Communication method and communication apparatus

By receiving the key length information of the terminal device in the network device and determining the security algorithm based on the information, the problem of how to negotiate a reasonable security protection algorithm between the terminal device and the network side is solved, and the effect of saving computing resources and improving communication efficiency is achieved.

WO2025108327A1PCT designated stage expired Publication Date: 2025-05-30HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/133285
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-24
Filing Date
2024-11-20
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When negotiating security protection algorithms between the terminal device and the network side, how to determine a reasonable security protection algorithm to save computing resources, especially when the terminal device supports multiple security protection algorithms.

Method used

The network device receives the key length indication information of the terminal device, and determines a suitable security algorithm based on the key length to ensure that the input key length of the security algorithm is less than or equal to the key length of the terminal device.

Benefits of technology

It realizes the selection of a reasonable security algorithm based on the key length of the terminal device, thereby saving computing resources and improving communication efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024133285_30052025_PF_FP_ABST
    Figure CN2024133285_30052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a communication method and a communication device. The method comprises: a network device receiving first indication information indicating the length of a first key, the first key being a key of a terminal device; on the basis of the length of the first key, the network device determining a first security algorithm, the length of an input key of the first security algorithm being less than or equal to the length of the first key; and transmitting a message between the network device and the terminal device, the message being a message provided with security protection on the basis of the first security algorithm. The network device can determine a reasonable security algorithm on the basis of the key of the terminal device, thereby saving computing resources. The length of the input key of the security algorithm can be less than or equal to the length of the first key.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and communication device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on November 24, 2023, with application number 202311600455.2, and priority to the Chinese patent application with the invention name “Communication Method and Communication Device”, all contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communications, and more particularly, to a communication method and a communication device. Background Art

[0003] A terminal device and the network can negotiate a security protection algorithm to protect messages transmitted between the terminal device and the network. For example, the terminal device and the network can negotiate the algorithms required for confidentiality and integrity protection based on the security mode control procedure (SMC) of the non-access stratum (NAS) and access stratum (AS). If the user identity module of the terminal device supports the storage of keys of various lengths and the terminal device supports multiple security protection algorithms, how to determine a reasonable security protection algorithm is an issue that needs to be considered. A terminal device and the network can negotiate a security protection algorithm to protect messages transmitted between the terminal device and the network. For example, the terminal device and the network can negotiate the algorithms required for confidentiality and integrity protection based on the security mode control procedure (SMC) of the non-access stratum (NAS) and access stratum (AS). If the user identity module of the terminal device supports the storage of keys of various lengths and the terminal device supports multiple security protection algorithms, how to determine a reasonable security protection algorithm is an issue that needs to be considered. Summary of the Invention

[0004] The present application provides a communication method and a communication device, which can select a reasonable security protection algorithm and save computing resources.

[0005] In a first aspect, a communication method is provided, which may be executed by a network device or a component of the network device (eg, a chip or circuit), and is not limited in this application.

[0006] The method includes: a network device receives first indication information, the first indication information indicates the length of a first key, the first key is the key of a terminal device; the network device determines a first security algorithm based on the length of the first key, the length of the input key of the first security algorithm is less than or equal to the length of the first key; the network device transmits a message to the terminal device, the message is a message that is securely protected based on the first security algorithm. Or,

[0007] The method includes: a network device receives first indication information, the first indication information indicates the length of a first key, and the first key is the key of a terminal device; the network device transmits a message with the terminal device, the message is a message that is security-protected based on the first security algorithm, the first security algorithm is determined based on the length of the first key, and the length of the input key of the first security algorithm is less than or equal to the length of the first key.

[0008] Based on the above solution, the network device can determine a reasonable security algorithm based on the key of the terminal device to save computing resources, wherein the length of the input key of the security algorithm can be less than or equal to the length of the first key.

[0009] In combination with the first aspect, in certain implementations of the first aspect, the network device is a first core network device, and the network device receives the first indication information from the second core network device and / or the terminal device.

[0010] In combination with the first aspect, in certain implementations of the first aspect, the network device is an access network device, and the network device receives the first indication information from the first core network device and / or the terminal device.

[0011] In combination with the first aspect, in certain implementations of the first aspect, the network device determines the first security algorithm based on the length of the first key, the security capability information of the terminal device, and the algorithm priority list, the security capability information of the terminal device indicates the security algorithms supported by the terminal device, and the algorithm priority list is used to indicate the priority of the security algorithms supported by the network side.

[0012] In combination with the first aspect, in certain implementations of the first aspect, the first security algorithm is one of the security algorithms supported by the terminal device, the length of the input key of the first security algorithm is less than or equal to the length of the first key, the priority of the first security algorithm is higher than the priority of the second security algorithm in the algorithm priority list, and the second security algorithm includes security algorithms supported by the terminal device whose input key length is less than or equal to the length of the first key except the first security algorithm.

[0013] In combination with the first aspect, in certain implementations of the first aspect, the network device determines the length of a security key based on the first security algorithm, where the security key is the key used by the security algorithm, and the length of the security key is the same as the length of an input key of the first security algorithm.

[0014] In combination with the first aspect, in certain implementations of the first aspect, the network device sends a second indication message to the terminal device, where the second indication message indicates the length of the first key, and the length of the first key is used to determine the length of the key output by the key derivation algorithm, and the output key is used to generate a security key, which is the key used by the security algorithm.

[0015] In a second aspect, a communication method is provided. The method may be executed by a terminal device or by a component of the terminal device (such as a chip or circuit), which is not limited in this application.

[0016] The method includes: sending a first indication message to a network device, the first indication message indicating the length of a first key, the first key being the key of a terminal device, the length of the first key being used by the first core network device to determine the length of an input key of a first security algorithm, the length of the input key of the first security algorithm being less than or equal to the length of the first key; and transmitting a message with the network device, the message being a message that is security-protected based on the first security algorithm.

[0017] Based on the above scheme, by indicating the length of the first key to the network device, the network device can determine a reasonable security algorithm based on the key of the terminal device, saving computing resources, wherein the length of the input key of the security algorithm can be less than or equal to the length of the first key.

[0018] In combination with the second aspect, in some implementations of the second aspect, before sending the first indication information to the network device, the length of the first key is obtained from the user identity recognition module.

[0019] In combination with the second aspect, in certain implementations of the second aspect, before transmitting a message with the network device, the length of the key output by the key derivation algorithm is determined based on the length of the first key, and the key output by the key derivation algorithm is used to generate a security key, which is the key used by the first security algorithm.

[0020] On the third aspect, a communication method is provided. The method can be executed by the second core network device or by a component of the second core network device (such as a chip or circuit), and this application does not limit this.

[0021] The method includes: determining the length of a first key of a terminal device; sending a first indication message to a first core network device, the first indication message indicating the length of the first key, the length of the first key being used to determine the length of a key input to a first security algorithm, the length of the input key of the first security algorithm being less than or equal to the length of the first key, and the first security algorithm being used to provide security protection for messages transmitted with the terminal device.

[0022] Based on the above scheme, by determining and indicating the length of the first key to the network device, the network device can determine a reasonable security algorithm based on the key of the terminal device, saving computing resources, wherein the length of the input key of the security algorithm can be less than or equal to the length of the first key.

[0023] In combination with the third aspect, in certain implementations of the third aspect, identification information of the terminal device is received from the first core network device; and the length of the first key is determined based on the identification information of the terminal device.

[0024] In combination with the third aspect, in certain implementations of the third aspect, the length of the key output by the key derivation algorithm is determined based on the length of the first key, and the output key is used to generate a security key, which is the key used by the security algorithm.

[0025] In a fourth aspect, a communication method is provided. The method can be executed by a terminal device or by a component of the terminal device (such as a chip or circuit), and this application does not limit this.

[0026] The method includes: sending security capability information of a terminal device to a network device, the security capability information indicating a security algorithm supported by the terminal device, the length of an input key of the security algorithm supported by the terminal device being less than or equal to the length of a first key, the first key being the key of the terminal device, and the security capability information of the terminal device being used by the first core network device to determine a first security algorithm; and transmitting a message with the network device, the message being a message that is security-protected based on the first security algorithm.

[0027] Based on the above scheme, by sending the security capability information of the terminal device to the network device, the length of the input key of the security algorithm supported by the terminal device indicated by the security capability information is less than or equal to the length of the first key, so that the network device can determine a reasonable security algorithm based on the security capability information of the terminal device, thereby saving computing resources.

[0028] In combination with the fourth aspect, in certain implementations of the fourth aspect, before sending the security capability information of the terminal device to the network device, the length of the first key is obtained from the user identity recognition module.

[0029] In combination with the fourth aspect, in certain implementations of the fourth aspect, before transmitting a message with the network device, the security capability information of the terminal device to be sent to the network device is determined based on the length of the first key and the security capability information configured in the terminal device.

[0030] In combination with the fourth aspect, in certain implementations of the fourth aspect, before transmitting a message with the network device, the length of the key output by the key derivation algorithm is determined based on the length of the first key, and the key output by the key derivation algorithm is used to generate a security key, which is the key used by the first security algorithm.

[0031] In a fifth aspect, a communication method is provided. The method can be executed by a network device or by a component of the network device (such as a chip or circuit), and this application does not limit this.

[0032] The method includes: receiving security capability information of a terminal device, the security capability information indicating a security algorithm supported by the terminal device, the length of an input key of the security algorithm supported by the terminal device being less than or equal to the length of a first key, the first key being the key of the terminal device; transmitting a message with the terminal device, the message being a message that is security-protected based on a first security algorithm, the first security algorithm being one of the security algorithms supported by the terminal device.

[0033] Based on the above scheme, by sending the security capability information of the terminal device to the network device, the length of the input key of the security algorithm supported by the terminal device indicated by the security capability information is less than or equal to the length of the first key, so that the network device can determine a reasonable security algorithm based on the security capability information of the terminal device, thereby saving computing resources.

[0034] In combination with the fifth aspect, in certain implementations of the fifth aspect, before transmitting a message with the terminal device, the algorithm priority list determines the first security algorithm based on the security capability information of the terminal device, and the priority of the first security algorithm is higher than the security algorithms supported by the terminal device other than the first security algorithm included in the algorithm priority list.

[0035] In combination with the fifth aspect, in certain implementations of the fifth aspect, the length of the security key is determined based on the first security algorithm, the security key is the key used by the security algorithm, and the length of the security key is the same as the length of the input key of the first security algorithm.

[0036] In the sixth aspect, a communication device is provided, which includes a transceiver unit and a processing unit. The transceiver unit is used to receive first indication information, which indicates the length of a first key, and the first key is the key of a terminal device; the processing unit is used to determine a first security algorithm based on the length of the first key, and the length of the input key of the first security algorithm is less than or equal to the length of the first key; the device transmits a message with the terminal device, which is a message that is security protected based on the first security algorithm.

[0037] In combination with the sixth aspect, in certain implementations of the sixth aspect, the apparatus is a first core network device, and the transceiver unit is specifically used to receive the first indication information from the second core network device and / or the terminal device.

[0038] In combination with the sixth aspect, in certain implementations of the sixth aspect, the apparatus is an access network device, and the transceiver unit is specifically used to receive the first indication information from the first core network device and / or the terminal device.

[0039] In combination with the sixth aspect, in certain implementations of the sixth aspect, the processing unit is specifically used to determine the first security algorithm based on the length of the first key, the security capability information of the terminal device, and the algorithm priority list, the security capability information of the terminal device indicates the security algorithms supported by the terminal device, and the algorithm priority list is used to indicate the priority of the security algorithms supported by the network side.

[0040] In combination with the sixth aspect, in certain implementations of the sixth aspect, the first security algorithm is one of the security algorithms supported by the terminal device, the length of the input key of the first security algorithm is less than or equal to the length of the first key, the priority of the first security algorithm is higher than the priority of the second security algorithm in the algorithm priority list, and the second security algorithm includes security algorithms supported by the terminal device whose input key length is less than or equal to the length of the first key except the first security algorithm.

[0041] In combination with the sixth aspect, in certain implementations of the sixth aspect, the processing unit is also used to determine the length of a security key based on the first security algorithm, where the security key is the key used by the security algorithm, and the length of the security key is the same as the length of the input key of the first security algorithm.

