AF can use A-KID to find the K corresponding to A-KID in AAnF.AKMA . Step 306: UE generates K AKMA and A-KID. In one possible implementation, when the UE decides to use the AKMA service, K is generated. AKMA and A-KID. UE generates K AKMA and A-KID method, and AUSF generates K AKMA The method is the same as A-KID. K generated by UE AKMA K generated by AUSF AKMA The A-KID generated by the UE is the same as the A-KID generated by the AUSF. The UE can receive the KID from the core network by executing the main authentication process. AUSF . It should be noted that there is no time sequence relationship between step 306 and the above steps 301 to 305, and step 306 can be executed at any step after the main authentication process. According to the above scheme, UE and AUSF generate the same K AKMA and A-KID, and AUSF will K AKMA Register A-KID with AAnF so that AAnF can use K AKMA And A-KID to derive other keys. Referring to FIG. 4( a ), the AF deduces K after the master authentication provided in the embodiment of the present application AF The method flow chart is shown in FIG. 1 , and in the flow chart, AF can directly interact with AAnF. The method includes the following steps: Before the UE and AF communicate, the UE and AF need to know whether to use AKMA. The UE and AF can implicitly determine to use AKMA, or the AF can instruct the UE to use AKMA. Before the UE and AF communicate, that is, before the UE executes step 401a, the UE has generated AKMA. AKMA and A-KID, AUSF has generated K AKMA and A-KID, and the generated K AKMA and A-KID is sent to AAnF. 401a. When the UE initiates communication with the AF, the UE sends an Application Session Establishment Request message to the AF. The application session establishment request contains the A-KID. Before the UE initiates communication with the AF, the UE can perform the main authentication process and generate the KID after the main authentication process. AKMA and A-KID, the process may refer to the description of the embodiment of FIG. 3 . 402a, AF sends an AKMA application key acquisition request (Naanf_AKMA_ApplicationKey_GetRequest) message to AAnF. The trigger condition for the AF to execute step 402 may be receiving an application session establishment request message. The AKMA application key acquisition request message contains A-KID and AF_ID. A-KID comes from the application session establishment request in the above step 401a, and AF_ID is the identification information of the AF. In one possible implementation, after receiving the application session establishment request from the UE, the AF first determines whether an activated context associated with the A-KID is stored locally based on the A-KID in the application session establishment request. If an activated context associated with the A-KID is stored, it indicates that the AF has established AKMA communication with the UE before, so the AF can obtain the K corresponding to the A-KID from the context. AF , the subsequent steps 402a to 406a do not need to be performed, and the process ends. If no activated context associated with the A-KID is stored, the AF can select an AAnF from one or more AAnFs corresponding to the RID in the A-KID, and send the above-mentioned AKMA application key acquisition request message to the AAnF. Step 403a, AAnF generates K AF . In one possible implementation, AAnF obtains the K corresponding to the A-KID in the AKMA application key acquisition request message from the local AKMA Based on the K AKMA and AF_ID, generate K AF , and determine K AF The expiration time. In a possible implementation, after receiving the AKMA application key acquisition request message from the AF, the AAnF checks whether the AAnF can provide the AKMA service to the AF according to the configured local policy or the authorization information or policy corresponding to the AF_ID obtained from the NRF. If the check shows that the AKMA service can be provided to the AF, the subsequent process will be continued. If the check shows that the AKMA service cannot be provided to the AF, the AAnF rejects the AKMA application key acquisition request message of the AF, that is, does not provide the AKMA service to the AF. AF If the AAnF checks that it can provide the AF with the AKMA service, the AAnF obtains the K corresponding to the A-KID from the local AKMA If we can get K AKMA , indicating that the UE can be authorized to use the AKMA service, so step 403a is executed.AKMA , indicating that the UE cannot be authorized to use the AKMA service, so step 403a is not performed. It should be noted that if AAnF locally stores the K corresponding to A-KID AF , then AAnF can obtain the K locally AF , there is no need to perform step 403a. If the K corresponding to A-KID is not stored locally AF , then AAnF executes step 403a. AAnF generates K AF An example is as follows: AAnF obtains the corresponding K from the local according to A-KID AMKA , using K AKMA As the key K and parameters 1 to 3 are used as the input of the key derivation function, K is generated AF : Parameter 1: FC = 0x82; Parameter 2: P0 = AF_ID; Parameter 3: L0 = length of AF_ID. That is, parameter 3 is the length of AF_ID. AF_ID = FQDN of AF || security protocol identifier of the interface between UE and AF. "||" is a connector. FQDN is the abbreviation of fully qualified domain name. 404a. AAnF sends an AKMA application key acquisition response (Naanf_AKMA_ApplicationKey_GetResponse) message to AF. The AKMA application key acquisition response message contains K AF and K AF The end time of K AF The end time of K AF In the present embodiment, K AF The termination time is also called K AF The expiration time is uniformly described here and will not be repeated later. 405a. AF sends an application session establishment response message to the UE. If AF receives K from AAnF AF and K AF If the AF receives a response indicating a failure or error from the AAnF, the application session establishment response message indicates that the application session establishment failed. The application session establishment response message may include a failure reason value, which may be K AFFailed to obtain. 406a. UE generates K AF . UE generates K AF The method and AAnF generate K AF The method is the same as that of UE, so the K generated by UE is AF K generated by AAnF AF This step 406a can be performed in the main authentication process and in the process of generating K AKMA Therefore, step 406a can be performed at any time before or after step 401a. In a possible implementation, when the UE decides to communicate with the AF, K is generated. AF . It should be noted that if the above application session establishment response indicates that the application session establishment fails, the UE may trigger a new application session establishment request to the AF, in which a new A-KID is included, thereby triggering a new round of derivation of the KID. AF process. Subsequently, when the UE communicates with the AF, it can be based on K AF The key used for communication between the two parties is derived, such as the session key, to encrypt and protect the communication information. AF As a shared key for establishing transport layer security (TLS) between UE and AF, that is, the K-based key between UE and AF AF Establish a TLS connection. According to the above scheme, UE and AAnF generate the same K AF , so that K can be used later AF Other keys can be deduced, such as The conversation key. Referring to FIG. 4( b ), the AF deduces K after the master authentication provided in the embodiment of the present application AF The method flow diagram is as follows, and in the flow, AF cannot interact with AAnF directly, but interacts with AAnF through NEF. The method may include: Before the UE and AF communicate, the UE and AF need to know whether to use AKMA. The UE and AF can implicitly determine to use AKMA, or the AF can instruct the UE to use AKMA. Before the UE and AF communicate, that is, before the UE executes step 401a, the UE has generated AKMA. AKMA and A-KID, AUSF has generated K AKMA and A-KID, and the generated K AKMA and A-KID is sent to AAnF. 401b. When the UE initiates communication with the AF, the UE sends an Application Session Establishment Request message to the AF. Step 401b may refer to step 401a. 402b. The AF discovers the NEF and sends a first key request message to the NEF. The first key request message may be a Knef_AKMA_AFKeyRequest message. The first key request message includes an A-KID and an AF_ID. The A-KID comes from the application session establishment request in step 401b above, and the AF_ID is the identification information of the AF. In a possible implementation, after receiving the application session establishment request from the UE, the AF first determines whether an activated context associated with the A-KID is stored locally based on the A-KID in the application session establishment request. If an activated context associated with the A-KID is stored, it indicates that the AF has established AKMA communication with the UE before, so the AF can obtain the K corresponding to the A-KID from the context. AF , the subsequent steps do not need to be performed, and the process ends. If the activated context associated with the A-KID is not stored, the AF can find the NEF according to the RID in the A-KID and send the first key request message to the NEF. 403b. NEF selects AAnF. For example, the NEF may obtain the RID from the A-KID and select an AAnF from one or more AAnFs corresponding to the RID. For another example, the NEF selects the AAnF according to a configured local policy. 404b. NEF sends a second key request message to AAnF. The second key request message may be a Naanf_AKMA_AFKeyRequest message. The second key request message includes an A-KID and an AF_ID. 405b, AAnF generates K AF . Among them, AAnF is based on K AKMA Generate K AF The K AKMAis obtained in the process shown in FIG3 above. In a possible implementation, after receiving the second key request message from the NEF, the AAnF checks whether the AAnF can provide the AKMA service to the AF according to the configured local policy or the authorization information or policy corresponding to the AF_ID obtained from the NRF. If the check shows that the AKMA service can be provided to the AF, the subsequent process is continued. If the check shows that the AKMA service cannot be provided to the AF, the AAnF rejects the second key request message of the NEF, that is, does not provide the K to the NEF. AF Instead, the NEF replies with a response indicating failure or error, and then the NEF replies with a response indicating failure or error to the AF. If the AAnF checks that it can provide the AKMA service to the AF, the AAnF obtains the K corresponding to the A-KID from the local AKMA If we can get K AKMA , indicating that the UE can be authorized to use the AKMA service, so that step 405b and subsequent steps are executed. AKMA , indicating that the UE cannot be authorized to use the AKMA service, thus generating K AF . AAnF generates K AF Afterwards, we can determine the K AF The end time of . It should be noted that if AAnF locally stores the K corresponding to A-KID AF , then AAnF can obtain the K locally AF , there is no need to perform step 405b. If the K corresponding to A-KID is not stored locally AF , then AAnF executes step 405b. 406b. AAnF sends a second key response message to NEF. The second key response message may be a Naanf_AKMA_AFKeyResponse message, and the second key response message includes K AF and K AF The end time of . 407b. NEF sends a first key response message to AF. The first key response message may be a Knef_AKMA_AFKeyResponse message, which includes K AF and K AF The end time of . 408b. AF sends an application session establishment response message to the UE. If AF receives K from NEF AF and K AFIf the AF receives a response indicating a failure or error from the NEF, the application session establishment response message indicates that the application session establishment failed. The application session establishment response message may include a failure reason value, which may be K AF Failed to obtain. 409b. UE generates K AF . Among them, UE generates K AF The method and AAnF generate K AF The method is the same as that of UE, so the K generated by UE is AF K generated by AAnF AF This step 409b can be performed in the main authentication process and in the process of generating K AKMA Execute at any time thereafter, so step 409b can be performed in step Executed any time before or after 401b. It should be noted that if the above application session establishment response indicates that the application session establishment fails, the UE may trigger a new application session establishment request to the AF, in which a new A-KID is included, thereby triggering a new round of derivation of the KID. AF process. Subsequently, when the UE communicates with the AF, it can be based on K AF The key used for communication between the two parties is derived, such as the session key, to encrypt and protect the communication information. According to the above scheme, UE and AAnF generate the same K AF , so that K AF can be used to deduce other keys, such as session keys, in the future. The processes of Figures 3, 4(a) and 4(b) all involve the main authentication process. The following describes a method flow of triggering the main authentication process by the home network of the UE. Figure 5 is a flow chart of a method of triggering the main authentication process by the home network of the UE provided in an embodiment of the present application. As shown in Figure 5, the method includes: 501. Based on the received events and local policies, UDM decides to trigger the main authentication process. Optionally, UDM can pre-configure the operator authentication policy (i.e., local policy) to determine when to trigger the primary authentication process. UDM decides to trigger and execute the primary authentication process triggered by the home network based on events or operator authentication policies. For example, AAnF sends a Nudm_UECM_AuthTrigger request to UDM based on certain factors, and UDM decides to trigger the primary authentication process based on the request. A prerequisite for UDM to trigger the primary authentication may be that UDM already has the AMF / SEAF information serving the UE, otherwise, UDM cannot contact any AMF / SEAF in subsequent steps. When the UE has no ongoing primary authentication, if UDM decides to trigger the primary authentication based on the received event or operator authentication policy, UDM determines the AMF / security anchor functionality (SEAF) serving the UE. If different AMFs are registered in UDM (UE can be registered to different AMFs through 3GPP access technology and non-3GPP access technology respectively, that is, UDM can register 2 AMFs serving the UE at the same time. Each AMF is linked to an access technology), UDM should select an AMF for re-authentication. The selection criteria of AMF depends on the local UDM authentication policy. 502. UDM sends an authentication notification message to AMF / SEAF. The authentication notification message contains the SUPI of the UE. The AMF / SEAF is the AMF / SEAF determined by the UDM as the service for the UE. 503. AMF / SEAF decides whether to trigger the primary authentication based on its local authentication policy and UE status. For example, if the UE is switching, or if the UE is already performing primary authentication before receiving the authentication notification message from the UDM, it is not necessary to trigger the primary authentication. The AMF / SEAF triggers the process of authenticating the UE by sending a Nausf_UEAuthentication_AuthenticateRequest message to the AUSF and executing the subsequent process. For details, please refer to the relevant processes in sections 6.1.2 and 6.1.3 of the 3GPP standard TS33.501. 504. AMF / SEAF sends an authentication response message to UDM. If the AMF / SEAF decides to trigger the primary authentication, the Authentication Response message is used to indicate that the AMF / SEAF decides to trigger the primary authentication. If the AMF / SEAF decides not to trigger the primary authentication, the Authentication Response message is used to indicate that the AMF / SEAF decides not to trigger the primary authentication. 505. AMF / SEAF starts the main authentication process. In the method flow of Figure 5, after UDM decides to trigger the main authentication process, it sends an authentication notification message to AMF / SEAF so that AMF / SEAF decides whether to trigger the main authentication based on its own local authentication policy and UE status. Figure 5 introduces the method flow of the UE's home network triggering the main authentication process. The following introduces another UPU process that can trigger the main authentication process. The UPU process is a process in which the UDM updates the UE parameters through the control plane process, where the UE parameters include a routing indicator (RID). After the UE successfully registers to the 5G network, the UDM can securely submit the updated parameters to the UE. Figure 6 is a schematic diagram of a UPU process provided in an embodiment of the present application. As shown in Figure 6, the UPU process may include: 601. UDM decides to perform UE parameter update. When the UE registers to the 5G system, UDM decides when to perform UE parameter updates through the control plane. 602. UDM sends a UPU protection message to AUSF. The UPU protection message may be a Nausf_UPUProtection message. The UPU protection message contains UPU data and a UPU message header. The UPU data includes updated UE parameters, such as the UE's RID. If the UDM determines that the UE is to respond to a successful security check of the received UPU data, the UDM shall set a corresponding indication in the UE parameter update information (see standard 3GPP TS 24.501).
