Communication method and communication apparatus
By introducing logic to determine whether to generate and activate a security context, the problems of high power consumption and processing complexity of terminal devices in the environment in the Internet of Things are solved, and the effect of secure communication and power consumption reduction is achieved.
Patent Information
- Application Number
- PCT/CN2024/127782
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-30
- Filing Date
- 2024-10-28
- Publication Date
- 2025-05-08
AI Technical Summary
In the environment of the Internet of Things, terminal devices need to achieve secure communication, but the interaction process of the prior art is complex, resulting in large power consumption, which requires reducing power consumption and simplifying processing complexity.
By introducing logic to determine whether to generate and activate a security context, unnecessary security context generation and activation are avoided, thereby reducing computing and storage overhead and reducing power consumption.
It realizes that while ensuring network communication security, it reduces the power consumption and processing complexity of terminal equipment, and simplifies service processes.
Smart Images

Figure CN2024127782_08052025_PF_FP_ABST
Abstract
Description
Communication method and communication device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on October 30, 2023, with application number 202311431049.8 and invention name “Communication Method and Communication Device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communications, and more particularly, to a communication method and a communication device. Background Art
[0003] In the environmental Internet of Things, terminal devices (e.g., tags) do not have their own power supply devices or rely on batteries. Instead, they obtain energy from the environment, such as solar energy, radio frequency, wind energy, hydropower, or tidal energy. The terminal devices support data perception, transmission, and distributed computing.
[0004] For example, when a server performs an operation on a tag (e.g., inventory, read, write, or invalidate), it can send instructions via the core network. Currently, achieving secure communication between tags and core network elements requires a complex interaction process, resulting in high power consumption. Therefore, reducing power consumption is a current issue that needs to be considered.
[0005] Summary of the Invention
[0006] The present application provides a communication method and a communication device, which can reduce power consumption and simplify processing complexity.
[0007] In a first aspect, a communication method is provided. The method can be executed by a terminal device, such as a mobile phone, automobile, drone, wearable device, or a chip or circuit in the terminal device. Furthermore, the terminal device can also be referred to as user equipment (UE), and thus the method can be executed by the UE, or by a chip or circuit in the UE. This application does not impose any specific limitations on this.
[0008] The method includes: a terminal device sends a registration request message, the registration request message is used to request registration to a network, and the registration request message includes an identifier of the terminal device; if the terminal device passes authentication of the network, the terminal device activates a security context, and the security context is used to protect secure communications between the terminal device and a network element; the terminal device performs an integrity check on a first message from the network element according to the security context, and the first message is used to request execution of a first operation on the terminal device; if the integrity check passes, the terminal device executes the first operation.
[0009] Optionally, the method also includes: the terminal device receives a first message from the network element. This application does not specifically limit the timing when the terminal device receives the first message. For example, the terminal device can receive the first message after activating the security context, or can receive the first message before activating the security context.
[0010] Optionally, the registration request message also includes the security capabilities of the terminal device. Optionally, the security capabilities of the terminal device can also be obtained from the operation requester or the unified data management network element. This acquisition method is transmitted through a secure interface, which can not only reduce the air interface overhead between the terminal device and the network element, but also avoid the interaction failure caused by malicious tampering by an attacker when the terminal device reports the security capabilities of the terminal device through the air interface, thereby ensuring network communication security. In this application, the security capabilities of the terminal device are used to determine the security algorithm in the security context.
[0011] Optionally, before the terminal device activates the security context, the method further includes: the terminal device determining whether to generate the security context. For example, the terminal device determines whether to generate the security context based on the operation instruction type of the first operation instruction; or the terminal device determines whether to generate the security context based on the type of the terminal device.
[0012] Optionally, before the terminal device activates the security context, the method further includes: the terminal device determining whether to activate the security context. For example, the terminal device determines whether to activate the security context based on the operation instruction type of the first operation instruction.
[0013] Illustratively, the operation instruction type may indicate one or more of an inventory operation, a read operation, a write operation, an invalidation operation, or other operations. Optionally, the operation instruction type may be carried in the first message, or the operation instruction type may not be carried in the first message. In this case, the operation instruction type and the first message may be sent simultaneously or separately, which is not limited in this application.
[0014] Optionally, the first message itself may indicate the first operation, in which case the first message may not carry the operation instruction type of the first operation. For example, the first message may be a read operation request message used to read data from a storage area of a terminal device or to collect data from the terminal device. In this case, the read operation request message may not carry the operation instruction type of the read operation.
[0015] Based on the above scheme, by adding judgment logic on whether to generate a security context and whether to activate a security context, unnecessary security context generation and / or activation can be avoided, which can reduce the computing and storage overhead of the terminal device, avoid the limited storage resources of the terminal device from being occupied, and reduce the power consumption of the terminal device. It should be understood that the generation of a security context and the activation of a security context are related, so one can choose to execute one when judging. For example, after judging whether to generate a security context, the activation of the security context also needs to be executed; for example, if the security context is activated, it means that the security context needs to be generated before the security context is activated, so the judgment of generating a security context and the judgment of activating a security context can be equivalent, that is, the judgment of whether to generate a security context and the judgment of whether to activate a security context can replace each other, or exist at the same time.
[0016] It should be noted that this application does not specifically limit the timing of activating the security context by the terminal device. For example, the terminal device may immediately generate and activate the security context if the network authentication is successful; alternatively, the terminal device may first generate the security context if the network authentication is successful, and then activate the security context after receiving the first message; alternatively, the terminal device may not generate the security context if the network authentication is successful, and then generate and activate the security context after receiving the first message.
[0017] According to the solution provided in the present application, when the terminal device passes the authentication of the network, the security context is activated. The terminal device can then perform an integrity check on the first message from the network side that indicates the execution of the first operation based on the security context to determine whether the first message has been maliciously tampered with, and execute the first operation while the first message is securely protected. On the one hand, this technical solution can ensure secure communication between the terminal device and the network element. On the other hand, by decoupling the NAS SMC process from the activation of the security context, that is, after the terminal device authenticates the network, there is no need to execute the NAS SMC process again, the number of information interactions between the terminal device and the network element is reduced. Compared with the prior art, in which the terminal device and the core network element sequentially execute the authentication process, trigger the NAS SMC process, and the service execution process, this implementation method can execute the first operation while ensuring the security of network communications, simplify the entire service process, reduce processing complexity, and reduce processing delay.
[0018] In combination with the first aspect, in certain implementations of the first aspect, the terminal device activates the security context, including: the terminal device skips the NAS SMC process and activates the security context based on the capabilities of the terminal device and / or the type of the terminal device, that is, the terminal device determines to activate the security context when the terminal device passes the authentication of the network based on the capabilities of the terminal device and / or the type of the terminal device.
[0019] Exemplarily, the type of terminal device includes a tag type, such as an active tag, a passive tag, or a semi-passive tag. In the case where the type of terminal device is a passive tag, the terminal device skips the NAS SMC process and activates the security context. This is because for terminal devices of passive tag type, the storage and computing capabilities are weak and the cost is relatively low. It may support an integrity security protection algorithm and / or a confidentiality security protection algorithm. Therefore, the terminal device and the network element can uniquely determine the security algorithm used to activate the security context, and the two do not need to negotiate the security algorithm through the NAS SMC process. That is, the NAS SMC process can be skipped, and the corresponding context for integrity security protection and / or the corresponding context for confidentiality security protection can be activated according to a confidentiality protection algorithm and / or an integrity protection algorithm supported by the terminal device of passive tag type.
[0020] Exemplarily, the capabilities of the terminal device are used to indicate the confidentiality protection algorithms and / or integrity protection algorithms supported by the terminal device. When the capabilities of the terminal device indicate that the terminal device supports a confidentiality protection algorithm and / or an integrity protection algorithm, the terminal device and the network element can uniquely determine the security algorithm used to activate the security context without having to negotiate the security algorithm through the NAS SMC process. In this case, the terminal device skips the NAS SMC process and activates the security context.
[0021] Based on the above solution, the terminal device can choose to skip the NAS SMC process according to the terminal device capabilities and / or the type of the terminal device, and activate the security context if the authentication is passed. This implementation method can simplify the entire service process, reduce processing complexity, and reduce processing delay by omitting the NAS SMC process while ensuring the security of network communications.
[0022] In combination with the first aspect, in some implementations of the first aspect, the terminal device activates the security context, including: in response to an EAP-success message and / or an authentication request message received by the terminal device in the authentication process, the terminal device activates the security context.
[0023] Exemplarily, the EAP-success message indicates that the network has successfully authenticated the terminal device. That is, if the terminal device receives an EAP-success message after sending a registration request message, indicating that the network has successfully authenticated the terminal device, the terminal device activates the security context in response to the EAP-success message if the terminal device has successfully authenticated the network.
[0024] Exemplarily, the authentication request message includes a network-side authentication vector, which is used by the terminal device to authenticate the network. Specifically, after sending a registration request message, the terminal device receives the authentication request message, authenticates the network based on the authentication vector carried in the authentication request message, and activates the security context if the terminal device successfully authenticates the network.
[0025] Based on the above solution, after receiving the EAP-success message and / or the authentication request message, the terminal device activates the security context when it determines that the network has successfully authenticated the terminal device and / or the terminal device has successfully authenticated the network, thereby ensuring secure information interaction between the terminal device and the network.
[0026] In combination with the first aspect, in certain implementations of the first aspect, the terminal device activates the security context, including: the terminal device activates the security context according to a locally configured security algorithm, the security algorithm including an integrity security algorithm and / or a confidentiality security algorithm, that is, the terminal device can uniquely determine the security algorithm used to activate the security context based on a confidentiality protection algorithm and / or an integrity security algorithm locally configured by the terminal device, without the need to negotiate the security algorithm through the NAS SMC process, and thus the security context can be activated when it is determined that the terminal device has passed the authentication of the network.
[0027] Exemplarily, the security algorithm locally configured by the terminal device includes a confidentiality protection algorithm (e.g., the ZUC confidentiality security protection algorithm) and / or an integrity protection algorithm (e.g., the SNOW integrity security protection algorithm), then the terminal device can activate the security context according to the ZUC confidentiality security protection algorithm and / or the SNOW integrity security protection algorithm.
[0028] Based on the above solution, since the locally configured security algorithm includes a confidentiality protection algorithm and / or an integrity protection algorithm, the terminal device can uniquely determine the security algorithm used to activate the security context, so there is no need to negotiate the security algorithm through the NAS SMC process, reducing the interaction process between the terminal device and the network element, simplifying the processing complexity, and reducing the processing delay.
[0029] In combination with the first aspect, in some implementations of the first aspect, the terminal device activates the security context, including: the terminal device activates the security context according to a received registration acceptance message or a first message, where the registration acceptance message is used to accept the registration request of the terminal device.
[0030] Optionally, the registration acceptance message may be a first message, in which case the registration acceptance message may carry an operation instruction type instructing the terminal device to perform a first operation.
[0031] Exemplarily, the message received by the terminal device after sending the registration request message is a registration acceptance message, indicating that the network accepts the registration request of the terminal device. In response to the registration acceptance message, the security context is activated when the terminal device passes the authentication of the network.
[0032] Exemplarily, the terminal device activates the security context according to the security algorithm indicated by the security algorithm identifier carried in the registration acceptance message, and the security algorithm includes an integrity security algorithm and / or a confidentiality security algorithm. For example, if the registration acceptance message carries a confidentiality protection algorithm identifier (for example, the confidentiality security protection algorithm identifier is used to indicate the ZUC confidentiality security protection algorithm) and / or an integrity protection algorithm identifier (for example, the integrity security protection algorithm identifier is used to indicate the SNOW integrity security protection algorithm), it means that the terminal device and the network element can uniquely determine the security algorithm used to activate the security context without having to negotiate the security algorithm through the NAS SMC process. Therefore, the terminal device can activate the security context according to the ZUC confidentiality security protection algorithm and / or the SNOW integrity security protection algorithm if the terminal device passes the authentication of the network.
[0033] Based on the above solution, since the registration acceptance message carries a confidentiality protection algorithm identifier and / or an integrity protection algorithm identifier, the terminal device can uniquely determine the security algorithm used to activate the security context, so there is no need to negotiate the security algorithm through the NAS SMC process, reducing the interaction process between the terminal device and the network element, simplifying the processing complexity, and reducing the processing delay.
[0034] In combination with the first aspect, in some implementations of the first aspect, the terminal device activates the security context, including: the terminal device activates the security context according to the operation instruction type of the first operation.
[0035] Exemplarily, when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, the terminal device determines to activate the security context.
[0036] Optionally, when the operation instruction type indicates an inventory operation, the terminal device determines not to activate the security context.
[0037] Based on the above scheme, whether to activate the security context is determined based on whether the first operation indicated by the operation instruction type is a read operation, a write operation, or an invalidation operation, thereby avoiding unnecessary generation and / or activation of the security context for the inventory operation, reducing the computing and storage overhead of the terminal device, avoiding the storage resources of the terminal device from being occupied, and reducing the power consumption of the terminal device.
[0038] In combination with the first aspect, in some implementations of the first aspect, the method further includes: the terminal device determines whether to decrypt the first message according to the operation instruction type of the first operation.
[0039] Exemplarily, when the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, the terminal device determines not to decrypt the first message.
[0040] Exemplarily, when the operation instruction type indicates a write operation, the terminal device determines to decrypt the first data ciphertext carried in the first message, wherein the first data ciphertext is obtained by encrypting the first data, and the first data is data to be written to the storage area of the terminal device.
[0041] Based on the above scheme, the operation instruction type is associated with whether the first message is decrypted, and then whether the first message is decrypted is determined according to the operation instruction type, so as to avoid the terminal device performing unnecessary decryption calculations or decryption operations when determining an inventory operation, a read operation, or an invalidation operation, thereby reducing the computing overhead and power consumption of the terminal device.
[0042] In combination with the first aspect, in certain implementations of the first aspect, the method also includes: the terminal device determines whether to perform security protection on the second message based on the operation instruction type of the first operation, the security protection includes integrity security protection and / or confidentiality security protection, and the second message is used to indicate whether the first operation is executed successfully; the terminal device sends the second message to the network element.
[0043] In combination with the first aspect, in certain implementations of the first aspect, the terminal device determines whether to perform security protection on the second message based on the operation instruction type of the first operation, including: when the operation instruction type indicates an inventory operation, the terminal device determines not to perform integrity security protection on the second message; when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, the terminal device determines to perform integrity security protection on the second message.
[0044] In combination with the first aspect, in certain implementations of the first aspect, the terminal device determines whether to perform security protection on the second message based on the operation instruction type of the first operation, including: when the operation instruction type indicates an inventory operation, a write operation, or an invalidation operation, the terminal device determines not to perform confidentiality security protection on the second message. This is because when the first operation is an inventory operation, a write operation, or an invalidation operation, the corresponding second message sent by the terminal device to the network element can be regarded as a response message to the first message, which is used to indicate whether the terminal device performs the first operation or whether the first operation is successfully executed. At this time, the second message may not carry parameters that require confidentiality security protection, so there is no need to perform confidentiality security protection on the second message. Optionally, in this case, the second message may not be sent.
[0045] Exemplarily, when the operation instruction type indicates a read operation, the terminal device determines to perform confidentiality security protection on the second data to obtain a second data ciphertext. The second data is data read from a storage area of the terminal device or data collected by the terminal device, and the second data ciphertext is carried in the second message.
[0046] Optionally, when the first message is a registration accept message, the second message may be a registration complete message. For example, the registration accept message may carry information for updating terminal device parameters, where the terminal device parameters may be slice information or closed access group information. Furthermore, after updating the terminal device parameters, the terminal device may send a registration complete message to the network element.
[0047] It should be understood that in order to ensure network communication security, the terminal device performs integrity protection on the second message.
[0048] Based on the above scheme, the operation instruction type is associated with whether the second message is confidentiality protected, and then whether the second message is confidentiality protected is determined according to the operation instruction type. This avoids the terminal device from performing unnecessary confidentiality security protection when determining inventory operations, write operations, or failure operations, etc., which can reduce the computing overhead and power consumption of the terminal device.
[0049] In combination with the first aspect, in certain implementations of the first aspect, the method also includes: the terminal device determines whether to delete the security context based on the type of the terminal device, specifically including one or more of the following: when the type of the terminal device is an active tag or a semi-passive tag, the terminal device determines not to delete the security context; when the type of the terminal device is a passive tag, the terminal device determines to delete the security context.
[0050] Based on the above solution, by adding the judgment logic of whether to delete the security context, it is avoided that the security context is not deleted or saved when the terminal device type is a passive tag, thereby reducing the computing and storage overhead of the terminal device, avoiding the limited storage resources of the terminal device from being occupied, and reducing the power consumption of the terminal device.
[0051] In a second aspect, a communication method is provided. This method can be executed by a network element, or by a chip or circuit for a network element, but this application does not limit this. For ease of description, the following description uses execution by a network element as an example. It should be understood that when the TMF is set up independently, this method may be executed by the TMF in cooperation with other network elements (such as the AMF). This application does not limit this.
[0052] The method includes: receiving a registration request message from a terminal device, the registration request message is used to request registration to a network, and the registration request message includes an identifier of the terminal device; activating a security context when authentication of the terminal device is successful, the security context is used to protect secure communications between the terminal device and a network element; performing integrity security protection on a first message based on the security context, the first message is used to request a first operation to be performed on the terminal device; and sending the first message to the terminal device.
[0053] Optionally, before activating the security context, the method further includes: determining whether to generate a security context, for example, based on the operation instruction type of the first operation instruction; or based on the type of the terminal device.
[0054] Optionally, before activating the security context, the method further includes: determining whether to activate the security context, for example, determining whether to activate the security context according to the operation instruction type of the first operation instruction.
[0055] Based on the above solution, by adding judgment logic on whether to generate a security context and whether to activate the security context, unnecessary generation and / or activation of the security context can be avoided, which can reduce computing and storage overhead, avoid storage resources from being occupied, and reduce power consumption.
[0056] It should be noted that this application does not impose any specific restrictions on the timing of activating the security context. For example, the security context may be generated and activated immediately upon successful authentication of the terminal device; alternatively, the security context may be generated first upon successful authentication of the terminal device, and then activated after receiving a service request message from the operation requester; alternatively, the security context may not be generated upon successful authentication of the terminal device, and then generated and activated after receiving a second service request message.
[0057] According to the solution provided in the present application, when the network authenticates the terminal device, the security context is activated, and then it can be determined that the first message to be sent is integrity-secured. On the one hand, it can ensure secure communication between the terminal device and the network element. On the other hand, the NAS SMC process is decoupled from the activation of the security context, that is, the NAS SMC process does not need to be executed after the network authenticates the terminal device. This can reduce the number of information interactions between the terminal device and the network element, simplify the processing flow of the entire service process, and reduce processing complexity and processing delay.
[0058] In combination with the second aspect, in certain implementations of the second aspect, the security capabilities of the terminal device are used to determine the security algorithm in the security context, and the method also includes: obtaining the security capabilities of the terminal device from the operation requester; or, obtaining the security capabilities of the terminal device from the terminal device; or, obtaining the security capabilities of the terminal device from a unified data management network element.
[0059] It should be understood that the security capabilities of the terminal device obtained from the operation requester or the unified data management network element are transmitted through a security-protected interface, which can not only reduce the air interface overhead between the terminal device and the network element, but also avoid the interaction failure caused by malicious tampering by an attacker when the terminal device reports the security capabilities of the terminal device through the air interface, thereby ensuring the security of network communications.
[0060] In combination with the second aspect, in certain implementations of the second aspect, activating the security context includes: skipping the NAS SMC process and activating the security context based on the capabilities of the terminal device and / or the type of the terminal device.
[0061] In combination with the second aspect, in certain implementations of the second aspect, the NAS SMC process is skipped and the security context is activated according to the type of the terminal device, including: when the type of the terminal device is a passive tag, the NAS SMC process is skipped and the security context is activated.
[0062] In combination with the second aspect, in certain implementations of the second aspect, the NAS SMC process is skipped and the security context is activated based on the capabilities of the terminal device, including: when the capabilities of the terminal device indicate that the terminal device supports a confidentiality protection algorithm and / or an integrity protection algorithm, the NAS SMC process is skipped and the security context is activated.
[0063] In conjunction with the second aspect, in certain implementations of the second aspect, activating the security context includes: activating the security context according to a locally configured security algorithm, the security algorithm including an integrity security algorithm and / or a confidentiality security algorithm;
[0064] In combination with the second aspect, in some implementations of the second aspect, activating the security context includes: activating the security context according to the operation instruction type of the first operation.
[0065] In combination with the second aspect, in certain implementations of the second aspect, the security context is activated according to the operation instruction type of the first operation, including one or more of the following: activating the security context when the operation instruction type indicates a read operation; activating the security context when the operation instruction type indicates a write operation; activating the security context when the operation instruction type indicates an invalidation operation.
[0066] In combination with the second aspect, in some implementations of the second aspect, the method further includes: determining whether to perform confidentiality security protection on the first message according to the operation instruction type of the first operation.
[0067] In combination with the second aspect, in certain implementations of the second aspect, determining whether to perform confidentiality and security protection on the first message is based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, determining that confidentiality and security protection is not performed on the first message; when the operation instruction type indicates a read operation, determining that confidentiality and security protection is not performed on the first message; when the operation instruction type indicates an invalidation operation, determining that confidentiality and security protection is not performed on the first message; when the operation instruction type indicates a write operation, determining that confidentiality and security protection is performed on the first data, and obtaining a first data ciphertext, the first data being data to be written to a storage area of the terminal device, and the first message including the first data ciphertext.
[0068] In combination with the second aspect, in certain implementations of the second aspect, the method also includes: receiving a second message from the terminal device, the second message being used to indicate whether the first operation is executed successfully; and determining whether to perform security protection (integrity check and / or decryption) on the second message based on the operation instruction type of the first operation.
[0069] In combination with the second aspect, in certain implementations of the second aspect, determining whether to perform an integrity check on the second message is based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, determining that an integrity check is to be performed on the second message; when the operation instruction type indicates an inventory operation, determining not to perform an integrity check on the second message.
[0070] In combination with the second aspect, in certain implementations of the second aspect, determining whether to decrypt the second message is based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates a read operation, determining to decrypt the second data ciphertext carried in the second message to obtain the second data, wherein the second data is data read from a storage area of the terminal device or data collected by the terminal device; when the operation instruction type indicates a write operation, determining not to decrypt the second message; when the operation instruction type indicates an invalidation operation, determining not to decrypt the second message; when the operation instruction type indicates an inventory operation, determining not to decrypt the second message.
[0071] In combination with the second aspect, in certain implementations of the second aspect, the method also includes: determining whether to delete the security context based on the type of the terminal device, specifically including one or more of the following: when the type of the terminal device is an active tag or a semi-passive tag, determining not to delete the security context; when the type of the terminal device is a passive tag, determining to delete the security context.
[0072] Based on the above solution, by determining the judgment logic for deleting the security context, the computing and storage overhead of the network element can be reduced, the power consumption of the network element can be reduced, and the network side can be guaranteed to provide services for more terminal devices, avoiding network congestion, etc.
[0073] In combination with the second aspect, in certain implementations of the second aspect, the method further includes: receiving a service request message from an operation requester, the service request message being used to request execution of a first operation on a terminal device, and sending a first service response message to the operation requester according to an operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, the first service response message is used to indicate that the first operation is successfully executed, and the first service response message includes an identifier of the terminal device; when the operation instruction type indicates a read operation and the integrity check and / or decryption of the second message passes, the first service response message is used to indicate that the first operation is successfully executed, and the first service response message includes an identifier of the terminal device and second data, wherein the second data is obtained by decrypting a ciphertext of the second data, and the second data is data read from a storage area of the terminal device or collected by the terminal device; when the operation instruction type indicates a write operation and the integrity check of the second message passes, the first service response message is used to indicate that the first operation is successfully executed, and the first service response message includes an identifier of the terminal device; when the operation instruction type indicates an invalidation operation and the integrity check of the second message passes, the first service response message is used to indicate that the first operation is successfully executed, and the first service response message includes an identifier of the terminal device.
[0074] In combination with the second aspect, in some implementations of the second aspect, the method also includes: receiving a service request message from an operation requester, the service request message being used to request execution of a first operation on a terminal device, and sending a second service response message to the operation requester according to the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates a read operation and the integrity check of the second message fails and / or the decryption of the second message fails, the second service response message is used to indicate that the first operation failed; when the operation instruction type indicates a write operation and the integrity check of the second message fails, the second service response message is used to indicate that the first operation failed; when the operation instruction type indicates an invalid operation and the integrity check of the second message fails, the second service response message is used to indicate that the first operation failed.
[0075] In combination with the second aspect, in certain implementations of the second aspect, the method also includes: receiving a service request message from an operation requester, the service request message is used to request execution of a first operation on a terminal device, and if authentication of the terminal device fails, sending a third service response message to the operation requester, the third service response message is used to indicate that execution of the first operation has failed.
[0076] The beneficial effects of the above-mentioned second aspect and certain implementation methods of the second aspect can be referred to the corresponding description of the first aspect, and will not be repeated here.
[0077] In a third aspect, a communication method is provided. This method can be executed by an operation requester (e.g., an AF), or by a chip or circuit used for the operation requester, although this application does not limit this. For ease of description, the following description is based on an example of execution by the operation requester.
[0078] The method includes: the operation requesting party sends a service request message to a network element, the service request message is used to request to perform a first operation on a terminal device, and the service request message includes the security capabilities of the terminal device; the operation requesting party receives a service response message from the network element, and the service response message is used to indicate whether the first operation is performed successfully.
[0079] Optionally, the service request message further includes an operation instruction type, where the operation instruction type is used to indicate the first operation.
[0080] Optionally, the service request message itself may indicate the first operation. In this case, the service request message may not carry the operation instruction type of the first operation. For example, the service request message may be a read operation request message used to read data from a storage area of a terminal device or to collect data from the terminal device. In this case, the read operation request message may not carry the operation instruction type of the read operation.
[0081] Exemplarily, the service request message also includes one or more of the terminal device identifier, the operation instruction type, and the first data, wherein the operation instruction type is used to indicate the first operation, the security capability of the terminal device is used to indicate one or more integrity security protection algorithms and / or confidentiality security protection algorithms supported by the terminal device, and the first data is data to be written to the storage area of the terminal device.
[0082] Based on the above solution, the operation requester can obtain services such as reading, writing, inventorying, or invalidation by sending a service request message to the network element to request the execution of a first operation on the terminal device. It should be understood that the security capabilities of the terminal device obtained by the network element from the operation requester are transmitted through a secure interface, which can not only reduce the air interface overhead between the terminal device and the network element, but also avoid the interaction failure caused by malicious tampering by an attacker when the terminal device reports the terminal device's security capabilities through the air interface, thereby ensuring network communication security.
[0083] In combination with the third aspect, in certain implementations of the third aspect, when the operation instruction type indicates an inventory operation, the service response message includes the identification of the terminal device; or, when the operation instruction type indicates a read operation, the service response message includes the identification of the terminal device and second data, and the second data is data read from a storage area of the terminal device or collected by the terminal device; or, when the operation instruction type indicates a write operation, the service response message includes the identification of the terminal device; or, when the operation instruction type indicates an invalidation operation, the service response message includes the identification of the terminal device.
[0084] In combination with the third aspect, in some implementations of the third aspect, when the network element fails to authenticate the terminal device, the service response message is used to indicate that the first operation has failed.