[0042] In combination with the sixth aspect, in certain implementations of the sixth aspect, the transceiver unit is also used to send a second indication message to the terminal device, where the second indication message indicates the length of the first key. The length of the first key is used to determine the length of the key output by the key derivation algorithm. The output key is used to generate a security key, which is the key used by the security algorithm.

[0043] In the seventh aspect, a communication device is provided, which includes a transceiver unit, wherein the transceiver unit is used to send a first indication information to a network device, wherein the first indication information indicates the length of a first key, wherein the first key is the key of the terminal device, and the length of the first key is used by the first core network device to determine the length of an input key of a first security algorithm, wherein the length of the input key of the first security algorithm is less than or equal to the length of the first key; the transceiver unit is also used to transmit a message with the network device, wherein the message is a message that is security-protected based on the first security algorithm.

[0044] In combination with the seventh aspect, in certain implementations of the seventh aspect, the apparatus further includes a processing unit configured to obtain the length of the first key from the user identity identification module before sending the first indication information to the network device.

[0045] In combination with the seventh aspect, in certain implementations of the seventh aspect, before transmitting a message with the network device, the processing unit is also used to determine the length of the key output by the key derivation algorithm based on the length of the first key, and the key output by the key derivation algorithm is used to generate a security key, which is the key used by the first security algorithm.

[0046] In the eighth aspect, a communication device is provided, which includes a transceiver unit and a processing unit, the processing unit is used to determine the length of a first key of a terminal device; the transceiver unit is used to send a first indication information to a first core network device, the first indication information indicates the length of the first key, the length of the first key is used to determine the length of the key input by a first security algorithm, the length of the input key of the first security algorithm is less than or equal to the length of the first key, and the first security algorithm is used to securely protect messages transmitted with the terminal device.

[0047] In combination with the eighth aspect, in certain implementations of the eighth aspect, the transceiver unit is specifically used to receive identification information of the terminal device from the first core network device; the transceiver unit is also used to determine the length of the first key based on the identification information of the terminal device.

[0048] In combination with the eighth aspect, in certain implementations of the eighth aspect, the processing unit is also used to determine the length of the key output by the key derivation algorithm based on the length of the first key, and the output key is used to generate a security key, which is the key used by the security algorithm.

[0049] In the ninth aspect, a communication device is provided, which includes a transceiver unit, which is used to send security capability information of the device to a network device, the security capability information indicates a security algorithm supported by the device, the length of an input key of the security algorithm supported by the device is less than or equal to the length of a first key, the first key is the key of the device, and the security capability information of the device is used by the first core network device to determine a first security algorithm; the transceiver unit is used to transmit a message with the network device, which is a message that is security protected based on the first security algorithm.

[0050] In combination with the ninth aspect, in certain implementations of the ninth aspect, the apparatus further includes a processing unit configured to obtain the length of the first key from the user identity identification module before sending the security capability information of the apparatus to the network device.

[0051] In combination with the ninth aspect, in certain implementations of the ninth aspect, the processing unit is also used to determine the security capability information of the device to be sent to the network device based on the length of the first key and the security capability information configured in the device before transmitting the message with the network device.

[0052] In combination with the ninth aspect, in certain implementations of the ninth aspect, the processing unit is also used to determine the length of the key output by the key derivation algorithm based on the length of the first key before transmitting a message with the network device. The key output by the key derivation algorithm is used to generate a security key, which is the key used by the first security algorithm.

[0053] In the tenth aspect, a communication device is provided, which includes a transceiver unit and a processing unit, the transceiver unit is used to receive security capability information of a terminal device, the security capability information indicates a security algorithm supported by the terminal device, the length of an input key of the security algorithm supported by the terminal device is less than or equal to the length of a first key, and the first key is the key of the terminal device; the transceiver unit is also used to transmit a message with the terminal device, the message is a message that is security-protected based on a first security algorithm, and the first security algorithm is one of the security algorithms supported by the terminal device.

[0054] In combination with the tenth aspect, in certain implementations of the tenth aspect, the apparatus further includes a processing unit, which is used to determine the first security algorithm based on the security capability information of the terminal device and the algorithm priority list before transmitting a message with the terminal device, wherein the priority of the first security algorithm is higher than the security algorithms supported by the terminal device other than the first security algorithm included in the algorithm priority list.

[0055] In combination with the tenth aspect, in certain implementations of the tenth aspect, the processing unit is further used to determine the length of a security key based on the first security algorithm, where the security key is the key used by the security algorithm, and the length of the security key is the same as the length of the input key of the first security algorithm.

[0056] In an eleventh aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and configured to execute instructions in the memory to implement the method of the first and fifth aspects, and any possible implementation of the first and fifth aspects. Optionally, the communication device further comprises a memory. Optionally, the communication device further comprises a communication interface, the processor being coupled to the communication interface.

[0057] In one implementation, the communication device is a network device. When the communication device is a network device, the communication interface may be a transceiver or an input / output interface.

[0058] In another implementation, the communication device is a chip configured in a network device. When the communication device is a chip configured in a network device, the communication interface may be an input / output interface.

[0059] Optionally, the transceiver may be a transceiver circuit. Optionally, the input / output interface may be an input / output circuit.

[0060] In a twelfth aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and is configured to execute instructions in the memory to implement the method of the second and fourth aspects, and any possible implementation of the second and fourth aspects. Optionally, the communication device further comprises a memory. Optionally, the communication device further comprises a communication interface, the processor being coupled to the communication interface.

[0061] In one implementation, the communication device is a terminal device. When the communication device is a terminal device, the communication interface may be a transceiver, or an input / output interface.

[0062] In another implementation, the communication device is a chip configured in a terminal device. When the communication device is a chip configured in a terminal device, the communication interface may be an input / output interface.

[0063] In a thirteenth aspect, a communication device is provided, comprising a processor. The processor is coupled to a memory and configured to execute instructions in the memory to implement the method of the third aspect and any possible implementation of the third aspect. Optionally, the communication device further comprises a memory. Optionally, the communication device further comprises a communication interface, the processor being coupled to the communication interface.

[0064] In one implementation, the communication device is a second core network device. When the communication device is a second core network device, the communication interface may be a transceiver, or an input / output interface.

[0065] In another implementation, the communication device is a chip configured in the second core network device. When the communication device is a chip configured in the second core network device, the communication interface may be an input / output interface.

[0066] In a fourteenth aspect, a processor is provided, comprising: an input circuit, an output circuit, and a processing circuit. The processing circuit is configured to receive a signal through the input circuit and transmit a signal through the output circuit, so that the processor executes the method of any possible implementation of aspects 1 to 5.

[0067] In a specific implementation, the processor may be one or more chips, the input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be a transistor, a gate circuit, a trigger, or various logic circuits. The input signal received by the input circuit may be received and input by a receiver, and the signal output by the output circuit may be output to and transmitted by a transmitter. The input circuit and the output circuit may be the same circuit, which functions as an input circuit and an output circuit at different times. The embodiments of the present application do not limit the specific implementation of the processor and various circuits.

[0068] In a fifteenth aspect, a processing device is provided, comprising a processor and a memory. The processor is configured to read instructions stored in the memory and receive signals via a receiver and transmit signals via a transmitter to execute the method of any possible implementation of aspects 1 to 5.

[0069] Optionally, there are one or more processors and one or more memories.

[0070] Optionally, the memory may be integrated with the processor, or be provided separately from the processor.

[0071] In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM). The memory can be integrated with the processor on the same chip, or can be set on different chips. The embodiments of the present application do not limit the type of memory and the setting method of the memory and the processor.

[0072] It should be understood that related data interaction processes, such as sending indication information, can be the process of outputting indication information from the processor, and receiving capability information can be the process of receiving input capability information from the processor. Specifically, data output by the processor can be output to the transmitter, and input data received by the processor can be received from the receiver. The transmitter and receiver can be collectively referred to as a transceiver.

[0073] The processing device in the fifteenth aspect may be one or more chips. The processor in the processing device may be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, or the like; when implemented in software, the processor may be a general-purpose processor implemented by reading software code stored in a memory, which may be integrated into the processor or located independently of the processor.

[0074] In the sixteenth aspect, a computer program product is provided, which includes: a computer program (also referred to as code, or instructions), which, when executed, enables a computer to execute a method in any possible implementation of the first to fifth aspects above.

[0075] In the seventeenth aspect, a computer-readable storage medium is provided, which stores a computer program (also referred to as code, or instructions) which, when run on a computer, enables the method in any possible implementation of the above-mentioned first to fifth aspects to be executed.

[0076] In the eighteenth aspect, a communication system is provided, comprising at least one of the aforementioned terminal device, network device and second core network device. BRIEF DESCRIPTION OF THE DRAWINGS

[0077] FIG1 is a schematic diagram of a network architecture 100 .

[0078] FIG2 is a schematic diagram of a key architecture.

[0079] FIG3 is a schematic flow chart of a NAS SMC process.

[0080] FIG4 is a schematic flow chart of an AS SMC process.

[0081] FIG5 is a schematic flowchart of a communication method 500 provided in this application.

[0082] FIG6 is a schematic flowchart of a communication method 600 provided in this application.

[0083] FIG7 is a schematic flowchart of a communication method 700 provided in this application.

[0084] FIG8 is a schematic flowchart of a communication method 800 provided in this application.

[0085] FIG9 is a schematic flowchart of a communication method 800 provided in this application.

[0086] FIG10 is a schematic block diagram of a communication device 10 provided in an embodiment of the present application.

[0087] FIG11 is a schematic diagram of another communication device 20 provided in an embodiment of the present application.

[0088] FIG12 is a schematic diagram of a chip system 30 provided in an embodiment of the present application. DETAILED DESCRIPTION

[0089] The technical solution in this application will be described below with reference to the accompanying drawings.

[0090] The technical solutions provided in this application can be applied to various communication systems, such as new radio (NR) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, etc. The technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.

[0091] In the communication system, the part operated by the operator can be called a public land mobile network (PLMN), or an operator network, etc. PLMN is a network established and operated by the government or an operator approved by it for the purpose of providing land mobile communication services to the public. It is mainly a public network in which mobile network operators (MNOs) provide mobile broadband access services to users. The PLMN described in the embodiment of the present application may specifically be a network that meets the requirements of the 3GPP standard, referred to as a 3GPP network. 3GPP networks generally include but are not limited to 5G networks, fourth-generation mobile communications (4th-generation, 4G) networks, and other future communication systems, such as (6th-generation, 6G) networks, etc. This technical solution is also applicable to SNPN (Stand-alone Non-Public Network).

[0092] For the convenience of description, the embodiments of the present application will be described using PLMN or 5G network as an example.

[0093] Figure 1 is a schematic diagram of a network architecture 100, using the 5G network architecture based on a service-oriented architecture for non-roaming scenarios as defined in the 3GPP standardization process as an example. As shown, the network architecture consists of three components: the terminal device component, the DN, and the operator network PLMN component. The following briefly describes the functions of the network elements in each component.

[0094] The terminal device part may include a terminal device 110, which may also be referred to as user equipment (UE). The terminal device 110 in this application is a device with wireless transceiver functions, which can communicate with one or more core network (CN) devices via an access network device (or also referred to as an access device) in a radio access network (RAN) 140. The terminal device 110 may also be referred to as an access terminal, terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent or user device, etc. The terminal device 110 may be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it may also be deployed on water (such as ships, etc.); it may also be deployed in the air (such as airplanes, balloons and satellites, etc.). The terminal device 110 may be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a smart phone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), etc. Alternatively, the terminal device 110 may be a handheld device with wireless communication capabilities, a computing device, or other device connected to a wireless modem, an in-vehicle device, a wearable device, an unmanned aerial vehicle (UAV), or a terminal in the Internet of Things (IoT), the Internet of Vehicles (IoV), any terminal in a 5G network or future networks, a relay user device, or a terminal in a future evolving 6G network, etc. The relay user device may be, for example, a 5G residential gateway (RG). For example, the terminal device 110 can be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. The terminal device here refers to a 3GPP terminal. The embodiments of the present application do not limit the type or category of the terminal device. For ease of explanation, this application will be described later using UE as an example to refer to the terminal device.

[0095] The operator network PLMN part may include but is not limited to the (radio) access network (R)AN) 120 and the core network (CN) part.