[0035] ) and includes an ACK indication set to 1 in the UPU message header, indicating that the UDM needs the expected UPU-XMAC-I UE UDM expected UPU-XMAC-I UE Allows the UDM to verify that the UE has received the UPU data correctly. 603. AUSF sends a UPU protection response message to UDM. The UPU protection response message may be a Nausf_UPUProctection response message. The UPU protection response message includes UPU data, UPU counter, UPU message header and UPU-MAC-I AUSF UPU-MAC-I AUSF It is the message authentication code (MAC) generated after the integrity protection of UPU data. The count value used in the protection process. UPU counter can also be recorded as Counter UPUThe AUSF and UE will compare the UPU counter with the K AUSF The UPU counter is generally a 16-bit counter. The UPU counter is used to avoid replay attacks. For example, when the UE derives K AUSF When UE sets UPU counter to 0, AUSF derives K AUSF AUSF will set the UPU counter to 1 when Optionally, in the case where the UPU protection message also includes an ACK indication set to 1, the UPU protection response message also includes UPU-XMAC-I UE It should be noted that UPU-MAC-I AUSF Based on UPU data, UPU counter and K AUSF Calculated by UPU-XMAC-I UE Based on the ACK indication, UPU counter and K AUSF To calculate it. 604. UDM sends an SDM notification message to AMF. The SDM notification message is Nudm_SDM_Notification message. The SDM notification message includes: UPU data, UPU counter, UPU message header and UPU-MAC-I AUSF In one possible implementation, UDM calls the Nudm_SDM_Notification service operation. If AMF supports UPU transparent container, the operation includes UPU transparent container. If not, the access and mobility subscription data includes UE parameter update data, UPU-MAC-I AUSF If the UDM includes an ACK indication set to 1 in the UPU message header, the expected UPU-XMAC-I shall be temporarily stored. UE . The SDM notification message sent by UDM to AMF contains a UPU message header, and its format is shown in Figure 7. Figure 7 is a schematic diagram of the format of the UPU message header. REG indicates whether the re-authentication process needs to be triggered. When it is set to a valid value, the UE needs to trigger the main authentication process later. ACK is used to indicate whether the UE needs to confirm the successful security check of the received UE parameter update data. When ACK is set to a valid value (for example, 1), the UE needs to confirm the successful security check of the received UE parameter update data. 605. AMF sends a DL NAS transmission message to the UE. DL NAS transmission messages include UPU data, UPU counter, UPU message header and UPU-MAC-I AUSF . DL is the abbreviation of downlink. NAS is the abbreviation of non-access stratum (NAS). The UPU message header includes an ACK indication set to 1, and the ACK indication is used to request (or instruct) the UE to confirm that the security check of the received UPU data is successful. After receiving the SDM notification message, the AMF sends a DL NAS transmission message to the served UE. 606. UE verifies UPU-MAC-I AUSF . As a possible implementation, after receiving the DL NAS transmission message, the UE calculates the UPU-MAC-I according to the received UPU data and UPU counter in the same way as the AUSF. AUSF , and verify the calculated UPU-MAC-I AUSF Is it consistent with the received UPU-MAC-I AUSF When the calculated UPU-MAC-I AUSF With the received UPU-MAC-I AUSF If they are the same, the verification is successful. AUSF In the case of successful verification, if the UPU data contains parameters protected by a secure packet, the ME in the UE sends the parameters protected by the secure packet to the USIM card in the UE. AUSF When the verification is successful, if the UPU data does not contain parameters protected by the security group, the ME in the UE updates its stored parameters according to the parameters in the UPU data. When the UDM has requested the UE to confirm that the security check of the received UPU data is successful (that is, the ACK in the UPU message header is set to a valid value, such as 1), the terminal device has successfully verified the UPU-MAC-I AUSF , and after updating the parameters according to the UPU data, the UE shall execute the following step S507. 607. The UE sends a UL NAS transmission message to the AMF. UL NAS transport messages include UPU-MAC-I UE It should be noted that UPU-MAC-I UE According to K AUSF UE calculates UPU-MAC-I UE The same way as AUSF calculates UPU-MAC-I UEIn the same manner, the UL NAS transmission message includes UPU-MAC-I UE UPU-MAC-I carried in the UPU protection response message UE same. 608. AMF sends an SDM information request message to UDM. The SDM information request message is a Nudm_SDM_Info request message. The SDM information request message includes a transparent container, which includes a UPU-MAC-I UE In one possible implementation, if the AMF receives a UPU-MAC-I in a UL NAS transport message UE If a transparent container is present, AMF sends an SDM information request message with the transparent container to UDM. 609. UDM compares the received UPU-MAC-I UE UPU-XMAC-I and storage UE Are they consistent? If the UDM instructs the UE to confirm a successful security check on the received UE parameter update data, the UDM shall send the received UPU-MAC-I UE The expected UPU-XMAC-I temporarily stored by the UDM in step 604 UE It should be understood that if the received UPU-MAC-I UE UPU-XMAC-I and storage UE If they are inconsistent, it means there is a security risk in the network. The above is a brief introduction to the UPU process. For specific details, please refer to the existing technology and will not be repeated here. The AKMA process and the UPU process are introduced above. The following is a method flow of combining the AKMA process and the UPU process. FIG8 is a method flow of combining the AKMA process and the UPU process provided by an embodiment of the present application. As shown in FIG8, the method includes: 801. UE and AUSF execute the main authentication process. 802. AUSF generates K AKMA -1 and A-KID-1. Step 802 may refer to step 303 in Figure 3. A possible way for AUSF to generate A-KID-1 is as follows: Generate A-TID; After generating A-TID, A-KID-1 may be constructed according to RID-1, A-TID and home network identifier. RID-1 refers to the RID of the UE, that is, the RID of the UE before executing step 5. 803. AUSF sends an AKMA anchor key registration request (Naanf_AKMA_AnchorKey_Register Request) message to AAnF. The AKMA point key registration request message contains SUPI, A-KID-1 and K AKMA -1. The AAnF is an AAnF selected by the AUSF from one or more AAnFs corresponding to RID-1 in A-KID-1. AKMA -1 is associated (or corresponds to). Through A-KID-1, the K corresponding to A-KID-1 can be found in AAnF. AKMA In other words, A-KID-1 is used to find the K corresponding to A-KID-1 in AAnF. AKMA For example, AF can use A-KID-1 to find the K corresponding to A-KID-1 in AAnF. AKMA . 804. AAnF sends an AKMA anchor key registration response (Naanf_AKMA_AnchorKey_RegisterResponse) message to AUSF. It should be noted that step 801 to step 804 belong to the AKMA process, see FIG. 3 . 805. UDM updates UE parameters through the UPU process. The UE parameters include the RID of the UE. The UDM updates the UE parameters through the UPU process, at least updating the RID of the UE from RID-1 to RID-2. Step 805 can refer to the UPU process of Figure 6. In other words, the method flow in Figure 8 is a possible implementation of step 805. 806. Before using the AKMA service, the UE generates K AKMA -1 and uses the updated RID (ie, RID-2) to generate A-KID-2. For example, before the UE sends an Application Session Establishment Request message to the AF, it generates K AKMA -1 and uses the updated RID (i.e., RID-2) to generate A-KID-2. AKMA -1 is UE according to K AUSF Generated, K AUSF The same value is used at the UE and AUSF. The UE generates K AKMA -1 method and AUSF generate K AKMA-1, please refer to the above step 303. The possible ways for the UE to generate A-KID-2 are as follows: Generate A-TID; After generating A-TID, A-KID-2 can be constructed according to RID-2, A-TID and home network identifier. The A-TID generated by the UE can be the same as the A-TID generated by the AUSF. Since RID-2 is different from RID-1, A-KID-2 is different from A-KID-1. 807. When the UE initiates communication with the AF, the UE sends an Application Session Establishment Request message to the AF. The application session establishment request includes A-KID-2. 808. AF sends an AKMA application key acquisition request (Naanf_AKMA_ApplicationKey_GetRequest) message to AAnF. The AKMA application key acquisition request message includes A-KID-2 and AF_ID. AF_ID is the identification information of AF. In one possible implementation, the AF selects an AAnF from one or more AAnFs corresponding to the RID-2 in A-KID-2, and sends the above-mentioned AKMA application key acquisition request message to the AAnF. If the AF cannot determine the AAnF corresponding to the RID-2 according to the RID-2 in A-KID-2, it sends an application session establishment response message to the UE. The application session establishment response message indicates that the application session establishment failed, and the application session establishment response message may include a failure reason value, which may be that the AAnF corresponding to RID-2 was not obtained. 809, AAnF did not find the K corresponding to A-KID-2 AKMA When the application key is obtained, a response (Naanf_AKMA_ApplicationKey_GetResponse) message is sent to AKMA. The AKMA application key acquisition response message indicates the AKMA application key (ie, K AF ) failed, the AKMA application key acquisition response message may include a failure reason value, which may be that the K corresponding to A-KID-2 is not found. AKMA Because the UE sends A-KID-2, the AKMA application key acquisition request message carries A-KID-2, but AAnF uses A-KID-1, so AAnF cannot find the K corresponding to the UE. AKMA -1, so UE and AF cannot use AKMA services. 809. The AF sends an application session establishment response message to the UE. The application session establishment response message indicates that the application session establishment failed. The application session establishment response message may include a failure reason value, which may be that the K AF . In the method flow shown in FIG8 , the reason why the UE and AF cannot use the AKMA service is that the AKMA process stipulates that the UE side only needs to generate an AKMA security context before using the AKMA service. However, before the UE side uses the AKMA service, the UDM can update the RID on the UE side through the UPU process. Before using the AKMA service, the UE side will generate a new A-KID based on the new RID, which causes the A-KID stored on the UE side and the AAnF to be different. Therefore, after the UE initiates the AKMA service, the AAnF cannot find the AKMA security context based on the A-KID. In the embodiment of the present application, for the convenience of description, the intermediate key K AUSF The derived key is called the AKMA security context. The AKMA security context includes but is not limited to: K AKMA , K AF . The technical solution of the present application can solve the problem of avoiding or reducing the error caused by the network updating the parameters on the UE when the UE executes the relevant service. For example, the technical solution of the present application can solve the problem that the AAnF cannot find the corresponding AKMA security context after the UE initiates the AKMA service. In other words, the technical solution of the present application can enable the AAnF to find the corresponding AKMA security context after the UE initiates the AKMA service. AKMA security context, and then successfully use AKMA service. The technical solution of this application is introduced below in conjunction with Figures 9 to 17. FIG9 is a flow chart of a communication method provided in an embodiment of the present application. As shown in FIG9 , the method includes: 901. A UE supporting a first service generates a first message after updating a first parameter. The above-mentioned first message includes authentication indication information for instructing the AMF to trigger the process of authenticating the above-mentioned UE. The first parameter is associated with the first service. The first parameter and the first service are associated in that the first parameter will be directly or indirectly used in the process related to the first service, or used in the context of the related service of the first service. In a possible implementation, the first parameter is a parameter directly or indirectly used by the UE supporting the first service when using the first service, and the process of authenticating the UE includes: an operation associated with the first service performed based on the new first parameter, and the operation is performed so that the UE can successfully use the first service. In this possible implementation, after updating the first parameter, the UE supporting the first service performs the process of authenticating the UE to perform the operation associated with the first service based on the new first parameter, so that the UE supporting the first service can successfully use the first service after updating the first parameter. Exemplarily, the first service is an AKMA service, and the first parameter is RID. In a possible implementation, before generating the first message, the UE performs the following operations: receiving a second message from the AMF, wherein the second message includes a new first parameter; the UE updates the old first parameter to the new first parameter; and determines that it supports the first service. Generating the first message may include: in response to the UE supporting the first service and the UE updating the old first parameter to the new first parameter, the UE generates the first message carrying the authentication indication information. 