[0085] In combination with the third aspect, in some implementations of the third aspect, the service response message includes a failure reason value, and the failure reason value is used to indicate that the authentication of the terminal device fails.
[0086] The beneficial effects of the third aspect and certain implementation methods of the third aspect can be referred to the relevant description of the first aspect, and will not be repeated here.
[0087] In a fourth aspect, a communication method is provided. The method can be executed by a terminal device, such as a mobile phone, automobile, drone, wearable device, etc., or a chip or circuit in the terminal device. In addition, the terminal device can also be referred to as user equipment, and thus the method can be executed by the user equipment, or a chip or circuit in the user equipment. This application does not specifically limit this.
[0088] The method includes: a terminal device sends a registration request message, the registration request message is used to request registration to a network, and the registration request message includes an identifier of the terminal device; the terminal device receives a first message from a network element, the first message is used to request execution of a first operation on the terminal device; the terminal device determines whether to activate a security context based on an operation instruction type of the first operation, and the security context is used to protect secure communications between the terminal device and the network element.
[0089] In combination with the fourth aspect, in certain implementations of the fourth aspect, the terminal device determines whether to activate the security context based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, the terminal device determines not to activate the security context; when the operation instruction type indicates a read operation, the terminal device determines to activate the security context; when the operation instruction type indicates a write operation, the terminal device determines to activate the security context; when the operation instruction type indicates an invalidation operation, the terminal device determines to activate the security context.
[0090] It should be noted that the activation security context in this application can be replaced by the generation of a security context.
[0091] Illustratively, the operation instruction type may indicate one or more of an inventory operation, a read operation, a write operation, an invalidation operation, or other operations. Optionally, the operation instruction type may be carried in the first message, or the operation instruction type may not be carried in the first message. In this case, the operation instruction type and the first message may be sent simultaneously or separately, which is not limited in this application.
[0092] Exemplarily, the first message itself may also indicate the first operation, in which case the first message may not carry the operation instruction type of the first operation. For example, the first message may be a read operation request message used to read data from a storage area of a terminal device or to collect data from the terminal device. In this case, the read operation request message may not carry the operation instruction type of the read operation.
[0093] In combination with the fourth aspect, in certain implementations of the fourth aspect, when it is determined that the security context is activated, the terminal device performs integrity verification and / or decryption on the first message based on the security context; when the integrity verification and / or decryption passes, the terminal device performs the first operation based on the operation instruction type.
[0094] In combination with the fourth aspect, in certain implementations of the fourth aspect, when it is determined that the security context is not activated, the terminal device does not perform integrity verification and / or decryption on the first message; the terminal device performs the first operation according to the operation instruction type; or, the terminal device discards the first message, that is, the terminal device may not perform the first operation.
[0095] It should be understood that when the terminal device determines to activate the security context, the terminal device can perform integrity verification and / or decryption on the received first message based on the activated security context; when the terminal device determines not to activate the security context, the terminal device does not need to perform integrity verification and decryption on the first message.
[0096] In combination with the fourth aspect, in certain implementations of the fourth aspect, after activating the security context, the terminal device determines whether to perform integrity verification and / or decryption on the first message.
[0097] In combination with the fourth aspect, in certain implementations of the fourth aspect, the terminal device determines whether to perform integrity verification and / or decryption on the first message, including: the terminal device determines whether to perform integrity verification and / or decryption on the first message based on the operation instruction type of the first operation.
[0098] In combination with the fourth aspect, in certain implementations of the fourth aspect, the terminal device determines whether to perform an integrity check on the first message based on the operation instruction type, including one or more of the following: when the operation instruction type is an inventory operation, the terminal device determines not to perform an integrity check on the first message; when the operation instruction type is a read operation, the terminal device determines to perform an integrity check on the first message; when the operation instruction type is a write operation, the terminal device determines to perform an integrity check on the first message; when the operation instruction type is an invalidation operation, the terminal device determines to perform an integrity check on the first message.
[0099] In combination with the fourth aspect, in certain implementations of the fourth aspect, the terminal device determines whether to decrypt the first message based on the operation instruction type, including one or more of the following: when the operation instruction type is an inventory operation, the terminal device determines not to decrypt the first message; when the operation instruction type is a read operation, the terminal device determines not to decrypt the first message; when the operation instruction type is a write operation, the terminal device determines to decrypt the first data ciphertext carried in the first message to obtain the first data, wherein the first data is data to be written to the storage area of the terminal device; when the operation instruction type is an invalidation operation, the terminal device determines not to decrypt the first message.
[0100] In combination with the fourth aspect, in certain implementations of the fourth aspect, the terminal device determines whether to activate the security context based on the operation instruction type of the first operation, including: the terminal device determines whether to activate the corresponding security context for integrity security protection and / or the corresponding security context for confidentiality security protection based on the operation instruction type.
[0101] Exemplarily, when the operation instruction type indicates an inventory operation, the terminal device determines not to activate the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection, that is, the terminal device does not need to generate a security context; when the operation instruction type indicates a read operation or an invalidation operation, the terminal device determines to activate the corresponding security context for integrity security protection; when the operation instruction type indicates a write operation, the terminal device determines to activate the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection.
[0102] In combination with the fourth aspect, in certain implementations of the fourth aspect, the terminal device sends a second message to the network element, and the second message is used to indicate whether the first operation is executed successfully; wherein, when the operation instruction type is a read operation, the second message includes a second data ciphertext, and the second data ciphertext is obtained by encrypting the second data, and the second data is data read from the storage area of the terminal device or collected by the terminal device.
[0103] Optionally, when the operation instruction type is an inventory operation, the terminal device may not send the second message. At this time, the core network sends the terminal device identifier to the operation requester, and the terminal device identifier can be obtained from the registration request message.
[0104] In combination with the fourth aspect, in certain implementations of the fourth aspect, before the terminal device sends the second message to the network element, the method also includes: the terminal device determines whether to perform security protection on the second message based on the type of operation instruction, and the security protection includes confidentiality security protection and / or integrity security protection.
[0105] In combination with the fourth aspect, in certain implementations of the fourth aspect, the terminal device determines whether to perform security protection on the second message based on the operation instruction type, including one or more of the following: when the operation instruction type is an inventory operation, the terminal device determines not to perform integrity security protection on the second message; when the operation instruction type is a read operation, the terminal device determines to perform integrity security protection on the second message; when the operation instruction type is a write operation, the terminal device determines to perform integrity security protection on the second message; when the operation instruction type is an invalidation operation, the terminal device determines to perform integrity security protection on the second message.
[0106] In combination with the fourth aspect, in certain implementations of the fourth aspect, the terminal device determines whether to perform security protection on the second message based on the operation instruction type, including one or more of the following: when the operation instruction type is an inventory operation, the terminal device determines not to perform confidentiality security protection on the second data; when the operation instruction type is a read operation, the terminal device determines to perform confidentiality security protection on the second message; when the operation instruction type is a write operation, the terminal device determines not to perform confidentiality security protection on the second message; when the operation instruction type is an invalidation operation, the terminal device determines not to perform confidentiality security protection on the second message.
[0107] In combination with the fourth aspect, in certain implementations of the fourth aspect, the method also includes: determining whether to delete the security context based on the type of the terminal device, specifically including one or more of the following: when the type of the terminal device is an active tag or a semi-passive tag, determining not to delete the security context; when the type of the terminal device is a passive tag, determining to delete the security context.
[0108] Exemplarily, the first message may be a registration accept message, and the second message may be a registration complete message; or, the first message may be a NAS SMC message, and the second message may be a NAS SMP message.
[0109] The beneficial effects of the fourth aspect and certain implementation methods of the fourth aspect can be referred to the corresponding description of the first aspect and will not be repeated here.
[0110] In a fifth aspect, a communication method is provided. The method can be executed by a network element, or can also be executed by a chip or circuit for a network element, and this application does not limit this. For ease of description, the following is an example of execution by a network element. It should be understood that when the TMF is set up independently, the method may be executed by the TMF and other network elements (such as the AMF). This application does not limit this.
[0111] The method includes: receiving a registration request message from a terminal device, the registration request message is used to request registration to a network, and the registration request message includes an identifier of the terminal device; determining whether to activate a security context based on an operation instruction type of a first operation, the security context being used to protect secure communications between the terminal device and a network element; if it is determined that the security context is activated, performing security protection on a first message to be sent based on the security context, the first message being used to request execution of a first operation on the terminal device; sending the first message to the terminal device; or, if it is determined that the security context is not activated, sending the first message to the terminal device.
[0112] Optionally, the first message includes an operation instruction type, where the operation instruction type is used to indicate the first operation.
[0113] In combination with the fifth aspect, in certain implementations of the fifth aspect, whether to activate the security context is determined based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, determining not to activate the security context; when the operation instruction type indicates a read operation, determining to activate the security context; when the operation instruction type indicates a write operation, determining to activate the security context; when the operation instruction type indicates an invalidation operation, determining to activate the security context.
[0114] In combination with the fifth aspect, in certain implementations of the fifth aspect, a service request message is received from the operation requester, and the service request message is used to request to perform a first operation on the terminal device; a service response message is sent to the operation requester, and the service response message is used to indicate whether the first operation is performed successfully.
[0115] Optionally, the service request message includes an operation instruction type, where the operation instruction type is used to indicate the first operation.
[0116] In combination with the fifth aspect, in certain implementations of the fifth aspect, after the security context is activated, it is determined whether to perform security protection on the first message.
[0117] In combination with the fifth aspect, in certain implementations of the fifth aspect, determining whether to activate the security context is based on the operation instruction type of the first operation, including: determining whether to activate the corresponding security context for integrity security protection and / or the corresponding security context for confidentiality security protection based on the operation instruction type.
[0118] Exemplarily, when the operation instruction type indicates an inventory operation, it is determined not to activate the security context corresponding to the integrity security protection and the security context corresponding to the confidentiality security protection, that is, there is no need to generate a security context; when the operation instruction type indicates a read operation or an invalidation operation, it is determined to activate the security context corresponding to the integrity security protection; when the operation instruction type indicates a write operation, it is determined to activate the security context corresponding to the integrity security protection and the security context corresponding to the confidentiality security protection.
[0119] In combination with the fifth aspect, in certain implementations of the fifth aspect, the security capabilities of the terminal device are used to determine the security algorithm in the security context, and the method also includes: obtaining the security capabilities of the terminal device from the operation requester; or, obtaining the security capabilities of the terminal device from the terminal device; or, obtaining the security capabilities of the terminal device from a unified data management network element.
[0120] In combination with the fifth aspect, in certain implementations of the fifth aspect, determining whether to perform security protection on the first message includes: the terminal device determines whether to perform security protection on the first message based on the operation instruction type of the first operation.
[0121] In combination with the fifth aspect, in certain implementations of the fifth aspect, determining whether to perform security protection on the first message is based on the operation instruction type, including one or more of the following: when the operation instruction type is an inventory operation, determining not to perform integrity security protection on the first message; when the operation instruction type is a read operation, determining to perform integrity security protection on the first message; when the operation instruction type is a write operation, determining to perform integrity security protection on the first message; when the operation instruction type is an invalidation operation, determining to perform integrity security protection on the first message.
[0122] In combination with the fifth aspect, in certain implementations of the fifth aspect, determining whether to perform security protection on the first message is based on the operation instruction type, including one or more of the following: when the operation instruction type is an inventory operation, determining that confidentiality security protection is not performed on the first message; when the operation instruction type is a read operation, determining that confidentiality security protection is not performed on the first message; when the operation instruction type is a write operation, determining that confidentiality security protection is performed on the first data to obtain a first data ciphertext, wherein the first data ciphertext is carried in the first message, and the first data is data to be written to the storage area of the terminal device; when the operation instruction type is an invalidation operation, determining that confidentiality security protection is not performed on the first message.
[0123] In combination with the fifth aspect, in certain implementations of the fifth aspect, before sending the first message to the terminal device, the method also includes: determining whether to send the first message to the terminal device based on the type of the terminal device; and determining to send the first message to the terminal device when the type of the terminal device is a tag type.
[0124] In combination with the fifth aspect, in certain implementations of the fifth aspect, before sending the first message to the terminal device, the method also includes: determining whether to send the first message to the terminal device based on the business type corresponding to the first operation; and determining to send the first message to the terminal device when the business type corresponding to the first operation is a label service.
[0125] In combination with the fifth aspect, in certain implementations of the fifth aspect, before sending a service response message to the operation requester, the method also includes: receiving a second message from the terminal device, the second message being used to indicate whether the first operation is successfully executed; wherein, when the operation instruction type is a read operation, the second message includes a second data ciphertext, the second data ciphertext is obtained by encrypting the second data, and the second data is data read from a storage area of the terminal device or collected by the terminal device.
[0126] In combination with the fifth aspect, in certain implementations of the fifth aspect, whether to perform integrity verification and / or decryption on the second message is determined based on the type of operation instruction.
[0127] In combination with the fifth aspect, in certain implementations of the fifth aspect, whether to perform integrity verification and / or decrypt the second message is determined based on the operation instruction type, specifically including one or more of the following: when the operation instruction type is an inventory operation, determining not to perform integrity verification on the second message; when the operation instruction type is a read operation, determining to perform integrity verification on the second message; when the operation instruction type is a write operation, determining to perform integrity verification on the second message; when the operation instruction type is an invalidation operation, determining to perform integrity verification on the second message.
[0128] In combination with the fifth aspect, in certain implementations of the fifth aspect, whether to perform integrity verification and / or decrypt the second message is determined based on the operation instruction type, specifically including one or more of the following: when the operation instruction type is a read operation, determining to decrypt the second data ciphertext to obtain the second data; when the operation instruction type is an inventory or write operation or an invalidation operation, determining not to decrypt the second message.
[0129] In combination with the fifth aspect, in certain implementations of the fifth aspect, whether to delete the security context is determined based on the type of the terminal device, specifically including one or more of the following: when the type of the terminal device is an active tag or a semi-passive tag, determining not to delete the security context; when the type of the terminal device is a passive tag, determining to delete the security context.
[0130] In combination with the fifth aspect, in certain implementations of the fifth aspect, sending a service response message to the operation requester includes: sending a service response message to the operation requester according to the operation instruction type, specifically including one or more of the following: when the operation instruction type indicates an inventory operation and the integrity check of the second message passes, the service response message is used to indicate that the first operation is successfully executed, and the service response message includes the identification of the terminal device; when the operation instruction type indicates a read operation and the integrity check of the second message passes, the service response message is used to indicate that the first operation is successfully executed, and the service response message includes the identification of the terminal device and the second data, wherein the second data is obtained by decrypting the ciphertext of the second data, and the second data is data read from the storage area of the terminal device or collected by the terminal device; when the operation instruction type indicates a write operation and the integrity check of the second message passes, the service response message is used to indicate that the first operation is successfully executed, and the service response message includes the identification of the terminal device; when the operation instruction type indicates an invalidation operation and the integrity check of the second message passes, the service response message is used to indicate that the first operation is successfully executed, and the service response message includes the identification of the terminal device.
[0131] In combination with the fifth aspect, in certain implementations of the fifth aspect, sending a service response message to the operation requester includes: sending a service response message to the operation requester according to the operation instruction type, specifically including one or more of the following: when the operation instruction type indicates a read operation and the integrity check of the second message fails and / or the decryption of the second message fails, the service response message is used to indicate that the first operation failed; when the operation instruction type indicates a write operation and the integrity check of the second message fails, the service response message is used to indicate that the first operation failed; when the operation instruction type indicates an invalid operation and the integrity check of the second message fails, the service response message is used to indicate that the first operation failed; when the operation instruction type indicates an inventory operation and the integrity check of the second message fails, the service response message is used to indicate that the first operation failed.
[0132] In conjunction with the fifth aspect, in certain implementations of the fifth aspect, if authentication of the terminal device fails, the service response message is used to indicate that the first operation failed. Optionally, the service response message carries a failure reason value to indicate that authentication of the terminal device failed.
[0133] Exemplarily, the first message may be a registration accept message, and the second message may be a registration complete message; or, the first message may be a NAS SMC message, and the second message may be a NAS SMP message.
[0134] The beneficial effects of the above-mentioned fifth aspect and certain implementation methods of the fifth aspect can be referred to the relevant description of the second aspect, which will not be repeated here.
[0135] In a sixth aspect, a communication method is provided, which can be executed by a terminal device, or can also be executed by a chip or circuit for a terminal device, which is not limited in this application. For ease of description, the following description is based on an example of execution by a terminal device.
[0136] The method includes: a terminal device sends a registration request message, the registration request message is used to request registration with a network, and the registration request message includes an identifier of the terminal device; the terminal device receives a first message from a network element, the first message is used to instruct execution of a first operation on the terminal device, and the first message is a NAS SMC message; the terminal device activates a security context according to the NAS SMC message, and the security context is used to protect secure communications between the terminal device and the network element; the terminal device performs integrity verification and / or decryption on the first message from the network element according to the security context; and after the integrity verification and / or decryption, the terminal device performs the first operation.
[0137] Optionally, the method further includes: executing an authentication process between the terminal device and the network. For example, if the network successfully authenticates the terminal device, a first message is sent to the terminal device, and correspondingly, the terminal device receives the first message from the network device.
[0138] According to the solution provided in the present application, the first operation is performed on the terminal device through the NAS SMC message instruction, that is, the NAS SMC process is used to perform service execution, which reduces the number of information interactions between the terminal device and the network element. Compared with the existing technology, the terminal device and the network element sequentially execute the authentication process, trigger the NAS SMC process, and the service execution process. This implementation method can execute the first operation while ensuring the security of network communications, simplify the processing flow of the entire service process, and reduce processing complexity and processing delay.
[0139] In combination with the sixth aspect, in certain implementations of the sixth aspect, the terminal device activates the security context according to the NAS SMC message, including: the terminal device activates the security context according to the operation instruction type of the first operation.
[0140] In combination with the sixth aspect, in certain implementations of the sixth aspect, before the terminal device activates the security context according to the operation instruction type of the first operation, the method also includes: the terminal device determines whether to activate the security context according to the operation instruction type of the first operation.
[0141] It should be understood that generating a security context and activating a security context are related, and therefore, one or the other can be selected during the judgment. For example, after determining whether to generate a security context, activating the security context also needs to be performed; for example, if determining to activate the security context, it means that the security context needs to be generated before activating the security context. Therefore, the judgments of generating a security context and activating the security context are equivalent. In other words, the judgment of whether to generate a security context and the judgment of whether to activate the security context can be interchangeable or can exist simultaneously.
[0142] Based on the above solution, by adding the judgment logic of whether to activate the security context and avoiding unnecessary generation and / or activation of the security context, the computing and storage overhead of the terminal device can be reduced, the limited storage resources of the terminal device can be avoided from being occupied, and the power consumption of the terminal device can be reduced.
[0143] In combination with the sixth aspect, in certain implementations of the sixth aspect, the terminal device determines whether to activate the security context based on the operation instruction type of the first operation, including: when the operation instruction type indicates an inventory operation, the terminal device determines not to activate the security context; when the operation instruction type indicates a read operation, the terminal device determines to activate the security context; when the operation instruction type indicates a write operation, the terminal device determines to activate the security context; when the operation instruction type indicates an invalidation operation, the terminal device determines to activate the security context.
[0144] Based on the above scheme, whether to activate the security context is determined based on whether the first operation indicated by the operation instruction type is a read operation, a write operation, or an invalidation operation, thereby avoiding unnecessary generation and / or activation of the security context for the inventory operation, reducing the computing and storage overhead of the terminal device, avoiding the storage resources of the terminal device from being occupied, and reducing the power consumption of the terminal device.
[0145] In combination with the sixth aspect, in certain implementations of the sixth aspect, the terminal device activates a security context based on the operation instruction type of the first operation, including: when the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, the terminal device activates the corresponding security context for integrity security protection; when the operation instruction type indicates a write operation, the terminal device activates the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection.
[0146] In combination with the sixth aspect, in certain implementations of the sixth aspect, the method further includes: the terminal device activating the security context according to the type of the terminal device.
[0147] In combination with the sixth aspect, in certain implementations of the sixth aspect, before the terminal device activates the security context according to the type of the terminal device, the method further includes: the terminal device determines whether to activate the security context according to the type of the terminal device.
[0148] In combination with the sixth aspect, in certain implementations of the sixth aspect, the terminal device determines whether to activate the security context based on the type of the terminal device, including: when the type of the terminal device is an active tag or a semi-passive tag, the terminal device determines to activate the security context; when the type of the terminal device is a passive tag, the terminal device activates the security context based on the operation instruction type of the first operation.
[0149] In combination with the sixth aspect, in certain implementations of the sixth aspect, the terminal device activates a security context according to the type of the terminal device, including: when the type of the terminal device is an active tag or a semi-passive tag, the terminal device activates the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection; when the type of the terminal device is a passive tag and the operation instruction type of the first operation indicates an inventory operation, a read operation, or an invalidation operation, the terminal device activates the corresponding security context for integrity security protection; when the type of the terminal device is a passive tag and the operation instruction type of the first operation indicates a write operation, the terminal device activates the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection.
[0150] In combination with the sixth aspect, in certain implementations of the sixth aspect, before the terminal device performs integrity verification and / or decryption on the first message from the network element based on the security context, the method also includes: the terminal device determines whether to perform integrity verification and / or decryption on the first message based on the operation instruction type of the first operation.
[0151] In combination with the sixth aspect, in certain implementations of the sixth aspect, the terminal device determines whether to perform an integrity check on the first message based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, the terminal device determines not to perform an integrity check on the first message; when the operation instruction type indicates a read operation, the terminal device determines to perform an integrity check on the first message; when the operation instruction type indicates an invalidation operation, the terminal device determines to perform an integrity check on the first message; when the operation instruction type indicates a write operation, the terminal device determines to perform an integrity check on the first message.
[0152] Based on the above scheme, the operation instruction type is associated with whether the integrity check of the first message is performed, and then whether the integrity check of the first message is performed is determined according to the operation instruction type, so as to avoid the terminal device from performing unnecessary integrity check operations when determining the inventory operation, which can reduce the computing overhead and power consumption of the terminal device.
[0153] In combination with the sixth aspect, in certain implementations of the sixth aspect, the terminal device determines whether to decrypt the first message based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, the terminal device determines not to decrypt the first message; when the operation instruction type indicates a read operation, the terminal device determines not to decrypt the first message; when the operation instruction type indicates an invalidation operation, the terminal device determines not to decrypt the first message; when the operation instruction type indicates a write operation, the terminal device determines to decrypt the first data ciphertext carried in the first message to obtain the first data, where the first data is the data to be written to the storage area of the terminal device.
[0154] Based on the above scheme, the operation instruction type is associated with whether the first message is decrypted, and then whether the first message is decrypted is determined according to the operation instruction type, so as to avoid the terminal device performing unnecessary decryption calculations or decryption operations when determining an inventory operation, a read operation, or an invalidation operation, thereby reducing the computing overhead and power consumption of the terminal device.
[0155] In combination with the sixth aspect, in certain implementations of the sixth aspect, the method also includes: the terminal device determines whether to perform security protection on the second message based on the operation instruction type of the first operation, the security protection includes integrity security protection and / or confidentiality security protection, the second message is used to indicate whether the first operation is executed successfully, and the second message is a NAS SMP message; the terminal device sends the second message to the network element.
[0156] In combination with the sixth aspect, in certain implementations of the sixth aspect, the terminal device determines whether to perform security protection on the second message based on the operation instruction type, including one or more of the following: when the operation instruction type indicates an inventory operation, the terminal device determines not to perform integrity security protection on the second message; when the operation instruction type indicates a read operation, the terminal device determines to perform integrity security protection on the second data; when the operation instruction type indicates a write operation, the terminal device determines to perform integrity security protection on the second message; when the operation instruction type indicates an invalidation operation, the terminal device determines to perform integrity security protection on the second message.
[0157] Based on the above scheme, the operation instruction type is associated with whether the second message is to be protected for integrity and security, and then whether the second message is to be protected for integrity and security is determined according to the operation instruction type. This avoids the terminal device from performing unnecessary integrity and security protection when determining the inventory operation, and can reduce the computing overhead and power consumption of the terminal device.
[0158] In combination with the sixth aspect, in certain implementations of the sixth aspect, the terminal device determines whether to perform security protection on the second message based on the operation instruction type, including one or more of the following: when the operation instruction type indicates an inventory operation, the terminal device determines not to perform confidentiality security protection on the second message; when the operation instruction type indicates a read operation, the terminal device determines to perform confidentiality security protection on the second data and obtains a second data ciphertext, where the second data is data in a storage area of the terminal device or data collected by the terminal device, and the second data ciphertext is carried in the second message; when the operation instruction type indicates a write operation, the terminal device determines not to perform confidentiality security protection on the second message; when the operation instruction type indicates an invalidation operation, the terminal device determines not to perform confidentiality security protection on the second message.
[0159] Based on the above scheme, the operation instruction type is associated with whether the second message is confidentiality protected, and then whether the second message is confidentiality protected is determined according to the operation instruction type. This avoids the terminal device from performing unnecessary confidentiality security protection when determining inventory operations, write operations, or failure operations, etc., which can reduce the computing overhead and power consumption of the terminal device.
[0160] In combination with the sixth aspect, in certain implementations of the sixth aspect, the method also includes: the terminal device determines whether to delete the security context based on the type of the terminal device, specifically including one or more of the following: when the type of the terminal device is an active tag or a semi-passive tag, the terminal device determines not to delete the security context; when the type of the terminal device is a passive tag, the terminal device determines to delete the security context.
[0161] Based on the above solution, by adding the judgment logic of whether to delete the security context, it is avoided that the security context is not deleted or saved when the terminal device type is a passive tag, thereby reducing the computing and storage overhead of the terminal device, avoiding the limited storage resources of the terminal device from being occupied, and reducing the power consumption of the terminal device.
[0162] In the seventh aspect, a communication method is provided. The method can be executed by a network element, or can also be executed by a chip or circuit for a network element, and this application does not limit this. For ease of description, the following is an example of execution by a network element. It should be understood that when the TMF is set up independently, the method may be executed by the TMF and other network elements (such as the AMF). This application does not limit this.
[0163] The method includes: receiving a registration request message from a terminal device, the registration request message is used to request registration with a network, and the registration request message includes an identifier of the terminal device; activating a security context, the security context is used to protect secure communications between the terminal device and a network element; performing security protection on a first message according to the security context, the security protection including integrity security protection and / or confidentiality security protection, the first message is used to instruct execution of a first operation on the terminal device, and the first message is a NAS SMC message; and sending the first message after security protection to the terminal device.
[0164] Optionally, the method further includes: performing an authentication process between the terminal device and the network. For example, if the network successfully authenticates the terminal device, activating a security context and sending a first security-protected message to the terminal device. In other words, the NAS SMC message is a security-protected message.
[0165] According to the solution provided in the present application, the first operation is performed on the terminal device through the NAS SMC message instruction, that is, the NAS SMC process is used to perform service execution, which reduces the number of information interactions between the terminal device and the network element. Compared with the existing technology, the terminal device and the network element sequentially execute the authentication process, trigger the NAS SMC process, and the service execution process. This implementation method can execute the first operation while ensuring the security of network communications, simplify the processing flow of the entire service process, and reduce processing complexity and processing delay.
[0166] In combination with the seventh aspect, in certain implementations of the seventh aspect, the security capabilities of the terminal device are used to determine the security algorithm in the security context, and the method also includes: obtaining the security capabilities of the terminal device from the operation requester; or, obtaining the security capabilities of the terminal device from the terminal device; or, obtaining the security capabilities of the terminal device from a unified data management network element.