[0096] (R)AN 120 can be considered a subnetwork of the operator network, serving as the implementation system between service nodes in the operator network and terminal device 110. To access the operator network, terminal device 110 first passes through (R)AN 120, which then connects to service nodes in the operator network. The access network device (RAN device) in the embodiment of the present application is a device that provides wireless communication functions for the terminal device 110, and can also be called a network device. The RAN device includes but is not limited to: the next generation node base station (gNB) in the 5G system, the evolved node B (eNB) in the long term evolution (LTE), the radio network controller (RNC), the node B (NB), the base station controller (BSC), the base transceiver station (BTS), the home base station (for example, home evolved node B, or home node B, HNB), the base band unit (BBU), the transmission point (TRP), the transmitting point (TP), the small base station device (pico), the mobile switching center, or the network device in the future network. In systems using different wireless access technologies, the name of the device with the access network device function may be different. For the convenience of description, in all embodiments of the present application, the above-mentioned device that provides wireless communication functions for the terminal device 110 is collectively referred to as the access network device or simply referred to as RAN or AN. It should be understood that this document does not limit the specific type of access network equipment.

[0097] The CN part may include but is not limited to the following NFs: user plane function (UPF) 130, network exposure function (NEF) 131, network function repository function (NRF) 132, policy control function (PCF) 133, unified data management function (UDM) 134, unified data repository function (UDR) 135, network data analytics function (NWDAF) 136, authentication server function (AUSF) 137, access and mobility management function (AMF) 138, and session management function (SMF) 139.

[0098] Data network DN 140, also known as a packet data network (PDN), is typically located outside of a carrier network, such as a third-party network. Of course, in some implementations, the DN may also be deployed by the carrier, meaning that the DN is part of a PLMN. This application does not restrict whether the DN is a PLMN. A carrier network PLMN can access multiple data network DNs 140, and various services can be deployed on the data network DN 140, providing data and / or voice services to the terminal device 110. For example, data network DN 140 may be the private network of a smart factory, where sensors installed in the workshop may be terminal devices 110. A control server for the sensors is deployed within data network DN 140, and the control server can provide services to the sensors. The sensors can communicate with the control server, obtain instructions from the control server, and transmit collected sensor data to the control server according to the instructions. For another example, data network DN 140 may be a company's internal office network, where the company's employees' mobile phones or computers may be terminal devices 110, allowing the employees' mobile phones or computers to access information and data resources on the company's internal office network. Terminal device 110 can establish a connection with the operator network through an interface provided by the operator network (e.g., N1) and use data and / or voice services provided by the operator network. Terminal device 110 can also access data network DN 140 through the operator network and use operator services deployed on data network DN 140 and / or services provided by third parties.

[0099] The following is a brief description of the NF functions included in CN.

[0100] 1. UPF 130 is a gateway provided by the operator, serving as the gateway for communication between the operator network and the data network DN 140. UPF 130 includes user-plane-related functions such as packet routing and transmission, packet inspection, service usage reporting, Quality of Service (QoS) processing, lawful interception, uplink packet inspection, and downlink packet storage.

[0101] 2. NEF 131 is a control plane function provided by the operator. It mainly enables third parties to use the services provided by the network, supports the network to open its capabilities, event and data analysis, provides PLMN security configuration information from external applications, and converts interactive information inside and outside the PLMN. It provides an API interface open to the operator network and provides interaction between external servers and internal operator networks.

[0102] 3. NRF 132 is a control plane function provided by the operator. It is used to maintain real-time information about network functions and services in the network. For example, it supports network service discovery, maintains the services supported by the NF profile of the NF instance, supports service discovery of the service communication proxy (SCP), maintains the SCP profile of the SCP instance, sends notifications about newly registered, deregistered, and updated NFs and SCPs, and maintains the health status of NF and SCP operations.

[0103] 4. PCF 133 is the control plane function provided by the operator. It supports a unified policy framework to govern network behavior, provide policy rules to other control functions, and provide contract information related to policy decisions.

[0104] 5. UDM 134 is a control plane function provided by the operator and is responsible for storing information such as the subscriber permanent identifier (SUPI), the generic public subscription identifier (GPSI), and credentials of subscribers in the operator's network.

[0105] Among them, the SUPI will first be protected for confidentiality during transmission, and the confidentiality-protected SUPI is called a hidden user subscription identifier (SUCI). The information stored in the UDM 134 can be used for authentication and authorization of the terminal device 110 to access the operator network. Among them, the subscribers of the above-mentioned operator network can specifically be users who use the services provided by the operator network, such as users who use China Telecom's mobile phone chip card (Subscriber Identity Module, SIM card) or users who use China Mobile's mobile phone chip card. The credentials of the above-mentioned subscribers can be a long-term key stored in the mobile phone chip card or a small file storing information related to the encryption of the mobile phone chip card, which is used for authentication and / or authorization. It should be noted that the permanent identifier, credentials, security context, authentication data (cookie), and token are equivalent to information related to verification / authentication and authorization. In the embodiment of the present application, for the convenience of description, no distinction or restriction is made.

[0106] 6. UDR 135 is a control plane function provided by the operator. It provides the UDM with the functions of storing and retrieving subscription data, the PCF with the functions of storing and retrieving policy data, and the user's NF group ID information.

[0107] 7. NWDAF 136 is a control plane function provided by the operator. Its primary function is to collect data from the NF, external application function (AF), and operations, administration, and maintenance (OAM) systems, and to provide NWDAF service registration, data exposure, and data analysis to the NF and AF. In this application, NWDAF is primarily responsible for security-related data analysis. Therefore, NWDAF can also be understood as a network element with security analysis capabilities. The term "NWDAF" is merely an example, and other network element names may be used in the future. This application does not limit this.

[0108] 8. AUSF 137 is a control plane function provided by the operator and is typically used for level 1 authentication, that is, authentication between the terminal device 110 (subscriber) and the operator's network. After receiving an authentication request initiated by the subscriber, AUSF 137 can authenticate and / or authorize the subscriber using the authentication information and / or authorization information stored in UDM 134, or generate authentication and / or authorization information for the subscriber through UDM 134. AUSF 137 can also provide the subscriber with feedback on the authentication and / or authorization information.

[0109] 9. AMF 138 is a control plane network function provided by the operator network, responsible for access control and mobility management of the terminal device 110 accessing the operator network, such as mobility status management, allocation of user temporary identity, authentication and authorization of users, etc.

[0110] AMF 138 is used to establish a non-access stratum (NAS) connection with the UE and has the same 5G NAS security context as the UE. The 5G NAS security context may include K AMF , NAS-level keys and their corresponding key identifiers, UE security capabilities, uplink NAS COUNT values, and downlink NAS COUNT values. NAS-level keys include NAS confidentiality protection keys and NAS integrity protection keys, which are used for confidentiality protection and integrity protection of NAS messages, respectively.

[0111] 10. SMF 139 is a control plane network function provided by the operator network and is responsible for managing the PDU session of the terminal device 110. A PDU session is a channel for transmitting PDUs. The terminal device needs to transmit PDUs to and from the data network DN 140 through a PDU session. The SMF 139 is responsible for establishing, maintaining, and deleting PDU sessions. SMF 139 includes session management (such as session establishment, modification, and release, including tunnel maintenance between the user plane function UPF 130 and (R)AN 120), selection and control of the UPF 130, service and session continuity (SSC) mode selection, roaming, and other session-related functions.

[0112] 11. AF 141 is a control plane network function provided by the operator network. It is used to provide application layer information and can interact with the policy framework through network open function elements or directly interact with the policy framework to make policy decision requests. It can be located inside or outside the operator network.

[0113] It is understood that the above network elements or functions can be physical entities in hardware devices, software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (e.g., a cloud platform). Simply put, an NF can be implemented by hardware or software.

[0114] In Figure 1, Nnef, Nnrf, Npcf, Nudm, Nudr, Nnwdaf, Nausf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface serial numbers. For example, the meaning of the above interface serial numbers can be found in the meaning defined in the 3GPP standard protocol, and this application does not limit the meaning of the above interface serial numbers. It should be noted that the interface name between the various network functions in the figure is only an example. In a specific implementation, the interface name of the system architecture may also be other names, which is not limited by this application. In addition, the name of the message (or signaling) transmitted between the above network elements is only an example and does not constitute any limitation on the function of the message itself.

[0115] For ease of explanation, in the embodiments of this application, network functions (such as NEF 131…SMF 139) are collectively referred to as NFs. That is, the NFs described later in the embodiments of this application can be replaced with any network function. Furthermore, FIG1 schematically illustrates only some network functions, and the NFs described later are not limited to those shown in FIG1.

[0116] It should be understood that the above-mentioned network architecture applied to the embodiment of the present application is only a network architecture described from the perspective of service-oriented architecture. The network architecture applicable to the embodiment of the present application is not limited to this. Any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiment of the present application.

[0117] It should also be understood that the AMF, SMF, UPF, NEF, AUSF, NRF, PCF, and UDM shown in the figure can be understood as network elements used to implement different functions in the core network, for example, they can be combined into network slices as needed. These core network network elements can be independent devices or integrated into the same device to implement different functions. This application does not limit the specific form of the above network elements.

[0118] It should also be understood that the above naming is defined only to facilitate the distinction between different functions and should not constitute any limitation to this application. This application does not exclude the possibility of adopting other naming in 5G networks and other future networks. For example, in a 6G network, some or all of the above network elements may continue to use the terminology used in 5G, or may adopt other names.

[0119] To facilitate understanding of the embodiments of the present application, some basic concepts involved in the present application are briefly explained.

[0120] 1. Key Architecture

[0121] In the 5G system (5GS), taking the 5G authentication and key agreement (5G AKA) protocol as an example, the key architecture generated by the key hierarchy is shown in Figure 2. Among them, the keys related to identity authentication may include K, CK (cipher key), IK (integrity key), and the key hierarchy includes the following keys in sequence: AUSF key (K AUSF ), anchor key (K SEAF ), AMF key (K AMF ), NAS signaling key (K NASint , K NASenc ), non-3GPP access key (K N3IWF ), NG-RAN key (K gNB ), the key transmitted by the user plane (K UPint , K UPenc ), RRC signaling key (K RRCint , K RRCenc ).

[0122] Specifically, in 5GS, security network elements (or network elements with root keys) include the UDM, AMF, AUSF, authentication credential repository and processing function (ARPF) network element, and security anchor function (SEAF) network element. The ARPF is primarily used to store user root keys and related authentication subscription data, and calculate the 5G authentication vector. The SEAF is primarily used to derive the underlying NAS and AS keys based on the anchor key and compare authentication results.

[0123] The following is a description of each of the above keys:

[0124] (1)K AUSF : K in the home network AUSF K is derived from CK and IK by mobile equipment (ME) and ARPF AUSF . K AUSF Received from the ARPF as part of the 5G home environment authentication vector (HEAV).

[0125] (2)K SEAF :ME and AUSF from K AUSF Derived anchor key. K AUSF Provided by AUSF to SEAF in the serving network.

[0126] (3)K AMF :K in service network AMF It is ME and SEAF from K SEAF Derived key. K AMF Further derived by the ME and source AMF when performing horizontal key derivation.

[0127] (4)NAS signaling key: K NASint It is ME and AMF from K AMF The derived key that is used to protect NAS signaling using a specific integrity algorithm. K NASenc It is ME and AMF from K AMF The derived key is used to protect NAS signaling using a specific encryption algorithm.

[0128] (5)K N3IWF :K N3IWF It is ME and AMF from K AMF Derived key for non-3GPP access. KN3IWF Not forwarded between N3IWFs.

[0129] (6)K gNB :K gNB It is ME and AMF from K AMF Derived key. K gNB Further derived by the ME and source gNB when performing horizontal or vertical key derivation.

[0130] (7) User plane UP transmission key: K UPint ME and gNB from K gNB The key generated by the ME is used to protect the user plane data between the ME and the gNB using a specific integrity algorithm. UPenc ME and gNB from K gNB The derived key is used to protect data transmitted by UP using a specific encryption algorithm.

[0131] (8)RRC signaling key: K RRCint ME and gNB from K gNB A derived key used to protect RRC signaling using a specific integrity algorithm. RRCenc ME and gNB from K gNB A derived key that is used to protect RRC signaling using a specific encryption algorithm.

[0132] It should be understood that when deriving new keys from a secret key, a key derivation function (KDF) may be used. A key derivation function is a function that uses a pseudo-random function to derive one or more keys from a master key. A key derivation function can extend a key to a longer key or obtain a key in a desired format.