902. The UE sends a first message to the AMF. Correspondingly, the AMF receives the first message from the UE. 903. In response to the authentication indication information in the first message, the AMF triggers a process for authenticating the UE. The process of AMF triggering authentication of UE may be triggering the main authentication process shown in Figure 3. After AMF triggers the process of authenticating UE, the process shown in Figure 3 may be executed, which will not be repeated here. In the embodiment of the present application, after updating the first parameter, the UE supporting the first service generates a first message and sends the first message to the AMF to trigger the process of authenticating the UE, and then the process of authenticating the UE is used to perform related operations based on the new first parameter, which can avoid or reduce the situation where an error occurs when the UE executes the first service due to the update of the first parameter. For example, the first service is an AKMA service, and the first parameter is an RID. By triggering the process of authenticating the UE, the A-KID generated based on the new RID can be stored in the AAnF, so that the AAnF can find the corresponding AKMA security context after the UE initiates the AKMA service, and then successfully use the AKMA service. FIG10 is a flow chart of another communication method provided in an embodiment of the present application. The method flow in FIG11 is a possible implementation of the method described in FIG10. As shown in FIG10, the method includes: 1001. AMF sends a second message to UE. Correspondingly, the UE receives a second message from the AMF. The second message includes the new first parameter of the UE. In other words, the second message includes the updated first parameter of the UE. For example, the first parameter is the RID. Exemplarily, the second message is a message for updating the first parameter of the UE. The first parameter includes the RID of the UE. 1002. The UE updates the old first parameter to the new first parameter based on the second message. In a possible implementation, the second message further includes integrity check information; the UE, based on the second message, updates the old first parameter to the new first parameter, including: when it is determined based on the integrity check information that the integrity check of the new first parameter is successful, the UE updates the old first parameter to the new first parameter. Exemplarily, the second message is a DL NAS transmission message (see FIG. 6 ), and the integrity check information includes UPU-MAC-I AUSF In this possible implementation, it can be ensured that the new first parameter received by the UE is correct. 1003. The UE determines that it supports the first service. The order between step 1003 and step 1001 is not limited. Step 1003 may be before step 1001 or after step 1001. The first service may be an AKMA service. There are many ways for the UE to determine that it supports the first service, which are not limited in this application. For example, the UE may determine that it supports the first service by deploying or running an application that supports the first service. For another example, the UE determines that it supports the first service by the first service that it is about to use. For another example, the UE determines that it supports the first service based on configuration data indicating that the UE supports the first service. Exemplarily, the first service is an AKMA service. 1004. In response to the UE supporting the first service and the UE updating the old first parameter to the new first parameter, the UE generates a first message carrying authentication indication information. The authentication indication information is used to instruct the AMF to trigger the process of authenticating the above-mentioned UE. In a possible implementation, the second message further includes indication information for instructing the UE to perform a re-registration process, and step 1004 may be replaced by: when the UE supports the first service and the UE updates the old first parameter to the new first parameter, in response to the indication information of the re-registration process, the UE generates the first message of the authentication indication information. Exemplary, The first message is a registration request message. In a possible implementation, the first message also includes a key identifier, which is a key identifier received by the UE from the AMF in the last registration process; the AMF can determine the key corresponding to the key identifier based on the key identifier, and use the key to decode and perform at least one of integrity protection verification on the first message. 1005. The UE sends a first message to the AMF. Correspondingly, the AMF receives the first message from the UE. 1006. In response to the authentication indication information in the first message, the AMF triggers a process for authenticating the UE. The process of AMF triggering authentication of UE may be to trigger the main authentication process shown in FIG3. Exemplarily, the first service is AKMA service, and the first parameter includes the RID of UE; by executing the main authentication process for UE (see FIG3), AUSF generates A-KID based on the new first parameter (ie, RID), and AAnF stores the A-KID generated based on the new first parameter and K AKMK . 1007. The UE sends an application session establishment request message to the AF supporting the first service. Exemplarily, when the first service is an AKMA service, the UE sends an application session establishment request message to the AF supporting the first service. When the first service is other services, the UE may execute processes related to other services. Correspondingly, the AF supporting the first service receives an application session establishment request message from the UE. The application session establishment request message includes an AKMA key identifier A-KID generated based on the new first parameter. In a possible implementation, the AF supporting the first service responds to the application session establishment request message and performs the operation performed by the AF in FIG. 4(a) or FIG. 4(b) after receiving the application session establishment request message. The AF can obtain the AF's key K through the A-KID generated based on the new RID and its own identification information. AF and K AF The end time of . 1008. In response to the UE's AKMA service, the UE generates an AKMA key and an A-KID corresponding to the AKMA key, and generates a key K for the AF according to the AKMA key and the AF's identifier.AF . Step 1007 and step 1008 are optional. Subsequently, when the UE communicates with the AF, it can be based on K AF The key used for communication between the two parties is derived, such as the session key, to encrypt and protect the communication information. In an embodiment of the present application, after updating the first parameter, the UE supporting the AKMA service generates a first message and sends the first message to the AMF to trigger a process for authenticating the UE, and then performs related operations based on the new first parameter through the process for authenticating the UE, thereby avoiding or reducing the situation in which errors occur when the UE executes the first service due to updating the first parameter. FIG11 is a flow chart of another communication method provided in an embodiment of the present application. The method flow in FIG11 is a possible implementation of the method described in FIG9 . As shown in FIG11 , the method includes: 1101. A UE supporting a first service sends a first registration request message to an AMF. The first registration request message carries the UE's SUCI or 5G globally unique temporary identifier (5G-GUTI). The first registration request message is used to request registration with the network. 1102. AMF triggers the main authentication process in response to the first registration request message. The main authentication process may refer to the main authentication process in FIG. 3 , and may refer to the existing protocol 3GPP TS 33.501. 1103. Execute the main authentication result confirmation process. Exemplarily, an authentication result can be obtained based on the above-mentioned primary authentication of the UE supporting the first service, and then the AUSF and UDM perform the primary authentication result confirmation process. 1104. Execute the NAS SMC process, wherein the NAS SMC message sent by the AMF to the UE carries a key identifier, and the UE stores the key identifier. SMC is the abbreviation of security mode command (SMC). In a possible implementation, the value of the key identifier may not be 7, for example, it may be 1. The key identifier is associated with a key. 1105. Execute the remaining registration process. In the remaining registration process, the process of AMF registering with UDM may be executed. The purpose of this process is to register the AMF that is serving the UE with UDM. After receiving the AMF registration information, UDM will store AMF related information, such as AMF ID. It should be noted that the UE can register with different AMFs, such as AMF1 and AMF2, through 3GPP access technology and non-3GPP access technology, that is, AMF1 and AMF2 can provide services for the same UE. Multiple AMF related information can be stored in UDM, such as AMF1 ID and AMF2 ID. Exemplarily, the AMF sends a registration response message to the UE to indicate that the UE has successfully registered, and the UE can then request to establish a session to access various services on the data network. 1106. AMF sends a second message to the UE. The second message includes indication information for instructing the UE to perform a re-registration procedure and a new first parameter of the UE. 1107. The UE updates the old first parameter to the new first parameter based on the second message. In a possible implementation, the second message further includes integrity check information; when determining the new first parameter based on the integrity check information When the integrity check of the number is successful, the UE updates the old first parameter to the new first parameter. 1108. The UE determines that it supports the first service. The order of step 1108 and step 1107 is not limited. 1109. When the UE supports the first service and the UE updates the old first parameter to the new first parameter, in response to the indication information of the re-registration process, the UE generates a second registration request message. The second registration request message includes authentication indication information for instructing the AMF to trigger a process for authenticating the UE and the key identifier. 1110. The UE sends a second registration request message to the AMF. Correspondingly, the AMF receives a second registration request message from the UE. 1111. AMF determines the key corresponding to the key identifier, and uses the key to perform at least one of decoding and integrity protection verification on the second registration request message. The second registration request message may be an example of the above-mentioned first message. 1112. In response to the authentication indication information in the second registration request message, the AMF triggers a process for authenticating the UE. In the embodiment of the present application, after updating the first parameter, the UE supporting the first service sends a second registration request message to the AMF to trigger the process of authenticating the UE, and then generates information that enables the UE to successfully use the first service based on the new first parameter through the process of authenticating the UE. In addition, the second registration request message carries a key identifier, which can provide security protection for the second registration request message. FIG12 is a flow chart of another communication method provided by an embodiment of the present application. The method flow in FIG12 is an example of the method described in FIG9. The inventive idea of the method flow shown in FIG12 is: after the UE supporting the AKMA service determines that the UE parameters updated by the UPU process include the RID, it initiates a registration request message to the AMF, and the registration request message carries the indication information for instructing the AMF to authenticate the UE, so that the A-KID generated by the RID updated in the UPU process is stored in the AAnF. As shown in FIG12, the method includes: 1201. The UE supporting AKMA service executes the main authentication process with the AUSF. It is uniformly explained here that the UE in this article refers to a UE supporting a first service, and the first service includes an AKMA service. 1202. AUSF generates K AKMA -1 and A-KID-1. Step 1202 may refer to step 303 in FIG. 3. A possible way for AUSF to generate A-KID-1 is as follows: Generate A-TID; After generating A-TID, A-KID-1 may be constructed according to RID-1, A-TID and home network identifier. RID-1 refers to the RID of the UE, that is, the RID of the UE before executing step 1205 (that is, the old RID). 1203. AUSF sends an AKMA anchor key registration request (Naanf_AKMA_AnchorKey_Register Request) message to AAnF. The AKMA point key registration request message contains SUPI, A-KID-1 and K AKMA -1. The AAnF is an AAnF selected by the AUSF from one or more AAnFs corresponding to RID-1 in A-KID-1. AKMA -1 is associated (or corresponds to). Through A-KID-1, the K corresponding to A-KID-1 can be found in AAnF. AKMA In other words, A-KID-1 is used to find the K corresponding to A-KID-1 in AAnF. AKMA For example, AF can use A-KID-1 to find the K corresponding to A-KID-1 in AAnF. AKMA . 