[0167] In combination with the seventh aspect, in certain implementations of the seventh aspect, activating the security context includes: activating the security context according to the operation instruction type of the first operation and / or the type of the terminal device.
[0168] In combination with the seventh aspect, in certain implementations of the seventh aspect, before activating the security context based on the operation instruction type of the first operation and / or the type of the terminal device, the method also includes: determining whether to activate the security context based on the operation instruction type of the first operation and / or the type of the terminal device.
[0169] In combination with the seventh aspect, in certain implementations of the seventh aspect, determining whether to activate the security context is based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, determining not to activate the security context; when the operation instruction type indicates a read operation, determining to activate the security context; when the operation instruction type indicates a write operation, determining to activate the security context; when the operation instruction type indicates an invalidation operation, determining to activate the security context.
[0170] In combination with the seventh aspect, in certain implementations of the seventh aspect, determining whether to activate the security context is based on the type of the terminal device, including one or more of the following: when the type of the terminal device is an active tag or a semi-passive tag, determining to activate the security context; when the type of the terminal device is a passive tag, activating the security context based on the operation instruction type of the first operation.
[0171] In combination with the seventh aspect, in certain implementations of the seventh aspect, activating a security context according to the operation instruction type of the first operation and / or the type of the terminal device includes: activating a corresponding security context for integrity security protection and / or a corresponding security context for confidentiality security protection according to the operation instruction type of the first operation and / or the type of the terminal device.
[0172] In combination with the seventh aspect, in certain implementations of the seventh aspect, the corresponding security context for integrity security protection and / or the corresponding security context for confidentiality security protection are activated according to the operation instruction type of the first operation, including: when the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, the terminal device activates the corresponding security context for integrity security protection; when the operation instruction type indicates a write operation, the terminal device activates the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection.
[0173] In combination with the seventh aspect, in certain implementations of the seventh aspect, the corresponding security context for integrity security protection and / or the corresponding security context for confidentiality security protection are activated according to the type of the terminal device, including: when the type of the terminal device is an active tag or a semi-passive tag, activating the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection; when the type of the terminal device is a passive tag and the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, activating the corresponding security context for integrity security protection; when the type of the terminal device is a passive tag and the operation instruction type indicates a write operation, activating the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection.
[0174] In combination with the seventh aspect, in certain implementations of the seventh aspect, before performing security protection on the first message according to the security context, the method further includes: determining whether to perform security protection on the first message according to the operation instruction type of the first operation.
[0175] In combination with the seventh aspect, in certain implementations of the seventh aspect, determining whether to perform security protection on the first message is based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, determining not to perform integrity security protection on the first message; when the operation instruction type indicates a read operation, determining to perform integrity security protection on the first message; when the operation instruction type indicates an invalidation operation, determining to perform integrity security protection on the first message; when the operation instruction type indicates a write operation, determining to perform integrity security protection on the first message.
[0176] In combination with the seventh aspect, in certain implementations of the seventh aspect, determining whether to perform security protection on the first message is based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, determining that confidentiality security protection is not performed on the first message; when the operation instruction type indicates a read operation, determining that confidentiality security protection is not performed on the first message; when the operation instruction type indicates an invalidation operation, determining that confidentiality security protection is not performed on the first message; when the operation instruction type indicates a write operation, determining that confidentiality security protection is performed on the first data, and obtaining a first data ciphertext, the first data being data to be written to the storage area of the terminal device, and the first data ciphertext is carried in the first message.
[0177] In combination with the seventh aspect, in certain implementations of the seventh aspect, the method further includes: receiving a second message from the terminal device, the second message being used to indicate whether the first operation is successfully executed, and the second message being a NAS SMP message.
[0178] In combination with the seventh aspect, in certain implementations of the seventh aspect, the method further includes: determining whether to perform integrity verification and / or decryption on the second message based on the operation instruction type of the first operation.
[0179] In combination with the seventh aspect, in certain implementations of the seventh aspect, determining whether to perform an integrity check on the second message is based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, determining not to perform an integrity check on the second message; when the operation instruction type indicates a read operation, determining to perform an integrity check on the second message; when the operation instruction type indicates an invalidation operation, determining to perform an integrity check on the second message; when the operation instruction type indicates a write operation, determining to perform an integrity check on the second message.
[0180] In combination with the seventh aspect, in certain implementations of the seventh aspect, determining whether to decrypt the second message is based on the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates a read operation, determining to decrypt the second data ciphertext carried in the second message to obtain the second data, where the second data is data in a storage area of the terminal device or data collected by the terminal device; when the operation instruction type indicates a write operation, determining not to decrypt the second message; when the operation instruction type indicates an invalidation operation, determining not to decrypt the second message; when the operation instruction type indicates an inventory operation, determining not to decrypt the second message.
[0181] In combination with the seventh aspect, in certain implementations of the seventh aspect, the method also includes: determining whether to delete the security context based on the type of the terminal device, specifically including one or more of the following: when the type of the terminal device is an active tag or a semi-passive tag, determining not to delete the security context; when the type of the terminal device is a passive tag, determining to delete the security context.
[0182] In combination with the seventh aspect, in some implementations of the seventh aspect, the method also includes: receiving a service request message from an operation requester, the service request message is used to request to perform a first operation on the terminal device; sending a service response message to the operation requester according to the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, the service response message includes the identification of the terminal device; when the operation instruction type indicates a read operation, the service response message includes the identification of the terminal device and second data, the second data being data read from a storage area of the terminal device or collected by the terminal device; when the operation instruction type indicates a write operation, the service response message includes the identification of the terminal device; when the operation instruction type indicates an invalid operation, the service response message is used to indicate that the first operation is successfully executed, and the service response message includes the identification of the terminal device.
[0183] In combination with the seventh aspect, in certain implementations of the seventh aspect, the method further includes: receiving a service request message from an operation requester, the service request message being used to request execution of a first operation on a terminal device, and sending a first service response message to the operation requester according to the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates an inventory operation, the first service response message is used to indicate that the first operation is successfully executed, and the first service response message includes an identifier of the terminal device; when the operation instruction type indicates a read operation and the integrity check and / or decryption of the second message passes, the first service response message is used to indicate that the first operation is successfully executed, and the first service response message includes an identifier of the terminal device and second data, wherein the second data is obtained by decrypting a ciphertext of the second data, and the second data is data read from a storage area of the terminal device or collected by the terminal device; when the operation instruction type indicates a write operation and the integrity check of the second message passes, the first service response message is used to indicate that the first operation is successfully executed, and the first service response message includes an identifier of the terminal device; when the operation instruction type indicates an invalidation operation and the integrity check of the second message passes, the first service response message is used to indicate that the first operation is successfully executed, and the first service response message includes an identifier of the terminal device.
[0184] In combination with the seventh aspect, in some implementations of the seventh aspect, the method also includes: receiving a service request message from an operation requester, the service request message is used to request execution of a first operation on the terminal device, and sending a second service response message to the operation requester according to the operation instruction type of the first operation, including one or more of the following: when the operation instruction type indicates a read operation and the integrity check of the second message fails and / or the decryption of the second message fails, the second service response message is used to indicate that the first operation failed; when the operation instruction type indicates a write operation and the integrity check of the second message fails, the second service response message is used to indicate that the first operation failed; when the operation instruction type indicates an invalid operation and the integrity check of the second message fails, the second service response message is used to indicate that the first operation failed.
[0185] In conjunction with the seventh aspect, in certain implementations of the seventh aspect, the method further includes: receiving a service request message from an operation requester, the service request message being used to request execution of a first operation on a terminal device; and if authentication of the terminal device fails, sending a third service response message to the operation requester, the third service response message being used to indicate failure of execution of the first operation. Optionally, the third service response message carries a failure reason value indicating failure of authentication of the terminal device.
[0186] The beneficial effects of the seventh aspect and certain implementation methods of the seventh aspect can be referred to the relevant description of the sixth aspect, which will not be repeated here.
[0187] In an eighth aspect, a communication device is provided. The device includes: a transceiver unit, configured to send a registration request message to a terminal device, the registration request message being used to request registration with the network, the registration request message including an identifier of the terminal device; a processing unit, configured to activate a security context when the terminal device successfully authenticates the network, the security context being used to protect secure communications between the terminal device and the terminal device; the processing unit is further configured to perform an integrity check on a first message from a network element based on the security context, the first message being used to request execution of a first operation on the terminal device; and the processing unit is further configured to execute the first operation when the integrity check succeeds.
[0188] The transceiver unit can perform the reception and transmission processing in the aforementioned first aspect, and the processing unit can perform other processing except reception and transmission in the aforementioned first aspect.
[0189] In a ninth aspect, a communication device is provided. The device includes: a transceiver unit, configured to receive a registration request message from a terminal device, the registration request message being used to request registration with a network and including an identifier of the terminal device; a processing unit, configured to activate a security context when authentication of the terminal device is successful, the security context being used to protect secure communications between the terminal device and a network element; the processing unit further configured to perform integrity security protection on a first message based on the security context, the first message being used to request a first operation to be performed on the terminal device; and the transceiver unit further configured to send the first message to the terminal device.
[0190] The transceiver unit can perform the reception and transmission processing in the aforementioned second aspect, and the processing unit can perform other processing except reception and transmission in the aforementioned second aspect.
[0191] In a tenth aspect, a communication device is provided. The device includes: a transceiver unit configured to send a service request message to a network element, the service request message being used to request execution of a first operation on a terminal device, the service request message including security capabilities of the terminal device; and the transceiver unit being further configured to receive a service response message from the network element, the service response message being used to indicate whether the first operation was successfully executed.
[0192] The transceiver unit can perform the receiving and sending processing in the aforementioned third aspect, and the processing unit can perform other processing except receiving and sending in the aforementioned third aspect.
[0193] In an eleventh aspect, a communication device is provided. The device includes: a transceiver unit configured to send a registration request message to a network element, the registration request message being used to request registration with the network and including an identifier of a terminal device; the transceiver unit further configured to receive a first message from the network element, the first message being used to request execution of a first operation on the terminal device; and a processing unit configured to determine whether to activate a security context based on an operation instruction type of the first operation, the security context being used to protect secure communication between the terminal device and the network element.
[0194] The transceiver unit can perform the receiving and sending processing in the aforementioned fourth aspect, and the processing unit can perform other processing except receiving and sending in the aforementioned fourth aspect.
[0195] In a twelfth aspect, a communication device is provided. The device includes: a transceiver unit, configured to receive a registration request message from a terminal device, the registration request message being used to request registration with a network and including an identifier of the terminal device; a processing unit, configured to determine whether to activate a security context based on an operation instruction type of a first operation, the security context being used to protect secure communications between the terminal device and a network element; the processing unit, further configured to, if it is determined that the security context is to be activated, perform security protection on a first message to be sent based on the security context, the first message being used to request execution of a first operation on the terminal device; and the transceiver unit, further configured to send the first message to the terminal device; or, if it is determined that the security context is not to be activated, the transceiver unit, further configured to send the first message to the terminal device.
[0196] The transceiver unit can perform the reception and transmission processing in the aforementioned fifth aspect, and the processing unit can perform other processing except reception and transmission in the aforementioned fifth aspect.
[0197] In a thirteenth aspect, a communication device is provided. The device includes: a transceiver unit, configured to send a registration request message to a network element, the registration request message being used to request registration with the network, the registration request message including an identifier of a terminal device; the transceiver unit, further configured to receive a first message from the network element, the first message being used to instruct execution of a first operation on the terminal device, the first message being a NAS SMC message; a processing unit, configured to activate a security context according to the NAS SMC message, the security context being used to protect secure communication between the terminal device and the network element; the processing unit, further configured to perform integrity verification and / or decryption on the first message from the network element according to the security context; and the processing unit, further configured to cause the terminal device to execute the first operation after the integrity verification and / or decryption.
[0198] The transceiver unit can perform the reception and transmission processing in the aforementioned sixth aspect, and the processing unit can perform other processing except reception and transmission in the aforementioned sixth aspect.
[0199] In a fourteenth aspect, a communication device is provided. The device includes: a transceiver unit, configured to receive a registration request message from a terminal device, the registration request message being used to request registration with a network and including an identifier of the terminal device; a processing unit, configured to activate a security context, the security context being used to protect secure communications between the terminal device and a network element; the processing unit being further configured to perform security protection on a first message based on the security context, the security protection including integrity security protection and / or confidentiality security protection, the first message being used to instruct execution of a first operation on the terminal device, the first message being a NAS SMC message; and the transceiver unit being further configured to send the first message, after security protection, to the terminal device.
[0200] The transceiver unit can perform the reception and transmission processing in the aforementioned sixth aspect, and the processing unit can perform other processing except reception and transmission in the aforementioned sixth aspect.
[0201] In the fifteenth aspect, a communication device is provided, comprising a processor, the processor being coupled to a memory, the memory being used to store a computer program, the processor being used to call and run the computer program from the memory, so that the communication device executes the method of the above-mentioned first to third aspects and any possible implementation thereof, or the communication device executes the method of the above-mentioned third to fifth aspects and any possible implementation thereof.
[0202] Optionally, there are one or more processors and one or more memories.
[0203] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.
[0204] Optionally, the communication device further includes a transceiver.
[0205] In the sixteenth aspect, a communication system is provided, including a terminal device, a network element and / or an operation requester, wherein the terminal device is used to execute the method in the above-mentioned first aspect or fourth aspect or sixth aspect and any possible implementation thereof, the network element is used to execute the method in the above-mentioned second aspect or fifth aspect or seventh aspect and any possible implementation thereof, and the operation requester is used to execute the method in the above-mentioned third aspect and any possible implementation thereof.
[0206] In the seventeenth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program or code, and when the computer program or code is run on a computer, the computer executes the method in the above-mentioned first to third aspects and any possible implementation thereof, or the computer executes the method in the above-mentioned fourth to sixth aspects and any possible implementation thereof.
[0207] In aspect 18, a chip is provided, comprising at least one processor, wherein the at least one processor is coupled to a memory, the memory being used to store a computer program, and the processor being used to call and run the computer program from the memory, so that a terminal device equipped with the chip system executes the method in the first aspect, fourth aspect, or sixth aspect and any possible implementation thereof, or a core network element equipped with the chip system executes the method in the second aspect, fifth aspect, or seventh aspect and any possible implementation thereof, or an operation requesting party equipped with the chip system executes the method in the third aspect and any possible implementation thereof.
[0208] The chip may include an input circuit or interface for sending information or data, and an output circuit or interface for receiving information or data.
[0209] In the nineteenth aspect, a computer program product is provided, comprising: a computer program code, which, when run, executes the method in the above-mentioned first to fifth aspects and any possible implementation thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0210] FIG1 is a schematic diagram of a network architecture 100 applicable to an embodiment of the present application;
[0211] FIG2 is a schematic diagram of a network architecture 200 applicable to an embodiment of the present application;
[0212] FIG3 is a flow chart of a service triggering and execution method 300;
[0213] FIG4 is a flow chart of a communication method 400 provided in an embodiment of the present application;
[0214] FIG5 is a flow chart of a communication method 500 provided in an embodiment of the present application;
[0215] FIG6 is a flow chart of a communication method 600 provided in an embodiment of the present application;
[0216] FIG7 is a flow chart of a communication method 700 provided in an embodiment of the present application;
[0217] FIG8 is a schematic structural diagram of a communication device 1000 provided in an embodiment of the present application;
[0218] FIG9 is a schematic structural diagram of a communication device 2000 provided in an embodiment of the present application;
[0219] FIG10 is a schematic structural diagram of a chip system 3000 provided in an embodiment of the present application. DETAILED DESCRIPTION
[0220] The technical solution in this application will be described below with reference to the accompanying drawings.
[0221] The technical solutions provided in this application can be applied to various communication systems, such as new radio (NR) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, etc. The technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.
[0222] In a communication system, the part operated by an operator may be referred to as a public land mobile network (PLMN), or as an operator network, etc. PLMN is a network established and operated by the government or an operator approved by it for the purpose of providing land mobile communication services to the public. It is mainly a public network in which mobile network operators (MNOs) provide mobile broadband access services to users. The PLMN described in the embodiments of the present application may specifically be a network that complies with the standards of the 3rd Generation Partnership Project (3GPP), referred to as a 3GPP network. 3GPP networks generally include but are not limited to fifth-generation mobile communication (5th-generation, 5G) networks, fourth-generation mobile communication (4th-generation, 4G) networks, and other future communication systems, such as (6th-generation, 6G) networks.
[0223] For the convenience of description, the embodiments of the present application will be described using PLMN or 5G network as an example.
[0224] Figure 1 is a schematic diagram of a network architecture 100 applicable to an embodiment of the present application. As shown in Figure 1 , the network architecture is an Ambient IoT (A-IoT) architecture, which can also be referred to as a Passive IoT (P-IoT). The network architecture includes a terminal device 110, a core network element 120, and an operation requester 130. Optionally, the network architecture also includes a reader.
[0225] Below, each network node included in the environmental Internet of Things architecture 200 is briefly described.
[0226] 1. Terminal device 110
[0227] The terminal device 110 itself is not equipped with or does not rely on power devices such as batteries. It can obtain energy through radio, solar energy, radio frequency, light energy, wind energy, water energy, thermal energy, kinetic energy or tidal energy to support data perception, transmission and distributed computing. This application does not limit the way it obtains energy.
[0228] Exemplarily, the terminal device 110 can be in the form of a tag or other terminal forms. This application does not limit the form and name of the terminal device. For details, please refer to the relevant description of the terminal device part described in Figure 2 below. For ease of explanation, the embodiment of this application takes the terminal device 110 as a tag as an example. It should be understood that the tag includes a passive tag, a semi-passive tag, and an active tag. Among them, the passive tag can be called a type A device, which is characterized by no energy storage and cannot generate signals independently; the semi-passive tag can be called a type B device, which is characterized by a certain amount of energy storage for reflecting signals and cannot generate signals independently; the active tag can be called a type C device, which is characterized by energy storage and can generate signals independently, such as including an active radio frequency component for transmission.
[0229] 2. Core network element 120
[0230] The core network element 120 may be a core network element in a 5G network. For details, see the relevant description of the core network portion shown in FIG2 below. For example, the core network element may be an access and mobility management function (AMF), which is responsible for access control and mobility management of the terminal device 110 accessing the operator network, such as mobility state management, allocation of temporary user identities, authentication and authorization of users, and other functions.
[0231] 3. Operation requester 130
[0232] The operation requester 130 can be understood as a device that sends an operation instruction type, including but not limited to: a server, a passive Internet of Things server P-IoT server, an application function (AF), a network function (NF) or other devices that send an operation instruction type. Exemplarily, the operation requester 130 can correspond to a certain type of user, and this type of user can include an enterprise, a tenant, a third party or a company, and this application is not limited to this. Among them, the operation requester 130 corresponding to a certain type of user can be understood as the operation requester 130 belonging to this type of user and being managed by this type of user.
[0233] When the operation requester 130 performs an operation on the terminal device 110, the operation instruction type may be sent through the core network element 120. The operation instruction type includes but is not limited to: inventory operation, read operation, write operation, invalidation operation, etc. Optionally, the core network element 120 may send the operation instruction type to the terminal device through a reader.
[0234] In one example, the operation requester 130 may send the operation instruction type to the terminal device 110 through the control plane channel. Exemplarily, the operation requester 130 sends the operation instruction type to the core network element 120, and then the core network element 120 sends the operation instruction type to the terminal device 110. At this time, the server may be an NF, AF, an application server (AS) or a passive Internet of Things application function (P-IoT AF). Among them, the control plane device may be an AMF, NEF, SMF, PCF, UDM, network slice, or standalone non-public network (SNPN) authentication and authorization function (NSSAAF).
[0235] 4. Reader
[0236] The reader can interact with the terminal device 110 via radio frequency signals or wireless signals. In one example, when the terminal device 110 enters the effective recognition range of the reader, the terminal device 110 receives the radio frequency signal emitted by the reader and, using the energy obtained from the induced current, transmits the information stored in the chip (corresponding to a passive tag). In another example, the terminal device 110 stores some electrical energy through solar energy or other means and can actively transmit a signal of a certain frequency (corresponding to a semi-passive or active tag). After the reader receives and decodes the signal, it sends the data to the central information system for processing.
[0237] Exemplarily, the reader can be an access network device, such as a base station, a pole station, a micro base station, a macro station, an integrated access and backhaul (IAB) node, etc. This application does not limit the form and name of the reader. Optionally, the reader can also be a terminal device, such as a mobile phone, an IoT device, a handheld reader, etc. In this case, the operation requester 130 can send instructions to the reader through the user plane device and the access network device (such as RAN), requesting to perform one or more of the following operations: inventory operation (or inventory operation), read operation, write operation, and invalidation operation. For ease of explanation, the embodiment of this application is described as an example in which the reader is a base station (such as gNB). At this time, the reader has the function of performing at least one of the following operations on the terminal device 110: inventory operation (or inventory operation), read operation, write operation, invalidation operation (or deactivation operation), etc.
[0238] The following is a brief description of the above operations.
[0239] (1) Inventory operation, that is, taking inventory of the existing terminal devices, can also be understood as obtaining the identification information of the terminal devices. The identification of the terminal device can be assigned by the enterprise or by the operator. For example, the identification of the terminal device can be a globally unique code (such as the Electronic Product Code (EPC)) or a temporary identification. In the inventory process, the operation requester 130 can send an inventory instruction, and the inventory instruction can include at least one of the identification range, reader identification, and location information of the terminal device. After receiving the inventory instruction, the reader or core network element 120 takes inventory of the terminal device 110 according to the inventory instruction and sends the identification information of the terminal device to the operation requester 130. Alternatively, the operation requester 130 transmits the inventory instruction to the terminal device 110 through the reader or the core network network element 120. The terminal device 110 knows that it is an inventory operation based on the content of the instruction, and then sends the identification information of the terminal device 110 to the operation requester 130 through the reader or the core network network element 120. Alternatively, the terminal device 110 sends the identification information of the terminal device 110 to the core network network element 120 through the reader, and the core network network element 120 forwards the identification information of the terminal device 110 to the operation requester 130.
[0240] (2) Read operation, i.e., reading data from the terminal device 110. The terminal device 110 may have a storage function, and its storage area may store data. If the operation requester 130 sends a read instruction, the reader or core network element 120 performs a read operation on the terminal device 110 according to the read instruction, reads the data from the storage area of the terminal device 110, and sends the data to the operation requester 130.
[0241] (3) Write operation, i.e., writing data to the terminal device 110. If the operation requester 130 sends a write instruction including data #1, the reader or core network element 120 performs a write operation on the terminal device 110 according to the write instruction, and writes data #1 into the storage area of the terminal device 110.
[0242] (4) Invalidation operation, that is, invalidating or deactivating the terminal device 110. If the operation requester 130 can send an invalidation instruction, and the invalidation instruction includes the identifier of the terminal device 110 (i.e., the identifier of the terminal device 110 that is desired to be deactivated or invalidated), the reader or the core network element 120 performs an invalidation operation on the terminal device 110 according to the invalidation instruction. After the operation is completed, the terminal device 110 is invalidated or deactivated, which means that the terminal device 110 can no longer be inventoried or other operations can be performed. In other words, after the terminal device 110 is invalidated or deactivated, the reader cannot obtain information about the invalid terminal device 110, nor can it exchange messages with the invalid terminal device 110.
[0243] It should be understood that the network architecture 100 shown in Figure 1 above is only an example given for ease of understanding. The network architecture applicable to the embodiments of the present application is not limited to this. Any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiments of the present application.
[0244] Figure 2 is a schematic diagram of a network architecture 200 applicable to an embodiment of the present application. This diagram illustrates a 5G network architecture based on a service-based architecture (SBA) in a non-roaming scenario, as defined in the 3GPP standardization process. As shown in Figure 2 , the network architecture comprises three components: a terminal device component, a data network (DN), and a carrier network (PLMN). The functions of the network elements in each component are briefly described below.
[0245] (1) The terminal equipment part may include UE 210, which may also be referred to as user equipment (UE). The UE 210 in this application is a device with wireless transceiver functions, which can communicate with one or more core network (CN) devices via the access network device (or also referred to as access device) in the radio access network (RAN) 220. UE 210 may also be referred to as an access terminal, terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent or user device, etc. UE 210 may be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it may also be deployed on the water (such as a ship, etc.); it may also be deployed in the air (such as an airplane, balloon and satellite, etc.). UE 210 may be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a smart phone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), etc. Alternatively, UE 210 may also be a handheld device with wireless communication capabilities, a computing device, or other device connected to a wireless modem, an in-vehicle device, a wearable device, an unmanned aerial vehicle (UAV) device, or a terminal in the Internet of Things (IoT), the Internet of Vehicles (IoV), a terminal of any form in a 5G network and future networks, a relay user device, or a terminal in a future evolved 6G network, etc. The relay user device may be, for example, a 5G residential gateway (RG). For example, UE 210 may be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. Alternatively, UE 210 may also be a logical entity, a smart device (such as a mobile phone), a terminal device such as a smart terminal, or a communication device such as a server, a gateway, a base station, or a controller, or an IoT device (such as a tag, see 110 shown in FIG. 1 ), a sensor, an electricity meter, a water meter, or other IoT devices. The embodiments of the present application do not limit the type or category of terminal devices. For ease of explanation, the present application will hereinafter use UE or label to represent terminal devices as an example.
[0246] (2) The data network portion may include a data network DN 240, also known as a packet data network (PDN), which is typically located outside the operator's network, such as a third-party network. In some implementations, the DN may also be deployed by the operator, i.e., the DN is part of the PLMN. This application does not restrict whether the DN belongs to the PLMN. DN 240 can deploy a variety of services to provide data and / or voice services to UE 210.
[0247] (3) The PLMN portion of the operator network may include, but is not limited to, the (radio) access network (R)AN 120 and the core network (CN). UE 210 can establish a connection with the operator network through interfaces provided by the operator network (e.g., N1) and use data and / or voice services provided by the operator network. UE 210 can also access DN 240 through the operator network and use operator services and / or services provided by third parties deployed on DN 240.
[0248] (R)AN 220 can be considered a sub-network of the operator network and is the implementation system between the service nodes in the operator network and UE 210. To access the operator network, UE 210 first passes through (R)AN 220 and then connects to the service nodes of the operator network through (R)AN 220. The access network device (RAN device) in the embodiment of the present application is a device that provides wireless communication functions for UE 210, and can also be called a network device. RAN devices include but are not limited to: the next generation node base station (gNB) in the 5G system, the evolved node B (eNB) in the long term evolution (LTE), the radio network controller (RNC), the node B (NB), the base station controller (BSC), the base transceiver station (BTS), the home base station (for example, home evolved node B, or home node B, HNB), the base band unit (BBU), the transmission point (TRP), the transmitting point (TP), the small base station device (pico), the mobile switching center, or the network device in the future network. In systems using different wireless access technologies, the name of the device with the access network device function may be different. For the convenience of description, in all embodiments of the present application, the above-mentioned device that provides wireless communication functions for UE 210 is collectively referred to as the access network device or simply referred to as RAN or AN. It should be understood that this document does not limit the specific type of access network equipment.
[0249] The CN part may include but is not limited to the following network functions (NF): user plane function (UPF) 230, network exposure function (NEF) 231, network function repository function (NRF) 232, policy control function (PCF) 233, unified data management function (UDM) 234, unified data repository function (UDR) 235, application function (AF) 236, authentication server function (AUSF) 237, access and mobility management function (AMF) 238, and session management function (SMF) 239.