[0133] Exemplarily, CK and IK can be derived based on a random challenge (RAND), an authentication token (AUTH), and K, wherein the network side sends RAND and AUTH to the UE in plain text, that is, except for K, other inputs for calculating CK and IK are sent in plain text.

[0134] In addition, the underlying algorithms of f1-f5 can use two algorithms: MILENAGE algorithm and Tuak algorithm.

[0135] Among them, the Tuak algorithm supports 128 bits and 256 bits, that is, the input key K can be 128 or 256 bits, and the output CK and IK can be 128 bits or 256 bits; the current MILENAGE algorithm supports 128 bits, that is, the input key K is 128 bits, and the output CK and IK are 128 bits; in the R19 stage, it may be upgraded to 256 bits, that is, the MILENAGE algorithm can support an input K of 256 bits, and the output CK and IK are also 256 bits.

[0136] According to security principles, since the keys used for communication between the UE and the network are all derived from long-term keys, and no other unknown random factors are introduced during the derivation process, when the UE's long-term key is 128 bits, the maximum overall security strength it can provide is 128 bits, and it cannot provide 256 bits of security strength. Using the above key derivation method, the corresponding keys can be derived and used to protect the corresponding NAS, RRC, and user plane (UP) data.

[0137] 2. NAS security context:

[0138] For example, the NAS security context can be divided into a full NAS security context and a partial NAS security context from the perspective of whether it is complete.

[0139] Some NAS security contexts include: K AMF and its associated key identifier (ngKSI), UE security capability, uplink NAS counter value, and downlink NAS counter value. Compared to the partial NAS security context, the full NAS security context also includes integrity security protection keys and confidentiality security protection (or encryption security protection) keys, as well as the selected integrity security protection algorithm and confidentiality security protection algorithm.

[0140] For example, from the perspective of source, NAS security context can be divided into native NAS security context and mapped NAS security context.

[0141] Among them, K in the native NAS security context AMF It is generated by executing the main authentication process and is identified by the native ngKSI; it maps the K in the NAS security context AMF It is generated from other keys during the interaction between networks of different generations (such as generated from 4G keys during the interaction from 4G to 5G) and is identified by the mapped ngKSI.

[0142] For example, NAS security contexts can be divided into current and non-current from a status perspective. A current NAS security context refers to a security context that was recently activated, while a non-current NAS security context refers to a security context that is not in use.

[0143] As can be seen from the above, the specific types of NAS security contexts may include mapped, fully native, or partially native security contexts. The status may be active or inactive. For example, after the UE and the core network complete the primary authentication, a partially native context is generated, and the status is inactive. The AMF initiates a NAS security mode control (SMC) process to the UE. After the NAS SMC succeeds, a fully native NAS context is generated, and the status is active.

[0144] 3. Security Algorithm Selection Process

[0145] In the following process, the network side or the UE side selects a security algorithm for confidentiality security protection and / or integrity security protection.

[0146] 1) Initial NAS security context establishment

[0147] For example, each AMF can provide a priority list of algorithms allowed for use through network management configuration. The algorithm priority list can include algorithms used for NAS integrity security protection (denoted as NAS integrity protection algorithms) and algorithms used for NAS confidentiality security protection (NAS encryption algorithms). The algorithms in these lists can be sorted according to the priority determined by the operator.

[0148] To establish the NAS security context, the AMF may select a NAS encryption algorithm and a NAS integrity protection algorithm. The AMF may then initiate a NAS Security Mode Command (SMC) procedure and include the selected algorithms and UE security capabilities in a message sent to the UE. For example, the AMF may select a NAS encryption algorithm and a NAS integrity protection algorithm that have a higher priority and are also present in the UE security capabilities based on an ordered list.

[0149] Optionally, during N2 handover or mobility registration update, the AMF serving the UE may change, which may cause the security algorithm used to establish NAS security to change. In this case, the target AMF indicates to the UE (e.g. using a NAS container) the security algorithm selected for N2 handover and mobility registration update (using a NAS SMC).

[0150] 2) Initial AS security context establishment

[0151] For example, each RAN node can be configured through network management to provide a priority list of algorithms allowed for use. The algorithm priority list can include algorithms for AS integrity security protection (denoted as AS integrity protection algorithms) and algorithms for AS confidentiality security protection (AS encryption algorithms). When establishing an AS security context in the RAN node, the AMF can send the UE security capabilities to the RAN node. The RAN node selects the AS encryption algorithm and AS integrity protection algorithm with the highest priority that also exist in the UE security capabilities from its configured list. The algorithm selected by the RAN node can be indicated to the UE in the AS SMC process. The AS encryption algorithm selected by the RAN node can be used for encryption of the user plane and RRC signaling (when activated), and the selected AS integrity protection algorithm can be used for integrity protection of the user plane and RRC signaling (when activated).

[0152] 3) Xn switching

[0153] When an Xn handover occurs between a source RAN node (gNB / ng-eNB) and a target RAN node (gNB / ng-eNB), the source RAN node may send the target RAN node (e.g., via a Handover Request message) the encryption and integrity protection algorithms used by the source cell, as well as the UE security capabilities. The target RAN node may also select a higher-priority algorithm from the received UE security capabilities based on a locally configured algorithm priority list. If the algorithm selected by the target RAN node differs from the algorithm selected by the source RAN node, the target RAN node may indicate the selected algorithm to the UE in a Handover Command message. If the UE does not receive an indication of the integrity and encryption algorithms, it continues to use the same algorithms as before the handover.

[0154] When an Xn handover occurs between an ng-eNB and a gNB, the algorithm selected in the target RAN node is notified to the UE in the handover command. For example, in a path switch message, the target RAN node may send the UE security capabilities received from the source RAN node to the AMF; the AMF verifies whether the UE security capabilities received from the target RAN node match the UE security capabilities locally stored by the AMF. If they do not match, the AMF may send its locally stored UE security capabilities to the target RAN node in a path switch confirm message. If the target RAN node receives the UE security capabilities from the AMF in the path switch confirm message, the target RAN node may use the UE security capabilities to update the UE's AS security context. The target RAN node may select the highest priority algorithm from the algorithm priority list based on the locally configured algorithm priority list and the UE security capabilities. If the algorithm selected by the target RAN node is different from the algorithm used by the source RAN node, the target RAN node initiates an intra-cell handover procedure and indicates the selected algorithm in the cell handover process.

[0155] 4) N2 switching

[0156] When an N2 handover occurs between a source RAN node and a target RAN node, the target AMF may send the UE security capabilities to the target RAN node in the NGAP Handover Request message. The target RAN node selects the higher-priority algorithm from the UE security capabilities based on the locally configured algorithm priority list. If the algorithm selected by the target RAN node differs from the algorithm used by the source RAN node, the target RAN node may indicate the selected algorithm to the UE in the Handover Command message. If the UE does not receive any selection of integrity and encryption algorithms, it will continue to use the same algorithms as before the handover.

[0157] For N2 handover, the source RAN node may send the AS algorithms used in the source cell to the target RAN node. The AS algorithms used in the source cell are provided to the target RAN node so that the target RAN node can use these algorithms during potential RRC connection reestablishment.

[0158] 5) Migrate from RRC_INACTIVE state to RRC_CONNECTED state

[0159] When transitioning from RRC_INACTIVE to RRC_CONNECTED, the source RAN node may send the UE security capabilities and the encryption and integrity protection algorithms used by the source cell to the target RAN node in the Xn-AP Retrieve UE Context Response message. The target RAN node may check whether it supports the received encryption and integrity algorithms. For example, the target RAN node should check the received algorithms against its locally configured algorithm priority list. If the target RAN node selects the same security algorithm, the target RAN node shall use the selected algorithm to derive RRC integrity and RRC encryption keys to protect the RRC Resume message and send it to the UE on SRB1.

[0160] If the target RAN node does not support the received algorithm, or if the target RAN node prefers to use a different algorithm, the target RAN node sends an RRC Setup message over SRB0 to continue with the RRC connection establishment. The UE then performs NAS-based RRC recovery and negotiates a suitable algorithm with the target RAN node via the AS SMC procedure.

[0161] 4. Security Activation Process

[0162] 1) NAS security mode command (SMC) process:

[0163] For example, the functions of the NAS SMC process are as follows:

[0164] (1) After the primary authentication is completed, the AMF initiates a NAS SMC message to convert the partial native context into a full native context for subsequent use.

[0165] (2) Changing the NAS security algorithm in the current NAS security context. For example, in scenarios where an AMF change occurs (such as N2 handover or mobility registration), the NAS security algorithm in the current NAS security context needs to be changed.

[0166] (3) Change the uplink NAS count value in the most recent NAS security mode complete (SMP) message to refresh K gNB .

[0167] (4) Send the selected EPS NAS security algorithm to the UE.

[0168] For easier understanding, the NAS SMC process is described in detail with reference to Figure 3.

[0169] FIG3 is a schematic flow chart of a NAS SMC process, which includes the following steps:

[0170] S310: AMF configures a priority list of algorithms allowed to be used.

[0171] Exemplarily, the AMF is configured with a NAS integrity security protection algorithm priority list (e.g., the NAS integrity security protection algorithms configured on the AMF include the AES128 integrity security protection algorithm, the SNOW128 integrity security protection algorithm, the ZUC128 integrity security protection algorithm, the null integrity security protection algorithm, etc.), and a NAS confidentiality security protection algorithm priority list (e.g., the NAS confidentiality security protection algorithms configured on the AMF include the ZU128C confidentiality security protection algorithm, the AES128 confidentiality security protection algorithm, the SNOW128 confidentiality security protection algorithm, the null integrity security protection algorithm, etc.).

[0172] Among them, the priorities of the configured multiple integrity security protection algorithms are ranked from high to low, for example, they can be AES128 integrity security protection algorithm, SNOW128 integrity security protection algorithm, ZUC128 integrity security protection algorithm, and empty integrity security protection algorithm; the priorities of the configured multiple confidentiality security protection algorithms are ranked from high to low, respectively, ZUC128 confidentiality security protection algorithm, AES128 confidentiality security protection algorithm, SNOW128 confidentiality security protection algorithm, and empty integrity security protection algorithm.

[0173] The AMF obtains the UE security capabilities and selects the NAS integrity security protection algorithm and the NAS confidentiality security protection algorithm based on the UE security capabilities and the algorithm priority list.

[0174] The UE security capabilities include the integrity security protection algorithms and confidentiality security protection algorithms supported by the UE. The AMF selects the algorithm with the highest priority supported by the UE security capabilities from its algorithm priority list. For example, if the UE security capabilities include the supported NAS integrity security protection algorithms of AES128 and SNOW128, the integrity security protection algorithm selected by the AMF is the AES128 integrity security protection algorithm. For another example, if the UE security capabilities include the supported NAS confidentiality security protection algorithms of AES128 and ZUC128, the confidentiality security protection algorithm selected by the AMF is the ZUC128 confidentiality security protection algorithm.

[0175] S320, AMF activates NAS integrity security protection.

[0176] Before sending the NAS SMC message, the AMF activates NAS integrity security protection.

[0177] For example, AMF calculates the integrity security protection key K NASint Furthermore, the AMF performs integrity security calculation on the NAS SMC message and obtains the NAS MAC. For example, the calculation input key of the NAS MAC is K NASint ,The input parameters are the bearer identifier, the direction parameter, the value of the counter, and the ,cell in the NAS SMC message to be protected, and the security ,protection algorithm used is the selected integrity security ,protection algorithm.

[0178] The bearer identifier is used to distinguish different bearers. For example, in a 3GPP connection, the bearer identifier may be "0x01", and in a non-3GPP connection, the bearer identifier may be "0x02". The direction parameter is used to distinguish whether it is an uplink message or a downlink message. For example, in an uplink message, the direction parameter takes a value of 0, and in a downlink message, the direction parameter takes a value of 1. The value of the counter is used as a freshness parameter to prevent replay attacks. The information elements in the NAS SMC message to be protected may include a selected EPS security protection algorithm, an international mobile station equipment identity and software version number (IMEISV) request indication, etc.

[0179] It should be noted that the NAS SMC message performs integrity security protection but does not perform confidentiality security protection, because the UE side needs to use the parameters in the message (such as ngKSI, etc.) to obtain the key and algorithm for integrity verification.

[0180] S330: AMF sends a NAS SMC message to the UE.