1204. AAnF sends an AKMA anchor key registration response (Naanf_AKMA_AnchorKey_RegisterResponse) message to AUSF. It should be noted that step 1201 to step 1204 belong to the AKMA process, see FIG. 3 . 1205. UDM updates UE parameters through the UPU process, where the UPU data includes the RID of the UE. Step 1205 may include steps 601 to 606 in FIG. 6 , or may include steps 601 to 609 . 1206. After updating the RID, the UE sends a registration request message to the AMF. The registration request message includes authentication indication information for instructing the AMF to trigger the process of authenticating the UE. In other words, the authentication indication information is used to instruct the AMF to trigger the main authentication process for the UE. The authentication indication information can be a key identifier. For example, the key identifier is set to a preset value. The preset value can be 111, or other values. After receiving the registration request message, the AMF determines to authenticate the UE based on the key identifier. The authentication indication information can also be a newly defined bit. For example, setting the bit to 0 indicates that the main authentication is not required, and setting the bit to 1 indicates that the main authentication is required. The registration request message is an example of the first message in Figure 9. In one possible implementation, before initiating a registration request message to the AMF, the UE performs the following operations: receiving a second message from the AMF (for example, a DL NAS transmission message in the UPU process, see Figure 6), wherein the second message includes a new RID, i.e., RID-2; the UE updates the old RID to the new RID; the UE determines that it supports the AKMA service; the above-mentioned initiation of a registration request message to the AMF includes: in response to the UE supporting the AKMA service and the UE updating the old RID to the above-mentioned new RID, the UE generates a registration request message carrying the above-mentioned authentication indication information. In one possible implementation, before initiating a registration request message to the AMF, the UE performs the following operations: receiving a second message from the AMF (for example, a DL NAS transmission message in the UPU process, see Figure 6), wherein the second message includes a new RID, i.e., RID-2, and indication information for instructing the above-mentioned UE to perform a re-registration process; the above-mentioned initiation of a registration request message to the AMF includes: when the above-mentioned UE supports the above-mentioned AKMA and the above-mentioned UE updates the above-mentioned old RID to the above-mentioned new RID, in response to the indication information of the above-mentioned re-registration process, the above-mentioned UE generates a registration request message including the above-mentioned authentication indication information. In one possible implementation, the second message also includes information for integrity verification; when it is determined based on the integrity verification information that the integrity verification of the new RID is successful, the UE updates the old first parameter to the new first parameter. The AMF sends the second message to the UE in response to the message from the UDM including the indication information, the verification information and the new parameters of the UE. Exemplarily, when the UDM determines that the RID of the UE supporting the AKMA service needs to be updated, the UDM sends a message to the AMF including the indication information, the verification information and the new parameters of the UE. 1207. AMF triggers the main authentication process based on the authentication indication information included in the registration request message. 1208. AUSF sends an authentication vector acquisition request (Nudm_UEAuthentication_GetRequest) message to UDM. 1209. UDM sends an authentication vector acquisition response (Nudm_UEAuthentication_GetResponse) message to AUSF. 1210. AUSF generates K AKMA -1 and A-KID-2. In a possible implementation, if the authentication vector acquisition response message includes AKMA indication information, the AUSF stores K according to the AKMA indication information. AUSF , and after the main certification process is successfully completed, according to K AUSF Generate K AKMA -1 and A-KID-2. AUSF according to K AUSF An example of generating A-TID-2 is as follows: AUSF uses K AUSF A-TID-2 is generated using the key K and the following parameters 1 to 5 as input to the key derivation function: Parameter 1: FC = 0x81; that is, parameter 1 is 0x81; Parameter 2: P0 = "A-TID"; that is, parameter 2 is the string "A-TID"; Parameter 3: L0 = length of "A-TID"; (e.g., 0x00 0x05) Parameter 4: P1 = SUPI; Parameter 5: L1 = length of SUPI. Among them, after AUSF generates A-TID, it can construct A-KID-2 based on RID-2, A-TID and the home network identifier. 1211. AUSF sends an AKMA anchor key registration request (Naanf_AKMA_AnchorKey_Register Request) message to AAnF. The AKMA point key registration request message contains SUPI, A-KID-2 and K AKMA The AAnF is an AAnF selected by the AUSF from one or more AAnFs corresponding to RID-2 in A-KID-2. 1212. AAnF sends an AKMA anchor key registration response (Naanf_AKMA_AnchorKey_RegisterResponse) message to AUSF. AAnF can convert A-KID-2 and K AKMA Through A-KID-2, you can find the K corresponding to this A-KID in AAnF. AKMA In other words, A-KID-2 is used to find the K corresponding to A-KID-2 in AAnF. AKMA For example, AF can use A-KID-2 to find the K corresponding to A-KID-2 in AAnF. AKMA . 1213. Before using the AKMA service, the UE generates K AKMA -1 and uses the updated RID (ie, RID-2) to generate A-KID-2. For example, before the UE sends an Application Session Establishment Request message to the AF, it generates K AKMA -1 and uses the updated RID (i.e., RID-2) to generate A-KID-2. AKMA -1 is UE according to K AUSF Generated, K AUSF The same value is used at the UE and AUSF. The UE generates K AKMA -1 method and AUSF generate K AKMA -1, refer to the above step 303. The possible ways for UE to generate A-KID-2 are as follows: Generate A-TID; After generating A-TID, A-KID-2 can be constructed according to RID-2, A-TID and home network identifier. 1214. When the UE initiates communication with the AF, the UE sends an Application Session Establishment Request message to the AF. The application session establishment request includes A-KID-2. 1215. AF sends an AKMA application key acquisition request (Naanf_AKMA_ApplicationKey_GetRequest) message to AAnF. The trigger condition for the AF to execute step 1215 may be receiving an application session establishment request message. The AKMA application key acquisition request message includes A-KID-2 and AF_ID. A-KID-2 comes from the application session establishment request in step 1214 above, and AF_ID is the identification information of the AF. 1216, AAnF generates K AF . AAnF generates K AF An example is as follows: AAnF obtains the corresponding K from the local according to A-KID AMKA , using K AKMA as key K and parameters 1 to 3 as key derivation The input of the function generates K AF : Parameter 1: FC = 0x82; Parameter 2: P0 = AF_ID; Parameter 3: L0 = length of AF_ID. That is, parameter 3 is the length of AF_ID. AF_ID = FQDN of AF || security protocol identifier of the interface between UE and AF. "||" is a connector. FQDN is the abbreviation of fully qualified domain name. 1217. AAnF sends an AKMA application key acquisition response (Naanf_AKMA_ApplicationKey_GetResponse) message to AF. The AKMA application key acquisition response message contains K AF and K AF The end time of . 1218. AF sends an application session establishment response to the UE. If AF receives K from AAnF AF and K AF If the AF receives a response indicating a failure or error from the AAnF, the application session establishment response indicates that the application session establishment failed. The application session establishment response may include a failure reason value, which may be K AF Failed to obtain. 1219. UE generates K AF . UE generates K AFThe method and AAnF generate K AF The method is the same as that of UE, so the K generated by UE is AF K generated by AAnF AF The same. This step 1219 can be performed at any time after step 1205. The UE can pre-configure the AF_ID, or the AF sends the AF_ID to the UE, that is, informs the UE of its identification information. The UE can also obtain the AF_ID of the AF in other ways, which are not limited here. In an embodiment of the present application, after updating the RID, the UE initiates a registration request message to the AMF, which can instruct the AMF to trigger the process of authenticating the UE, so that the A-KID-2 generated by the RID updated in the UPU process is stored in the AAnF, so that the AAnF can find the corresponding AKMA security context after the UE initiates the AKMA service, and then successfully use the AKMA service. Figure 13 is a flow chart of another communication method provided by an embodiment of the present application. Figure 9 describes a scheme in which the UE decides whether to trigger a process for authenticating the UE. Figure 13 describes three schemes. The first scheme is that the UDM decides whether to instruct the UE to trigger the main authentication process, the second scheme is that the UDM decides whether to instruct the above-mentioned UE to perform a re-registration process, and the third scheme is that the UDM decides whether to instruct the UE to trigger the main authentication process and whether to instruct the above-mentioned UE to perform a re-registration process. The method flow of Figure 13 and the method flow in Figure 10 can both avoid or reduce errors that occur when the UE executes the first service. As shown in Figure 13, the method includes: 1301. When the UDM determines that a first parameter of a UE supporting a first service needs to be updated, the UDM generates a third message. The third message includes at least one of the first indication information for instructing the UE to trigger the main authentication process and the second indication information for instructing the UE to perform a re-registration process, as well as a new first parameter of the UE. The first parameter is associated with the first service. In a possible implementation, the third message is a message for updating the parameters of the UE (including the first parameter). Exemplarily, the first service is an AKMA service, and the first parameter includes the RID of the UE. In a possible implementation, the first indication information and the second indication information are two independent indication information. In a possible implementation, the first indication information and the second indication information are one indication information. That is, the first indication information (or the second indication information) can be used to instruct the UE to trigger the main authentication process, and can also be used to instruct the UE to perform a re-registration process, that is, to instruct the UE to initiate a re-registration process. Exemplarily, the above-mentioned third message includes first indication information, which includes two bits. When the two bits are 10, the first indication information is used to instruct the UE to perform a re-registration process, and at the same time instruct the UE to trigger the main authentication process, that is, to force the UE to trigger the main authentication process; when the two bits are 00, the first indication information is used to instruct the UE not to perform a re-registration process, and at the same time instruct the UE not to trigger the main authentication process; when the two bits are 01, the first indication information is used to instruct the UE to perform a re-registration process, and at the same time instruct the UE not to force the main authentication process to trigger the main authentication process; when the two bits are 11, they are temporarily set to invalid values waiting for subsequent definition. In one possible implementation, before generating the third message, the UDM performs the following operations: determining a message that the first parameter of the UE needs to be updated; the UDM determines that the UE supports the first service. There are multiple ways for the UDM to determine whether the UE supports the first service. In one possible implementation, the UDM may determine whether the UE supports the first service based on the UE's contract data. For example, when the UE's contract data records that the UE supports the first service, or the contract data of the first service corresponding to the UE indicates that the UE supports the first service, the UDM determines that the UE supports the first service. Generating the third message may include: in response to the UE supporting the first service and the UDM determining that the first parameter of the UE needs to be updated, the UDM generates the third message carrying at least one of the first indication information and the second indication information. An example of the UDM determining that the first parameter of the UE needs to be updated is: the UDM decides to execute the UE parameter update UPU process for updating the first parameter of the UE. 1302. UDM sends a third message to AMF. Optionally, the third message may further include integrity check information, and the integrity check information is used to check the integrity of the new first parameter. Exemplarily, the third message is an SDM notification message, referring to the message sent in step 604 in FIG. 6 , the third message includes UPU data (including the new first parameter), a UPU message header, a UPU counter, and a UPU-MAC-I AUSF The UPU message header includes the above The second indication information and at least one of the first indication information. 