[0250] The following is a brief description of the NF functions included in CN.
[0251] 1. UPF 230 is a gateway provided by the operator, serving as the gateway for communication between the operator network and DN 240. It is primarily responsible for packet routing and transmission, packet inspection, service usage reporting, Quality of Service (QoS) processing, lawful interception, uplink packet inspection, and downlink packet storage. UPF 230, also known as user plane equipment, receives user data from DN 240 and transmits it to UE 210 via (R)AN 220. UPF 230 also receives user data from UE 210 via (R)AN 220 and forwards it to DN 240. The transmission resources and scheduling functions within UPF 230 that serve UE 210 are managed and controlled by SMF 239.
[0252] 2. NEF 231 is a control plane function provided by the operator. It primarily enables third parties to use network services. It supports network exposure, event and data analysis, provision of secure provisioning information from external applications to the PLMN, and conversion of information exchanged within and outside the PLMN. NEF 231, also known as the network exposure device, provides NNEF services.
[0253] 3. NRF 232 is a control plane function provided by the operator. It is used to maintain real-time information about network functions and services in the network. For example, it supports network service discovery, maintains the services supported by the NF profile of the NF instance, supports service discovery of the service communication proxy (SCP), maintains the SCP profile of the SCP instance, sends notifications about newly registered, deregistered, and updated NFs and SCPs, and maintains the health status of NF and SCP operations.
[0254] 4. PCF 233 is the control plane function provided by the operator. It supports a unified policy framework to govern network behavior, provide policy rules to other control functions, and provide contract information related to policy decisions.
[0255] 5. The UDM 234 is a control plane function provided by the operator and is responsible for storing information such as the subscriber permanent identifier (SUPI), the generic public subscription identifier (GPSI), and credentials of subscribers in the operator's network. This information can be used to authenticate and authorize UE 210 to access the operator's network. The SUPI is encrypted during transmission and is called a hidden subscriber subscription identifier (SUCI). The UDM 234 may also be referred to as a unified data management device, a unified data management network element, a data management device, or a unified data management entity.
[0256] 6. UDR 235 is a control plane function provided by the operator. It provides functions such as storage and retrieval of subscription data for the UDM, storage and retrieval of policy data for the PCF, and storage and retrieval of user NF group ID information. UDR 235 can also be referred to as user database device, user database entity, or user database network element. The user database primarily includes the following functions: storage and access of subscription data, policy data, application data, and other types of data.
[0257] 7. AF 236 is a control plane function provided by the operator. It primarily interacts with other NFs in the PLMN to provide services such as providing roaming UEs with information about the network they wish to visit, guiding data flow routing, and providing access to NEF 231. The AF can be deployed within the PLMN or outside the operator's network.
[0258] 8. AUSF 237 is a control plane function provided by the operator and is typically used for level 1 authentication, that is, authentication between UE 210 (subscriber) and the operator's network. After receiving an authentication request initiated by a subscriber, AUSF 237 can authenticate and / or authorize the subscriber using the authentication information and / or authorization information stored in UDM 234, or generate authentication and / or authorization information for the subscriber through UDM 234. AUSF 237 can also provide the subscriber with feedback on the authentication and / or authorization information.
[0259] 9. AMF 238 is a control plane network function provided by the operator network. It is responsible for access control and mobility management for UE 210 accessing the operator network, including, for example, mobility state management, allocation of temporary user identities, authentication and authorization of users, etc. Exemplarily, AMF 238 may also be referred to as access and mobility management device, access and mobility management function entity, access and mobility management function network element, mobility management device, mobility management network element, mobility management entity, etc., and may provide NAMF services.
[0260] 10. SMF 239 is a control plane network function provided by the operator network. It is responsible for managing the protocol data unit (PDU) session of UE 210. The terminal device transmits PDUs to and from DN 240 through PDU sessions. SMF 239 is responsible for establishing, maintaining, and deleting PDU sessions. SMF 239 includes session management (such as session establishment, modification, and release, including tunnel maintenance between the user plane function UPF 230 and (R)AN 220), selection and control of UPF 230, service and session continuity (SSC) mode selection, roaming, and other session-related functions. SMF 239 can also be called a session management device and can provide Nsmf services.
[0261] It is understood that the above network elements or functions can be physical entities in hardware devices, software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (e.g., a cloud platform). Simply put, an NF can be implemented by hardware or software.
[0262] It should be understood that the above naming is defined only to facilitate the distinction between different functions and should not constitute any limitation to this application. This application does not exclude the possibility of adopting other naming in 5G networks and other future networks. For example, in a 6G network, some or all of the above network elements may continue to use the terminology used in 5G, or may adopt other names.
[0263] In Figure 2, Nnef, Nnrf, Npcf, Nudm, Nudr, Naf, Nausf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface serial numbers. For example, the meaning of the above interface serial numbers can be found in the meaning defined in the 3GPP standard protocol, and this application does not limit the meaning of the above interface serial numbers. It should be noted that the interface name between the various network functions in Figure 2 is only an example. In a specific implementation, the interface name of the system architecture may also be other names, which is not limited by this application. In addition, the name of the message (or signaling) transmitted between the above network elements is only an example and does not constitute any limitation on the function of the message itself.
[0264] For ease of explanation, in the embodiments of this application, network functions (such as NEF 231, ..., SMF 239) are collectively referred to as NFs. That is, the NFs described later in the embodiments of this application can be replaced with any network function. Furthermore, FIG2 schematically illustrates only some network functions, and the NFs described later are not limited to the network functions shown in FIG2.
[0265] It should be understood that the above-mentioned network architecture 200 applied to the embodiment of the present application is only a network architecture described from the perspective of a service-oriented architecture, and the network architecture applicable to the embodiment of the present application is not limited thereto, and any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiment of the present application. The AMF, SMF, UPF, NEF, AUSF, NRF, PCF, and UDM shown in Figure 2 can be understood as network elements used to implement different functions in the core network, for example, they can be combined into network slices as needed. These core network network elements can be independent devices, or they can be integrated into the same device to implement different functions. This application does not limit the specific form of the above-mentioned network elements.
[0266] Based on the network architecture of Figures 1 and 2 above, in combination with Figure 3, the terminal device 110 is taken as UE (or tag), the core network element 120 is AMF, the reader is gNB, and the operation request method 130 is AF as an example to briefly explain the service triggering and execution method. For the undetailed parts, please refer to the existing protocol.
[0267] Figure 3 is a flow chart of a method for triggering and executing a service. As shown in Figure 3, the method 300 includes the following steps. For parts not described in detail, reference may be made to existing protocols.
[0268] S301, AF sends a service request message to AMF, and correspondingly, AMF receives the service request message from AF.
[0269] The service request message may be a Service Request message, used to request that operation #1 be performed on the UE. The service request message may include an operation instruction type (e.g., action or command) and a UE ID range. The operation instruction type is used to indicate that the current AF requests that operation #1 be performed on the UE, including but not limited to: inventory operation, read operation, write operation, and invalidation operation. The specific operations may be explained in the relevant description above. Optionally, when the operation instruction type indicates a write operation (or, operation #1 is a write operation), the service request message also includes data #1 (data1), which is used to represent the data to be written to the UE storage area. The UE ID range is used to indicate the group to which the UE belongs. The group may include one or more UEs, so the AF may request that operation #1 be performed on one or more UEs. Alternatively, the UE ID range may be a collection of individual UE IDs or a filter for UE matching (e.g., a MASK, which may be implemented as a field containing wildcards). For example, when the MASK is 123***, the UE ID is a 6-digit ID that begins with 123, which is not limited in this application.
[0270] Exemplarily, the AF may send a service request message to the AMF through the NEF to request that operation #1 be performed on the UE. For example, the AF sends service request message #1 to the NEF, and the NEF sends service request message #2 to the AMF, where service request message #1 and service request message #2 may be the same or different. For example, the source address carried in service request message #1 is for the AF, and the destination address is used to indicate the NEF, while the source address carried in service request message #2 is for the NEF, and the destination address is used to indicate the AMF.
[0271] S302: The AMF sends an N2 message to the gNB. Correspondingly, the gNB receives the N2 message from the AMF.
[0272] Exemplarily, the N2 message may be an N2 message, where the N2 message includes a random access indication and a MASK. The random access indication is used to trigger the gNB to initiate an incentive to the UE so that the UE accesses the network.
[0273] S303: The gNB sends a selection command message to the UE. Correspondingly, the UE receives the selection command message from the gNB.
[0274] Exemplarily, the selection command message includes a UE identifier or a UE identifier group for triggering the target UE to access the network. For example, when the selection command message includes a MASK of 123***, it indicates that the target UE with a 6-digit identifier starting with 123 accesses the network.
[0275] S304: The UE establishes a connection with the gNB.
[0276] Exemplarily, the UE randomly accesses the network, that is, the UE establishes a communication connection with the gNB.
[0277] S305: The UE sends a request message to the AMF. Correspondingly, the AMF receives the request message from the UE.
[0278] The request message is used to request a service. The request message may include UE identification information (e.g., UE ID) and UE security capabilities, where the UE security capabilities are used to indicate one or more security algorithms supported by the UE, including confidentiality security algorithms and / or integrity security algorithms.
[0279] Exemplarily, the integrity security algorithm includes one or more of the following: the AES integrity security protection algorithm, the SNOW integrity security protection algorithm, the ZUC integrity security protection algorithm, or the null integrity security protection algorithm; and the confidentiality protection algorithm includes one or more of the following: the ZUC confidentiality security protection algorithm, the AES confidentiality security protection algorithm, the SNOW confidentiality security protection algorithm, or the null integrity security protection algorithm. For example, the UE security capability is used to indicate that the integrity security algorithms supported by the UE are the SNOW integrity security protection algorithm and the ZUC integrity security protection algorithm, and the confidentiality security algorithm supported by the UE is the ZUC confidentiality security protection algorithm.
[0280] Optionally, the UE may send a request message to the AMF via the gNB. For example, the UE sends a request message #1 to the gNB, and the gNB then sends a request message #2 to the AMF. Request messages #1 and #2 are used to request services from the network. Request messages #1 and #2 carry the UE ID and security algorithms supported by the UE, such as the SNOW integrity security algorithm, the ZUC integrity security algorithm, and the ZUC confidentiality security algorithm. For ease of understanding and description, the request message is described as a Registration Request message. It should be understood that the Registration Request message is used to request registration with the network.
[0281] S306: The UE and the network perform authentication.
[0282] Exemplarily, AMF triggers the authentication process for UE. The authentication method includes but is not limited to: 5G Authentication and Key Agreement (5G-AKA) authentication method, Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA') authentication method. For example, AMF sends an authentication request #1 to AUSF, AUSF sends an authentication request #2 to UDM, authentication request #1 and authentication request #2 are used to request authentication of UE, UDM generates an authentication vector and sends authentication response #1 to AUSF, AUSF sends authentication response #2 to AMF, authentication response #1 and authentication response #2 include authentication vectors, such as authentication vectors of 5G-AKA or authentication vectors of EAP-AKA'. Taking the authentication vector of EAP-AKA' as an example, the AMF sends an EAP Request / AKA'-Challenge message to the UE through a NAS message. After the UE completes authentication and authentication of the network, it sends an EAP-Response / AKA'-Challenge message to the AMF through a NAS message. The AMF then sends a Nausf_UE Authentication_Authenticate Request message to the AUSF, carrying the EAP-Response / AKA'-Challenge message. The AUSF verifies the EAP-Response / AKA'-Challenge message. If the verification is successful, the UE is authenticated, and an EAP Success message is sent to the UE through the AMF to indicate that the authentication is successful. For the specific authentication implementation method, please refer to the relevant description of the existing protocol TS 33.501.
[0283] S307: AMF configures a priority list of algorithms allowed to be used.
[0284] Exemplarily, the configuration may be dynamically configured (configured) by the network management device or platform through signaling or messages, or it may be pre-configured (pre-configured). For example, it may be implemented by pre-saving the corresponding code, table or other method that can be used to indicate the algorithm priority list in the AMF. This application does not limit its implementation method. For example, the network management device or platform configures the AMF with an allowed algorithm priority list including an integrity security algorithm priority list and / or a confidentiality security algorithm priority list. This configuration may be pre-configured, or the AMF may send a request message to the network management device or platform in step S307 to obtain the algorithm priority list, and then the network management device or platform configures the AMF based on the request message. This application does not limit this.
[0285] For example, the algorithm priorities in the integrity security algorithm priority list are from high to low: AES integrity security protection algorithm, SNOW integrity security protection algorithm, ZUC integrity security protection algorithm, and null integrity security protection algorithm; the algorithm priorities in the confidentiality security algorithm priority list are from high to low: ZUC confidentiality security protection algorithm, AES confidentiality security protection algorithm, SNOW confidentiality security protection algorithm, and null integrity security protection algorithm.
[0286] It should be understood that the security algorithms included in the integrity security algorithm priority list and / or confidentiality security algorithm priority list provided above, as well as the corresponding algorithm priority rankings, are merely examples given for ease of understanding and are not limited in this application.
[0287] It should be noted that this application does not limit the time of occurrence of the above-mentioned step S307. Step S307 can occur at any time before step S308, such as before step S301, or after step S305.
[0288] S308: AMF selects an integrity security protection algorithm and / or a confidentiality security protection algorithm based on the UE security capabilities and the algorithm priority list.
[0289] Exemplarily, based on the UE security capabilities carried in the above step S305 and the algorithm priority list configured by the AMF in S307, the integrity security protection algorithm and confidentiality security protection algorithm selected by the AMF are: SNOW integrity security protection algorithm and ZUC confidentiality security protection algorithm, respectively.
[0290] It should be understood that after the authentication process in step S306, the UE and the AMF side usually generate or obtain a new NAS layer key (e.g., K AMF ), where the NAS layer key (e.g. K AMF The NAS SMC process is activated by triggering the NAS SMC process, which corresponds to steps S309 and S310. It should be noted that the NAS SMC process is used to notify the UE of the selected integrity security algorithm and confidentiality security algorithm, and to activate the NAS layer key.
[0291] S309: AMF sends a NAS SMC message to the UE. Correspondingly, the UE receives the NAS SMC message from the AMF.
[0292] Exemplarily, the NAS SMC message includes but is not limited to: the integrity security protection algorithm identifier and / or confidentiality security protection algorithm identifier selected by the AMF in step S308, ngKSI, replayed UE security capabilities, and MAC#1. The integrity security protection algorithm identifier is used to identify the SNOW integrity security protection algorithm selected in step S308, and the confidentiality security protection algorithm identifier is used to identify the ZUC confidentiality security protection algorithm selected in step S308. ngKSI is used to identify the NAS layer key K AMF This is because the UE may store multiple NAS security contexts, and ngKSI is used to identify a specific NAS security context. The replayed UE security capabilities are used to verify whether the UE security capabilities have been tampered with, that is, to prevent downgrade attacks. For example, the AMF uses the SNOW integrity security protection algorithm selected by the AMF to perform integrity security protection on the NAS SMC message. After the NAS SMC message is integrity protected, the calculation result of the integrity security protection can be recorded as MAC#1. The MAC#1 is carried in the NAS SMC message for the UE to perform integrity verification on the received NAS SMC message.
[0293] It should be understood that the input parameters for the AMF to calculate MAC#1 include: bearer identifier, direction parameter, counter value (counter), and information elements in the NAS SMC message. The bearer identifier is used to distinguish different bearers. For example, in a 3GPP connection, the bearer identifier can be "0x01"; in a non-3GPP connection, the bearer identifier can be "0x02". The direction parameter is used to distinguish whether the NAS SMC message is an uplink message or a downlink message. For example, in an uplink message, the direction parameter value is 0; in a downlink message, the direction parameter value is 1. The counter value is used as a freshness parameter to prevent replay attacks.
[0294] Exemplarily, the NAS security context stored in the above-mentioned UE includes: one or more of: a key identifier, a UE security capability, an uplink and downlink NAS count value, a confidentiality security protection key, an integrity security protection key, a selected integrity security protection algorithm identifier, and a confidentiality security protection algorithm identifier.
[0295] It is understood that integrity security protection can be achieved through physical or cryptographic means to ensure that information is not tampered with or modified without authorization during generation, transmission, storage, or thereafter. There are various ways to implement integrity security protection for information through cryptographic methods, such as using a one-way function (such as a hash function) with a symmetric key (integrity protection key) and the message as input parameters to generate a MAC to achieve integrity security protection for the message. Exemplarily, integrity security protection can refer to integrity protection of the message to be transmitted based on a selected integrity security protection algorithm and integrity security protection key. For example, the integrity protection key can be a NAS integrity key (Knasint). Knasint is used to provide integrity security protection for the message to be transmitted. Exemplarily, Knasint can be a UE-level key, and the input key for deriving Knasint is Kamf. The input parameters include a constant used to calculate Knasint and an integrity security protection algorithm identifier. Similarly, confidentiality security protection can refer to encryption of the message to be transmitted based on a selected confidentiality security protection algorithm and confidentiality security protection key. For example, the confidentiality security protection key may be Knasenc, which is used to perform confidentiality security protection on the message to be sent. Exemplarily, Knasenc may be a UE-level key, and the input key for deriving Knasenc is Kamf. The input parameters include a constant used to calculate Knasenc and a confidentiality security protection algorithm identifier.
[0296] Furthermore, the UE performs an integrity check on the received NAS SMC message. For example, the UE calculates MAC#2 based on the SNOW integrity security protection algorithm carried in the NAS SMC message. The specific calculation method can refer to the calculation method of MAC#1 mentioned above. Then, the UE compares MAC#1 with the MAC#1 value carried in the NAS SMC message. If the two are the same, it can be considered that the integrity check has passed; otherwise, the integrity check has failed. If the integrity check is successful, the UE saves the integrity security protection algorithm and confidentiality security protection algorithm carried in the NAS SMC message as part of the NAS security context, and uses the NAS security context to perform security protection on subsequent NAS messages (such as the NAS SMP message in step S310).
[0297] S310, the UE sends a NAS SMP message to the AMF, and correspondingly, the AMF receives the NAS SMP message from the UE.
[0298] The NAS SMP message includes MAC#2.
[0299] S311, AMF sends a registration accept message to the UE, and correspondingly, the UE receives the registration accept message from the AMF.
[0300] Exemplarily, in response to the NAS SMP message, or based on the UE information (such as authorization information, configuration information, etc.) received from other network elements, the AMF sends a registration accept message to the UE. Optionally, the registration accept message carries information for updating UE parameters, where the UE parameters may be slice information or closed access group information, etc. Further optionally, after updating the UE parameters, the UE may send a registration complete message to the AMF (not shown in the figure).
[0301] It should be noted that the above step S311 can be performed before step S312 or after step S313, and this application does not impose any restrictions on this.
[0302] Further, for the operation instruction type carried in the service request message of step S301 above, the AMF requests to perform operation #1 on the UE and executes the following step S312.
[0303] S312: The AMF sends a NAS message to the UE. Correspondingly, the UE receives the NAS message from the AMF.
[0304] The NAS message carries an operation instruction type, which is used to instruct to perform operation #1 on the UE.
[0305] It should be understood that, based on the above-described NAS SMC process, this NAS message is integrity-protected. For example, the AMF performs integrity protection on the NAS message based on the integrity protection algorithm selected in step S308. Optionally, when the operation instruction type indicates a write operation, the AMF performs confidentiality protection on data #1 in the NAS message based on the confidentiality protection algorithm selected in step S308. Accordingly, the UE performs an integrity check on the NAS message. If the integrity check succeeds, and further, optionally, if decryption is successful, the UE performs operation #1.
[0306] In one example, when the operation instruction type indicates a write operation, the NAS message includes the data ciphertext #1 carried in step S301, requesting the UE to write data #1 to the UE's storage area. Accordingly, if the UE passes the integrity check on the NAS message and successfully decrypts data ciphertext #1, the UE obtains data #1 and writes data #1 to the UE's storage area. For example, the UE may perform a decryption calculation or decryption operation on data ciphertext #1 based on a NAS confidentiality key (e.g., Knasenc) in the NAS security context to obtain the data plaintext, i.e., data #1.
[0307] In another example, when the operation instruction type indicates a read operation, the NAS message is used to request reading data stored or collected by the UE. Accordingly, if the UE passes the integrity check on the NAS message, the NAS response message in step S313 carries the data #2 stored or collected by the UE and sends it to the AMF. It should be noted that the NAS response message is integrity- and confidentiality-protected. For example, the UE uses the integrity security key and confidentiality security key in the NAS security context to protect the integrity and confidentiality of the NAS response message and the data #2 carried by the message, respectively.
[0308] In another example, when the operation instruction type indicates a failure operation, it is used to indicate that the UE is failed or deactivated, which means that the UE cannot be inventoried or other operations can no longer be performed. In other words, after the UE fails or is deactivated, the AF or AMF cannot obtain the UE's information (such as the UE ID) or exchange messages with the UE.
[0309] In another example, when the operation instruction type indicates an inventory operation, the information used to indicate the inventory of the UE, or to obtain the UE identification information, is used. For example, the UE sends the UE identification information to the AMF based on the operation instruction type. The UE identification information may be included in the NAS response message in step S313. Optionally, the AMF may include the UE ID obtained in step S305 in the service response message in step S314 and send it to the AF based on the operation instruction type.
[0310] S313: The UE sends a NAS response message to the AMF. Correspondingly, the AMF receives the NAS response message from the UE.
[0311] The NAS response message is used to indicate the completion status of operation #1.
[0312] S314, AMF sends a service response message to AF, and correspondingly, AF receives the service response message from AMF.
[0313] The service response message may be a service response message, which indicates the completion of operation #1. The service response message includes the UE ID. Optionally, when the operation instruction type indicates a read operation, the service response message also includes data #2.
[0314] It should be noted that the above process of UE requesting registration service from AMF is only an example given for easy understanding. This application is also applicable to processes such as UE requesting service update, deregistration service, service discovery, service authorization, service status subscription / status notification, etc.
[0315] In summary, the above method 300 supports the provision of passive IoT services, that is, it describes the process of the AF triggering the execution of operations on the UE. In this implementation, the operation instructions between the UE and the AMF are only executed after the authentication process (see step S306) and the NAS SMC process (see steps S309-S310) are completed. That is, steps S312 and S313 are executed after steps S306, S309-S310 are completed. The overall processing flow is relatively complex, resulting in excessive power consumption and increased latency for the AF to obtain services.
[0316] In view of this, the present application provides a communication method and a communication device, which activate the security context when the authentication between the terminal device and the network is passed, simplify the overall processing flow, reduce processing complexity and latency, and reduce power consumption.
[0317] To facilitate understanding of the embodiments of the present application, the following points are explained:
[0318] First, in this application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments based on their internal logical relationships.
[0319] Second, in this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b and c can mean: a, or b, or c, or a and b, or a and c, or b and c, or a, b and c. Wherein a, b and c can be single or multiple, respectively.
[0320] Third, throughout this application, the terms "first," "second," and various numerical references (e.g., #1, #2, etc.) are used to distinguish between different messages for ease of description and are not intended to limit the scope of the embodiments of this application. For example, they are used to distinguish between different messages, rather than to describe a specific order or precedence. It should be understood that the terms described in this manner are interchangeable, where appropriate, to enable description of scenarios beyond the embodiments of this application.
[0321] Fourth, in this application, the terms "comprise" and "have" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or are inherent to these processes, methods, products or apparatuses.
[0322] Fifth, in this application, "used to indicate" can include being used for direct indication and being used for indirect indication. When describing that a certain indication information is used to indicate A, it can include that the indication information directly indicates A or indirectly indicates A, and does not necessarily mean that the indication information carries A.
[0323] The indication methods involved in the embodiments of this application should be understood to encompass various methods that enable the party to be indicated to obtain information to be indicated. The information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately. The transmission period and / or timing of these sub-information can be the same or different. This application does not limit the specific transmission method.
[0324] In the embodiments of the present application, the "indication information" may be an explicit indication, i.e., a direct indication via signaling, or may be obtained based on parameters indicated by the signaling, in combination with other rules, other parameters, or by deduction. It may also be an implicit indication, i.e., based on a rule or relationship, or based on other parameters, or by deduction. This application does not impose specific limitations on this.
[0325] Sixth, in this application, "protocol" may refer to a standard protocol in the field of communications, such as the 5G protocol, the NR protocol, and related protocols used in future communication systems, and this application does not limit this. "Predefined" may include pre-definition. For example, protocol definition. "Preconfiguration" can be implemented by pre-saving corresponding codes, tables, or other methods that can be used to indicate relevant information in the device, and this application does not limit its specific implementation method.
[0326] Seventh, in this application, "storage" may refer to storage in one or more memories. The one or more memories may be provided separately or integrated into an encoder or decoder, a processor, or a communication device. The one or more memories may also be provided in part separately and in part integrated into a decoder, a processor, or a communication device. The memory may be any type of storage medium and is not limited in this application.
[0327] Eighth, in this application, "communication" can also be described as "data transmission", "information transmission", "data processing", etc. "Transmission" includes "sending" and "receiving".
[0328] The communication method provided in the embodiments of the present application will be described in detail below with reference to the accompanying drawings, and can be applied to the communication system shown in FIG. 1 or FIG. 2 above.
[0329] Figure 4 is a flow chart of a communication method 400 provided in an embodiment of the present application. As shown in Figure 4, the terminal device, the core network element, and the operation requester interact with each other, and the method includes one or more of the following steps. For parts not fully described, reference may be made to existing protocols.
[0330] S401: The operation requesting party sends a service request message to a core network element. Correspondingly, the core network element receives the service request message from the operation requesting party.
[0331] The service request message may be a service request message, used to request execution of a first operation on the terminal device, and the first operation may be one or more of an inventory operation, a read operation, a write operation, an invalidation operation or other operations.
[0332] Exemplarily, the service request message includes an identifier of a terminal device, such as a UE ID; or the service request message includes an identifier group (e.g., a UE ID range or a UE ID group), where the identifier group includes the UE ID. The identifier group is used to indicate a group to which the terminal device belongs, and the group may include one or more terminal devices. Thus, the operation requester can request services for one or more terminal devices.
[0333] Optionally, in the above step S401, the operation requesting party may also send a service request message to the base station, and then the base station sends the service request message to the core network element to instruct to perform the first operation on the terminal device.
[0334] In the embodiment of the present application, the terminal device may be purchased, used, and managed by the operation requester (e.g., AF), that is, the operation requester may know the security capabilities of the terminal device. Optionally, the operation requester may also obtain the security capabilities of the terminal device from the UDM / UDR.
[0335] Optionally, the service request message also includes one or more of an operation instruction type (e.g., action or command), the terminal device's security capabilities, or first data. The operation instruction type indicates the first operation, the terminal device's security capabilities indicate one or more integrity security protection algorithms and / or confidentiality security protection algorithms supported by the terminal device, and the first data is data to be written to a storage area of the terminal device. For examples of integrity security protection algorithms and / or confidentiality security protection algorithms, reference can be made to the description of method 300 above.
[0336] For example, when the first operation is an inventory operation, the service request message is used to inventory the information of the terminal device, or to obtain identification information of the terminal device, such as UE ID.
[0337] For example, when the first operation is a read operation, the service request message is used to read data in a storage area of the terminal device, or data collected by the terminal device (for example, the second data described below). Optionally, the service request message carries the security capabilities of the terminal device, and correspondingly, the core network element can store the security capabilities of the terminal device.