[0181] The NAS SMC message includes but is not limited to the selected confidentiality security protection algorithm, the selected integrity security protection algorithm, ngKSI, the replayed UE security capability, K AMF Change indication, etc. Among them, the selected confidentiality algorithm and the selected integrity security protection algorithm are part of the NAS security context, which are used by the UE and AMF to negotiate the security protection algorithm for subsequent security protection. AMF The replayed UE security capabilities are used to verify whether the security capabilities have been tampered with, i.e. to prevent downgrade attacks, K AMF The change indication is used to instruct the UE to calculate the new K AMF .

[0182] The NAS SMC message includes a "Security Header Type" information element, which is used to indicate the protection mode of the NAS message. When the NAS message is a NAS SMC message, the value of this information element is 0011, which is used to indicate the use of 5G NAS security context for integrity security protection;

[0183] It should be noted that the confidentiality security protection algorithm and integrity security protection algorithm carried in the NAS SMC message will subsequently serve as part of the security context.

[0184] S340: AMF activates confidentiality protection for uplink NAS messages.

[0185] After sending the NAS SMC message, the AMF activates the deconfidentiality protection (e.g. decryption) of the uplink NAS messages.

[0186] S350: The UE verifies the NAS SMC message.

[0187] For example, the UE obtains the corresponding K according to ngKSI. NASint , and performs integrity verification according to the integrity security protection algorithm carried in the message. If the integrity verification succeeds, the UE activates the integrity security protection and confidentiality security protection of the uplink NAS message and the decryption operation of the downlink message.

[0188] S360, the UE sends a NAS SMP message to the AMF.

[0189] If the verification in step S350 is successful, the UE sends a NAS SMP message to the AMF, which is protected by integrity security and confidentiality security. For example, the integrity security protection key is K NASint The integrity security protection algorithm is the integrity security protection algorithm selected in step S330, and the confidentiality security protection key is K NASenc The confidentiality security protection algorithm is the confidentiality security protection algorithm selected in step S330. NAS MAC is used for integrity security protection. The AMF receives the NAS SMP message and performs decryption and integrity verification on the message.

[0190] When the NAS message is a NAS SMP message, the value of this information element is 0100, which is used to indicate the use of the 5G NAS security context for confidentiality and integrity security protection.

[0191] S370: AMF activates confidentiality protection for NAS downlink messages.

[0192] After receiving the NAS SMP message, the AMF activates confidentiality protection (e.g., encryption) for NAS downlink messages.

[0193] It should be noted that in the existing security mechanism, confidentiality security protection and integrity security protection are independent of each other, that is, the keys and algorithms are isolated.

[0194] 2)AS SMC process:

[0195] For example, the AS SMC process is mainly used to negotiate radio resource control (RRC) and user plane (UP) algorithms and to activate RRC security. The RRC reconfiguration message is mainly used to activate UP security.

[0196] For ease of understanding, the AS SMC process is described in detail with reference to Figure 4.

[0197] FIG4 is a schematic flow chart of an AS SMC process, which includes the following steps:

[0198] S410: The access network device configures a priority list of algorithms allowed to be used.

[0199] Exemplarily, an AS integrity security protection algorithm priority list is configured on the access network device (e.g., the AS integrity security protection algorithms configured on the access network device include AES integrity security protection algorithm, SNOW integrity security protection algorithm, ZUC integrity security protection algorithm, empty integrity security protection algorithm, etc., wherein the priorities of the configured multiple integrity security protection algorithms are ranked from high to low as AES integrity security protection algorithm, SNOW integrity security protection algorithm, ZUC integrity security protection algorithm, and empty integrity security protection algorithm), as well as an AS confidentiality security protection algorithm priority list (e.g., the AS confidentiality security protection algorithms configured on the access network device include ZUC confidentiality security protection algorithm, AES confidentiality security protection algorithm, SNOW confidentiality security protection algorithm, and empty integrity security protection algorithm, wherein the priorities of the configured multiple confidentiality security protection algorithms are ranked from high to low as ZUC confidentiality security protection algorithm, AES confidentiality security protection algorithm, SNOW confidentiality security protection algorithm, and empty integrity security protection algorithm).

[0200] The access network device receives the UE security capabilities and selects the AS integrity security protection algorithm and the AS confidentiality security protection algorithm based on the UE security capabilities and the algorithm priority list.

[0201] For example, if the UE security capabilities include the supported AS integrity security protection algorithms as AES integrity security protection algorithm and SNOW integrity security protection algorithm, the integrity security protection algorithm selected by the access network device is the AES integrity security protection algorithm; for another example, if the UE security capabilities include the supported AS confidentiality security protection algorithms as AES confidentiality security protection algorithm and ZUC confidentiality security protection algorithm, the confidentiality security protection algorithm selected by the access network device is the ZUC confidentiality security protection algorithm.

[0202] S420: Activate RRC integrity security protection.

[0203] Before sending the AS SMC message, the access network device activates RRC integrity security protection.

[0204] Exemplarily, the access network device performs integrity security calculation on the AS SMC message and obtains MAC-I. Exemplarily, the calculation input key of AS MAC is K RRCint ,The input parameters are the bearer identifier, the direction parameter, the counter value, etc. The security ,protection algorithm used is the selected integrity security ,protection algorithm.

[0205] Among them, the bearer identifier is used to distinguish different bearers. For example, in a 3GPP connection, the bearer identifier can be "0x01", and in a non-3GPP connection, the bearer identifier can be "0x02"; the direction parameter is used to distinguish whether it is an uplink message or a downlink message. For example, in an uplink message, the direction parameter takes a value of 0, and in a downlink message, the direction parameter takes a value of 1; the value of the counter is used as a freshness parameter to prevent replay attacks.

[0206] It should be noted that only integrity protection is performed in the AS SMC message, not confidentiality protection, because the UE side needs to use the parameters in the message (such as ngKSI, etc.) to obtain the key and algorithm for integrity verification.

[0207] S430: The access network device sends an AS SMC message to the UE.

[0208] The AS SMC message includes, but is not limited to, the selected confidentiality and integrity security algorithms. These algorithms are part of the AS security context and are used by the UE and access network device to negotiate the security algorithms for subsequent security protection.

[0209] It should be noted that the security protection algorithms for RRC messages and UP messages can be unified, that is, the selected confidentiality security protection algorithm and the selected integrity security protection algorithm are applicable to both the security protection of RRC messages and the security protection of UP messages; the security protection algorithms for RRC messages and UP messages can be independent, that is, the message includes the selected RRC confidentiality security protection algorithm, the selected RRC integrity security protection algorithm, the selected UP confidentiality security protection algorithm, and the selected UP integrity security protection algorithm.

[0210] S440: The access network device activates confidentiality protection of uplink RRC messages.

[0211] After sending the AS SMC message, the access network device activates the deconfidentiality protection (eg, decryption) of the uplink RRC message.

[0212] S450, the UE verifies the AS SMC message.

[0213] For example, the UE obtains the corresponding K RRCint , and performs integrity check according to the integrity security protection algorithm carried in the message. If the integrity check succeeds, the UE activates the integrity security protection and confidentiality security protection of the uplink RRC message and the decryption operation of the downlink message.

[0214] S460, the UE sends an AS SMP message to the access network device.

[0215] If the verification in step S450 is successful, the UE sends an AS SMP message to the access network device. The message is protected by integrity security and confidentiality security. For example, the integrity security protection key is K RRCint The integrity security protection algorithm is the integrity security protection algorithm selected by the AS SMC message in step S430, and the confidentiality security protection key is K RRCenc ,The confidentiality security protection algorithm is the selected confidentiality security protection algorithm carried in the AS SMC message in step S430.

[0216] S470: The UE activates RRC uplink message confidentiality.

[0217] After sending the AS SMP message, the UE activates RRC uplink message confidentiality protection.

[0218] S480: The access network device activates RRC downlink message confidentiality protection.

[0219] After receiving the AS SMP message, the access network device activates RRC downlink message confidentiality (eg, encryption).

[0220] It should be noted that in the existing security mechanism, confidentiality security protection and integrity security protection are independent of each other, that is, the keys and algorithms are isolated.

[0221] In general, the security algorithm of the 5G mobile communication network is negotiated and selected by the network side (AMF / RAN) based on the UE security capabilities reported by the UE and the network side's own capabilities (such as the configured security protection algorithm), and a security algorithm with a higher priority supported by both the network side and the UE side is selected. For example, for the UE side, if the UE supports a 256-bit security algorithm, or in other words, the UE security capabilities include a 256-bit security algorithm and the network side also supports a 256-bit security algorithm, the security algorithm negotiated by the network side and the UE side can be 256 bits. However, in this case, if the long-term key in the UE's user identity module (e.g., a universal subscriber identity module (USIM) card) is 128 bits (for example, when the user replaces the ME but does not replace the USIM card), the key generated based on the long-term key and the negotiated security algorithm can only support 128 bits of security. At this time, using a 256-bit security algorithm may result in a waste of computing resources.

[0222] In view of this, the present application provides a communication method, which can enable the network side and the UE to negotiate and determine a reasonable security algorithm, thereby saving computing resource overhead.

[0223] In order to facilitate understanding of the embodiments of the present application, the following explanations are made.

[0224] First, in this application, "used to indicate" can include being used for direct indication and being used for indirect indication. When describing that a certain indication information is used to indicate A, it can include that the indication information directly indicates A or indirectly indicates A, but it does not mean that the indication information must include A.

[0225] The information indicated by the indication information is referred to as the information to be indicated. During the specific implementation process, there are many ways to indicate the information to be indicated. The information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately. The transmission period and / or transmission timing of these sub-information can be the same or different. The specific transmission method is not limited in this application. The transmission period and / or transmission timing of these sub-information can be predefined, for example, according to a protocol, or can be configured by the transmitting device through sending configuration information to the receiving device.

[0226] Second, "at least one" shown in the present application refers to one or more, and "a plurality of" refers to two or more. In addition, in the embodiments of the present application, "first", "second" and various digital numbers (for example, "#1", "#2", etc.) are only for the convenience of description and are not used to limit the scope of the embodiments of the present application. The size of the sequence number of each process below does not mean the order of execution. The execution order of each process should be determined by its function and inherent logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. It should be understood that the objects described in this way can be interchanged where appropriate, so that the schemes other than the embodiments of the present application can be described. In addition, in the embodiments of the present application, words such as "510", "520" are only for the convenience of description and are not used to limit the order of execution of steps.

[0227] Third, in this application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplarily" or "for example" is intended to present the relevant concepts in a concrete manner.

[0228] Fourth, the term "storage" used in the embodiments of this application may refer to storage in one or more memories. The one or more memories may be provided separately or integrated into an encoder or decoder, a processor, or a communication device. The one or more memories may also be provided in part separately and in part integrated into a decoder, a processor, or a communication device. The memory may be any type of storage medium, and this application is not limited thereto.

[0229] Fifth, the "protocol" involved in the embodiments of the present application may refer to a standard protocol in the communication field, for example, it may include an LTE protocol, an NR protocol, and related protocols used in future communication systems. This application does not limit this.

[0230] Sixth, in the embodiments of the present application, "under the circumstances", "when", and "if" can sometimes be used interchangeably. It should be pointed out that when the distinction between them is not emphasized, the meanings they intend to express are consistent.

[0231] Seventh, in the embodiments of this application, various terms and English abbreviations, such as radio resource control (RRC), are provided for ease of description and should not constitute any limitation on this application. This application does not exclude the possibility of defining other terms in existing or future protocols that can achieve the same or similar functions.

[0232] Eighth, the term "and / or" in this document simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the related objects are in an "or" relationship.

[0233] It should be understood that the embodiments shown below do not specifically limit the specific structure of the execution subject of the method provided in the embodiments of the present application. As long as it is possible to communicate according to the method provided in the embodiments of the present application by running a program that records the code of the method provided in the embodiments of the present application. For example, the execution subject of the method provided in the embodiments of the present application can be the first core network device, or a functional module in the first core network device that can call and execute the program.

[0234] FIG5 is a schematic flow chart of a communication method 500 provided in the present application, which may include the following steps.

[0235] S510: The network device receives first indication information.

[0236] The first indication information indicates the length of a first key, where the first key is a key of the terminal device, for example, the first key is a long-term key of the terminal device.

[0237] Specifically, the first key may be a long-term key stored in a user identity module of the terminal device, and the length of the long-term key may be, for example, 128 bits or 256 bits.