1303. In response to the third message, the AMF sends a fourth message to the UE. The fourth message includes at least one of the first indication information for instructing the UE to trigger the primary authentication process and the second indication information for instructing the UE to perform a re-registration process, and the new first parameter of the UE. Exemplarily, the fourth message is a DL NAS transmission message. 1304. When the third message includes first indication information for instructing the UE to trigger the main authentication process, in response to the first indication information, the UE sends a first message to the AMF. The above-mentioned first message includes authentication indication information used to instruct the AMF to trigger a process for authenticating the UE. Step 1304 may be replaced by: when the third message includes the first indication information and the second indication information, in response to the first indication information and the second indication information, the UE sends a first message to the AMF, where the first message is a registration request message including the authentication indication information. The first message is used to request that the UE be registered with the network. Step 1304 may be replaced by: when the third message includes the second indication information but does not include the first indication information, in the case where the UE supports the first service and the UE updates the old first parameter to the new first parameter, in response to the indication information of the re-registration process, the UE generates the first message including the authentication indication information, and the first message is a registration request message. In a possible implementation, after receiving the fourth message, the UE updates the old first parameter to the new first parameter; in the case where the UE supports the first service, in response to the indication information of the re-registration process, the UE generates the first message including the authentication indication information, and the first message is a registration request message. The UE may determine that it supports the first service before receiving the fourth message; or it may determine that it supports the first service after receiving the fourth message. In a possible implementation, the fourth message also includes integrity check information; the UE updating the old first parameter to the new first parameter includes: in the case where the integrity check of the new first parameter is determined to be successful based on the integrity check information, the UE updates the old first parameter to the new first parameter. 1305. In response to the authentication indication information in the first message, the AMF triggers the process of authenticating the UE. The process of AMF triggering authentication of UE may be triggering the main authentication process shown in Figure 3. After AMF triggers the process of authenticating UE, the process shown in Figure 3 may be executed, which will not be repeated here. In the embodiment of the present application, when the UDM determines that the first parameter of the UE supporting the first service needs to be updated, the UDM generates a third message and sends the third message to the AMF to instruct the UE to trigger the main authentication process, and then performs related operations based on the new first parameter through the process of authenticating the UE, which can avoid or reduce the situation where an error occurs when the UE executes the first service due to updating the first parameter. For example, the first service is an AKMA service, and the first parameter is an RID. By triggering the process of authenticating the UE, the A-KID generated based on the new RID can be stored in the AAnF, so that the AAnF can find the corresponding AKMA security context after the UE initiates the AKMA service, and then successfully use the AKMA service. FIG14 is a flow chart of another communication method provided by an embodiment of the present application. The method flow in FIG14 is a possible implementation of the method described in FIG13. The inventive idea of the method flow shown in FIG14 is: when it is determined that the RID of the UE supporting the AKMA service needs to be updated, the message sent by the UDM in the UPU process instructs the UE to perform the primary authentication so that the A-KID generated by the RID updated in the UPU process is stored in the AAnF. As shown in FIG14, the method includes: 1401. UE and AUSF execute the main authentication process. 1402. AUSF generates K AKMA -1 and A-KID-1. 1403. AUSF sends an AKMA anchor key registration request (Naanf_AKMA_AnchorKey_Register Request) message to AAnF. 1404. AAnF sends an AKMA anchor key registration response (Naanf_AKMA_AnchorKey_RegisterResponse) message to AUSF. Steps 1401 to 1404 may refer to steps 1201 to 1204 and will not be described in detail here. 1405. UDM updates UE parameters through the UPU process, wherein, when UDM determines that the RID of the UE supporting the AKMA service needs to be updated, it sends a third message to the AMF, and the third message includes at least one of the first indication information for instructing the UE to trigger the main authentication process and the second indication information for instructing the UE to perform a re-registration process, as well as the new RID of the UE. Exemplarily, the third message is an SDM notification message. Referring to the message sent in step 604 in FIG. 6 , the third message includes UPU data (including the first parameter), a UPU message header, a UPU counter, and a UPU-MAC-I. AUSF , the UPU message header includes at least one of the above-mentioned second indication information and the above-mentioned first indication information. Step 1405 may include steps 601 to 609 in FIG. 6 , wherein the SDM notification message includes a UPU message header, the format of which is shown in FIG. 7 , and REG is used to instruct the UE to trigger the re-registration process. In one possible implementation, REG is used to indicate whether the UE needs to initiate a registration request for re-authentication. For example, REG includes a 2-bit value, 00 represents that the UE does not need to initiate a registration process, 01 represents that the UE needs to initiate a registration process, but does not force the master authentication, 10 represents that the UE needs to initiate a registration process and force the master authentication at the same time, and 14 is temporarily set to invalid The value is to be defined later. In one possible implementation, a new IE (which can be included in the UPU message header in the SDM notification message) is defined to indicate whether the main authentication process needs to be triggered. For example, a new AUTHIE (occupying one or more bits) is added. When the value of the IE is set to 1, it indicates that the main authentication process needs to be triggered. When the value of the IE is set to 0, it indicates that the main authentication process does not need to be triggered. In one possible implementation, when the UE supports AKMA service and the UPU process is to update the RID, the message sent by the UDM in the UPU process carries the above-mentioned first indication information. For example, the first indication information is a newly added AUTHIE. When the UE supports AKMA service and the UDM wants to update the RID, the UDM sets the value of AUTHIE (corresponding to the first indication information) in the message sent in the UPU process to 1, indicating that the UE needs to trigger the main authentication process. The UDM can determine whether the UE supports the AKMA service before executing the UPU process; it can also determine whether the UE supports the AKMA service after deciding to execute the UPU process. Exemplarily, after deciding to execute the UPU process, the UDM determines whether the UE's RID needs to be updated, that is, whether the UPU data sent by the UDM includes the RID; if so, and the UE supports the AKMA service, the UDM sets the value of AUTHIE in the message sent in the UPU process to a valid value. Exemplarily, after deciding to execute the UPU process, UDM determines whether it is necessary to update the UE's RID, that is, whether the UPU data sent by UDM includes the RID, and whether the UE supports the AKMA service; if it is necessary to update the UE's RID and the UE supports the AKMA service, UDM sets the AUTHIE in the message sent in the UPU process to a valid value. In one possible implementation, when the UE supports the AKMA service and the UPU process is for updating the RID, the UDM sets the value of REG in the UPU message header in the message sent in the UPU process to a valid value to indicate that the UE needs to trigger the re-registration process. The UDM can determine whether the UE supports the AKMA service based on the UE's contract information before executing the UPU process; or it can determine whether the UE supports the AKMA service based on the UE's contract information after deciding to execute the UPU process. Exemplarily, after deciding to execute the UPU process, the UDM determines whether the UPU process is triggered to update the UE's RID, that is, determines whether the UPU data sent by the UDM includes the RID; if so, and the UE supports the AKMA service, the UDM sets the value of REG in the UPU message header in the message sent in the UPU process to a valid value. Exemplarily, after deciding to execute the UPU process, UDM determines whether the UPU process is triggered to update the UE's RID, that is, determines whether the UPU data sent by UDM includes RID, and determines whether the UE supports AKMA service; if the UE's RID needs to be updated and the UE supports AKMA service, UDM sets the value of REG in the UPU message header in the message sent in the UPU process to a valid value. UDM decides to execute the UPU process, which can be understood as UDM being triggered to update the UPU process for pre-configured data by the network administrator or under specific conditions. After deciding to execute the UPU process, UDM determines whether the UPU process is triggered to update the UE's RID, which can be further understood as UDM needs to determine whether the UPU process is triggered to update the UE's RID before starting to execute the UPU process. 1406. In response to the first indication information in the DL NAS transmission message, the UE sends a registration request message to the AMF. The DL NAS transmission message may be a message sent by the AMF to the UE after the AMF receives the above-mentioned third message. The DL NAS transmission message may include at least one of the first indication information for instructing the UE to trigger the main authentication process and the second indication information for instructing the UE to perform the re-registration process, as well as the new RID of the UE. The registration request message contains authentication indication information, and the authentication indication information is used to indicate that the AMF needs to authenticate the UE. The authentication indication information may be a key identifier. For example, the key identifier is set to a preset value. The preset value may be 141, or other values. After receiving the registration request message, the AMF determines to authenticate the UE based on the key identifier. The authentication indication information may also be a newly defined bit. For example, setting the value of the bit to 0 indicates that the main authentication is not required, and setting the value of the bit to 1 indicates that the main authentication is required. Step 1406 may be replaced by: when the DL NAS transmission message includes the second indication information but does not include the first indication information, in the case where the UE supports the first service and the UE updates the old first parameter to the new first parameter, in response to the indication information of the re-registration process (i.e., the second indication information), the UE generates a registration request message including the authentication indication information. In a possible implementation, after receiving the DL NAS transmission message, the UE updates the old first parameter to the new first parameter; in the case where the UE supports the first service, in response to the indication information of the re-registration process, the UE generates the first message including the authentication indication information, and the first message is a registration request message. The UE may determine that it supports the first service before receiving the DL NAS transmission message; or it may determine that it supports the first service after receiving the DL NAS transmission message. In a possible implementation, the DL NAS transmission message also includes verification information; the UE updating the old first parameter to the new first parameter includes: in the case where it is determined based on the verification information that the DL NAS transmission message passes the integrity verification, the UE updates the old first parameter to the new first parameter. 1407. AMF triggers the main authentication process based on the authentication indication information included in the registration request message. 1408. AUSF sends an authentication vector acquisition request (Nudm_UEAuthentication_GetRequest) message to UDM. 1409. UDM sends an authentication vector acquisition response (Nudm_UEAuthentication_GetResponse) message to AUSF. 1410, AUSF generates K AKMA and A-KID-2. 1411. AUSF sends AKMA anchor key registration request to AAnF (Naanf_AKMA_AnchorKey_Register Request) information. 1412. AAnF sends an AKMA anchor key registration response (Naanf_AKMA_AnchorKey_RegisterResponse) message to AUSF. 1413. Before using the AKMA service, the UE generates K AKMA -1 and use the updated RID (ie RID-2) to generate K AKMA -1. 1414. When the UE initiates communication with the AF, the UE sends an Application Session Establishment Request message to the AF. The application session establishment request includes A-KID-2. 