[0338] For example, when the first operation is a write operation, the service request message also includes first data for requesting that the first data be written into a storage area of the terminal device. Optionally, the service request message carries the security capability of the terminal device, and correspondingly, the core network element can store the security capability of the terminal device.
[0339] For example, when the first operation is a failure operation, the service request message is used to disable or deactivate the terminal device, meaning that the terminal device cannot be subsequently inventoried or subjected to other operations. In other words, after the terminal device fails or is deactivated, the operation requester cannot obtain information about the terminal device or exchange messages with it. Optionally, the service request message carries the security capabilities of the terminal device, and accordingly, the core network element can store the security capabilities of the terminal device.
[0340] In the embodiments of the present application, the security capabilities of a terminal device and the identifier of the terminal device can be a one-to-one relationship or a one-to-many relationship, that is, the security capabilities of the terminal device can be the security capabilities corresponding to a single terminal device or the security capabilities corresponding to a group of terminal devices, where one or more terminal devices in the group have the same security capabilities. For example, the security capabilities of UEs with UE IDs of 000000 to 000100 are first UE security capabilities, and the security capabilities of UEs with UE IDs of 000101 to 001000 are second UE security capabilities.
[0341] S402, the terminal device sends a registration request message to the core network element, and correspondingly, the core network element receives the registration request message from the terminal device.
[0342] The registration request message may be a registration request message, which is used to request registration with a network.
[0343] Specifically, the registration request message is used to register the terminal device with the network. Exemplarily, the registration request message includes an identifier of the terminal device (eg, UE ID).
[0344] Optionally, the registration request message also includes the security capabilities of the terminal device. For specific interpretation, please refer to the relevant description of step S305 above.
[0345] In one example, the terminal device may send a registration request message to a core network element through a base station.
[0346] Optionally, the registration request message here can be described in a higher level as a "third message" to request network services. The third message can be a NAS message or a combination of message #a sent by the terminal device to the base station and message #2 sent by the base station to the core network element. This application does not limit this.
[0347] Optionally, the present application does not specifically limit the order in which the above steps S401 and S402 are executed. In addition, step S401 only needs to be executed before step S405, for example, after executing step S402 or S403a.
[0348] Optionally, before executing step S402, the method further includes step S402a:
[0349] S402a, the core network element triggers the terminal device to access the network, that is, the terminal device establishes a communication connection with the base station. For specific implementation methods, please refer to the relevant descriptions of steps S302 to S304 of the above method 300.
[0350] Furthermore, in order to ensure communication security between the terminal device and the network, an authentication process is performed between the terminal device and the network. Specific implementation of the authentication process can be found in the description of step S306 of the above method 300, which will not be repeated here.
[0351] S403a: When the core network element successfully authenticates the terminal device, the core network element activates the security context.
[0352] It should be noted that this application does not specifically limit the timing of the core network element activating the security context. For example, the core network element may immediately generate and activate the security context if the terminal device is authenticated successfully; or, the core network element may first generate the security context if the terminal device is authenticated successfully, and then activate the security context after receiving the service request message in step S401; or, the core network element may generate and activate the security context after receiving the service request message in step S401.
[0353] S403b: When the terminal device passes the network authentication, the terminal device activates the security context.
[0354] It should be noted that this application does not specifically limit the timing of activating the security context by the terminal device. For example, the terminal device may immediately generate and activate the security context if the network authentication is successful; or the terminal device may first generate the security context if the network authentication is successful, and then activate the security context after receiving the first message in step S405; or the terminal device may generate and activate the security context after receiving the first message in step S405.
[0355] It should be noted that this application does not limit the order in which the above steps S403a and S403b are executed.
[0356] Optionally, the above authentication process can be performed once or multiple times. For example, when the terminal device is a passive tag, authentication is performed each time the terminal device communicates with the core network element. Alternatively, when the terminal device is an active or semi-passive tag, the core network element may authenticate the terminal device once every T1 period.
[0357] It should be understood that if the authentication passes, subsequent steps S403a, S403b, and S409 are executed. If the authentication fails, subsequent steps S403a, S403b, and S408 are not required, and the core network element may proceed to step S409, whereby the core network element sends a service response message to the operation requester, indicating that the first operation has failed. Optionally, the service response message includes a failure cause value indicating that authentication of the terminal device has failed.
[0358] Optionally, before executing step S403a, the method may further include steps S403c and S403d, whereby the core network element selects an appropriate security algorithm based on the security capabilities of the terminal device. Optionally, step S403c may occur before or after the above-mentioned authentication process, and this application does not limit this.
[0359] S403c: The core network element obtains the security capability of the terminal device.
[0360] Exemplarily, the core network element may obtain the security capabilities of the terminal device from the terminal device, for example, the security capabilities of the terminal device are carried in the registration request message in step S402.
[0361] Exemplarily, the core network element can obtain the security capabilities of the terminal device from the UDM / UDR. For example, when the core network element passes the authentication of the terminal device, the core network element sends a request message to the UDM / UDR to obtain the contract data of the terminal device, wherein the contract data of the terminal device includes the security capabilities of the terminal device.
[0362] Exemplarily, the core network element may obtain the security capability of the terminal device from the operation requester, for example, the security capability of the terminal device is carried in the service request message in step S401.
[0363] It should be understood that in the latter two implementation methods, the security capabilities of the terminal device are transmitted through a security-protected interface, which can not only reduce the air interface overhead between the terminal device and the core network element, but also avoid the interaction failure caused by malicious tampering by an attacker when the terminal device reports the security capabilities of the terminal device through the air interface.
[0364] Optionally, the core network element may determine whether to execute step S403c and / or step S403d according to the type of the operation instruction.
[0365] For example, the triggering condition of step S403c may be: the core network element successfully authenticates the terminal device, and the first operation requested by the operation requester is a read operation, a write operation, or an invalidation operation. In other words, if the core network element determines that the terminal device fails authentication and / or the first operation is an inventory operation, step S403c may not be performed.
[0366] For another example, when the operation instruction type indicates any one of a read operation, a write operation, or a disable operation, step S403d is executed; when the operation instruction type indicates an inventory operation, step S403d can be skipped.
[0367] S403d: The core network element selects an integrity security protection algorithm and / or a confidentiality security protection algorithm based on the security capability of the terminal device and the algorithm priority list.
[0368] Optionally, before executing step S403d, the core network element configures an algorithm priority list. For specific configuration methods, refer to the relevant description of step S307 of method 300. Optionally, step S403d may occur before step S403a or during the execution of step S403a. That is, if the core network element successfully authenticates the terminal device, the core network element selects an integrity security protection algorithm and / or a confidentiality security protection algorithm based on the security capabilities of the terminal device and the algorithm priority list, and then activates the security context.
[0369] For example, if the security capability of a terminal device indicates that the terminal device supports a confidentiality security protection algorithm and an integrity security protection algorithm, then the security algorithm selected by the core network element is a confidentiality security protection algorithm and an integrity security protection algorithm supported by the terminal device. For example, the AES integrity security protection algorithm and the AES confidentiality security protection algorithm, the core network element can determine whether the AES integrity security protection algorithm and the AES confidentiality security protection algorithm are included in the algorithm priority list configured by the core network element, or in other words, the core network element confirms whether it is allowed to use (or whether it supports) the AES integrity security protection algorithm and the AES confidentiality security protection algorithm.
[0370] Exemplarily, if the security capability of the terminal device indicates that the terminal device supports multiple confidentiality security protection algorithms and / or multiple integrity security protection algorithms, the core network network element can select one of the confidentiality security protection algorithms and / or one of the integrity security protection algorithms, and notify the terminal device of the selected confidentiality security protection algorithm and / or one of the integrity security protection algorithms. For example, the core network network element can determine whether the algorithm priority list configured by itself contains the confidentiality security protection algorithm and / or integrity security protection algorithm supported by the terminal device. If so, the core network network element can preferentially select the confidentiality security protection algorithm and / or integrity security protection algorithm with a higher priority supported by the terminal device from the algorithm priority list, and notify the terminal device of the selected confidentiality security protection algorithm and / or integrity security protection algorithm with a higher priority. Optionally, the core network element can carry the selected confidentiality security protection algorithm and / or integrity security protection algorithm in the first message of the following step S405 and send it to the terminal device, or can also send it to the terminal device through other messages. For example, the algorithm priorities in the integrity security algorithm priority list configured by the core network element are, from high to low, the following: AES integrity security algorithm, SNOW integrity security algorithm, ZUC integrity security algorithm, and null integrity security algorithm; the algorithm priorities in the configured confidentiality security algorithm priority list are, from high to low, the following: ZUC confidentiality security algorithm, AES confidentiality security algorithm, SNOW confidentiality security algorithm, and null integrity security algorithm. If the terminal device supports the SNOW integrity security algorithm and the ZUC integrity security algorithm, and the ZUC confidentiality security algorithm, the core network element selects the SNOW integrity security algorithm and the ZUC confidentiality security algorithm, and notifies the terminal device of the selected security algorithm for subsequent security context activation.
[0371] Based on the above implementation, when the core network element successfully verifies the security algorithm, it indicates that the core network element allows the use of (or supports) the security algorithm indicated by the security capability of the terminal device, and then continues to execute the method shown in, for example, steps S403a to S409; when the core network element fails to verify the security algorithm, there is no need to execute steps S403a to S408, and the core network element can execute step S409, that is, the core network element sends a service response message to the operation requester, and the service response message is used to indicate that the first operation failed to execute. Optionally, the service response message includes a failure reason value, which is used to indicate that the security algorithm supported by the core network element does not match the security capability of the terminal device, that is, the core network element rejects the service request of the operation requester.
[0372] Optionally, in the above step S403a, when the core network element authenticates the terminal device, the core network element determines whether to generate a security context (or understands as determining whether to activate the security context) before activating the security context. It should be understood that generating a security context and activating a security context are related, so one can choose to execute one when judging. For example, after judging that a security context is generated, activating the security context also needs to be executed; for example, judging that a security context is activated, it means that a security context needs to be generated before activating the security context, so the judgment of generating a security context and activating the security context can be equivalent, that is, the judgment of whether to generate a security context and whether to activate the security context can replace each other, or exist at the same time. That is, the method can also include the following step S403e.
[0373] S403e: The core network element determines whether to activate the security context.
[0374] In the first example, the core network element determines whether to activate the security context based on the operation instruction type of the first operation, which can also be understood as: the core network element determines whether to perform security protection on the message or information element corresponding to the first operation between the core network element and the terminal device.
[0375] Exemplarily, the security context includes a corresponding context for confidentiality security protection and / or a corresponding context for integrity security protection, and may include, for example, one or more of the following: a key identifier, security capabilities of the terminal device, uplink and downlink NAS count values, an integrity security protection algorithm identifier, and a confidentiality security protection algorithm identifier. For specific explanations, refer to the relevant description of the method 300. Accordingly, security protection includes confidentiality security protection and / or integrity security protection.
[0376] For example, when the operation instruction type indicates an inventory operation, the core network element determines not to activate the security context, that is, determines not to perform security protection on the messages or information elements corresponding to the first operation between the core network element and the terminal device. This is because for the inventory operation, the core network element can obtain the terminal device identifier from the registration request message based on step S402 above, and then send the terminal device identifier to the operation requester, thus completing the inventory operation. In other words, the core network element does not need to interact with the terminal device regarding messages for the inventory operation, and there is no need to generate and / or activate a security context for security protection of messages corresponding to the inventory operation.
[0377] For example, when the operation instruction type is a read operation, a write operation, or an invalidation operation, the core network network element determines to activate the security context, that is, to determine to perform security protection on the message or information element corresponding to the first operation between the core network network element and the terminal device. This is because for a read operation, the core network network element reads data from the storage area of the terminal device or reads data collected by the terminal device; for a write operation, the core network network element notifies the terminal device to write the first data (from the operation requester) into the storage area of the terminal device; for an invalidation operation, the core network network element performs an invalidation operation on the terminal device and notifies the terminal device that it has or is about to fail, that is, the terminal device may no longer perform other operations. Therefore, for the above-mentioned read operation, write operation, or invalidation operation, the terminal device and the core network network element perform information interaction, and the communication security between the two can be protected by activating the security context.
[0378] Optionally, regardless of the type of operation instruction, the core network element in step S403e activates the security context. Furthermore, the core network element may determine what type of security context to activate based on the operation type, that is, determine whether to perform integrity security protection and / or confidentiality security protection based on the operation instruction type. The specific implementation method is described below.
[0379] Optionally, the method further includes: the core network element determines to activate the corresponding context for confidentiality security protection and / or the corresponding context for integrity security protection, that is, determines to perform integrity security protection and / or confidentiality security protection on the message or cell corresponding to the first operation between the terminal device and the core network element, that is, determines what specific security protection to perform. It should be understood that the core network element may determine to activate the corresponding context for confidentiality security protection and / or the corresponding context for integrity security protection after determining to activate the security context, or may directly determine to activate the corresponding context for confidentiality security protection and / or the corresponding context for integrity security protection, that is, it may not make a judgment on whether to activate the security context.
[0380] Specifically, the core network element determines to activate a corresponding context for confidentiality security protection and / or a corresponding context for integrity security protection according to the type of the operation instruction.
[0381] For example, when the operation instruction type indicates an inventory operation, the core network element determines not to activate a context corresponding to integrity security protection and a context corresponding to confidentiality security protection.
[0382] For example, when the operation instruction type is a write operation, the core network element determines to activate the corresponding context for integrity security protection and the corresponding context for confidentiality security protection. In other words, the core network element determines to activate confidentiality security protection and integrity security protection. Specifically, the security context may include a confidentiality security protection key and an integrity security protection key.
[0383] For example, when the operation instruction type is a read operation or an invalidation operation, the core network element determines to activate the corresponding context of integrity security protection, that is, the core network element determines to activate integrity security protection. Specifically, the security context may include an integrity security protection key.
[0384] In the second example, the core network element determines whether to activate the security context based on the type of the terminal device, which can also be understood as: the core network element determines whether to perform security protection on the message or information element corresponding to the first operation between the core network element and the terminal device.
[0385] Exemplarily, the core network element can obtain the type of terminal device from the UDM / UDR, including active tags, semi-passive tags, or passive tags. For specific explanations, please refer to the relevant description in Figure 1 above.
[0386] For example, when the type of the terminal device is an active tag or a semi-passive tag, the core network element determines to activate the security context, that is, determines to perform security protection on the message or information element corresponding to the first operation between the core network element and the terminal device.
[0387] For example, when the terminal device is a passive tag, the core network element determines whether to activate the security context based on the operation instruction type, that is, it determines whether to perform security protection on the message or information element corresponding to the first operation between the core network element and the terminal device based on the operation instruction type. For the specific implementation method, please refer to the relevant description of the first example above.
[0388] Optionally, the method further includes: the core network element determines to activate the corresponding context of confidentiality security protection and / or the corresponding context of integrity security protection according to the type of the terminal device.
[0389] For example, when the terminal device is an active tag or a semi-passive tag, the core network element determines to activate the context corresponding to the integrity security protection and the context corresponding to the confidentiality security protection. In other words, the core network element determines to activate the confidentiality security protection and the integrity security protection. Specifically, the security context may include a confidentiality security protection key and an integrity security protection key.
[0390] For example, when the type of the terminal device is a passive tag and the operation instruction type indicates an inventory operation, the core network element determines not to activate the context corresponding to the integrity security protection and the context corresponding to the confidentiality security protection.
[0391] For example, when the terminal device is a passive tag and the operation instruction type indicates a write operation, the core network element determines to activate the context corresponding to the integrity security protection and the context corresponding to the confidentiality security protection. In other words, the core network element determines to activate the confidentiality security protection and the integrity security protection. Specifically, the security context may include a confidentiality security protection key and an integrity security protection key.
[0392] For example, when the terminal device is a passive tag and the operation instruction type indicates a read operation or an invalidation operation, the core network element determines to activate the corresponding context of integrity security protection. Specifically, the security context may include an integrity security protection key.
[0393] In this application, the confidentiality security protection key is used for confidentiality security protection of communication between the terminal device and the core network element, and the integrity security protection key is used for integrity security protection of communication between the terminal device and the core network element. The deduction process of the integrity security protection key (for example, Knasint) and the confidentiality security protection key (Knasenc) can refer to the relevant description of the above method 300.
[0394] Optionally, the core network element determines whether to skip the NAS SMC process (that is, not executing the NAS SMC process before activating the security context), which can also be called determining the timing of activating the security context, or determining how to activate the security context, etc., including the following implementation methods.
[0395] (1) The core network element determines whether to skip the NAS SMC process based on the capabilities of the terminal device. The implementation method of skipping the NAS SMC process and activating the security context in this application can also be called a low-power security context activation method, or activating the security context when the core network element successfully authenticates the terminal device.
[0396] For example, if the terminal device's capabilities indicate that the terminal device supports a confidentiality protection algorithm (e.g., the ZUC confidentiality security protection algorithm) and / or an integrity protection algorithm (e.g., the SNOW integrity security protection algorithm), the core network element can skip the NAS SMC process, that is, activate the security context when the core network element successfully authenticates the terminal device. At this point, the terminal device and the core network element can uniquely determine the security algorithm used to activate the security context, and there is no need for the two to negotiate the security algorithm through the NAS SMC process.
[0397] (2) The core network element determines whether to skip the NAS SMC process based on the type of terminal device.
[0398] Exemplarily, the terminal device includes a low-power terminal device (such as an IoT device, or a tag, etc.) or a non-low-power terminal device (also referred to as an ordinary terminal device). Optionally, for a low-power terminal device, the NAS SMC process can be skipped, and for an ordinary terminal device, the NAS SMC process can be skipped. The storage and computing capabilities of low-power terminal devices are weak, and skipping the SMC process meets the low-power requirements. In addition, low-power devices may support a security algorithm, and there is no need to negotiate the security algorithm through the NAS SMC process.
[0399] Specifically, tags may include active tags, semi-passive tags, and passive tags. The core network element may determine whether to skip the NAS SMC process based on the type of tag. For example, when the terminal device is a passive tag, the core network element may choose to skip the NAS SMC process, that is, to activate the security context when the core network element successfully authenticates the terminal device. This is because for terminal devices of the passive tag type, the storage and computing capabilities are weak, and skipping the SMC process meets their low power consumption requirements. In addition, the cost of such devices is relatively low, and they may support an integrity security protection algorithm and / or a confidentiality security protection algorithm. Therefore, the terminal device and the core network element may uniquely determine the security algorithm used to activate the security context, and the two do not need to negotiate the security algorithm through the NAS SMC process. That is, when the core network element successfully authenticates the terminal device, the core network element may skip the NAS SMC process and activate the corresponding integrity security protection context and / or the corresponding confidentiality security protection context based on a confidentiality protection algorithm and / or an integrity protection algorithm supported by the terminal device of the passive tag type.
[0400] (3) The core network element determines whether to skip the NAS SMC process based on the locally configured security algorithm.
[0401] For example, when the security algorithm locally configured by the core network element includes a confidentiality protection algorithm (for example, the ZUC confidentiality security protection algorithm) and / or an integrity protection algorithm (for example, the SNOW integrity security protection algorithm), the terminal device and the core network element can uniquely determine the security algorithm used to activate the security context, and the two do not need to negotiate the security algorithm through the NAS SMC process. That is, when the core network element successfully authenticates the terminal device, the core network element can skip the NAS SMC process and activate the corresponding context for integrity security protection and / or the corresponding context for confidentiality security protection based on a locally configured confidentiality protection algorithm and / or an integrity protection algorithm.
[0402] It should be understood that the implementation methods provided above are merely examples for ease of understanding and do not constitute any limitation on the technical solutions of this application. The above-mentioned various implementation methods may be implemented independently or in combination, for example, including the following methods.
[0403] (4) The core network element determines whether to skip the NAS SMC process based on the type and capability of the terminal device.
[0404] For example, when the terminal device is a semi-passive tag and only supports the SNOW integrity security protection algorithm and the SNOW confidentiality security protection algorithm, the core network element may not execute the NAS SMC process. This is because the terminal device and the core network element can uniquely determine the security algorithm used to activate the security context, and the two do not need to negotiate the security algorithm through the NAS SMC process. Therefore, if the core network element successfully authenticates the terminal device, the core network element can activate the corresponding context for integrity security protection according to the SNOW integrity security protection algorithm, and activate the corresponding context for confidentiality security protection according to the SNOW confidentiality security protection algorithm.
[0405] (5) The core network element determines whether to skip the NAS SMC process based on the capabilities of the terminal device and the security algorithm locally configured in the core network element.
[0406] For example, when the security algorithms indicated by the terminal device's capabilities and the security algorithms locally configured by the core network element are both the ZUC integrity security protection algorithm and the SNOW confidentiality security protection algorithm, the core network element can skip the NAS SMC process. This is because at this time the terminal device and the core network element can uniquely determine the security algorithm used to activate the security context, and the two do not need to negotiate the security algorithm through the NAS SMC process. Therefore, the core network element can activate the corresponding context for integrity security protection according to the ZUC integrity security protection algorithm, and / or activate the corresponding context for confidentiality security protection according to the SNOW confidentiality security protection algorithm.
[0407] It should be understood that the combination implementation provided above is merely an example given for ease of understanding and does not constitute any limitation to the technical solution of the present application.
[0408] Optionally, in the above step S403b, the terminal device determines whether to generate a security context (or understands as determining whether to activate the security context) before activating the security context, that is, the method may also include the following step S403f.
[0409] S403f, the terminal device determines whether to activate the security context.
[0410] Exemplarily, the terminal device determines whether to activate the security context based on the operation instruction type of the first operation and / or the type of the terminal device. It can also be understood as: the terminal device determines whether security protection is performed on the message or information element corresponding to the first operation between the terminal device and the core network element. The specific implementation method refers to the relevant description on the core network element side in the above step S403e, which will not be repeated here.
[0411] Optionally, regardless of the type of operation instruction, the terminal device in step S403f activates the security context. Furthermore, the terminal device can determine what type of security context to activate based on the operation type, that is, whether to perform integrity security protection and / or confidentiality security protection based on the operation instruction type. The specific implementation method is described below.
[0412] Optionally, the method also includes: the terminal device determines whether to activate the corresponding context of confidentiality security protection and / or the corresponding context of integrity security protection based on the operation instruction type and / or the type of the terminal device, that is, based on the operation instruction type and / or the type of the terminal device, it determines whether to perform security protection on the message or information element corresponding to the first operation between the terminal device and the core network element. For the specific implementation method, please refer to the relevant description on the core network element side in the above step S403e, which will not be repeated here.
[0413] Optionally, the terminal device can determine whether to skip the NAS SMC process (that is, not execute the NAS SMC process before activating the security context), which can also be called determining the timing of activating the security context, or determining how to activate the security context, etc., including the following implementation methods.
[0414] (1) The terminal device determines whether to skip the NAS SMC process based on the terminal device's capabilities. The implementation method of skipping the NAS SMC process and activating the security context in this application can also be referred to as a low-power security context activation method, or as activating the security context when the terminal device successfully authenticates the core network element.
[0415] (2) The terminal device determines whether to skip the NAS SMC process based on the type of the terminal device.
[0416] (3) The terminal device determines whether to skip the NAS SMC process based on the locally configured security algorithm.
[0417] It should be understood that the specific implementation methods of the above (1)-(3) can refer to the relevant descriptions of the methods (1)-(3) on the core network element side above.
[0418] (4) The terminal device determines the time to generate and / or activate the security context based on the EAP-success message and / or authentication request message received in the authentication process. That is, the terminal device generates and / or activates the security context in response to the EAP-success message and / or authentication request message.
[0419] Exemplarily, the EAP-success message is used to indicate that the network has successfully authenticated the terminal device. That is, the message received by the terminal device after sending the registration request message is an EAP-success message, indicating that the network has successfully authenticated the terminal device. In response to the EAP-success message, the security context is activated when it is determined that the terminal device has successfully authenticated the network.
[0420] Exemplarily, the authentication request message includes a network-side authentication vector, which is used by the terminal device to authenticate the network. This authentication vector is used by the terminal device to authenticate the network. Specifically, after sending a registration request message, the terminal device receives the authentication request message, authenticates the network based on the authentication vector carried in the authentication request message, and activates the security context if the terminal device successfully authenticates the network.
[0421] (5) The terminal device determines the time to generate and / or activate the security context based on the received registration acceptance message or the first message. That is, in response to the registration acceptance message, the terminal device generates and / or activates the security context.
[0422] Optionally, the registration acceptance message may be a first message, and the registration acceptance message is used to accept the registration request of the terminal device. In this case, the registration acceptance message may carry an operation instruction type instructing the terminal device to perform a first operation.
[0423] Exemplarily, the message received by the terminal device after sending the registration request message is a registration acceptance message, indicating that the network accepts the registration request of the terminal device. In response to the registration acceptance message, the terminal device can activate the security context if the terminal device passes the authentication of the network.
[0424] Exemplarily, the terminal device can uniquely determine the security algorithm used to activate the security context based on a confidentiality protection algorithm identifier (for example, the confidentiality security protection algorithm identifier is used to indicate the ZUC confidentiality security protection algorithm) and / or an integrity protection algorithm identifier (for example, the integrity security protection algorithm identifier is used to indicate the SNOW integrity security protection algorithm) carried in the registration acceptance message. Therefore, there is no need to negotiate the security algorithm through the NAS SMC process, which can reduce the interaction process between the two. Then, when the terminal device passes the authentication of the network, the terminal device activates the confidentiality security key and / or integrity security key in the security context according to the ZUC confidentiality security protection algorithm and / or the SNOW integrity security protection algorithm.
[0425] It should be understood that the implementation methods provided above are merely examples for ease of understanding and do not constitute any limitation on the technical solutions of this application. The above-mentioned various implementation methods can be implemented independently or in combination, for example, including the following methods.
[0426] (6) The terminal device determines whether to skip the NAS SMC process based on the type of the terminal device and the capabilities of the terminal device.
[0427] (7) The terminal device determines whether to skip the NAS SMC process based on the terminal device's capabilities and the security algorithm locally configured on the terminal device.
[0428] It should be understood that the specific implementation methods of the above (6)-(7) can refer to the relevant descriptions of the methods (4)-(5) on the core network element side above.
[0429] (8) The terminal device generates and / or activates a security context based on the terminal device's capabilities, the security algorithm locally configured on the terminal device, and the EAP-success message and / or authentication request message received during the authentication process.
[0430] For example, when the type of the terminal device is a passive tag, the message received by the terminal device after sending the registration request message is an EAP-success message, and the security algorithm locally configured by the terminal device is: ZUC confidentiality security protection algorithm and / or SNOW integrity security protection algorithm, then it means that the network has successfully authenticated the terminal device. At the same time, the terminal device and the core network element can uniquely determine the security algorithm used to activate the security context. The two do not need to negotiate the security algorithm through the NAS SMC process, so the NAS SMC process can be skipped. At this time, in response to the EAP-success message, the terminal device can activate the corresponding context for integrity security protection and / or the corresponding context for confidentiality security protection according to the ZUC confidentiality security protection algorithm and / or the SNOW integrity security protection algorithm when it is determined that the terminal device has successfully authenticated the network.
[0431] It should be noted that the above-mentioned combination implementation methods are merely examples given for ease of understanding and should not constitute a limitation on the solution of this application.
[0432] S404: The core network element performs integrity protection and / or confidentiality security protection on the first message according to the security context.