[0238] As a possible implementation, the network device is a first core network device, which may be an AMF. The first core network device may receive the first indication information in the manner shown in S510a or S510b:

[0239] S510a: The second core network device sends the first indication information to the first core network device. Correspondingly, the first core network device receives the first indication information from the second core network device.

[0240] Exemplarily, the second core network device is a UDM. The second core network device receives identification information of a terminal device from the first core network device, for example, the identification information of the terminal device is a hidden user subscription identifier (SUCI); the second core network device decrypts the identification information of the terminal device to obtain a subscriber permanent identifier (SUPI) of the subscriber of the terminal device, and retrieves a long-term key of the terminal device from a stored key based on the SUPI of the terminal device, thereby obtaining the length of the first key.

[0241] Specifically, the second core network device may send the first indication information to the first core network device during the authentication process of the terminal device. For example, the second core network device sends the first indication information to the third core network device via a first message, so that the third core network device sends the first indication information to the first core network device. The third core network device may be, for example, an authentication server function network element.

[0242] Exemplarily, the second core network device may send the first indication information to the third core network device via a Nudm_UEAuthentication_Get Response message, and the third core network device may send the first indication information to the first core network device via a Nausf_UEAuthentication_Authenticate Response message.

[0243] Alternatively, the second core network device may send the first indication information to the first core network device after the terminal device is successfully authenticated. The first indication information may be carried in an existing message or a newly defined message without limitation.

[0244] Exemplarily, the first indication information can be a 1-bit value. For example, when the first indication information takes a value of 1, it indicates that the length of the first key is the first length, for example, 128 bits or 256 bits; when the first indication information takes a value of 0 or is not carried, it indicates that the length of the first key is the second length, for example, 256 bits or 128 bits.

[0245] Optionally, after the second core network device determines the length of the first key, the second core network device can also determine the length of the key derivation algorithm based on the length of the first key, and derive the second key based on the first key and the key derivation algorithm.

[0246] The length of the output key of the key derivation algorithm is equal to the length of the first key; the second key is used to determine the security key used by the first security algorithm. For example, the second key includes an integrity key (IK) and a cipher key (IK). The first security algorithm can be described later.

[0247] S510b: The terminal device sends the first indication information to the first core network device. Correspondingly, the first core network device receives the first indication information from the terminal device.

[0248] Optionally, before the terminal device sends the first indication information to the first core network device, the terminal device may obtain the length of the first key.

[0249] Exemplarily, the terminal device may obtain the length of the first key from the user identity module. For example, the user identity module may include an interface for invoking the length of the first key. The terminal device may receive the length of the first key by sending a request message to the user identity module requesting the length of the first key and receiving a response message from the user identity module.

[0250] Specifically, the terminal device may send the first indication information to the first core network device in an uplink NAS message. For example, the terminal device may carry the first indication information in a registration request message sent to the second core network device.

[0251] As another possible implementation, the network device is an access network device. The access network device may receive the first indication information in the manner shown in S510c or S510d:

[0252] S510c: The first core network device sends the first indication information to the access network device. Correspondingly, the access network device receives the first indication information from the first core network device.

[0253] Exemplarily, after receiving the first indication information from the second core network device (S510a) or the terminal device (S510b), the first core network device sends the first indication information to the access network device.

[0254] S510d: The terminal device sends the first indication information to the access network device. Correspondingly, the access network device receives the first indication information from the terminal device.

[0255] Optionally, before the terminal device sends the first indication information to the access network device, the terminal device may obtain the length of the first key. Exemplarily, the terminal device may obtain the length of the first key from a user identity module. For details, please refer to the description in S510b.

[0256] S520: The network device determines a first security algorithm based on the length of the first key.

[0257] The length of the key used by the first security algorithm is less than or equal to the length of the first key.

[0258] Specifically, if the network device is a first core network device (S520a), the first core network device may determine the first security algorithm based on the length of the first key, the security capability information of the terminal device, and the algorithm priority list.

[0259] The security capability information of the terminal device indicates the security algorithms supported by the terminal device. For example, the security capability information may include a list of security algorithms supported by the terminal device, and the list of security algorithms may include at least one security algorithm supported by the terminal device. The security capability information of the terminal device may refer to the UE security capabilities in S310. The algorithm priority list is used to configure the priority of the security algorithms supported by the network side. The algorithm priority list may refer to the description in S310.

[0260] Among them, the first security algorithm determined by the first core network device can be used to provide security protection for NAS messages transmitted between the terminal device and the first core network device. For example, the security algorithm is used to provide security protection for the security mode command message, security mode completion message transmitted in the NAS SMC process, and NAS messages transmitted after the NAS SMC process.

[0261] The first security algorithm is one of the security algorithms supported by the terminal device, or in other words, the first security algorithm is one of the algorithms in the list of algorithms supported by the terminal device. The length of the input key of the first security algorithm is less than or equal to the length of the first key, and the priority of the first security algorithm is higher than the priority of the second security algorithm in the algorithm priority list, wherein the second security algorithm includes security algorithms in the list of security algorithms supported by the terminal device, other than the first security algorithm, whose input key length is less than or equal to the length of the first key.

[0262] Exemplarily, the first core network device determines the first security algorithm based on the length of the first key, the security capability information of the terminal device, and the algorithm priority list in the following specific manner:

[0263] Method 1: The first core network device traverses the algorithm priority list from highest to lowest priority. If the terminal device's security capability information indicates that the terminal device supports the currently traversed security algorithm (denoted as security algorithm #1), and the length of the input key of security algorithm #1 is less than or equal to the length of the first key, then security algorithm #1 is determined as the first security algorithm. Otherwise, the algorithm priority list is traversed again until a security algorithm that meets the above conditions is found.

[0264] Method 2: The first core network device determines the security algorithm (recorded as security algorithm #3) supported by both the terminal device and the network device based on the security capability information of the terminal device and the algorithm priority list; the first core network device determines the security algorithm with the highest priority from the security algorithm #3 and the input key length less than or equal to the length of the first key as the first security algorithm based on the algorithm priority list.

[0265] For example, the security algorithms configured in the algorithm priority list include the AES256 AEAD algorithm, the SNOW256 AEAD algorithm, the ZUC256 AEAD algorithm, the AES128 encryption algorithm, the SNOW128 integrity security protection algorithm, the ZUC128 integrity security protection algorithm, and the null algorithm. The configured multiple encryption algorithms may be prioritized from high to low, for example, as follows: the AES256 AEAD algorithm, the SNOW256 AEAD algorithm, the ZUC256 AEAD algorithm, the AES128 encryption algorithm, and the null algorithm. The configured multiple integrity protection algorithms may be prioritized from high to low, as follows: the SNOW128 integrity protection algorithm, the ZUC128 integrity security protection algorithm, and the null algorithm.

[0266] Similarly, if the network device is an access network device, the access network device may determine the first security algorithm based on the length of the first key, the terminal device's security capability information, and an algorithm priority list. The terminal device's security capability information indicates a list of security algorithms supported by the terminal device; the algorithm priority list is used to configure the priorities of security algorithms supported by the network. For specific determination methods, refer to the method used by the first core network device to determine the first security algorithm.

[0267] The first security algorithm determined by the access network device may be used to provide security protection for AS messages transmitted between the terminal device and the access network device. For example, the security algorithm may be used to provide security protection for RRC messages (e.g., security mode command messages and security mode complete messages) transmitted during the AS SMC process; or for example, the security algorithm may be used to provide security protection for user plane (UP) messages transmitted after the AS SMC process.

[0268] Optionally, the method further includes: the network device determining the length of the security key according to the length of the first key.

[0269] The length of the security key is the same as the length of the input key of the first security algorithm. The security key is the key used by the first security algorithm. That is, based on the security key and the first security algorithm, integrity security protection and confidentiality security protection (encryption) can be performed on the sent message, or integrity verification and decryption can be performed on the received message. The security key can be a key shared between the terminal device and the network device. For example, the security key is a key derived and truncated based on the key generated in the main authentication process. For example, the security key determined by the first core network device can be K NASint and K NASenc Alternatively, the security key determined by the access network device is K UPint and K UPenc .

[0270] Specifically, if the selected first security algorithm is 128 bits, the length of the security key is determined to be 128 bits. For example, the first core network device will AMF The generated security key is truncated to 128 bits. For the specific truncation method, please refer to the existing relevant description.

[0271] If the selected security algorithm is 256 bits, the length of the security key is determined to be 256 bits. AMF The length of the generated security key is 512 bits, and the 512-bit key can be truncated to 256 bits.

[0272] Similarly, the access network equipment will be based on K gNB The generated security key is truncated to 128 bits or 256 bits.

[0273] In the case where the network device receives the first indication information from the second core network device, the method further includes: the network device sends second indication information to the terminal device, where the second indication information indicates the length of the first key.

[0274] Optionally, the method further includes: the length of the first key of the terminal device is used to determine the length of the key output by the key derivation algorithm, and the key output by the key derivation algorithm is used to generate the security key.

[0275] In one implementation, when the network device is a first core network device, the first core network device sends a non-access layer security mode command message to the terminal device, and the non-access layer security mode command message includes the second indication information.

[0276] In another implementation, when the network device is an access network device, the access network device sends an access layer security mode command message to the terminal device, and the access layer security mode command message carries the second indication information.

[0277] Optionally, the method further includes: the terminal device determining the length of the security key according to the first security algorithm, the length of the security key being the same as the length of the key used by the first security algorithm. For details, reference may be made to the above-mentioned method for determining the length of the security key by the first core network device, which will not be repeated here.

[0278] Optionally, before the network device determines the first security algorithm, it determines that a trigger condition is satisfied. This can be understood as: the network device selects the first security algorithm when the trigger condition is satisfied. The trigger condition includes, but is not limited to: after the primary authentication is completed, the network device determines to initiate a security mode command process; or a network device switching scenario; or the network device determines to change the uplink count value (e.g., a NAS counter rollover, triggering primary authentication), etc.

[0279] S530: The network device transmits a message to the terminal device.

[0280] Exemplarily, when the network device is the first core network device (S530a), the message may be a security mode command message transmitted in the NAS SMC process, a security mode completion message, and a NAS message transmitted after the NAS SMC process.

[0281] When the network device is an access network device (S530b), the message may be an RRC message transmitted in the AS SMC process (eg, a security mode command message, a security mode completion message); or a user plane (UP) message transmitted after the AS SMC process.

[0282] The message is a message that is security-protected based on the first security algorithm.

[0283] It should be understood that the security algorithm determined by the network device in the embodiment of the present application can be an authentication encryption algorithm that can achieve both confidentiality security protection and integrity security protection; or it can also be a confidentiality security protection algorithm and an integrity security protection algorithm; or it can also be an authentication encryption algorithm, a confidentiality security protection algorithm, and an integrity security protection algorithm, without limitation.

[0284] Based on the above solution, the network device can avoid wasting computing resources due to improper security algorithm selection by determining the first security algorithm based on the length of the first key. For example, if the key length used by the security algorithm determined by the network device is greater than the length of the first key, the key generated based on the first key and the security algorithm can only support the security of the first key length. In this case, security protection based on the security algorithm selected by the network device may result in a waste of computing resources.

[0285] FIG6 is a schematic flow chart of a communication method 600 provided in the present application, which may include the following steps.

[0286] S610: The terminal device sends security capability information of the terminal device to the network device. Correspondingly, the network device receives the security capability information of the terminal device.

[0287] The security capability information of the terminal device indicates a list of security algorithms supported by the terminal device, wherein the list of security algorithms includes at least one security algorithm supported by the terminal device, and the length of an input key of the security algorithm supported by the terminal device is less than or equal to the length of the first key.

[0288] Exemplarily, the terminal device may send the security capability information to the network device in an uplink NAS message. For example, the terminal device may carry the security capability information in a registration request message sent to the network device.

[0289] The network device may be a first core network device (S610a) or an access network device (S610b). Optionally, the terminal device may also send the security capability information to the first core network device and the access network device simultaneously. For example, the terminal device sends the security capability information to the first core network device via the access network device.

[0290] Optionally, before S610, the method further includes S601 and S602:

[0291] S601: The terminal device determines the length of the first key.

[0292] For the specific process of the terminal device determining the first key length, reference may be made to the description in S510b.