1415. AF sends an AKMA application key acquisition request (Naanf_AKMA_ApplicationKey_GetRequest) message to AAnF. 1416, AAnF generates K AF . 1417. AAnF sends an AKMA application key acquisition response (Naanf_AKMA_ApplicationKey_GetResponse) message to AF. 1418. AF sends an application session establishment response to the UE. 1419. UE generates K AF . Steps 1407 to 1419 may refer to steps 1207 to 1219 in FIG. 12 , and will not be described in detail here. In an embodiment of the present application, in response to the first indication information in the DL NAS transmission message, the UE initiates a registration request message to the AMF. Initiating a registration request message to the AMF can instruct the AMF to trigger the main authentication process so that the A-KID-2 generated by the RID updated in the UPU process is stored in the AAnF, so that the AAnF can find the corresponding AKMA security context after the UE initiates the AKMA service, and then successfully use the AKMA service. FIG. 15 is a flow chart of another communication method provided by an embodiment of the present application. FIG. 9 describes a scheme in which the UE decides whether to trigger a process for authenticating the UE. The scheme described in FIG. 15 is that after the UDM sends a third message for updating the first parameter of the UE supporting the first service, the AMF is requested to trigger the main authentication process of the UE. The method flow of FIG. 15 and the method flow of FIG. 9 can both avoid or reduce errors when the UE executes the first service. As shown in FIG. 15, the method includes: 1501. After sending a third message for updating a first parameter of a UE supporting a first service, the UDM generates a fifth message. The fifth message is used to request AMF to trigger the main authentication process of the UE. The first parameter is associated with the first service. In a possible implementation, before generating the fifth message, the UDM performs the following operations: the UDM sends the third message for updating the first parameter of the UE to the AMF; the UDM determines that the UE supports the first service. Generating the fifth message may include: in response to the UE supporting the first service and the UDM determining that the third message for updating the first parameter of the UE has been sent, the UDM generates the fifth message. 1502. UDM sends the fifth message to AMF. Correspondingly, AMF receives the fifth message from UDM. 1503. In response to the fifth message, the AMF determines whether to trigger the main authentication process for the UE. In one possible implementation, the AMF decides whether to trigger the primary authentication based on its local authentication policy and UE status. For example, if the UE is handing over, or if the UE is already in primary authentication before receiving the authentication notification message from the UDM, the primary authentication does not have to be triggered. 1504. AMF triggers the main authentication process for the UE. In the embodiment of the present application, when the UDM needs to update the first parameter of the UE supporting the first service, it sends a fifth message to the AMF, and can request the AMF to trigger the main authentication process, and then perform related operations based on the new first parameter through the process of authenticating the UE, which can avoid or reduce the situation where an error occurs when the UE executes the first service due to the update of the first parameter. For example, the first service is an AKMA service, and the first parameter is an RID. By triggering the process of authenticating the UE, the A-KID generated based on the new RID can be stored in the AAnF, so that the AAnF can find the corresponding AKMA security context after the UE initiates the AKMA service, and then successfully use the AKMA service. FIG16 is a flow chart of another communication method provided in an embodiment of the present application. The method flow in FIG16 is a possible implementation of the method described in FIG15. As shown in FIG16, the method includes: 1601. When the UDM determines that the first parameter of the UE needs to be updated, the UDM generates a third message. The third message includes UE update data, response indication information for indicating that the UE responds to the UDM request, and integrity check information for verifying the integrity of the UE update data. The UE update data includes the new first parameter of the UE. It is uniformly explained here that the content and / or function of the same message in different embodiments may be different. In a possible implementation, when the UDM determines that a first parameter of the UE supporting the first service needs to be updated, the UDM generates a third message. 1602. UDM sends a third message to AMF. Correspondingly, AMF receives the third message from UDM. 1603. In response to the third message, the AMF sends a fourth message to the UE. Correspondingly, the UE receives a fourth message from the AMF. The fourth message includes the above-mentioned UE update data, response indication information for indicating that the UE responds to the request of the UDM, and integrity check information for verifying the integrity of the above-mentioned new first parameter. 1604. When it is determined based on the integrity check information that the integrity check of the new first parameter is successful, the UE updates the old first parameter to the new first parameter. 1605. In response to the response indication information used to instruct the UE to respond to the UDM request, the UE sends a seventh message to the AMF. Correspondingly, the AMF receives a seventh message from the UE. The seventh message includes the second integrity check information, for example, the second integrity check information is UPU-MAC-I UE . 1606. In response to the seventh message, the AMF sends a sixth message to the UDM. The sixth message includes the second integrity check information. 1607. UDM determines that the UE supports the first service. Step 1607 may be performed at any time before step 1608. In one possible implementation, the UDM may determine whether the UE supports the first service based on the subscription data of the UE. For example, when the subscription data of the UE records that the UE supports the first service, or the subscription data of the first service corresponding to the UE indicates that the UE supports the first service, the UDM determines that the UE supports the first service. 1608. When it is determined based on the verification information in the sixth message that the UE correctly receives the UE update data, in response to the UE supporting the first service and the UDM determining that the third message for updating the first parameter of the UE has been sent, the UDM generates a fifth message. 1609. UDM sends the fifth message to AMF. Correspondingly, the AMF receives a fifth message from the UDM. The fifth message is used to request the AMF to trigger the main authentication process of the UE, and the first parameter is associated with the first service. 1610. In response to the fifth message, the AMF determines whether to trigger the main authentication process for the UE. 1611. AMF triggers the main authentication process for the UE. In the embodiment of the present application, after sending the third message for updating the first parameter of the UE supporting the first service, the UDM sends the fifth message to the AMF, which can request the AMF to trigger the main authentication process, and then perform related operations based on the new first parameter through the process of authenticating the UE, which can avoid or reduce the situation where an error occurs when the UE executes the first service due to the update of the first parameter. For example, the first service is an AKMA service, and the first parameter is an RID. By triggering the process of authenticating the UE, the A-KID generated based on the new RID can be stored in the AAnF, so that the AAnF can find the corresponding AKMA security context after the UE initiates the AKMA service, and then successfully use the AKMA service. FIG17 is a flow chart of a communication method provided by an embodiment of the present application. The inventive idea of the method flow shown in FIG17 is: after the UDM sends a message for updating the RID of the UE supporting the AKMA service in the UPU process (see FIG6 ), the main authentication process is triggered so that the A-KID generated by using the RID updated in the UPU process is stored in the AAnF. As shown in FIG17 , the method includes: 1701. UE and AUSF execute the main authentication process. 1702. AUSF generates K AKMA -1 and A-KID-1. 1703. AUSF sends an AKMA anchor key registration request (Naanf_AKMA_AnchorKey_Register Request) message to AAnF. 1704. AAnF sends an AKMA anchor key registration response (Naanf_AKMA_AnchorKey_RegisterResponse) message to AUSF. Steps 1701 to 1704 may refer to steps 1201 to 1204 in FIG. 12 . 1705. UDM updates UE parameters through the UPU process, wherein UDM sends a message for updating the RID of the UE supporting the AKMA service to the UE through the AMF. In one possible implementation, UDM decides to perform UE parameter update through the control plane, that is, decides to perform the UPU process; determines whether the UE supports the AKMA service and whether the UPU process updates the RID of the UE; if the UE supports the AKMA service and the UPU process updates the RID of the UE, UDM sets the ACK in the UPU message header of the message sent by it in the UPU process to 1. The messages sent by UDM in the UPU process include UPU protection (Nausf_UPUProtectio) messages and SDM notification (Nudm_SDM_Notification) messages. A trigger condition for UDM to set the ACK in the UPU message header of the message sent by it in the UPU process to 1 is: the UE supports the AKMA service and the UPU process updates the RID of the UE. In one possible implementation, after UDM decides to perform the UPU process, when the UPU process updates the RID of the UE, UDM determines that the UE supports the AKMA service, and UDM sets the ACK in the UPU message header of the message sent by it in the UPU process to 1. In a possible implementation, after the UDM decides to execute the UPU process, if the UE supports the AKMA service, when it is determined that the UPU process is to update the UE's RID, the UDM sets the ACK in the UPU message header of the message sent in the UPU process to 1. An example of step 1705 is as follows: UDM decides to perform UE parameter update through the control plane; UDM determines whether the UE supports AKMA service and whether the UPU process updates the RID of the UE; if the UE supports AKMA service and the UPU process updates the RID of the UE, UDM sends a UPU protection message to AUSF, and the UPU protection message includes SUPI, UPU data (including RID), and ACK indication. The value of the ACK indication is 1, indicating that UDM needs the expected UPU-XMAC-I UE AUSF sends a UPU protection response message to UDM, which contains a UPU counter and UPU-MAC-I AUSF ; UDM sends an SDM notification message to AMF. The SDM notification message includes UPU data, UPU counter, and UPU-MAC-I AUSF , the value of ACK in the UPU message header information in the SDM notification message is 1; the subsequent steps are steps 605 to 609 in Figure 6. 1706. After sending a message for updating the RID of the UE supporting the AKMA service, it is decided to trigger the main authentication process. Step 1706 may be replaced by: when the feedback information received from the UE passes the verification, the UDM decides to trigger the main authentication process. The feedback information received from the UE by the UDM may be UPU-MAC-I UE , the feedback information of the UE received by the UDM can be verified as follows: UPU-MAC-I received by the UDM UE UPU-XMAC-I and storage UE Consistent. One condition for UDM to decide to trigger the main authentication process may be that the UE supports the first service and the UPU process executed by UDM updates the RID of the UE. In one possible implementation, UDM decides to trigger the main authentication process when the UE supports the first service and the UPU process (i.e., the UPU process in step 1705) updates the RID of the UE. Exemplarily, UDM executes the UPU process, i.e., the above step 1705; when the feedback information of the UE received by UDM in the UPU process passes the verification, it determines whether the UE supports the AKMA service and whether the UPU process updates the RID of the UE; when the UE supports the AKMA service and the UPU process updates the RID of the UE, UDM decides to trigger the main authentication process. Exemplarily, UDM determines whether the UE supports the AKMA service; UDM executes the UPU process, i.e., the above step 1705; when the feedback information of the UE received by UDM in the UPU process passes the verification and the UE supports the AKMA service, it determines whether the UPU process updates the RID of the UE; when the UPU process updates the RID of the UE, UDM decides to trigger the main authentication process. 1707. UDM sends an authentication notification message to AMF. The authentication notification message contains the UE's SUPI. The AMF is the AMF determined by the UDM as the service provider for the UE. 1708. AMF decides whether to trigger the main authentication based on its local authentication policy and UE status. For example, if the UE is handing over, or if the UE is already in primary authentication before receiving the authentication notification message from the UDM, the primary authentication does not have to be triggered. 1709. AMF sends an authentication response message to UDM. If the AMF decides to trigger the primary authentication, the Authentication Response message is used to indicate that the AMF decides to trigger the primary authentication. If the AMF decides not to trigger the primary authentication, the Authentication Response message is used to indicate that the AMF decides not to trigger the primary authentication. 