[0433] Exemplarily, the core network element performs integrity protection on the first message to be sent based on the integrity security protection algorithm and / or the integrity security protection key Knasint in the security context, and may record the calculation result of the integrity security protection on the first message as MAC#1, which is carried in the first message in step S405. Similarly, the core network element performs confidentiality protection on the first data based on the confidentiality security protection algorithm and / or the confidentiality security protection key Knasenc in the security context to obtain a first data ciphertext, which is carried in the first message in step S405. For specific implementations of integrity protection and / or confidentiality security protection, reference may be made to the relevant description of method 300 above.
[0434] Optionally, before executing step S404, the method further includes step S404a:
[0435] In step S404a, the core network element determines whether to perform integrity security protection and / or confidentiality security protection on the first message. That is, based on the core network element's determination to activate the security context in step S403e above, the core network element may further determine whether security protection and / or what type of protection (integrity security protection and / or confidentiality security protection) is to be performed on the first message corresponding to the first operation between the core network element and the terminal device, or determine to activate the context corresponding to the integrity security protection and / or the context corresponding to the confidentiality security protection.
[0436] Exemplarily, the core network element determines whether to perform integrity security protection and / or confidentiality security protection on the first message according to the type of operation instruction.
[0437] For example, when the operation instruction type indicates an inventory operation, the core network element determines not to perform integrity security protection on the first message, that is, there is no need to generate and / or activate a context corresponding to integrity security protection.
[0438] For example, when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, the core network element determines to perform integrity security protection on the first message, that is, generates and / or activates a context corresponding to integrity security protection.
[0439] Among them, the calculation result of the integrity security protection of the first message by the above-mentioned core network network element is recorded as MAC#1, which is carried in the first message and sent to the terminal device for the terminal device to perform integrity verification on the first message.
[0440] For example, when the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, the core network element determines that confidentiality security protection is not performed on the first message, that is, there is no need to generate and / or activate the corresponding context for confidentiality security protection.
[0441] For example, when the operation instruction type indicates a write operation, the core network network element determines to perform confidentiality security protection on the first data carried in the service request message of step S401 to obtain a first data ciphertext, that is, to generate and / or activate the corresponding context for confidentiality security protection, and the first data ciphertext is carried in the first message.
[0442] It should be noted that the above-mentioned integrity security protection and confidentiality security protection for the first message can be implemented independently or in combination. For example, when the operation instruction type indicates an inventory operation, the core network network element may not perform integrity security protection on the first message and may not perform confidentiality security protection; when the operation instruction type indicates a read operation, the core network network element may perform integrity security protection on the first message and may not perform confidentiality security protection; when the operation instruction type indicates a write operation, the core network network element may perform integrity security protection on the first message and may not perform confidentiality security protection; when the operation instruction type indicates a write operation, the core network network element may perform integrity security protection on the first message and may perform confidentiality security protection on the first data.
[0443] Optionally, the core network element may also determine whether to activate the security context based on the above step S403e, and then perform corresponding security protection (integrity security protection and / or confidentiality security protection) on the first message according to the security context. That is, in the above example, the judgment step of the core network element determining whether to perform integrity security protection and / or confidentiality security protection on the first message may not be performed, and the judgment result of step S403e may be used. For example, in step S403e, if the core network element determines to activate the security context, then in step S404a, it may be determined to perform corresponding integrity security protection and / or confidentiality security protection on the first message; if the core network element determines not to activate the security context, then in step S406a, it is determined not to perform integrity security protection and / or confidentiality security protection on the first message.
[0444] S405, the core network element sends a first message to the terminal device, and correspondingly, the terminal device receives the first message from the core network element.
[0445] Exemplarily, the core network element may send the first message to the terminal device through the base station.
[0446] Optionally, the first message may be a registration acceptance message in response to step S402. That is, when the core network element determines that the authentication of the terminal device is passed, it skips the NAS SMC process and sends a security-protected registration acceptance message to the terminal device, thereby reducing the number of interactions between the terminal device and the core network element, simplifying the processing complexity of the entire process, and reducing processing delay. Optionally, the registration acceptance message may carry the operation instruction type of the first operation, which is used to instruct the network side to accept the registration request of the terminal device, and to instruct the terminal device to perform the first operation. For example, when the operation instruction type indicates a read operation, a write operation, or an invalid operation, the registration acceptance message also includes MAC#1. Wherein, when the operation instruction type indicates a write operation, the registration acceptance message also includes the first data ciphertext. Optionally, the operation instruction type of the first operation may not be carried in the registration acceptance message. In this case, the operation instruction type and the registration acceptance message may be sent simultaneously or separately, and this application does not limit this.
[0447] Optionally, the operation instruction type may be sent in plain text, for the terminal device to determine the first operation.
[0448] It should be noted that the present application does not impose any restrictions on the order in which the above steps S405 and S403b are executed. That is, the terminal device may first activate the security context and then receive the first message from the core network element; or, it may first receive the first message from the core network element and then activate the security context. That is, the present application does not impose any specific restrictions on the timing for the terminal device to activate the security context.
[0449] Optionally, the core network element may also send a registration acceptance message to the terminal device, that is, the first message is not a registration acceptance message. In this case, the registration acceptance message may be protected according to the above security context or not, which is not limited in this application.
[0450] S406: The terminal device performs integrity verification and / or decryption on the first message according to the security context.
[0451] Exemplarily, the terminal device calculates MAC#2 based on the integrity security protection algorithm in the security context. The specific calculation method can refer to the calculation method of MAC#1 described above. Furthermore, the terminal device compares MAC#1 and MAC#2 carried in the first message. If the two are identical, the integrity check is considered to have passed; otherwise, the integrity check has failed.
[0452] Exemplarily, the terminal device performs a decryption calculation or decryption operation on the first data ciphertext in the first message based on the confidentiality security protection algorithm and / or confidentiality security protection key (e.g., Knasenc) in the security context to obtain the first data, indicating a successful decryption; otherwise, the decryption fails. It should be understood that this implementation corresponds to a write operation.
[0453] Optionally, if the terminal device fails to perform integrity check in the above step S406, and / or decryption is unsuccessful, the terminal device refuses to perform the first operation. At this time, the second message in the following step S408 is used to indicate that the first operation failed. Optionally, the second message carries a failure reason value to indicate that the integrity check of the first message failed, and / or the decryption of the first data ciphertext was unsuccessful. Further, the core network network element sends a service response message in step S409 to indicate that the first operation failed. Optionally, the service response message carries a failure reason value to indicate that the integrity check of the first message failed, and / or the decryption of the first data ciphertext was unsuccessful.
[0454] Optionally, before executing step S406, the method further includes step S406a:
[0455] In step S406a, the terminal device determines whether to perform integrity check and / or decryption on the first message. That is, based on the terminal device's determination to activate the security context in step S403f above, the terminal device may further determine whether to perform de-security protection (integrity check and / or decryption) on the first message corresponding to the first operation between the terminal device and the core network element and / or what type of de-security protection to perform, or in other words, determine to activate the context corresponding to integrity security protection and / or the context corresponding to confidentiality security protection.
[0456] Exemplarily, the terminal device determines whether to perform integrity verification and / or decryption on the first message according to the type of operation instruction.
[0457] For example, when the operation instruction type indicates an inventory operation, the terminal device determines not to perform integrity check on the first message, that is, there is no need to generate and / or activate a corresponding context for integrity security protection.
[0458] For example, when the operation instruction type indicates a read operation, an invalidation operation, or a write operation, the terminal device determines to perform an integrity check on the first message, that is, to generate and / or activate a corresponding context for integrity security protection.
[0459] For example, when the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, the terminal device determines not to decrypt the first message, that is, there is no need to generate and / or activate a corresponding context for confidentiality security protection.
[0460] For example, when the operation instruction type indicates a write operation, the terminal device determines to decrypt the first data ciphertext carried in the first message to obtain the first data, that is, to generate and / or activate the corresponding context for confidentiality security protection.
[0461] It should be noted that the integrity check and decryption of the first message described above can be implemented independently or in combination. For example, if the operation instruction type indicates an inventory operation, the terminal device may not perform an integrity check on the first message and may not decrypt it. If the operation instruction type indicates a read operation, the terminal device may perform an integrity check on the first message and may not decrypt it. If the operation instruction type indicates an invalidation operation, the terminal device may perform an integrity check on the first message and may not decrypt it. If the operation instruction type indicates a write operation, the terminal device may perform an integrity check on the first message and may decrypt the first data ciphertext.
[0462] Optionally, the terminal device may also determine whether to activate the security context based on the above step S403f, and then perform corresponding security protection on the first message according to the security context. That is, in the above example, the terminal device may not perform the judgment step of determining whether to perform integrity verification and / or decryption on the first message based on the type of operation instruction, and may use the judgment result of step S403f. For example, in step S403f, if the terminal device determines to activate the security context, then in step S406a, it may be determined to perform integrity verification and / or decryption on the first message; if the terminal device determines not to activate the security context, then in step S406a, it may be determined not to perform integrity verification and / or decryption on the first message.
[0463] S407: If the integrity check passes and / or the decryption succeeds, the terminal device performs a first operation.
[0464] Exemplarily, when the integrity check passes and / or the decryption succeeds, the terminal device performs the first operation according to the operation instruction type.
[0465] For example, when the first operation is a read operation, the terminal device reports data in its storage area or collected data.
[0466] For example, when the first operation is a write operation, the terminal device writes the first data obtained by decryption in step S406 into a storage area of the terminal device.
[0467] For example, when the first operation is a disabling operation, the terminal device is determined to be disabled or inactivated.
[0468] For example, when the first operation is an inventory operation, the terminal device may report an identifier of the terminal device.
[0469] S408, the terminal device sends a second message to the core network element, and correspondingly, the core network element receives the second message from the terminal device.
[0470] The second message is used to indicate the execution status of the first operation.
[0471] Optionally, before executing step S408, the method further includes step S408a:
[0472] S408a: The terminal device performs integrity security protection and / or confidentiality security protection on the second message according to the security context.
[0473] Exemplarily, the terminal device performs integrity protection on the second message based on the integrity security protection algorithm and / or integrity security protection key Knasint in the security context. The calculation result of the integrity security protection on the second message can be recorded as MAC#2 and carried in the second message in step S408. Similarly, the terminal device performs confidentiality protection on the second data based on the confidentiality security protection algorithm and / or confidentiality security protection key Knasenc in the security context, obtaining a second data ciphertext, which is carried in the second message in step S408. The second data is data in a storage area of the terminal device, or data collected by the terminal device. For specific implementations of integrity protection and / or confidentiality security protection, please refer to the relevant description of method 300 above.
[0474] Optionally, when the first message in step S405 is a registration acceptance message, the second message may be a registration completion message. In this case, the registration completion message may carry MAC#2 and / or the second data ciphertext.
[0475] Optionally, before executing step S408a, the method further includes step S408b:
[0476] In step S408b, the terminal device determines whether to perform integrity security protection and / or confidentiality security protection on the second message. That is, based on the terminal device's determination to activate the security context in step S403f above, the terminal device can further determine whether security protection and / or what type of protection (integrity security protection and / or confidentiality security protection) is to be performed on the second message corresponding to the first operation between the terminal device and the core network element, or determine to activate the context corresponding to the integrity security protection and / or the context corresponding to the confidentiality security protection.
[0477] In one example, the terminal device determines whether to perform integrity security protection and / or confidentiality security protection on the second message according to the type of the operation instruction.
[0478] For example, when the operation instruction type indicates an inventory operation, the terminal device determines not to perform integrity security protection on the second message, that is, there is no need to generate and / or activate a context corresponding to integrity security protection.
[0479] For example, when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, the terminal device determines to perform integrity security protection on the second message, that is, generates and / or activates a corresponding context for integrity security protection.
[0480] For example, when the operation instruction type indicates an inventory operation, a write operation, or an invalidation operation, the terminal device determines not to perform confidentiality security protection on the second message, that is, there is no need to generate and / or activate a corresponding context for confidentiality security protection.
[0481] For example, when the operation instruction type indicates a read operation, the terminal device determines to perform confidentiality security protection on the second data to obtain a second data ciphertext, that is, to generate and / or activate the corresponding context for confidentiality security protection. The second data is data read from the storage area of the terminal device, or data collected by the terminal device.
[0482] It should be noted that the above-mentioned integrity security protection and confidentiality security protection for the second message can be implemented independently or in combination. For example, if the operation instruction type indicates an inventory operation, the terminal device may not perform integrity security protection on the second message, nor confidentiality security protection; if the operation instruction type indicates a read operation, the terminal device may perform integrity security protection on the second message, but not confidentiality security protection; if the operation instruction type indicates a write operation, the terminal device may perform integrity security protection on the second message, but not confidentiality security protection; if the operation instruction type indicates a write operation, the terminal device may perform integrity security protection on the second message, and not confidentiality security protection; if the operation instruction type indicates a write operation, the terminal device may perform integrity security protection on the second message, and confidentiality security protection on the second data.
[0483] Optionally, the terminal device may further determine whether to perform integrity security protection and / or confidentiality security protection on the second message based on the determination of whether to activate the security context in step S403f above, or further determine whether to perform integrity security protection and / or confidentiality security protection on the second message based on the determination of whether to perform integrity check and / or decryption on the first message in step S406a. That is, in the above example, the terminal device may not perform the step of determining whether to perform integrity security protection and / or confidentiality security protection on the second message based on the type of operation instruction, and may simply use the determination result of step S403f or S406a. For example, in step S403f, if the terminal device determines to generate and / or activate a security context, or, in step S406a, if the terminal device determines to perform integrity verification and / or decryption on the first message, then in step S408b, it is determined to perform integrity security protection and / or confidentiality security protection on the second message; if the terminal device determines not to generate and / or activate a security context, or, if the terminal device determines not to perform integrity verification and / or decryption on the first message, then in step S408b, it is determined not to perform integrity security protection and / or confidentiality security protection on the second message.
[0484] Optionally, after executing step S408, the method further includes steps S408c and S408d:
[0485] In step S408c, the core network element determines whether to perform integrity check and / or decryption on the second message. That is, based on the core network element's determination to activate the security context in step S403e above, the core network element may further determine whether to perform de-security protection (integrity check and / or decryption) on the second message corresponding to the first operation between the core network element and the terminal device and / or what type of de-security protection to perform, or in other words, determine to activate a context corresponding to integrity security protection and / or a context corresponding to confidentiality security protection.
[0486] In one example, the core network element determines whether to perform integrity check and / or decryption on the second message according to the type of the operation instruction.
[0487] For example, when the operation instruction type indicates an inventory operation, the core network element determines not to perform integrity check on the second message, that is, there is no need to generate and / or activate the corresponding context for integrity security protection.
[0488] For example, when the operation instruction type indicates a read operation, an invalidation operation, or a write operation, the core network element determines to perform integrity verification on the second message, that is, generates and / or activates a corresponding context for integrity security protection.
[0489] For example, when the operation instruction type indicates a read operation, the core network element determines to decrypt the second data ciphertext carried in the second message to obtain the second data, that is, to generate and / or activate the corresponding context for confidentiality security protection.
[0490] For example, when the operation instruction type indicates a write operation, an invalidation operation, or an inventory operation, the core network element determines not to decrypt the second message, that is, there is no need to generate and / or activate a corresponding context for confidentiality security protection.
[0491] It should be noted that the above-mentioned integrity check and decryption of the second message can be implemented independently or in combination. For example, when the operation instruction type indicates an inventory operation, the core network element may not perform an integrity check on the second message and may not decrypt it; when the operation instruction type indicates a write operation, the core network element may perform an integrity check on the second message and may not decrypt it; when the operation instruction type indicates an invalidation operation, the core network element may perform an integrity check on the second message and may not decrypt it; when the operation instruction type indicates a read operation, the core network element may perform an integrity check on the second message and decrypt the second data ciphertext.
[0492] Optionally, the core network element may further determine whether to perform integrity check and / or decryption on the second message based on the determination of whether to activate the security context in step S403e above, or further determine whether to perform integrity check and / or decryption on the second message based on the determination of whether to perform integrity security protection and / or confidentiality security protection on the first message in step S404a. That is, in the above example, the core network element may not perform the judgment step of determining whether to perform integrity check and / or decryption on the second message based on the type of operation instruction, and the judgment result of step S403e or S404a may be used. For example, in step S403e, if the core network network element determines to generate and / or activate a security context, or, in step S404a, if the core network network element determines to perform integrity security protection and / or confidentiality security protection on the first message, then in step S408c, it is determined to perform integrity verification and / or decryption on the second message; if the core network network element determines not to generate and / or activate a security context, or, if the core network network element determines not to perform integrity security protection and / or confidentiality security protection on the first message, then in step S408c, it is determined not to perform integrity verification and / or decryption on the second message.
[0493] S408d: The core network element performs integrity check and / or decryption on the second message according to the security context.
[0494] Exemplarily, the core network element calculates MAC#1 based on the integrity security protection algorithm in the security context, and compares MAC#1 carried in the second message with MAC#2. If the two are the same, it can be considered that the integrity check has passed; otherwise, the integrity check has failed.
[0495] Exemplarily, when the operation instruction type indicates a write operation, the core network element performs decryption calculation or decryption operation on the second data ciphertext in the second message according to the confidentiality security protection algorithm and / or confidentiality security protection key (e.g., Knasenc) in the security context to obtain the second data, that is, the decryption is successful; otherwise, the decryption fails.
[0496] Optionally, if the core network element fails to perform integrity verification and / or decryption in step S408d, the service response message in step S409 is used to indicate that the first operation failed. Optionally, the service response message carries a failure reason value to indicate that the integrity verification of the second message failed and / or the decryption of the second data ciphertext was unsuccessful.
[0497] S409 , the core network element sends a service response message to the operation requester, and correspondingly, the operation requester receives the service response message from the core network element.
[0498] The service response message may be a service response message, which is used to indicate the execution status of the first operation.
[0499] In the first example, when the following condition #1 is met, the service response message is used to indicate that the first operation is successfully executed. In this case, the service response message includes an identifier of the terminal device, and optionally, the service response message also includes second data.
[0500] Exemplarily, condition #1 includes: the authentication in the above steps S403a-S403b is passed, the supported security algorithm matches the security capability of the terminal device, the integrity check and / or decryption of the first message is successful, and the integrity check and / or decryption of the second message is successful.
[0501] Based on this implementation, step S409 may further include: the core network element sending a service response message to the operation requester according to the operation instruction type of the first operation.
[0502] For example, in a case where the operation instruction type indicates an inventory operation, a write operation, or a invalidation operation, the service response message includes an identifier of the terminal device.
[0503] For example, in a case where the operation instruction type indicates a read operation, the service response message includes the identifier of the terminal device and the second data.
[0504] In the second example, when any one or more of the following conditions are met, the service response message is used to indicate that the first operation has failed. In this case, the service response message includes an identifier of the terminal device, and optionally, the service response message also includes a failure reason value, which is used to indicate any one or more of the following conditions.
[0505] (1) The authentication in the above steps S403a and / or S403b fails;
[0506] (2) The core network element fails to verify the security algorithm in step S403d above, or in other words, the security algorithm supported by the core network element does not match the security capability of the terminal device;
[0507] (3) The integrity check and / or decryption of the first message in step S406 above fails;
[0508] (4) The integrity check and / or decryption of the second message in the above step S408c fails.
[0509] Optionally, the method further includes steps S410 and S411:
[0510] S410: The terminal device determines whether to delete the security context.
[0511] S411: The core network element determines whether to delete the security context.
[0512] Below, the implementation method of the core network element determining whether to delete the security context is used as an example to illustrate. The implementation method on the terminal device side can refer to the relevant description on the core network element side, which will not be repeated here.
[0513] In one example, the core network element determines whether to delete the security context, that is, whether to save the security context, based on the type of the terminal device.
[0514] For example, when the type of the terminal device is an active tag or a semi-passive tag, the core network element determines not to delete the security context, that is, the core network element saves the security context for subsequent secure interaction of information.
[0515] For example, when the terminal device is a passive tag, the core network element determines to delete the security context. Compared with terminal devices of semi-passive tag or active tag type, terminal devices of passive tag type have weaker storage and computing capabilities, so the security context does not need to be saved to save storage and computing overhead. In addition, for subsequent requests to perform operations such as inventory operations on terminal devices of passive tag type, no security context is required for security protection, so it is not necessary to store the security context. However, for terminal devices of semi-passive tag or active tag type, the security context can be saved. For subsequent requests to perform operations such as read operations, write operations or invalidation operations on terminal devices of semi-passive tag or active tag type, the security context can be used to protect information communication security without reactivating the security context, which can save computing overhead and reduce processing delay while ensuring communication security.
[0516] It should be noted that this application does not specifically limit the timing of deleting the security context between the terminal device and the core network element. Optionally, the terminal device can delete the security context at any time after generating the second message, for example, after sending the second message, the terminal device starts a timer and deletes the security context after the timer expires.
[0517] Optionally, the core network element may delete the security context at any time after integrity checking and / or decrypting the second message, for example, deleting the security context after sending a service response message, or the core network element may start a timer after sending a first message to the terminal device, and delete the security context if no second message is received from the terminal device after the timer expires.
[0518] Optionally, the tag management function related to the core network element in this application can be implemented on a tag management function (TMF). The TMF can be an independent network element or can be co-located with a base station (such as a RAN) or a core network element (such as an AMF).
[0519] For example, when TMF is deployed independently, functions such as management, authentication, and registration of terminal devices (such as tags) can be implemented on TMF, that is, the actions of the core network elements in the above embodiment can be performed by TMF. Optionally, the corresponding messages can be forwarded through AMF, or TMF and AMF can cooperate to perform the above method. For example, in S401, the service request message is received by TMF and sent to AMF; in S402, the registration request message is received by AMF and sent to TMF; S403 and 404 are executed by TMF; the first message in S405 is generated by TMF and sent to the terminal device through AMF; the second message in S408 is sent to TMF through AMF; and the service response message in S409 is sent by TMF.
[0520] For example, when TMF and AMF are jointly established, the management, authentication, registration of terminal devices (such as tags), activation of security contexts, security protection of messages or cells, and other functions can be implemented on the jointly established network elements. This application does not limit this.
[0521] The solution provided in this application ensures secure communication between terminal devices and core network elements by activating security contexts, and reduces the number of information interactions between terminal devices and core network elements by omitting the NAS SMC process, thereby simplifying the processing complexity of the entire service process, reducing processing delays, reducing power consumption, and further enabling the operation requester to obtain services effectively and quickly.
[0522] By adding judgment logic for whether to generate and / or activate a security context, as well as whether to delete a security context, the computing and storage overhead of terminal devices and core network elements is reduced, the limited storage resources of terminal devices are avoided from being occupied, the power consumption of terminal devices is reduced, and the network is guaranteed to be able to provide services to more terminal devices, avoiding network congestion. Especially for tag-type terminal devices, which usually obtain energy through radio or the environment, and have limited storage capacity, this may make the terminal device unable to store security context, affecting the secure interaction of information, and may cause the limited storage resources of the terminal device to be occupied, resulting in increased power consumption and other problems. In addition, reducing the air interface overhead between the terminal device and the core network element, for example, avoiding the interaction failure caused by malicious tampering by an attacker when the terminal device reports the terminal device security capabilities to the core network element via the air interface, can ensure network security.
[0523] Figure 5 is a flow chart of a communication method 500 provided in an embodiment of the present application, in which the terminal device is the UE (or tag), the core network element is the AMF, and the operation requester is the AF as the execution subject for interaction. This method can be regarded as a further refinement of the above-mentioned method 400. It should be understood that the embodiment shown in Figure 5 and the embodiment shown in Figure 4 can be coupled with each other and can refer to each other. Therefore, the relevant description in the above-mentioned method 400 is also applicable to this implementation method. The same or similar technical means may exist between the two. The content described in the embodiment shown in Figure 4 will not be repeated. Taking into account the cost and performance limitations of the tag-type UE, this implementation method is applicable to the UE supporting a confidentiality security protection algorithm and / or an integrity security protection algorithm, or the AMF carries the selected security algorithm in the registration acceptance message of step S509 to notify the UE. This implementation method reduces the interaction process between the UE and the AMF by omitting the NAS SMC process, simplifies the processing complexity of the entire process, and reduces the processing delay. As shown in Figure 5, the method includes the following multiple steps. The part that is not fully described can refer to the existing protocol.
[0524] S501, AF sends a service request message to AMF, and correspondingly, AMF receives the service request message from AF.
[0525] The parameters included in the service request message, their definitions, and specific implementation methods may refer to the relevant description of step S401 of the above method 400.
[0526] S502: UE accesses the network.
[0527] For the specific implementation, please refer to the relevant description of steps S302 to 304 of the above method 300.
[0528] S503: The UE sends a registration request message to the AMF. Correspondingly, the AMF receives the registration request message from the UE.
[0529] For the parameters included in the registration request message, their definitions, and specific implementations, please refer to the description of step S402 of the above method 400. At this time, the registration request message may not carry the security capabilities of the UE.
[0530] S504, authentication.
[0531] For the specific implementation of authentication, please refer to the relevant description of step S306 of the above method 300.
[0532] It should be understood that when the UE's authentication passes, steps S506 to S517 are continued. When the UE's authentication fails, steps S506 to S514, S516, and S517 are skipped and step S515 is executed. In this case, the service response message indicates that the first operation has failed, or that the AMF has rejected the AF's service request. Optionally, the service response message may carry a failure cause value to indicate that the UE authentication failed.
[0533] S505: AMF obtains UE security capabilities.
[0534] For the specific implementation, please refer to the relevant description of step S403c of the above method 400.
[0535] S506: AMF determines the security algorithm based on the UE security capabilities and the algorithm priority list.
[0536] The content, definition, and specific implementation of the security algorithm may refer to the description of step S403d of the above method 400.
[0537] Optionally, when the service request message is used to request a read operation, a write operation, or a disable operation on the UE, steps S504 to S506 are performed; when the service request message is used to request an inventory operation on the UE, steps S504 to S506 may not be performed;
[0538] S507: AMF determines whether to activate the security context.
[0539] Exemplarily, the AMF determines whether to generate a security context according to the operation instruction type. For specific implementation, please refer to the relevant description of step S403e of the above method 400.
[0540] It should be understood that this implementation can simplify the content of the security context and reduce storage and computing overhead on the network side.
[0541] Optionally, if the AMF authenticates the UE successfully, the AMF may determine whether to skip the NAS SMC process, determine the timing of activating the security context, or how to activate the security context. For specific implementation methods, please refer to the relevant description of step S403e above.
[0542] S508: The AMF determines whether to perform integrity protection and / or confidentiality security protection on the registration acceptance message.
[0543] Exemplarily, the AMF determines whether to perform integrity protection and / or confidentiality security protection on the registration acceptance message based on the operation instruction type. For specific implementation methods, please refer to the relevant description of step S404a of the above method 400.
[0544] Furthermore, when it is determined that integrity protection and / or confidentiality security protection is performed on the registration accept message, the AMF performs integrity protection and / or confidentiality security protection on the registration accept message according to the security context. For specific implementation methods, please refer to the relevant description of step S404 of the above method 400.
[0545] S509: AMF sends a registration accept message to the UE. Correspondingly, the UE receives the registration accept message from the AMF.
[0546] The content and interpretation of the registration acceptance message, as well as the specific implementation method, can be found in the description of step S405 of the above method 400.
[0547] S510: The UE determines whether to activate the security context.
[0548] Exemplarily, the UE may determine whether to activate the security context according to the operation instruction type in the registration acceptance message of step S509. For specific implementation, reference may be made to the relevant description of step S403f above.
[0549] It should be understood that this implementation can simplify the content of the security context and reduce the storage and computing overhead on the UE side.