[0293] S602: The terminal device determines the security capability information reported by the terminal device according to the length of the first key.

[0294] Exemplarily, when the terminal device is configured with terminal device security capability information (the security capability information can refer to the existing description, such as the UE security capability in S310), the terminal device selects a security algorithm whose input key length is less than or equal to the first key from the UE security capability according to the length of the first key and reports it.

[0295] S620: The network device determines a first security algorithm according to the security capability information of the terminal device.

[0296] When the network device is a first core network device (S620a), the first security algorithm determined by the first core network device can be used to provide security protection for messages transmitted between the terminal device and the first core network device.

[0297] When the network device is an access network device (S620b), the first security algorithm determined by the access network device can be used to perform security protection on messages transmitted between the terminal device and the access network device.

[0298] Exemplarily, the network device determines the first security algorithm according to the algorithm priority list and the security capability information of the terminal device.

[0299] For example, the network device traverses the algorithm priority list from high to low priority. If the currently traversed security algorithm #1 exists in the security capability information of the terminal device, the security algorithm #1 is determined as the first security algorithm. The priority of the security algorithm #1 is higher than the priority of other security algorithms supported by the terminal device included in the algorithm priority list.

[0300] Optionally, the method further includes:

[0301] S630: The first core network device sends the security capability information of the terminal device to the access network device. Correspondingly, the access network device receives the security capability information of the terminal device from the first core network device.

[0302] That is, when the network device is an access network device, the access network device can also receive security capability information of the terminal device from the first core network device.

[0303] S640: The network device transmits a message to the terminal device.

[0304] Exemplarily, when the network device is the first core network device (S650a), the message may be a security mode command message transmitted in the NAS SMC process, a security mode completion message, and a NAS message transmitted after the NAS SMC process.

[0305] When the network device is an access network device (S650b), the message may be an RRC message transmitted in the AS SMC process (eg, a security mode command message, a security mode completion message); or a user plane (UP) message transmitted after the AS SMC process.

[0306] The message is a message that is security-protected based on the first security algorithm.

[0307] Based on the above scheme, the network device determines the first security algorithm through the security capability information of the terminal device reported by the terminal device, wherein the length of the input key of the security algorithm supported by the terminal device included in the security capability information is less than or equal to the length of the first key, which can avoid the waste of computing resources due to unreasonable selection of the security algorithm.

[0308] It should be understood that the above process for determining the communication method is only an example, and the embodiments of the present application can also be applied to other scenarios where a security algorithm needs to be determined. For example, in Xn switching and / or N2 switching, the source RAN node can send the first indication information and / or the UE security capability (refer to the security capability information of the terminal device in S610) to the target RAN node, so that the target RAN node selects a reasonable security algorithm according to the communication method shown in the embodiments of the present application.

[0309] The communication method provided in the embodiment of the present application is described in detail below with reference to Figures 7 to 9.

[0310] Figure 7 is a schematic flow chart of a communication method provided by the present application. The method may include the following steps.

[0311] S701: The UE sends a registration request message to the AMF via the RAN. Correspondingly, the AMF receives the registration request message from the UE.

[0312] The registration request message includes identification information of the UE to be protected for confidentiality, UE security capability information, and other registration information.

[0313] Among them, the identification information of the UE for confidentiality protection is, for example, SUCI or 5G globally unique temporary UE identity (5G-GUTI); the security capability information of the UE indicates the security algorithms supported by the UE.

[0314] S702: The AMF sends the UE identification information to the UDM. Correspondingly, the UDM receives the UE identification information from the AMF.

[0315] S703: The UDM determines the length of the long-term key K (an example of the first key) according to the identification information of the UE.

[0316] Exemplarily, the UDM decrypts the identification information of the UE for confidentiality protection to obtain the identification information of the UE, such as the SUPI of the UE; the UDM determines the long-term key K based on the SUPI of the UE, for example, the long-term key K is the long-term key stored in the USIM card of the UE; the UDM retrieves the long-term key K based on the SUPI of the UE and determines the length of the long-term key of the UE.

[0317] For example, the length of the long-term key is 128 bits or 256 bits.

[0318] S704: The network and the UE perform a primary authentication process.

[0319] Exemplarily, the main authentication process of the network side and the UE can complete the identity authentication of the UE and the network side and derive the keys of each layer.

[0320] For example, in the main authentication process, UDM can calculate CK and IK based on the long-term key K and the key derivation algorithm (for example, MILENAGE 128 algorithm or MILENAGE 256 algorithm); UDM calculates Kasuf based on CK and IK, and AUSF calculates Kseaf based on Kausf; SEAF calculates K AMF For the specific calculation process, please refer to the existing relevant description.

[0321] Optionally, when deriving a key, the UDM may select the input length of the key derivation algorithm used according to the length of the long-term key K.

[0322] For example, UDM can choose to use the MILENAGE-128 algorithm or the MILENAGE-256 algorithm to perform f1-f5 calculations based on the length of the long-term key, thereby deriving 128-bit or 256-bit IK and CK, and deriving 256-bit (corresponding to CK and IK lengths of 128 bits) or 512-bit (corresponding to CK and IK lengths of 256 bits) K AUSF , K SEAF , K AMF wait.

[0323] Specifically, when the long-term key is 128 bits, the UDM can select a 128-bit key derivation algorithm and obtain 128-bit CK and IK, so that each network element can derive a 256-bit key, for example, a 256-bit K AUSF , K SEAF , K AMF wait.

[0324] When the long-term key is 256 bits, the UDM can select a 256-bit key derivation algorithm and obtain 256 CK and IK, so that each network element can derive a 512-bit key, for example, a 512-bit K AUSF , K SEAF , K AMF wait.

[0325] S705: UDM sends indication information #1 to AMF. Correspondingly, AMF receives indication information #1 from UDM.

[0326] This instruction information #1 (an example of the first instruction information) indicates the length of the long-term key K.

[0327] For example, the indication information #1 may directly indicate the length of the long-term key; or the indication information #1 may be a bit, and setting the bit to "0" indicates that the length of the long-term key is 128 bits; setting the bit to "1" indicates that the length of the long-term key is 256 bits, and vice versa.

[0328] Exemplarily, the UDM may send the indication information #1 to the AUSF via the Nudm_UEAuthentication_Get Response message, and the AUSF may send the indication information #1 to the AMF via the Nausf_UEAuthentication_Authenticate Response message.

[0329] Alternatively, after the UE is successfully authenticated, the UDM sends the indication information #1 to the AMF. The indication information #1 can be carried in an existing message or a newly defined message without limitation.

[0330] S706: AMF determines the security algorithm (an example of the first security algorithm) based on the length of the long-term key.

[0331] The security algorithm can refer to the description above. For example, the security algorithm is 128-EEA1.

[0332] Specifically, the AMF may determine the security algorithm based on the length of the long-term key, the UE's security capability information, and the configured algorithm priority list. The length of the input key of the security algorithm is less than or equal to the length of the long-term key.

[0333] For example, if the length of the long-term key is 128 bits, a security algorithm with a higher priority is selected from the 128-bit security algorithms supported by both the UE and the network side.

[0334] If the length of the long-term key is 256 bits, a security algorithm with a higher priority is selected from the 256-bit security algorithms supported by both the UE and the network.

[0335] If the length of the long-term key is 256 bits, then if the UE and / or the network side does not support the 256-bit security algorithm, a security algorithm with a higher priority is selected from the 128-bit security algorithms supported by both the UE and the network side.

[0336] S707: The AMF generates a NAS key and determines the length of the NAS key (an example of a security key) based on the selected security algorithm.

[0337] For example, AMF is calculated based on K AMF Generate a NAS key. The NAS key is K NASint and K NASenc The length of the NAS key is consistent with the length of the input key of the security algorithm.

[0338] From S704, we can see that K AMF The length of K can be 256 bits or 512 bits, so that AMF The generated NAS key is 256 bits or 512 bits respectively.

[0339] Specifically, if the length of the input key of the selected security algorithm is 128 bits, the length of the NAS key is determined to be 128 bits. For example, the AMF will AMF The generated NAS key is truncated to 128 bits. For the specific truncation method, please refer to the existing relevant description.

[0340] If the length of the input key of the selected security algorithm is 256 bits, the length of the NAS key is determined to be 256 bits. AMF If the length of the generated NAS key is 512 bits, the 512-bit key can be truncated to 256 bits.

[0341] The method also includes: the AMF sends indication information #2 (an example of second indication information) indicating the length of the long-term key to the UE, and / or sends indication information #3 indicating the security algorithm.

[0342] In one possible implementation, the AMF sends the indication information #2 and / or indication information #3 to the UE through the NAS SMC process. For details, please refer to S708 to S710.

[0343] In another possible implementation, the AMF sends the indication information #2 and / or indication information #3 to the UE through the AS SMC process of the access network device RAN. For details, please refer to S711 to S716.

[0344] S708: The AMF sends a NAS SMC to the UE. Correspondingly, the UE receives the NAS SMC from the AMF.

[0345] The NAS SMC may carry indication information #2, where the indication information #2 indicates the length of the long-term key.

[0346] Optionally, the NAS SMC carries indication information #3, which indicates the security algorithm selected by the AMF.

[0347] S709: The UE determines the length of the NAS key.

[0348] In a possible implementation, the UE determines the length of the NAS key (an example of a security key) according to the length of the long-term key and the security algorithm.

[0349] For example, the UE may select a key derivation algorithm (e.g., MILENAGE-128 or MILENAGE-256) based on the length of the long-term key to obtain the CK and IK. For example, if the long-term key is 128 bits long, the MILENAGE-128 algorithm is selected to derive a 128-bit CK and IK; if the long-term key is 256 bits long, the MILENAGE-256 algorithm is selected to derive a 256-bit CK and IK.

[0350] Furthermore, the UE determines the NAS key based on the CK and the IK.

[0351] If the length of the CK and IK is 128 bits, the UE derives a NAS key with a length of 256 bits; if the length of the CK and IK is 256 bits, the UE derives a NAS key with a length of 512 bits.

[0352] In the case where the UE derives a 256-bit or 512-bit NAS key, if the input to the security algorithm is 128 bits, the UE truncates the derived NAS key to 128 bits.

[0353] In the case where the UE derives a 256-bit NAS key, if the input of the security algorithm is 256 bits, the UE determines that the length of the NAS key is 256 bits.

[0354] In the case where the UE derives a 512-bit NAS key, if the input of the security algorithm is 256 bits, the UE truncates the derived NAS key to 256 bits.

[0355] In another possible implementation, the UE may determine the length of the NAS key according to the length of the input key of the security algorithm.

[0356] Exemplarily, if the NAS SMC does not carry the indication information #2, the UE may determine the length of the NAS key according to the length of the input of the security algorithm.

[0357] This implementation is applicable to scenarios where the UE and the network derive keys based on a fixed key derivation algorithm. For example, the NAS key derived by the UE based on the fixed key derivation algorithm is 256 bits or 512 bits.

[0358] In this case, if the length of the input to the security algorithm is 128 bits, the length of the NAS key is determined to be 128 bits; if the length of the input to the security algorithm is 256 bits, the length of the NAS key is determined to be 256 bits.

[0359] S710: The UE sends a NAS SMP to the AMF. In response, the AMF receives the NAS SMP from the UE.

[0360] S711: The AMF sends first information to the RAN. Correspondingly, the RAN receives the first information from the AMF.

[0361] The first information may include the UE's security capability information and the indication information #2. Alternatively, the UE's security capability information and the indication information #2 may be carried in different messages, without limitation.

[0362] It should be understood that the AMF can send the first information to the RAN in multiple processes. For details, please refer to the aforementioned security algorithm selection process.

[0363] S712: RAN determines a security algorithm according to the length of the long-term key.

[0364] For a specific determination method, reference may be made to the description in S706. The length of the input of the security algorithm selected by the RAN may be 128 bits or 256 bits.

[0365] S713: RAN generates an AS key (an example of a security key) and determines the length of the AS key according to the selected security algorithm.

[0366] The AS key (for example, K RRCint and K RRCenc ) is consistent with the length of the security algorithm.

[0367] Specifically, if the selected security algorithm is 128 bits, the length of the AS key is determined to be 128 bits. For example, the RAN will gNB The generated AS key is truncated to 128 bits.

[0368] If the selected security algorithm is 256 bits, the length of the AS key is determined to be 256 bits. gNBThe length of the generated AS key is 512 bits. You can truncate the 512-bit key to 256 bits.