1710. AMF triggers the main authentication process. 1711. AUSF sends an authentication vector acquisition request (Nudm_UEAuthentication_GetRequest) message to UDM. The authentication vector acquisition request message includes a SUPI or a subscription concealed identifier (SUCI). 1712. UDM sends an authentication vector acquisition response (Nudm_UEAuthentication_GetResponse) message to AUSF. 1713. AUSF generates K AKMA -1 and A-KID-2. 1714. AUSF sends an AKMA anchor key registration request (Naanf_AKMA_AnchorKey_Register Request) message to AAnF. 1715. AAnF sends an AKMA anchor key registration response (Naanf_AKMA_AnchorKey_RegisterResponse) message to AUSF. 1716. Before using the AKMA service, the UE generates K AKMA -1 and uses the updated RID (ie, RID-2) to generate A-KID-2. 1717. When the UE initiates communication with the AF, the UE sends an Application Session Establishment Request message to the AF. The application session establishment request includes A-KID-2. 1718. AF sends an AKMA application key acquisition request (Naanf_AKMA_ApplicationKey_GetRequest) message to AAnF. 1719, AAnF generates K AF . 1720. AAnF sends an AKMA application key acquisition response (Naanf_AKMA_ApplicationKey_GetResponse) message to AF. The AKMA application key acquisition response message contains K AF and K AF The end time of . 1721. AF sends an application session establishment response to the UE. 1722. UE generates K AF . Steps 1711 to 1722 may refer to steps 1208 to 1219 in FIG. 12 , which will not be described in detail here. In the embodiment of the present application, the UDM sends a RID for updating the UE supporting the AKMA service in the UPU process (see FIG. 6 ). After the message, the main authentication process is triggered so that A-KID-2 generated by the RID updated in the UPU process is stored in AAnF, so that AAnF can find the corresponding AKMA security context after the UE initiates the AKMA service, and then successfully use the AKMA service. The structure of a communication device that can implement the communication method provided in the embodiment of the present application is described below in conjunction with the accompanying drawings. The following only briefly describes the communication device. For the implementation details of the solution, please refer to the description of the method embodiment above, which will not be repeated below. FIG18 is a schematic diagram of the structure of a communication device 1800 provided in an embodiment of the present application. The communication device 1800 may correspond to the functions or steps implemented by the UE in the above-mentioned various method embodiments, may correspond to the functions or steps implemented by the UDM in the above-mentioned various method embodiments, and may correspond to the functions or steps implemented by the AMF in the above-mentioned various method embodiments. The communication device may include a processing module 1810 and a transceiver module 1820. In a possible implementation, a storage unit may also be included, which may be used to store instructions (codes or programs) and / or data. The processing module 1810 and the transceiver module 1820 may be coupled to the storage unit, for example, the processing module 1810 may read the instructions (codes or programs) and / or data in the storage unit to implement the corresponding method. The above-mentioned units may be independently arranged or partially or fully integrated. For example, the transceiver module 1820 may include a sending module and a receiving module. The sending module may be a transmitter, and the receiving module may be a receiver. The entity corresponding to the transceiver module 1820 may be a transceiver circuit, such as a transceiver or a communication interface. In some possible implementations, the communication device 1800 can implement the behaviors and functions of the UE in the above method embodiments. For example, the communication device 1800 can be a UE, or a component (such as a chip or circuit) applied to the UE. The transceiver module 1820 can be used to perform all receiving or sending operations performed by the UE in the embodiments of Figures 9 to 17. The processing module 1810 can be used to perform all operations except the transceiver operation performed by the UE in the embodiments of Figures 9 to 17. In some possible implementations, the communication device 1800 can implement the behaviors and functions of the UDM in the above method embodiments. For example, the communication device 1800 can be a UDM, or a component (such as a chip or circuit) used in the UDM. The transceiver module 1820 can be used to perform all receiving or sending operations performed by the UDM in the embodiments of Figures 11 to 17. The processing module 1810 can be used to perform all operations except the transceiver operations performed by the UDM in the embodiments of Figures 11 to 17. In some possible implementations, the communication device 1800 can implement the behaviors and functions of the AMF in the above method embodiments. For example, the communication device 1800 can be an AMF, or a component (such as a chip or circuit) applied to the AMF. The transceiver module 1820 can be used to perform all receiving or sending operations performed by the AMF in the embodiments of Figures 9 to 17. The processing module 1810 can be used to perform all operations except the transceiver operation performed by the AMF in the embodiments of Figures 9 to 17. FIG19 is a schematic diagram of the structure of another device 190 provided in an embodiment of the present application. The device in FIG19 may be the above-mentioned UE or a chip for the above-mentioned UE, or the above-mentioned UDM or a chip for the above-mentioned UDM, or the above-mentioned AMF or a chip for the above-mentioned AMF. As shown in FIG19 , the device 190 includes a processing circuit 1910 and a transceiver circuit 1920. In some embodiments of the present application, the processing circuit 1910 and the transceiver circuit 1920 may be used to perform functions or operations performed by the UE. The transceiver circuit 1920 is used, for example, to perform all receiving or sending operations performed by the UE in the embodiments of Figures 9 to 11. The processing circuit 1910 is used, for example, to perform all operations except the transceiver operation performed by the UE in the embodiments of Figures 9 to 11. In some embodiments of the present application, the processing circuit 1910 and the transceiver circuit 1920 may be used to perform functions or operations performed by the UDM. The transceiver circuit 1920 is used, for example, to perform all receiving or sending operations performed by the UDM in the embodiments of FIGS. 11 to 17. The processing circuit 1910 is used, for example, to perform all operations except the transceiver operation performed by the UDM in the embodiments of FIGS. 11 to 17. In some embodiments of the present application, the processing circuit 1910 and the transceiver circuit 1920 may be used to perform functions or operations performed by the AMF. The transceiver circuit 1920 is used, for example, to perform all receiving or sending operations performed by the AMF in the embodiments of FIGS. 9 to 11. The processing circuit 1910 is used, for example, to perform all operations except the transceiver operation performed by the AMF in the embodiments of FIGS. 9 to 11. In a possible implementation, the transceiver circuit 1920 includes at least one transceiver, and the processing circuit 1910 includes at least one processor, or a circuit in at least one processor for processing or control. The transceiver is used to communicate with other devices / apparatuses through a transmission medium. The processor uses the transceiver to send and receive data and / or signaling, and is used to implement the method in the above method embodiment. The processor can implement the function of the processing module 1810, and the transceiver can implement the function of the transceiver module 1820. Optionally, the transceiver may include a radio frequency circuit and an antenna, and the radio frequency circuit is mainly used for converting baseband signals and radio frequency signals and processing radio frequency signals. The antenna is mainly used to send and receive radio frequency signals in the form of electromagnetic waves. Input and output devices, such as touch screens, display screens, keyboards, etc. are mainly used to receive data input by users and output data to users. Optionally, the device 190 may also include at least one memory for storing program instructions and / or data. The memory is coupled to the processor. The coupling in the embodiment of the present application is an indirect coupling or communication connection between devices, units or modules, which may be electrical, mechanical or other forms, for information exchange between devices, units or modules. The processor may operate in conjunction with the memory. The processor may execute program instructions stored in the memory. At least one of the at least one memory may be included in the processor. The processor can read the software program in the memory, interpret and execute the instructions of the software program, and process the data of the software program. When data is sent wirelessly, the processor performs baseband processing on the data to be sent and outputs the baseband signal to the RF circuit. The RF circuit performs RF processing on the baseband signal and then sends the RF signal outward in the form of electromagnetic waves through the antenna. When data is sent to the device 190, the RF circuit receives the RF signal through the antenna, converts the RF signal into a baseband signal, and outputs the baseband signal to the processor. The processor converts the baseband signal into data and processes the data. In another implementation, the above-mentioned RF circuit and antenna can be set independently of the processor performing baseband processing. For example, in a distributed scenario, the RF circuit and antenna can be independent of the device 190 and arranged in a remote manner. The specific connection medium between the above-mentioned transceiver, processor and memory is not limited in the embodiments of the present application. In the embodiments of the present application, the processor may be one of the following devices: a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, or all or part of the circuits used for processing functions in the aforementioned devices, which may implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiments of the present application may be directly embodied as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor. In one possible implementation, the processing circuit 1910 includes at least one logic circuit, and the transceiver circuit 1920 includes at least one interface. The processing module 1810 in FIG. 18 can be implemented with a logic circuit, and the transceiver module 1820 in FIG. 18 can be implemented with an interface. Among them, the logic circuit can be a chip, a processing circuit, an integrated circuit or a system on chip (SoC) chip, etc., and the interface can be a communication interface, an input and output interface, etc. In the embodiment of the present application, the logic circuit and the interface can also be coupled to each other. The embodiment of the present application does not limit the specific connection method of the logic circuit and the interface. The present application also provides a computer-readable storage medium, in which a computer program or instruction is stored. When the computer program or instruction is executed on a computer, the computer executes the method of the above embodiment. The present application also provides a computer program product, which includes instructions or a computer program. When the instructions or the computer program are run on a computer, the method in the above embodiment is executed. The present application also provides a communication system, including the above-mentioned UE, the above-mentioned UDM and the above-mentioned AMF. The present application also provides a chip, which includes: a communication interface and a processor; the communication interface is used for sending and receiving signals of the above-mentioned chip; the processor is used to execute computer program instructions so that a communication device including the above-mentioned chip executes the method in the above-mentioned embodiment. In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The above computer program product includes one or more computer programs or instructions. When the above computer program or instruction is loaded and executed on a computer, the above process or function of the embodiment of the present application is executed in whole or in part. The above computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device or other programmable device. The above computer program or instruction may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the above computer program or instruction may be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired or wireless means. The above computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The above available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a tape; it may also be an optical medium, such as a digital video disc; it may also be a semiconductor medium, such as a solid-state hard disk. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media. In the various embodiments of the present application, unless otherwise specified or provided for in any logical conflict, the terms and / or descriptions between the different embodiments are consistent and may be referenced to each other, and the technical features in the different embodiments may be combined to form new embodiments according to their inherent logical relationships.