[0550] Optionally, when the UE passes the authentication of the core network element, the UE can determine whether to skip the NAS SMC process, determine the timing of activating the security context, or how to activate the security context, etc. The specific implementation method can refer to the relevant description of the above step S403f.
[0551] S511: The UE determines whether to perform integrity check and / or decryption on the registration accept message.
[0552] Exemplarily, the UE determines whether to perform integrity check and / or decryption on the first message according to the type of the operation instruction. For specific implementation, reference may be made to the relevant description of step S406a of the above method 400.
[0553] Furthermore, when it is determined to perform integrity verification and / or decryption on the registration acceptance message, the UE performs integrity verification and / or decryption on the registration acceptance message according to the integrity security protection algorithm and / or confidentiality security protection algorithm in the security context. For the specific implementation method, please refer to the relevant description of step S406 of the above method 400.
[0554] S512: If the integrity check passes and / or the decryption succeeds, the UE performs a first operation.
[0555] Exemplarily, when the integrity check passes and / or the decryption succeeds, the UE performs the first operation according to the operation instruction type. For specific implementation, reference may be made to the relevant description of step S407 of the above method 400.
[0556] S513: The UE determines whether to perform integrity protection and / or confidentiality protection on the registration completion message.
[0557] Exemplarily, the UE determines whether to perform integrity protection and / or confidentiality protection on the registration completion message according to the operation instruction type. For specific implementation, reference may be made to the relevant description of step S408b of the above method 400.
[0558] Furthermore, when it is determined that the registration completion message is to be integrity protected and / or confidentiality protected, the UE performs integrity security protection and / or confidentiality security protection on the registration completion message according to the integrity security protection algorithm and / or confidentiality security protection algorithm in the security context. For the specific implementation method, please refer to the relevant description of step S408a of the above method 400.
[0559] S514: The UE sends a registration completion message to the AMF. Correspondingly, the AMF receives the registration completion message from the UE.
[0560] The content and interpretation of the registration acceptance message, as well as the specific implementation method, can be found in the description of step S408 of the above method 400.
[0561] Optionally, the AMF determines whether to perform integrity verification and / or decryption on the registration completion message. For specific implementation methods, please refer to the relevant description of step S408c of the above method 400.
[0562] Further optionally, the AMF performs integrity verification and / or decryption on the registration completion message according to the security context. For specific implementation methods, please refer to the relevant description of step S408d of the above method 400.
[0563] S515, AMF sends a service response message to AF, and correspondingly, AF receives the service response message from AMF.
[0564] The content and interpretation of the service response message, as well as the specific implementation method, can be found in the description of step S409 of the above method 400.
[0565] S516: The UE and the AMF determine whether to delete the security context.
[0566] For the specific implementation, please refer to the relevant description of step S410 of the above method 400.
[0567] The solution provided by this application is that the UE and AMF ensure secure communication between them by activating a security context, and by omitting the NAS SMC process and carrying the operation instruction type of the first instruction in the registration acceptance message, the number of interactions between the UE and the AMF is reduced, the processing complexity is simplified, the latency is reduced, and at the same time, services can be effectively provided to the AF. By adding judgment logic on whether to generate and activate a security context, as well as whether to delete the security context, the computational and storage overhead of the UE and the AMF is reduced, the limited storage resources of the UE are avoided from being occupied, the power consumption of the UE is reduced, and the network side is guaranteed to provide services for more UEs, avoiding network congestion, etc. In addition, by reducing the air interface overhead between the UE and the AMF, for example, when the UE reports the UE security capabilities to the AMF through the air interface, the interaction failure caused by malicious tampering by an attacker is avoided, thereby ensuring network security.
[0568] Figure 6 is a flow chart of a communication method 600 provided in an embodiment of the present application. As shown in Figure 6, the terminal device, the core network element, and the operation requester are the execution entities to interact. The method includes the following steps. For parts not fully described, please refer to the description of the previous embodiment.
[0569] S601: The operation requesting party sends a service request message to a core network element. Correspondingly, the core network element receives the service request message from the operation requesting party.
[0570] S602, the terminal device sends a registration request message to the core network element, and correspondingly, the core network element receives the registration request message from the terminal device.
[0571] The service request message and registration request message involved in steps S601-S602 include the contents and interpretations thereof, as well as the specific implementation methods, which can be referred to the relevant descriptions of steps S401-S402 of the above method 400.
[0572] S603: The core network element activates the security context.
[0573] Among them, the security context is used to protect the secure communication between the terminal device and the core network element.
[0574] In the first example, the core network element activates the security context according to the operation instruction type of the first operation and / or the type of the terminal device. Specifically, the core network element can determine whether to activate the security context according to the operation instruction type of the first operation and / or the type of the terminal device.
[0575] For example, when the operation instruction type indicates an inventory operation, the core network element does not activate the security context; when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, the core network element activates the security context.
[0576] In a second example, the core network element activates the security context according to the operation instruction type of the first operation and / or the type of the terminal device. Specifically, the core network element may determine whether to activate the security context according to the operation instruction type of the first operation and / or the type of the terminal device.
[0577] For example, when the type of the terminal device is an active tag or a semi-passive tag, the core network element activates the security context; when the type of the terminal device is a passive tag, the core network element activates the security context according to the operation instruction type of the first operation. The specific implementation method can refer to the relevant description of the first example above.
[0578] Optionally, regardless of the type of operation instruction, the core network element in step S603 activates the security context. Further, the core network element can determine what type of security context to activate based on the operation type, that is, determine the integrity security protection and / or confidentiality security protection based on the operation instruction type. The specific implementation method is described below.
[0579] Optionally, the core network element activates a security context based on the operation instruction type of the first operation and / or the type of the terminal device, including: the core network element activates a security context corresponding to integrity security protection and / or a security context corresponding to confidentiality security protection based on the operation instruction type of the first operation and / or the type of the terminal device. That is, the core network element can determine which security context to activate based on the operation instruction type of the first operation and / or the type of the terminal device, that is, determine whether to enable integrity security protection and / or confidentiality security protection.
[0580] In a first example, the core network element activates a security context corresponding to integrity security protection and / or a security context corresponding to confidentiality security protection according to the operation instruction type of the first operation.
[0581] For example, when the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, the terminal device activates the corresponding security context for integrity security protection; when the operation instruction type indicates a write operation, the terminal device activates the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection. For specific implementation methods, please refer to the relevant description of step S403e of the above method 400.
[0582] In the second example, the core network element activates a security context corresponding to integrity security protection and / or a security context corresponding to confidentiality security protection according to the type of the terminal device.
[0583] For example, when the type of the terminal device is an active tag or a semi-passive tag, the core network network element activates the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection; when the type of the terminal device is a passive tag and the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, the core network network element activates the corresponding security context for integrity security protection; when the type of the terminal device is a passive tag and the operation instruction type indicates a write operation, the core network network element activates the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection. For the specific implementation method, please refer to the relevant description of step S403e of the above method 400.
[0584] Optionally, the method further includes: performing an authentication process between the terminal device and the network. For example, before the core network element activates the security context, the method further includes: the network authenticating the terminal device. For example, if the network successfully authenticates the terminal device, the core network element activates the security context.
[0585] Optionally, before the core network activates the security context, the method may further include: the core network network element obtaining the security capabilities of the terminal device, and selecting an integrity security protection algorithm and / or a confidentiality security protection algorithm based on the security capabilities of the terminal device and an algorithm priority list. It should be understood that the security capabilities of the terminal device are used to determine the security algorithms in the security context. Optionally, the core network network element may obtain the security capabilities of the terminal device from the operation requester, or the terminal device, or the unified data management network element. For specific implementation methods, please refer to the relevant description of steps S403c-S403d of the above method 400.
[0586] At step S604, the core network element performs security protection on the first message based on the security context. The first message is a NAS SMC message, which means that the NAS SMC message is a security-protected message. The security protection includes integrity protection and / or confidentiality protection. For specific implementation, refer to the description of step S404 of method 400 above.
[0587] It should be noted that the first message in this implementation manner may be used to activate a security context, to negotiate a security algorithm with the terminal device, and / or to instruct execution of a first operation on the terminal device.
[0588] Optionally, the core network element determines to perform a first operation on the terminal device through a NAS SMC message according to the type of the terminal device and / or the capability information of the terminal device, or determines to carry an operation instruction type for indicating the first operation in the NAS SMC message, or determines to adopt a low-power processing flow.
[0589] Furthermore, the core network element can determine whether to perform the first operation on the terminal device through the NAS SMC message instruction, or determine whether the NAS SMC message carries the operation instruction type for indicating the first operation, that is, determine whether to adopt a low-power processing flow, specifically including the following implementation methods.
[0590] (1) The core network element determines, based on the type of the terminal device, whether to instruct, through a NAS SMC message, to perform the first operation on the terminal device.
[0591] For example, for a low-power terminal device (such as an IoT device, or a tag, etc.), it is determined to perform the first operation on the terminal device through a NAS SMC message instruction; for a non-low-power terminal device (also referred to as an ordinary terminal device), it is determined not to perform the first operation on the terminal device through a NAS SMC message instruction.
[0592] The tag may specifically include an active tag, a semi-passive tag and / or a passive tag, etc. The core network element may determine whether to execute the first operation on the terminal device through a NAS SMC message instruction according to the type of the tag.
[0593] For example, taking a tag as an example, when the type of the terminal device is a passive tag, the core network element can instruct the terminal device to perform the first operation through a NAS SMC message.
[0594] (2) The core network element determines, based on the capability information of the terminal device, whether to instruct the terminal device to perform the first operation through a NAS SMC message.
[0595] Optionally, the core network element can obtain the capability information of the terminal device from the UDM / UDR / PCF / UE. The capability information of the terminal device can be used to indicate whether the terminal device supports parsing the NAS SMC message to obtain an instruction to perform the first operation, or to indicate whether the terminal device itself has the ability to parse the NAS SMC message to obtain an instruction to perform the first operation, or to indicate whether the terminal device can obtain the information element carried in the NAS SMC message, such as the operation instruction type of the first operation.
[0596] For example, when the capability information of the terminal device indicates that the terminal device is capable of parsing the information elements carried in the NAS SMC message, the core network network element can instruct the terminal device through the NAS SMC message to perform the first operation, that is, to perform the service in the NAS SMC process, thereby ensuring the communication security between the core network network element and the terminal device while reducing the number of signaling interactions between the two, simplifying the process, and reducing processing delays.
[0597] Optionally, before the core network element performs security protection on the first message according to the security context, the method further includes: the core network element determines whether to perform security protection on the first message.
[0598] In one example, the core network element determines whether to perform security protection on the first message according to the operation instruction type of the first operation.
[0599] For example, when the operation instruction type indicates an inventory operation, the core network network element determines not to perform integrity security protection on the first message; when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, the core network network element determines to perform integrity security protection on the first message. The specific implementation method can refer to the relevant description of step S404a of the above method 400.
[0600] For example, when the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, the core network network element determines not to perform confidentiality security protection on the first message; when the operation instruction type indicates a write operation, the core network network element determines to perform confidentiality security protection on the first data and obtains a first data ciphertext. The first data is data to be written to the storage area of the terminal device, and the first data ciphertext is carried in the first message. For the specific implementation method, please refer to the relevant description of step S404a of the above method 400.
[0601] Optionally, the calculation result of the core network element performing integrity security protection on the first message is recorded as MAC#1, carried in the first message and sent to the terminal device, so that the terminal device can perform integrity verification on the first message.
[0602] S605, the core network element sends a first message that has been security-protected to the terminal device. Correspondingly, the terminal device receives the first message from the core network element, where the first message is a NAS SMC message.
[0603] It should be understood that the NAS SMC message is a security-protected message.
[0604] Optionally, the NAS SMC message may carry an operation instruction type to indicate the first operation. For a specific definition of the operation instruction type, reference may be made to the description of the above method 400. Optionally, the operation instruction type may be sent in plain text.
[0605] Optionally, based on the core network element determining whether integrity security protection is performed on the first message in step S604 above, the core network element may further determine whether MAC#1 is included in the first message. For example, when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, the NAS SMC message may further include MAC#1, which is used by the terminal device to perform an integrity check on the NAS SMC message to determine whether it has been maliciously tampered with during transmission. When the operation instruction type indicates an inventory operation, the NAS SMC message does not include MAC#1.
[0606] Optionally, the terminal device may determine whether to carry MAC#1 in the NAS SMC message based on the terminal device type. For example, if the terminal device type is an active tag or a semi-passive tag, the NAS SMC message may carry MAC#1; if the terminal device type is a passive tag, the NAS SMC message may not carry MAC#1.
[0607] Optionally, based on the core network element determining whether confidentiality security protection is performed on the first message in step S604 above, the core network element may further determine whether to carry the first data ciphertext in the first message. For example, when the operation instruction type indicates a write operation, the NAS SMC message may further include the first data ciphertext, indicating that the data is to be written to a storage area of the terminal device.
[0608] Optionally, the NAS SMC message may carry the security algorithm selected by the core network element. Optionally, if the terminal device only supports one integrity security protection algorithm and / or one confidentiality security protection algorithm, the NAS SMC message may not carry the security algorithm selected by the core network element, and this application does not limit this.
[0609] S606: The terminal device activates the security context according to the NAS SMC message.
[0610] In the first example, the terminal device activates the security context according to the operation instruction type of the first operation. Specifically, the terminal device can determine whether to activate the security context according to the operation instruction type of the first operation and / or the type of the terminal device.
[0611] For example, when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, the terminal device determines to activate the security context; optionally, when the operation instruction type indicates an inventory operation, the terminal device may not activate the security context. For the specific implementation method, please refer to the relevant description of step S403f of the above method 400.
[0612] Optionally, the terminal device activates a security context according to the operation instruction type of the first operation, including: the terminal device activates a corresponding context for integrity security protection and / or a corresponding context for confidentiality security protection according to the operation instruction type of the first operation.
[0613] For example, when the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, the terminal device activates the corresponding security context for integrity security protection; when the operation instruction type indicates a write operation, the terminal device activates the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection. For specific implementation methods, please refer to the relevant description of step S403f of the above method 400.
[0614] In the second example, the terminal device activates the security context according to the type of the terminal device. Specifically, the terminal device can determine whether to activate the security context according to the type of the terminal device.
[0615] For example, when the terminal device is an active tag or a semi-passive tag, the terminal device activates the security context; when the terminal device is a passive tag, the terminal device activates the security context according to the operation instruction type of the first operation. For the specific implementation method, please refer to the relevant description of the first example.
[0616] Optionally, the terminal device activates a security context according to the type of the terminal device, including: the terminal device activates a corresponding context for integrity security protection and / or a corresponding context for confidentiality security protection according to the type of the terminal device.
[0617] For example, when the terminal device is an active tag or a semi-passive tag, the terminal device activates the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection; when the terminal device is a passive tag and the operation instruction type of the first operation indicates an inventory operation, a read operation, or an invalidation operation, the terminal device activates the corresponding security context for integrity security protection; when the terminal device is a passive tag and the operation instruction type of the first operation indicates a write operation, the terminal device activates the corresponding security context for integrity security protection and the corresponding security context for confidentiality security protection. For the specific implementation method, please refer to the relevant description of step S403f of the above method 400.
[0618] Optionally, before the terminal device activates the security context, the method further includes: the terminal device authenticates the network. For example, if the terminal device successfully authenticates the network, the terminal device activates the security context.
[0619] S607, the terminal device performs integrity verification and / or decryption on the first message according to the security context. For specific implementation, please refer to the relevant description of step S406 of the above method 400.
[0620] Optionally, before the terminal device performs integrity check and / or decryption on the first message according to the security context, the method further includes: the terminal device determines whether to perform integrity check and / or decryption on the first message.
[0621] In one example, the terminal device determines whether to perform integrity verification and / or decryption on the first message according to the operation instruction type of the first operation.
[0622] For example, when the operation instruction type indicates an inventory operation, the terminal device determines not to perform an integrity check on the first message; when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, the terminal device determines to perform an integrity check on the first message. The specific implementation method can refer to the relevant description of step S406a of the above method 400.
[0623] For example, when the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, the terminal device determines not to decrypt the first message; when the operation instruction type indicates a write operation, the terminal device determines to decrypt the first data ciphertext carried in the first message to obtain the first data, and the first data is the data to be written to the storage area of the terminal device. The specific implementation method can refer to the relevant description of step S406a of the above method 400.
[0624] S608: After integrity verification and / or decryption, the terminal device performs a first operation.
[0625] Exemplarily, if the integrity check and / or decryption passes, the terminal device performs the first operation. For specific implementation methods, reference may be made to the relevant description of step S407 of the above method 400. The terminal device performing the first operation may be by receiving a NAS SMC message to obtain an instruction from a core network element to perform the first operation on the terminal device, or the terminal device may parse an information element in the NAS SMC message to obtain an instruction type of the first operation, and then perform the first operation if the integrity check and / or decryption passes.
[0626] S609, the terminal device sends a second message to the core network element. Correspondingly, the core network element receives the second message from the terminal device, where the second message is a NAS SMP message.
[0627] Optionally, before the terminal device sends the second message to the core network network element, the method also includes: the terminal device determines whether to perform security protection on the second message, the security protection includes integrity security protection and / or confidentiality security protection, and the second message is used to indicate whether the first operation is executed successfully.
[0628] In one example, the terminal device determines whether to perform security protection on the second message according to the operation instruction type of the first operation.
[0629] For example, when the operation instruction type indicates an inventory operation, the terminal device determines not to perform integrity security protection on the second message; when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, the terminal device determines to perform integrity security protection on the second message. The specific implementation method can refer to the relevant description of step S408b of the above method 400.
[0630] For example, when the operation instruction type indicates an inventory operation, a write operation, or an invalidation operation, the terminal device determines not to perform confidentiality security protection on the second message; when the operation instruction type indicates a read operation, the terminal device determines to perform confidentiality security protection on the second data to obtain a second data ciphertext, where the second data is data in a storage area of the terminal device or data collected by the terminal device, and the second data ciphertext is carried in the second message. For the specific implementation method, please refer to the relevant description of step S408b of the above method 400.
[0631] Optionally, after the core network element receives the second message from the terminal device, the method further includes: the core network element determining whether to perform integrity verification and / or decryption on the second message.
[0632] In one example, the core network element determines whether to perform integrity check and / or decryption on the second message according to the operation instruction type of the first operation.
[0633] For example, when the operation instruction type indicates an inventory operation, the core network network element determines not to perform integrity check on the second message; when the operation instruction type indicates a read operation, a write operation, or an invalidation operation, the core network network element determines to perform integrity check on the second message. The specific implementation method can refer to the relevant description of step S408c of the above method 400.
[0634] For example, when the operation instruction type indicates a read operation, the core network network element determines to decrypt the second data ciphertext carried in the second message to obtain the second data, where the second data is data in the storage area of the terminal device or data collected by the terminal device; when the operation instruction type indicates an inventory operation, a write operation, or an invalidation operation, the core network network element determines not to decrypt the second message. For the specific implementation method, please refer to the relevant description of step S408c of the above method 400.
[0635] Optionally, based on the above-mentioned core network element, it is determined to perform integrity check and / or decryption on the second message. The core network element performs integrity check and / or decryption on the second message according to the security context. For the specific implementation method, please refer to the relevant description of step S408d of the above-mentioned method 400.
[0636] Optionally, the method further includes: the terminal device and / or the core network element determining whether to delete the security context. For example, the terminal device and / or the core network element determines whether to delete the security context based on the type of the terminal device. For specific implementation methods, please refer to the relevant description of steps S410-S411 of method 400 above.
[0637] S610, the core network element sends a service response message to the operation requester. Correspondingly, the operation requester receives the service response message from the core network element. For specific implementation, please refer to the relevant description of step S409 of the above method 400.
[0638] Optionally, the label management function related to the above-mentioned core network network element in this application can be implemented on the TMF network element, where the TMF can be an independent network element or can be jointly established with a base station (such as RAN) or a core network network element (such as AMF).
[0639] For example, when TMF is deployed independently, functions such as management, authentication, and registration of terminal devices (such as tags) can be implemented on TMF, that is, the actions of the core network elements in the above embodiment can be performed by TMF. Optionally, the corresponding messages can be forwarded through AMF. Or TMF and AMF cooperate to perform the above method. For example, in S601, the service request message is received by TMF and sent to AMF; in S602, the registration request message is received by AMF and sent to TMF; S603 and 604 are executed by TMF; the first message in S605 is generated by TMF and sent to the terminal device through AMF; the second message in S609 is sent to TMF through AMF; and the service response message in S610 is sent by TMF.
[0640] For example, when TMF and AMF are jointly established, the management, authentication, registration of terminal devices (such as tags), activation of security contexts, security protection of messages or cells, and other functions can be implemented on the jointly established network elements. This application does not limit this.
[0641] According to the solution provided in this application, a NAS SMC message is used to instruct the terminal device to perform a first operation, that is, to use the NAS SMC process for service execution. This reduces the number of information exchanges between the terminal device and the core network element while ensuring secure communication between the terminal device and the core network element. Compared to the prior art, in which the terminal device and the core network element sequentially perform an authentication process, trigger a NAS SMC process, and then perform a service execution process, this implementation method can perform the first operation while ensuring network communication security, simplify the entire service process, reduce processing complexity and latency, and reduce power consumption. By adding judgment logic for whether to generate and / or activate a security context, and whether to delete a security context, the computing and storage overhead of the terminal device and the core network element is reduced, avoiding the occupation of the terminal device's limited storage resources, reducing the power consumption of the terminal device, and ensuring that the network can provide services ...
Claims
1. A communication method, characterized in that: include: Sending a registration request message, the registration request message is used to request registration with the network, the registration request message includes an identifier of the terminal device; When the terminal device passes the authentication of the network, activating a security context, wherein the security context is used to protect secure communication between the terminal device and a network element; Performing an integrity check on a first message from the network element according to the security context, where the first message is used to request to perform a first operation on the terminal device; If the integrity check passes, the first operation is performed.
2. The method according to claim 1, characterized in that The activating security context comprises: According to the capability of the terminal device and / or the type of the terminal device, the NAS SMC process is skipped and the security context is activated.
3. The method according to claim 2, characterized in that The step of skipping the NAS SMC process and activating the security context according to the type of the terminal device includes: In the case that the type of the terminal device is a passive tag, the NAS SMC process is skipped and the security context is activated.
4. The method according to claim 2 or 3, characterized in that: The step of skipping the NAS SMC process and activating the security context according to the capability of the terminal device includes: When the capability of the terminal device indicates that the terminal device supports a confidentiality protection algorithm and / or an integrity protection algorithm, the NAS SMC process is skipped and the security context is activated.
5. The method according to any one of claims 1 to 4, characterized in that The activating security context comprises: In response to an EAP-success message and / or an authentication request message received by the terminal device in the authentication process, the security context is activated.
6. The method according to any one of claims 1 to 5, characterized in that The activating security context comprises: The security context is activated according to a locally configured security algorithm, the security algorithm comprising an integrity security algorithm and / or a confidentiality security algorithm.
7. The method according to any one of claims 1 to 6, characterized in that The activating security context comprises: The security context is activated according to a received registration acceptance message, where the registration acceptance message is used to accept a registration request of the terminal device.
8. The method according to claim 7, characterized in that The activating the security context according to the received registration acceptance message comprises: In response to the registration acceptance message received by the terminal device, activating the security context; and / or, The security context is activated according to a security algorithm indicated by a security algorithm identifier carried in the registration acceptance message, where the security algorithm includes an integrity security algorithm and / or a confidentiality security algorithm.
9. The method according to any one of claims 1 to 8, characterized in that The activating security context comprises: The security context is activated according to an operation instruction type of the first operation.
10. The method according to claim 9, characterized in that The activating the security context according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type indicates a read operation, activating the security context; When the operation instruction type indicates a write operation, activating the security context; In a case where the operation instruction type indicates a failure operation, the security context is activated.
11. The method according to any one of claims 1 to 10, characterized in that The method further comprises: Determine whether to decrypt the first message according to the operation instruction type of the first operation.
12. The method according to claim 11, characterized in that The determining whether to decrypt the first message according to the operation instruction type includes one or more of the following: In a case where the operation instruction type indicates an inventory operation, determining not to decrypt the first message; When the operation instruction type indicates a read operation, determining not to decrypt the first message; When the operation instruction type indicates an invalid operation, determining not to decrypt the first message; When the operation instruction type indicates a write operation, determining to decrypt the first data ciphertext carried in the first message, The first data ciphertext is obtained by encrypting the first data, and the first data is data to be written into the storage area of the terminal device.
13. The method according to any one of claims 1 to 12, characterized in that The method further comprises: Determining whether to perform security protection on a second message according to an operation instruction type of the first operation, wherein the security protection includes integrity security protection and / or confidentiality security protection, and the second message is used to indicate whether the first operation is successfully executed; Sending the second message to the network element.
14. The method according to claim 13, characterized in that The determining whether to perform security protection on the second message according to the operation instruction type includes one or more of the following: When the operation instruction type indicates an inventory operation, determining not to perform integrity security protection on the second message; When the operation instruction type indicates a read operation, determining to perform integrity security protection on the second message; When the operation instruction type indicates a write operation, determining to perform integrity security protection on the second message; In a case where the operation instruction type indicates an invalid operation, it is determined to perform integrity security protection on the second message.
15. The method according to claim 13 or 14, characterized in that The determining whether to perform security protection on the second message according to the operation instruction type includes one or more of the following: When the operation instruction type indicates an inventory operation, determining not to perform confidentiality security protection on the second message; When the operation instruction type indicates a read operation, determining to perform confidentiality security protection on the second data to obtain a second data ciphertext, where the second data is data in a storage area of the terminal device or data collected by the terminal device, and the second data ciphertext is carried in the second message; When the operation instruction type indicates a write operation, determining not to perform confidentiality security protection on the second message; In a case where the operation instruction type indicates an invalid operation, it is determined that confidentiality security protection is not performed on the second message.
16. The method according to any one of claims 1 to 15, characterized in that The method further comprises: Determining whether to delete the security context according to the type of the terminal device includes one or more of the following: In a case where the type of the terminal device is an active tag or a semi-passive tag, determining not to delete the security context; In a case where the type of the terminal device is a passive tag, it is determined to delete the security context.
17. The method according to any one of claims 13 to 16, characterized in that The first message is a registration acceptance message, and the second message is a registration completion message.
18. A communication method, characterized in that: include: receiving a registration request message from a terminal device, the registration request message being used to request registration with a network, the registration request message including an identifier of the terminal device; When the authentication of the terminal device is successful, activating a security context, wherein the security context is used to protect secure communication between the terminal device and a network element; Performing integrity security protection on a first message according to the security context, where the first message is used to request a first operation to be performed on the terminal device; Sending the first message to the terminal device.
19. The method according to claim 18, characterized in that The security capability of the terminal device is used to determine the security algorithm in the security context, and the method further includes: Acquire the security capability of the terminal device from the operation requester; or, Acquire the security capability of the terminal device from the terminal device; or, The security capability of the terminal device is obtained from a unified data management network element.
20. The method according to claim 18 or 19, characterized in that Activate the security context, including: According to the capability of the terminal device and / or the type of the terminal device, the NAS SMC process is skipped and the security context is activated.
21. The method according to claim 20, characterized in that According to the type of the terminal device, skipping the NAS SMC process and activating the security context includes: In the case that the type of the terminal device is a passive tag, the NAS SMC process is skipped and the security context is activated.
22. The method according to claim 20 or 21, characterized in that According to the capability of the terminal device, skipping the NAS SMC process and activating the security context includes: When the capability of the terminal device indicates that the terminal device supports a confidentiality protection algorithm and / or an integrity protection algorithm, the NAS SMC process is skipped and the security context is activated.
23. The method according to any one of claims 18 to 22, characterized in that Activate the security context, including: The security context is activated according to a locally configured security algorithm, the security algorithm comprising an integrity security algorithm and / or a confidentiality security algorithm.
24. The method according to any one of claims 20 to 23, characterized in that Activate the security context, including: The security context is activated according to an operation instruction type of the first operation.
25. The method according to claim 24, characterized in that Activating the security context according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type indicates a read operation, activating the security context; When the operation instruction type indicates a write operation, activating the security context; In a case where the operation instruction type indicates a failure operation, the security context is activated.
26. The method according to any one of claims 18 to 25, characterized in that The method further comprises: Whether to perform confidentiality security protection on the first message is determined according to the operation instruction type of the first operation.
27. The method according to claim 26, characterized in that Determining whether to perform confidentiality security protection on the first message according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type indicates an inventory operation, determining not to perform confidentiality security protection on the first message; When the operation instruction type indicates a read operation, determining not to perform confidentiality security protection on the first message; When the operation instruction type indicates an invalid operation, determining not to perform confidentiality security protection on the first message; When the operation instruction type indicates a write operation, it is determined to perform confidentiality security protection on the first data to obtain a first data ciphertext, where the first data is data to be written into a storage area of the terminal device, wherein the first message includes the first data ciphertext.
28. The method according to any one of claims 18 to 27, characterized in that The method further comprises: receiving a second message from the terminal device, where the second message is used to indicate whether the first operation is successfully performed; Determine whether to perform integrity check and / or decryption on the second message according to the operation instruction type of the first operation.
29. The method according to claim 28, characterized in that Determining whether to perform integrity check on the second message according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type indicates a read operation, determining to perform an integrity check on the second message; When the operation instruction type indicates a write operation, determining to perform an integrity check on the second message; When the operation instruction type indicates an invalid operation, determining to perform an integrity check on the second message; When the operation instruction type indicates an inventory operation, it is determined not to perform integrity check on the second message.
30. The method according to claim 28 or 29, characterized in that Determining whether to decrypt the second message according to the operation instruction type of the first operation includes one or more of the following: In a case where the operation instruction type indicates a read operation, determining to decrypt the second data ciphertext carried in the second message to obtain second data, where the second data is data in a storage area of the terminal device or data collected by the terminal device; When the operation instruction type indicates a write operation, determining not to decrypt the second message; When the operation instruction type indicates an invalid operation, determining not to decrypt the second message; In a case where the operation instruction type indicates an inventory operation, it is determined not to decrypt the second message.
31. The method according to any one of claims 18 to 30, characterized in that The method further comprises: Determining whether to delete the security context according to the type of the terminal device includes one or more of the following: In a case where the type of the terminal device is an active tag or a semi-passive tag, determining not to delete the security context; In a case where the type of the terminal device is a passive tag, it is determined to delete the security context.
32. The method according to any one of claims 18 to 31, characterized in that The method further comprises: receiving a service request message from an operation requester, wherein the service request message is used to request to perform the first operation on the terminal device; Sending a service response message to the operation requester according to the operation instruction type of the first operation includes one or more of the following: In the case where the operation instruction type indicates an inventory operation, the service response message includes an identification of the terminal device; In the case where the operation instruction type indicates a read operation, the service response message includes an identifier of the terminal device and second data, where the second data is data read from a storage area of the terminal device or collected by the terminal device; In the case where the operation instruction type indicates a write operation, the service response message includes an identifier of the terminal device; In the case where the operation instruction type indicates an invalid operation, the service response message includes the identifier of the terminal device.
33. A communication method, characterized in that: include: Sending a service request message to a network element, where the service request message is used to request to perform a first operation on a terminal device, and the service request message includes a security capability of the terminal device; A service response message is received from the network element, where the service response message is used to indicate whether the first operation is executed successfully.
34. The method according to claim 33, characterized in that The service request message further includes one or more of the identifier of the terminal device, the operation instruction type, or the first data; Among them, the operation instruction type indicates the first operation, the security capability of the terminal device indicates one or more integrity security protection algorithms and / or confidentiality security protection algorithms supported by the terminal device, and the first data is data to be written into the storage area of the terminal device.
35. The method according to claim 34, characterized in that In the case where the operation instruction type indicates an inventory operation, the service response message includes an identifier of the terminal device; or, In the case where the operation instruction type indicates a read operation, the service response message includes an identifier of the terminal device and second data, where the second data is data read from a storage area of the terminal device or collected by the terminal device; or In the case where the operation instruction type indicates a write operation, the service response message includes an identifier of the terminal device; or, In the case where the operation instruction type indicates an invalid operation, the service response message includes an identifier of the terminal device.
36. The method according to any one of claims 33 to 35, characterized in that In the case where the network element fails to authenticate the terminal device, the service response message is used to indicate that the first operation has failed.
37. A communication method, characterized in that: include: Sending a registration request message, the registration request message is used to request registration with the network, the registration request message includes an identifier of the terminal device; receiving a first message from a network element, where the first message is used to request to perform a first operation on the terminal device; Determine whether to activate a security context according to the operation instruction type of the first operation, where the security context is used to protect secure communication between the terminal device and the network element.
38. The method according to claim 37, characterized in that The method further comprises: In a case where it is determined to activate the security context, performing integrity verification and / or decryption on the first message according to the security context; When the integrity check and / or decryption passes, the first operation is performed according to the operation instruction type.
39. The method according to claim 37 or 38, characterized in that The method further comprises: In a case where it is determined not to activate the security context, not performing integrity check and / or not decrypting the first message; The first operation is performed according to the operation instruction type; or, the terminal device discards the first message.
40. The method according to any one of claims 37 to 39, characterized in that The method further comprises: After activating the security context, it is determined whether to perform integrity check and / or decryption on the first message.
41. The method according to claim 40, characterized in that The determining whether to perform integrity verification and / or decryption on the first message includes: Determine whether to perform integrity check and / or decryption on the first message according to the operation instruction type of the first operation.
42. The method according to claim 41, characterized in that Determining whether to perform integrity check on the first message according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type is an inventory operation, determining not to perform integrity check on the first message; When the operation instruction type is a read operation, determining to perform an integrity check on the first message; When the operation instruction type is a write operation, determining to perform an integrity check on the first message; When the operation instruction type is an invalid operation, determine to perform an integrity check on the first message.
43. The method according to claim 41 or 42, characterized in that Determining whether to decrypt the first message according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type is an inventory operation, determining not to decrypt the first message; When the operation instruction type is a read operation, determining not to decrypt the first message; In a case where the operation instruction type is a write operation, determining to decrypt the first data ciphertext carried in the first message to obtain first data, wherein the first data is data to be written into a storage area of the terminal device; When the operation instruction type is an invalid operation, it is determined not to decrypt the first message.
44. The method according to any one of claims 37 to 43, characterized in that The determining whether to activate the security context according to the operation instruction type of the first operation includes: According to the operation instruction type, it is determined to activate a security context corresponding to integrity security protection and / or a security context corresponding to confidentiality security protection.
45. The method according to any one of claims 37 to 44, characterized in that The method further comprises: Sending a second message to the network element, where the second message is used to indicate whether the first operation is performed successfully; Among them, when the operation instruction type is a read operation, the second message includes a second data ciphertext, and the second data ciphertext is obtained by encrypting the second data, and the second data is data read from the storage area of the terminal device or collected by the terminal device.
46. The method according to claim 45, characterized in that Before sending the second message to the network element, the method further includes: According to the operation instruction type, it is determined whether to perform security protection on the second message, where the security protection includes confidentiality security protection and / or integrity security protection.
47. The method according to claim 46, characterized in that The determining, according to the operation instruction type, whether to perform security protection on the second message includes one or more of the following: When the operation instruction type is an inventory operation, determining not to perform integrity security protection on the second message; When the operation instruction type is a read operation, determining to perform integrity security protection on the second message; When the operation instruction type is a write operation, determining to perform integrity security protection on the second message; When the operation instruction type is an invalid operation, determine to perform integrity security protection on the second message.
48. The method according to claim 46 or 47, characterized in that Determining whether to perform security protection on the second message according to the operation instruction type includes one or more of the following: When the operation instruction type is an inventory operation, determining not to perform confidentiality security protection on the second message; When the operation instruction type is a read operation, determining to perform confidentiality security protection on the second message; When the operation instruction type is a write operation, determining not to perform confidentiality security protection on the second message; When the operation instruction type is an invalid operation, it is determined that confidentiality security protection is not performed on the second message.
49. A communication method, characterized in that: include: receiving a registration request message from a terminal device, the registration request message being used to request registration with a network, the registration request message including an identifier of the terminal device; Determine whether to activate a security context according to the operation instruction type of the first operation, wherein the security context is used to protect secure communication between the terminal device and the network element; In a case where it is determined to activate the security context, performing security protection on a first message to be sent according to the security context, where the first message is used to request to perform a first operation on the terminal device; Sending the first message to the terminal device; or, In a case where it is determined not to activate the security context, the first message is sent to the terminal device.
50. The method according to claim 49, characterized in that The method further comprises: receiving a service request message from an operation requester, wherein the service request message is used to request to perform the first operation on the terminal device; A service response message is sent to the operation requester, where the service response message is used to indicate whether the first operation is executed successfully.
51. The method according to claim 49 or 50, characterized in that The method further comprises: After activating the security context, it is determined whether to perform security protection on the first message.
52. The method according to any one of claims 49 to 51, characterized in that The determining whether to activate the security context according to the operation instruction type of the first operation includes: According to the operation instruction type, it is determined to activate a security context corresponding to integrity security protection and / or a security context corresponding to confidentiality security protection.
53. The method according to any one of claims 49 to 52, characterized in that The security capability of the terminal device is used to determine the security algorithm in the security context, and the method further includes: Acquire the security capability of the terminal device from the operation requester; or, Acquire the security capability of the terminal device from the terminal device; or, The security capability of the terminal device is obtained from a unified data management network element.
54. The method according to any one of claims 51 to 53, characterized in that Determining whether to perform security protection on the first message includes: Whether to perform security protection on the first message is determined according to the operation instruction type of the first operation.
55. The method according to claim 54, characterized in that Determining whether to perform security protection on the first message according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type is an inventory operation, determining not to perform integrity security protection on the first message; When the operation instruction type is a read operation, determining to perform integrity security protection on the first message; When the operation instruction type is a write operation, determining to perform integrity security protection on the first message; When the operation instruction type is an invalid operation, determine to perform integrity security protection on the first message.
56. The method according to claim 54 or 55, characterized in that Determining whether to perform security protection on the first message according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type is an inventory operation, determining not to perform confidentiality security protection on the first message; When the operation instruction type is a read operation, determining not to perform confidentiality security protection on the first message; When the operation instruction type is a write operation, determine to perform confidentiality security protection on the first data to obtain a first data ciphertext, wherein the first data ciphertext is carried in the first message, and the first data is data to be written into a storage area of the terminal device; When the operation instruction type is an invalid operation, it is determined that confidentiality security protection is not performed on the first message.
57. The method according to any one of claims 49 to 56, characterized in that Before sending the first message to the terminal device, the method further includes: Determining whether to send the first message to the terminal device according to the type of the terminal device; In a case where the type of the terminal device is a tag type, it is determined to send the first message to the terminal device.
58. The method according to any one of claims 49 to 57, characterized in that Before sending the first message to the terminal device, the method further includes: determining, according to the service type corresponding to the first operation, whether to send the first message to the terminal device; When the service type corresponding to the first operation is a label service, it is determined to send the first message to the terminal device.
59. The method according to any one of claims 50 to 58, characterized in that Before sending a service response message to the operation requester, the method further includes: receiving a second message from the terminal device, where the second message is used to indicate whether the first operation is successfully performed; Among them, when the operation instruction type is a read operation, the second message includes a second data ciphertext, and the second data ciphertext is obtained by encrypting the second data, and the second data is data read from the storage area of the terminal device or collected by the terminal device.
60. The method according to claim 59, characterized in that The method further comprises: Determine whether to perform integrity check and / or decryption on the second message according to the operation instruction type.
61. The method according to claim 60, characterized in that Determining whether to perform integrity check and / or decryption on the second message according to the operation instruction type specifically includes one or more of the following: When the operation instruction type is an inventory operation, determining not to perform integrity check on the second message; When the operation instruction type is a read operation, determining to perform an integrity check on the second message; When the operation instruction type is a write operation, determining to perform an integrity check on the second message; When the operation instruction type is an invalid operation, determine to perform an integrity check on the second message.
62. The method according to claim 60 or 61, characterized in that Determining whether to perform integrity check and / or decryption on the second message according to the operation instruction type specifically includes one or more of the following: When the operation instruction type is a read operation, determining to decrypt the second data ciphertext to obtain the second data; When the operation instruction type is an inventory operation, a write operation, or an invalidation operation, it is determined not to decrypt the second message.
63. The method according to any one of claims 50 to 62, characterized in that Sending a service response message to the operation requester, including: Sending the service response message to the operation requester according to the operation instruction type specifically includes one or more of the following: When the operation instruction type indicates an inventory operation and the integrity check of the second message passes, the service response message is used to indicate that the first operation is successfully executed, and the service response message includes an identifier of the terminal device; When the operation instruction type indicates a read operation and the integrity check of the second message passes, the service response message is used to indicate that the first operation is successfully executed, and the service response message includes an identifier of the terminal device and second data, wherein the The second data is obtained by decrypting the second data ciphertext, and the second data is data read from the storage area of the terminal device or collected by the terminal device; When the operation instruction type indicates a write operation and the integrity check of the second message passes, the service response message is used to indicate that the first operation is successfully executed, and the service response message includes an identifier of the terminal device; When the operation instruction type indicates an invalid operation and the integrity check of the second message passes, the service response message is used to indicate that the first operation is successfully executed, and the service response message includes the identifier of the terminal device.
64. The method according to any one of claims 50 to 63, characterized in that Sending a service response message to the operation requester, including: Sending the service response message to the operation requester according to the operation instruction type specifically includes one or more of the following: In a case where the operation instruction type indicates a read operation, and the integrity check of the second message fails and / or the decryption of the second message fails, the service response message is used to indicate that the execution of the first operation fails; When the operation instruction type indicates a write operation and the integrity check of the second message fails, the service response message is used to indicate that the execution of the first operation fails; When the operation instruction type indicates an invalid operation and the integrity check of the second message fails, the service response message is used to indicate that the execution of the first operation fails; When the operation instruction type indicates an inventory operation and the integrity check of the second message fails, the service response message is used to indicate that the execution of the first operation has failed.
65. The method according to any one of claims 50 to 64, characterized in that The method further comprises: In the case where the authentication of the terminal device fails, the service response message is used to indicate that the first operation fails.
66. The method according to any one of claims 37 to 35, characterized in that Determining whether to activate the security context according to the operation instruction type of the first operation includes one or more of the following: In a case where the operation instruction type indicates an inventory operation, determining not to activate the security context; In a case where the operation instruction type indicates a read operation, determining to activate the security context; In a case where the operation instruction type indicates a write operation, determining to activate the security context; In a case where the operation instruction type indicates a failure operation, it is determined to activate the security context.
67. The method according to any one of claims 37 to 66, characterized in that The method further comprises: Determining whether to delete the security context according to the type of the terminal device may include one or more of the following: In a case where the type of the terminal device is an active tag or a semi-passive tag, determining not to delete the security context; In a case where the type of the terminal device is a passive tag, it is determined to delete the security context.
68. The method according to any one of claims 37 to 67, characterized in that The first message is a registration acceptance message, and the second message is a registration completion message; or, the first message is a NAS SMC message, and the second message is a NAS SMP message.
69. A communication method, characterized in that: include: Sending a registration request message to a network element, the registration request message being used to request registration with the network, the registration request message including an identifier of the terminal device; receiving a first message from the network element, where the first message is used to instruct to perform a first operation on the terminal device, and the first message is a NAS SMC message; activating a security context according to the NAS SMC message, the security context being used to protect secure communication between the terminal device and the network element; Performing integrity checking and / or decryption on a first message from the network element according to the security context; After the integrity check and / or decryption, the first operation is performed.
70. The method according to claim 69, characterized in that Before performing integrity checking and / or decrypting on the first message from the network element according to the security context, the method further includes: Determine whether to perform integrity check and / or decryption on the first message according to the operation instruction type of the first operation.
71. The method according to claim 70, characterized in that Determining whether to perform integrity check on the first message according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type indicates an inventory operation, determining not to perform integrity check on the first message; When the operation instruction type indicates a read operation, determining to perform an integrity check on the first message; When the operation instruction type indicates an invalid operation, determining to perform an integrity check on the first message; When the operation instruction type indicates a write operation, it is determined to perform an integrity check on the first message.
72. The method according to claim 70 or 71, characterized in that Determining whether to decrypt the first message according to the operation instruction type of the first operation includes one or more of the following: In a case where the operation instruction type indicates an inventory operation, determining not to decrypt the first message; When the operation instruction type indicates a read operation, determining not to decrypt the first message; When the operation instruction type indicates an invalid operation, determining not to decrypt the first message; In the case where the operation instruction type indicates a write operation, it is determined to decrypt the first data ciphertext carried in the first message to obtain first data, where the first data is data to be written into a storage area of the terminal device.
73. The method according to any one of claims 69 to 72, characterized in that The method further comprises: determining whether to perform security protection on a second message according to an operation instruction type of the first operation, wherein the security protection includes integrity security protection and / or confidentiality security protection, and the second message is used to indicate whether the first operation is successfully executed, and the second message is a NAS SMP message; The terminal device sends the second message to the network element.
74. The method according to claim 73, characterized in that Determining whether to perform security protection on the second message according to the operation instruction type includes one or more of the following: When the operation instruction type indicates an inventory operation, determining not to perform integrity security protection on the second message; When the operation instruction type indicates a read operation, determining to perform integrity security protection on the second message; When the operation instruction type indicates a write operation, determining to perform integrity security protection on the second message; In a case where the operation instruction type indicates an invalid operation, it is determined to perform integrity security protection on the second message.
75. The method according to claim 73 or 74, characterized in that Determining whether to perform security protection on the second message according to the operation instruction type includes one or more of the following: When the operation instruction type indicates an inventory operation, determining not to perform confidentiality security protection on the second message; When the operation instruction type indicates a read operation, determining to perform confidentiality security protection on second data to obtain second data ciphertext, where the second data is data in a storage area of the terminal device or data collected by the terminal device, and the second data ciphertext is carried in the second message; When the operation instruction type indicates a write operation, determining not to perform confidentiality security protection on the second message; In a case where the operation instruction type indicates an invalid operation, it is determined that confidentiality security protection is not performed on the second message.
76. A communication method, characterized in that: include: receiving a registration request message from a terminal device, the registration request message being used to request registration with a network, the registration request message including an identifier of the terminal device; activating a security context, where the security context is used to protect secure communication between the terminal device and the network element; Performing security protection on a first message according to the security context, where the security protection includes integrity security protection and / or confidentiality security protection, where the first message is used to instruct to perform a first operation on the terminal device, and where the first message is a NAS SMC message; Sending the first message that has been security-protected to the terminal device.
77. The method according to claim 76, characterized in that The security capability of the terminal device is used to determine the security algorithm in the security context, and the method further includes: Acquire the security capability of the terminal device from the operation requester; or, Acquire the security capability of the terminal device from the terminal device; or, The security capability of the terminal device is obtained from a unified data management network element.
78. The method according to claim 76 or 77, characterized in that Before performing security protection on the first message according to the security context, the method further includes: Whether to perform security protection on the first message is determined according to the operation instruction type of the first operation.
79. The method according to claim 78, characterized in that Determining whether to perform security protection on the first message according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type indicates an inventory operation, determining not to perform integrity security protection on the first message; When the operation instruction type indicates a read operation, determining to perform integrity security protection on the first message; In a case where the operation instruction type indicates an invalid operation, determining to perform integrity security protection on the first message; When the operation instruction type indicates a write operation, it is determined to perform integrity security protection on the first message.
80. The method according to claim 78 or 79, characterized in that Determining whether to perform security protection on the first message according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type indicates an inventory operation, determining not to perform confidentiality security protection on the first message; When the operation instruction type indicates a read operation, determining not to perform confidentiality security protection on the first message; When the operation instruction type indicates an invalid operation, determining not to perform confidentiality security protection on the first message; When the operation instruction type indicates a write operation, it is determined to perform confidentiality security protection on the first data to obtain a first data ciphertext, where the first data is data to be written into a storage area of the terminal device, and the first data ciphertext is carried in the first message.
81. The method according to any one of claims 76 to 80, characterized in that The method further comprises: A second message is received from the terminal device, where the second message is used to indicate whether the first operation is successfully executed, and the second message is a NAS SMP message.
82. The method according to claim 81, characterized in that The method further comprises: Determine whether to perform integrity check and / or decryption on the second message according to the operation instruction type of the first operation.
83. The method according to claim 82, characterized in that Determining whether to perform integrity check on the second message according to the operation instruction type of the first operation includes one or more of the following: When the operation instruction type indicates an inventory operation, determining not to perform integrity check on the second message; When the operation instruction type indicates a read operation, determining to perform an integrity check on the second message; When the operation instruction type indicates an invalid operation, determining to perform an integrity check on the second message; When the operation instruction type indicates a write operation, determine to perform an integrity check on the second message.
84. The method according to claim 82 or 83, characterized in that Determining whether to decrypt the second message according to the operation instruction type of the first operation includes one or more of the following: In a case where the operation instruction type indicates a read operation, determining to decrypt the second data ciphertext carried in the second message to obtain second data, where the second data is data in a storage area of the terminal device or data collected by the terminal device; When the operation instruction type indicates a write operation, determining not to decrypt the second message; When the operation instruction type indicates an invalid operation, determining not to decrypt the second message; In a case where the operation instruction type indicates an inventory operation, it is determined not to decrypt the second message.
85. The method according to any one of claims 76 to 84, characterized in that The method further comprises: receiving a service request message from an operation requester, wherein the service request message is used to request to perform the first operation on the terminal device; Sending a service response message to the operation requester according to the operation instruction type of the first operation includes one or more of the following: In the case where the operation instruction type indicates an inventory operation, the service response message includes an identification of the terminal device; In the case where the operation instruction type indicates a read operation, the service response message includes an identifier of the terminal device and second data, where the second data is data read from a storage area of the terminal device or collected by the terminal device; In the case where the operation instruction type indicates a write operation, the service response message includes an identifier of the terminal device; In the case where the operation instruction type indicates an invalid operation, the service response message includes the identifier of the terminal device.
86. The method according to any one of claims 69 to 85, characterized in that Activating a security context according to the NAS SMC message includes: The security context is activated according to an operation instruction type of the first operation.
87. The method according to claim 86, characterized in that Before activating the security context according to the operation instruction type of the first operation, the method further includes: Determining whether to activate the security context is determined according to an operation instruction type of the first operation.
88. The method according to claim 87, characterized in that Determining whether to activate the security context according to the operation instruction type of the first operation includes: In a case where the operation instruction type indicates an inventory operation, determining not to activate the security context; In a case where the operation instruction type indicates a read operation, determining to activate the security context; In a case where the operation instruction type indicates a write operation, determining to activate the security context; In a case where the operation instruction type indicates a failure operation, it is determined to activate the security context.
89. The method according to any one of claims 86 to 88, characterized in that Activating the security context according to the operation instruction type of the first operation includes: When the operation instruction type indicates an inventory operation, a read operation, or an invalidation operation, activating a security context corresponding to integrity security protection; When the operation instruction type indicates a write operation, a security context corresponding to integrity security protection and a security context corresponding to confidentiality security protection are activated.
90. The method according to any one of claims 69 to 89, characterized in that The method further comprises: The security context is activated according to the type of the terminal device.
91. The method according to claim 90, characterized in that Before activating the security context according to the type of the terminal device, the method further includes: Determine whether to activate the security context according to the type of the terminal device.
92. The method according to claim 91, characterized in that Determining whether to activate the security context according to the type of the terminal device includes: In a case where the type of the terminal device is an active tag or a semi-passive tag, determining to activate the security context; In a case where the terminal device is a passive tag, the security context is activated according to an operation instruction type of the first operation.
93. The method according to any one of claims 90 to 92, characterized in that Activating the security context according to the type of the terminal device includes: In the case where the type of the terminal device is an active tag or a semi-passive tag, activating a security context corresponding to integrity security protection and a security context corresponding to confidentiality security protection; When the terminal device is a passive tag and the operation instruction type of the first operation indicates an inventory operation, a read operation, or a failure operation, activating a security context corresponding to integrity security protection; When the terminal device is a passive tag and the operation instruction type of the first operation indicates a write operation, a security context corresponding to integrity security protection and a security context corresponding to confidentiality security protection are activated.
94. The method according to any one of claims 69 to 93, characterized in that The method further comprises: Determining whether to delete the security context according to the type of the terminal device includes one or more of the following: In a case where the type of the terminal device is an active tag or a semi-passive tag, determining not to delete the security context; In a case where the type of the terminal device is a passive tag, it is determined to delete the security context.
95. A communication system, characterized in that: include: A network element and an operation requester, the network element being used to execute the method as described in any one of claims 18 to 32, and the operation requester being used to execute the method as described in any one of claims 33 to 36.
96. The communication system according to claim 95, characterized in that The communication system further comprises a terminal device, wherein the terminal device is configured to execute the method according to any one of claims 1 to 17.
97. A communication system, characterized in that: include: A network element, wherein the network element is used to execute the method as described in any one of claims 49 to 68.
98. The communication system according to claim 97, characterized in that: The communication system further comprises a terminal device, which is configured to execute the method as claimed in any one of claims 37 to 48 and 66 to 68.
99. A communication system, characterized in that: include: A network element, wherein the network element is used to execute the method as described in any one of claims 76 to 95.
100. The communication system according to claim 99, characterized in that: The communication system also includes a terminal device, which is used to execute the method as described in any one of claims 69 to 75 and 86 to 94.
101. A communication device, characterized in that: include: One or more functional modules, wherein the one or more functional modules are used to execute the method as described in any one of claims 1 to 17, 37 to 48, 66 to 68, 69 to 75, 86 to 94, or the one or more functional modules are used to execute the method as described in any one of claims 18 to 32, 49 to 68, 76 to 95, or the one or more functional modules are used to execute the method as described in any one of claims 33 to 36.
102. A communication device, characterized in that: include: A processor, configured to execute a computer program stored in a memory so that the apparatus performs a method as described in any one of claims 1 to 17, 37 to 48, 66 to 68, 69 to 75, 86 to 94, or so that the apparatus performs a method as described in any one of claims 18 to 32, 49 to 68, 76 to 95, or so that the apparatus performs a method as described in any one of claims 33 to 36.
103. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program or instructions, and when the computer program or instructions are executed, the method according to any one of claims 1 to 94 is implemented.
104. A computer program product, characterized in that When the computer program product is executed, the method according to any one of claims 1 to 94 is implemented.
Citation Information
Patent Citations
Communication method and communication device
CN119922542A
Communication method and device, readable storage medium and chip system
CN116567677A
Evolved packet system (EPS) mobility configuration from wireless system
US20200396647A1
Communication method and apparatus, and device
WO2022067815A1
Data transmission method and related apparatus
WO2022087993A1