Claims
1. A communication method, characterized in that: include: The communication device supporting the first service generates a first message after updating the first parameter, wherein the first message includes authentication indication information for instructing an access and mobility management function network element to trigger a process for authenticating the communication device, and the first parameter is associated with the first service; The communication device sends the first message to the access and mobility management function network element.
2. The method according to claim 1, characterized in that Before generating the first message, the method further includes: The communication device receives a second message from the access and mobility management function network element, wherein the second message includes a new first parameter; The communication device updates the old first parameter to the new first parameter.
3. The method according to claim 1 or 2, characterized in that: The method further comprises: The communication device determines that it supports the first service.
4. The method according to claim 3, characterized in that The generating the first message comprises: In response to the communication device supporting the first service and the communication device updating the old first parameter to the new first parameter, the communication device generates the first message carrying the authentication indication information.
5. The method according to claim 3, characterized in that: The second message also includes instruction information for instructing the communication device to perform a re-registration process, and the generating the first message includes: When the communication device supports the first service and updates the old first parameter to the new first parameter, in response to the indication information of the re-registration process, the communication device generates the first message including the authentication indication information, wherein the first message is a registration request message.
6. The method according to any one of claims 2 to 5, characterized in that: The second message further includes integrity verification information for verifying all or part of the parameters in the second message; and the communication device updating the old first parameter to the new first parameter includes: In a case where it is determined based on the integrity check information that the integrity check of all or part of the parameters in the second message is successful, the communication device updates the old first parameter to the new first parameter.
7. The method according to any one of claims 1 to 6, characterized in that: The first service is an authentication and key management AKMA service, and the first parameter includes a routing indicator RID of the communication device.
8. The method according to any one of claims 2 to 6, characterized in that: The first service is an authentication and key management AKMA service, and the first parameter includes a routing indicator RID of the communication device; After the communication device sends the first message to the access and mobility management function network element, the method further includes: The communication device sends an application session establishment request message to an application function network element supporting the AKMA service, where the application session establishment request message includes an AKMA key identifier A-KID generated based on the new RID.
9. The method according to claim 8, characterized in that The method further comprises: The communication device generates an AKMA key and an AKMA key identifier A-KID corresponding to the AKMA key, and Generate a key K for the application function network element according to the AKMA key and the identifier of the application function network element AF .
10. A communication method, characterized in that: include: The access and mobility management function network element performs a registration procedure for registering the communication device with a network in response to a first registration request message from the communication device, the registration procedure comprising: the access and mobility management function network element sending a message including a key identifier to the communication device; The access and mobility management function network element receives a second registration request message from the communication device, wherein the second registration request message includes authentication indication information for instructing the access and mobility management function network element to trigger a process for authenticating the communication device and the key identifier; and In response to the authentication indication information, the access and mobility management function network element triggers a process of authenticating the communication device.
11. The method according to claim 10, characterized in that Before the access and mobility management function network element triggers a process for authenticating the communication device, the method further includes: The access and mobility management function network element performs integrity protection verification on the second registration request message according to the key corresponding to the key identifier.
12. The method according to claim 11, characterized in that Before the access and mobility management function network element receives the second registration request message from the communication device, the method further includes: The access and mobility management function network element sends a second message to the communication device, where the second message includes instruction information for instructing the communication device to perform a re-registration process.
13. The method according to claim 12, characterized in that The second message also includes integrity check information and new parameters of the communication device, the integrity check information is used to check all or part of the parameters in the second message, and the second message is used to update the parameters of the communication device.
14. The method according to claim 13, characterized in that The access and mobility management function network element sending a second message to the communication device includes: The access and mobility management function network element sends the second message to the communication device in response to a message from the unified data management network element including the indication information, the integrity check information and new parameters of the communication device.
15. A communication method, characterized in that: include: The unified data management network element generates a third message when determining that a first parameter of a communication device supporting a first service needs to be updated, the third message including at least one of first indication information for instructing the communication device to trigger a primary authentication process and second indication information for instructing the communication device to perform a re-registration process, and a new first parameter of the communication device, the first parameter being associated with the first service; The unified data management network element sends the third message to the access and mobility management function network element.
16. The method according to claim 15, characterized in that The method further comprises: The unified data management network element determines that the first parameter of the communication device needs to be updated.
17. The method according to claim 15 or 16, characterized in that The method further comprises: The unified data management network element determines that the communication device supports the first service.
18. The method according to claim 17, characterized in that Generating the third message comprises: In response to the communication device supporting the first service and the unified data management network element determining that a first parameter of the communication device needs to be updated, the unified data management network element generates the third message carrying at least one of the first indication information and the second indication information.
19. The method according to any one of claims 15 to 18, characterized in that The unified data management network element determines that the first parameter of the communication device needs to be updated, including: The unified data management network element decides to execute a user equipment parameter update UPU procedure for updating the first parameter of the communication device.
20. The method according to any one of claims 15 to 19, characterized in that The third message also includes integrity check information for verifying all or part of the parameters in the third message.
21. The method according to any one of claims 15 to 20, characterized in that The first service is an Authentication and Key Management (AKMA) service, and the first parameter includes a routing indicator (RID) of the communication device.
22. The method according to any one of claims 15 to 20, characterized in that The first indication information and the second indication information are the same indication information.
23. A communication method, characterized in that: include: The communication device supporting the first service receives a fourth message from the access and mobility management function network element, the fourth message including indication information for instructing the communication device to trigger a primary authentication process and a new first parameter of the communication device, the first parameter being associated with the first service; In response to the indication information, the communication device sends a first message to the access and mobility management function network element, where the first message includes authentication indication information for instructing the access and mobility management function network element to trigger a process for authenticating the communication device.
24. The method according to claim 23, characterized in that After the communication device supporting the first service receives a fourth message from an access and mobility management function network element, and before the communication device sends a first message to the access and mobility management function network element, the method further includes: The communication device updates the old first parameter to the new first parameter.
25. The method according to claim 24, characterized in that The fourth message also includes integrity check information; the communication device updates the old first parameter to the new first parameter including: In a case where it is determined based on the integrity check information that the integrity check of the new first parameter is successful, the communication device updates the old first parameter to the new first parameter.
26. The method according to any one of claims 23 to 25, characterized in that The first service is an authentication and key management AKMA service, and the first parameter includes a routing indicator RID of the communication device.
27. The method according to any one of claims 23 to 25, characterized in that The first service is an authentication and key management AKMA service, and the first parameter includes a routing indicator RID of the communication device; After the communication device sends the first message to the access and mobility management function network element, the method further includes: The communication device sends an application session establishment request message to an application function network element supporting the first service, where the application session establishment request message includes an AKMA key identifier A-KID generated based on the new first parameter.
28. The method according to claim 27, characterized in that The method further comprises: In response to the AKMA service of the communication device, the communication device generates an AKMA key and an AKMA key identifier A-KID corresponding to the AKMA key, and generates a key K for the application function network element according to the AKMA key and the identifier of the application function network element. AF .
29. A communication method, characterized in that: include: The unified data management network element generates a fifth message after sending the third message to the access and mobility management function network element, wherein the third message is used to update a first parameter of a communication device supporting a first service, and the fifth message is used to request the access and mobility management function network element to trigger a primary authentication process of the communication device, wherein the first parameter is associated with the first service; The unified data management network element sends the fifth message to the access and mobility management function network element.
30. The method according to claim 29, characterized in that The method further comprises: The unified data management network element sends the third message to the access and mobility management function network element.
31. The method according to claim 30, characterized in that The third message includes first integrity check information for verifying all or part of the parameters in the third message and new first parameters of the communication device.
32. The method according to any one of claims 29 to 31, characterized in that Before generating the fifth message, the method further includes: The unified data management network element determines that the communication device supports the first service.
33. The method according to claim 32, characterized in that The generating the fifth message comprises: In response to the communication device supporting the first service and the unified data management network element determining that the third message for updating the first parameter of the communication device has been sent, the unified data management network element generates the fifth message.
34. The method according to any one of claims 29 to 33, characterized in that The third message includes communication device update data and response indication information for instructing the communication device to respond to the UDM request.
35. The method according to claim 34, characterized in that Before generating the fifth message, the method further includes: The unified data management network element receives a sixth message from the access and mobility management function network element, where the sixth message includes second integrity check information generated in response to the response indication information, and the second integrity check information is used by the unified data management network element to check the sixth message; The generating the fifth message comprises: When it is determined that the integrity check of all or part of the parameters in the sixth message is successful based on the second integrity check information, in response to the communication device supporting the first service and the unified data management network element having sent the third message for updating the first parameters of the communication device, the unified data management network element generates the fifth message.
36. The method according to claim 34 or 35, characterized in that The method further comprises: When determining that the first parameter of the communication device needs to be updated, the unified data management network element generates the third message including the communication device update data and the response indication information.
37. The method according to any one of claims 29 to 36, characterized in that The first service is an authentication and key management AKMA service, and the first parameter includes a routing indicator RID of the communication device.
38. A communication device, characterized in that: The method comprises a module for implementing the method according to any one of claims 1 to 9.
39. A communication device, characterized in that: The method comprises modules for implementing the method according to any one of claims 10 to 14.
40. A communication device, characterized in that: Comprising modules for implementing the method of any one of claims 15 to 22.
41. A communication device, characterized in that: Comprising modules for implementing the method of any one of claims 23 to 28.
42. A communication device, characterized in that: Comprising modules for implementing the method of any one of claims 29 to 37.
43. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, the computer program including program instructions, which, when executed, cause the computer to execute the method as described in any one of claims 1 to 9, or, when executed, cause the computer to execute the method as described in any one of claims 10 to 14, or, when executed, cause the computer to execute the method as described in any one of claims 15 to 22, or, when executed, cause the computer to execute the method as described in any one of claims 23 to 28, or, when executed, cause the computer to execute the method as described in any one of claims 29 to 37.
44. A communication device, characterized in that: The method comprises a processor, wherein the processor is used to, when executing instructions, cause the communication device to perform the method as described in any one of claims 1 to 9, or cause the communication device to perform the method as described in any one of claims 10 to 14, or cause the communication device to perform the method as described in any one of claims 15 to 22, or cause the communication device to perform the method as described in any one of claims 23 to 28, or cause the communication device to perform the method as described in any one of claims 29 to 37.
45. The device according to claim 44, characterized in that The apparatus also includes a memory for storing the instructions.
46. A chip, characterized in that: The chip includes a processor and a communication interface, and the processor reads instructions stored in the memory through the communication interface to execute the method as described in any one of claims 1 to 9, or executes the method as described in any one of claims 10 to 14, or executes the method as described in any one of claims 15 to 22, or executes the method as described in any one of claims 23 to 28, or executes the method as described in any one of claims 29 to 37.
47. A computer program product, characterized in that When the computer program product runs on a computer, the computer executes the method according to any one of claims 1 to 9, or the method according to any one of claims 10 to 14, or the method according to any one of claims 15 to 22, or the method according to any one of claims 23 to 28, or the method according to any one of claims 29 to 37.
Citation Information
Patent Citations
Key acquisition method and device
CN113225176A
Network initiated primary authentication
WO2023187610A1
Authentication method and device
WO2023197273A1