[0369] S714: RAN sends AS SMC to UE. Correspondingly, UE receives AS SMC from RAN.

[0370] The AS SMC may carry indication information #2, where the indication information #2 indicates the length of the long-term key.

[0371] Optionally, the AS SMC carries indication information indicating the security algorithm selected by the RAN.

[0372] S715: The UE determines the length of the AS key (an example of a security key).

[0373] For example, the AS key is K UPint and K UPenc .

[0374] Exemplarily, the UE determines the length of the AS key according to the length of the long-term key and the security algorithm.

[0375] Alternatively, the UE may determine the length of the AS key according to the length of the input of the security algorithm.

[0376] For a specific determination method, please refer to the description in S709. The length of the AS key can be 128 bits or 256 bits.

[0377] S716: The UE sends the AS SMP to the RAN. Correspondingly, the RAN receives the AS SMP from the UE.

[0378] Figure 8 is a schematic flow chart of a communication method provided by the present application. The method includes the following steps.

[0379] S801: UE obtains the length of a long-term key.

[0380] Specifically, the long-term key may refer to the description in S701.

[0381] Exemplarily, the UE obtains the length of the long-term key from the USIM. For example, the UE sends a request message to the USIM, requesting the length of the long-term key. In response to the request message, the USIM sends the length of the long-term key to the UE. It is understood that a dedicated interface is enabled in the USIM to respond to the key length request from the UE to the USIM. Exemplarily, the request may be sent after PIN authentication.

[0382] Alternatively, the UE stores the length of the long-term key, for example, the UE stores the length of the long-term key obtained by the method shown in Figure 7. If the UE does not detect that the USIM card has been replaced, the UE stores the information about the length of the long-term key.

[0383] Alternatively, the UE obtains the length of the long-term key from the network device or the access network device. For example, see the case where indication information #2 is carried in steps S711-S714.

[0384] S802: The UE determines the security capability information of the UE (referred to as security capability information #1) according to the length of the long-term key.

[0385] The security capability information of the UE indicates the security algorithms supported by the UE, wherein the length of the input key of the security algorithm supported by the UE is less than or equal to the length of the key.

[0386] For example, the UE may determine the security capability information #1 based on the configured UE security capability information. The security algorithm supported by the UE indicated by the security capability information #1 is a security algorithm whose input key length is less than or equal to the length of the first key among the security algorithms supported by the terminal device indicated by the configured UE security capability information.

[0387] S803: The UE sends a registration request message to the AMF via the RAN. Accordingly, the AMF receives the registration request message from the UE.

[0388] For the registration request, please refer to the description in S701.

[0389] The registration request carries the UE's security capability information (security capability information #1).

[0390] For example, if the length of the long-term key is 128 bits, the UE only reports the security algorithm with an input of 128 bits through the security capability information.

[0391] If the length of the long-term key is 256 bits, the UE reports the security algorithm with 128 bits and / or 256 bits as input through the security capability information.

[0392] S804: The AMF sends the UE identification information to the UDM. Correspondingly, the UDM receives the UE identification information from the AMF.

[0393] S805: The UDM determines the length of the long-term key according to the identification information of the UE.

[0394] For this step, please refer to the description in S703.

[0395] For example, the length of the long-term key is 128 bits or 256 bits.

[0396] S806: The network and the UE perform a primary authentication process.

[0397] Exemplarily, the main authentication process of the network side and the UE can complete the identity authentication of the UE and the network side and derive the keys of each layer.

[0398] Optionally, when deriving a key, the UDM may select the input length of the key derivation algorithm used according to the length of the long-term key K.

[0399] Specifically, when the long-term key is 128 bits, the UDM can select a 128-bit key derivation algorithm and obtain 128 CK and IK, so that each network element can derive a 256-bit key, for example, a 256-bit K AUSF , K SEAF , K AMF wait.

[0400] When the long-term key is 256 bits, the UDM can select a 256-bit key derivation algorithm and obtain 256-bit CK and IK, so that each network element can derive a 512-bit key, for example, a 512-bit K AUSF , K SEAF , K AMF wait.

[0401] S807: The AMF determines the security algorithm based on the UE's security capability information and the configured algorithm priority list.

[0402] For example, the AMF selects a security algorithm with a higher priority from the security algorithms supported by both the UE and the network.

[0403] S808: The AMF generates a NAS key (an example of a security key) and determines the length of the NAS key based on the selected security algorithm.

[0404] For example, AMF is calculated based on K AMF Generate a NAS key, for example, the NAS key is K NASint and K NASenc The length of the NAS key is consistent with the length of the security algorithm.

[0405] For details of this step, please refer to the description in S707.

[0406] Optionally, the method further includes:

[0407] S809: The AMF and the UE execute the NAS SMC procedure. For details, please refer to the description in Figure 4.

[0408] Optionally, the method further includes S810 to S813:

[0409] S810: The AMF sends the UE's security capability information to the RAN. Correspondingly, the RAN receives the UE's security capability information from the AMF.

[0410] S811: The RAN determines a security algorithm based on the UE's security capability information and the configured algorithm priority list.

[0411] For this step, please refer to the description in S807.

[0412] S812: RAN generates an AS key (an example of a security key) and determines the length of the AS key according to the selected security algorithm.

[0413] For this step, please refer to the description in S713.

[0414] S813: RAN and UE execute the AS SMC process. For details, please refer to the existing related description.

[0415] For this step, please refer to the existing related description.

[0416] Figure 9 is a schematic flow chart of a communication method provided by the present application. The method includes the following steps.

[0417] S901: UE obtains the length of the long-term key.

[0418] Specifically, the long-term key may refer to the description in S801.

[0419] Exemplarily, the UE obtains the length of the long-term key from the USIM card. Specific details of this step may refer to S801.

[0420] S902: The UE sends a registration request message to the AMF via the RAN. Accordingly, the AMF receives the registration request message from the UE.

[0421] For the registration request, please refer to the description in S701.

[0422] The registration request carries indication information #2 and UE security capability information.

[0423] Indication information #2 indicates the length of the long-term key. Optionally, indication information #2 may be encrypted. Encrypting indication information #2 can protect the length of the long-term key. The specific encryption method may be encryption using the network-side public key that encrypted the SUPI (if no security context existed previously), or encryption using the previous NAS key (if a security context existed previously). The UE's security capability information indicates the security algorithms supported by the UE.

[0424] S903: The AMF sends the UE identification information and indication information #2 to the UDM. Correspondingly, the UDM receives the UE identification information and indication information #2 from the AMF.

[0425] S904: The UDM determines the length of the long-term key according to the identification information of the UE.

[0426] For this step, please refer to the description in S805.

[0427] For example, the length of the long-term key is 128 bits or 256 bits.

[0428] In one possible implementation, the UDM decrypts indication information #2, obtains the length of the long-term key sent by the UE, and compares it with the length of the long-term key obtained by retrieving the UE's identification information. If the two lengths are different, an error message is sent and subsequent steps are not executed.

[0429] S905: The network and the UE perform a primary authentication process.

[0430] Exemplarily, the main authentication process of the network side and the UE can complete the identity authentication of the UE and the network side and derive the keys of each layer.

[0431] Optionally, when deriving a key, the UDM may select the input length of the key derivation algorithm used according to the length of the long-term key K.

[0432] S906: UDM sends indication information #1 to AMF. Correspondingly, AMF receives indication information #1 from UDM.

[0433] The indication information #1 indicates the length of the long-term key K.

[0434] S907: AMF determines the length of the long-term key.

[0435] For example, the AMF may compare the lengths of the long-term keys in indication information #2 and indication information #1.

[0436] It should be noted that when the long-term key is encrypted with the NAS key, the AMF can compare the length of the long-term key in indication information #4 and indication information #1; when the long-term key is encrypted with the home network public key, UDM decryption comparison is required through the relevant steps in S904.

[0437] If the length of the long-term key indicated by indication information #2 is consistent with the length of the long-term key indicated by indication information #1, the length of the long-term key is determined to be the length of the long-term key indicated by indication information #1 or indication information #2.

[0438] If the length of the long-term key indicated by indication information #2 is inconsistent with the length of the long-term key indicated by indication information #1, an error is reported and subsequent steps are not executed.

[0439] S908: AMF determines the security algorithm based on the length of the long-term key.

[0440] Specifically, the AMF may determine the security algorithm based on the length of the long-term key, the UE's security capability information, and the configured algorithm priority list. This step may refer to the description in S706.

[0441] S909: The AMF generates a NAS key and determines the length of the NAS key based on the selected security algorithm.

[0442] For this step, please refer to the description in S707.

[0443] S910: The AMF sends a NAS SMC to the UE. Correspondingly, the UE receives the NAS SMC from the AMF.

[0444] This step can refer to the existing related descriptions

[0445] S911: The UE determines the length of the NAS key.

[0446] For example, the UE determines the length of the NAS key according to the length of the long-term key and the security algorithm obtained in S901. For details, please refer to the first possible implementation in S709.

[0447] In another possible implementation, the UE may determine the length of the NAS key according to the length of the input of the security algorithm. For details, please refer to the second possible implementation in S709.

[0448] S912: The UE sends a NAS SMP to the AMF. Correspondingly, the AMF receives the NAS SMP from the UE.

[0449] or,

[0450] S913: The AMF sends the first information to the RAN. Correspondingly, the RAN receives the first information from the AMF.

[0451] The first information may include security capability information of the UE and indication information #5, where the indication information #5 indicates the length of the long-term key.

[0452] S914: RAN determines a security algorithm based on the length of the long-term key.

[0453] For a specific determination method, reference may be made to the description in S706. The length of the input of the security algorithm selected by the RAN may be 128 bits or 256 bits.

[0454] S915: RAN generates an AS key (an example of a security key) and determines the length of the AS key according to the selected security algorithm.

[0455] The AS key (for example, K RRCint and K RRCenc ) is consistent with the length of the security algorithm.

[0456] Specifically, if the selected security algorithm is 128 bits, the length of the AS key is determined to be 128 bits. For example, the RAN will gNB The generated AS key is truncated to 128 bits.

[0457] If the selected security algorithm is 256 bits, the length of the AS key is determined to be 256 bits. gNB The length of the generated AS key is 512 bits. You can truncate the 512-bit key to 256 bits.

[0458] S916: RAN sends AS SMC to UE. Correspondingly, UE receives AS SMC from RAN.

[0459] For this step, please refer to the existing related description.

[0460] S917: The UE determines the length of the AS key.

[0461] For example, the AS key is K UPint and K UPenc .

[0462] Exemplarily, the UE determines the length of the AS key according to the length of the long-term key obtained in S901 and the security algorithm.

[0463] Alternatively, the UE may determine the length of the AS key according to the length of the input of the security algorithm.

[0464] For a specific determination method, please refer to the description in S709. The length of the AS key can be 128 bits or 256 bits.

[0465] S918: The UE sends the AS SMP to the RAN. Correspondingly, the RAN receives the AS SMP from the UE.

[0466] It should be understood that the size of the serial numbers of the above processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0467] It should also be understood that in the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced to each other, and the technical features in different embodiments can be combined to form new embodiments according to their internal logical relationships.

[0468] It should also be understood that in some of the above embodiments, the devices in the existing network architecture are mainly used as examples for illustrative description (such as network devices, terminal devices, etc.), and it should be understood that the embodiments of the present application do not limit the specific form of the devices. For example, devices that can achieve the same functions in the future are applicable to the embodiments of the present application.

[0469] It can be understood that in the above-mentioned method embodiments, the methods and operations implemented by devices (such as core network devices, access network devices and terminal devices) can also be implemented by components of the devices (such as chips or circuits).

[0470] The communication method provided in the embodiments of the present application is described in detail above in conjunction with Figures 5 to 9. The above communication method is mainly introduced from the perspective of the interaction between core network devices (e.g., a first core network device, a second core network device), access network devices, and terminal devices. It is understood that in order to implement the above functions, the core network devices, access network devices, and terminal devices include hardware structures and / or software modules corresponding to performing each function.

[0471] Those skilled in the art should be aware that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is performed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0472] The communication device provided in this application is described in detail below with reference to Figures 10 to 12. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment. Therefore, for matters not described in detail, reference can be made to the method embodiment above. For the sake of brevity, some contents will not be repeated.

[0473] In the embodiment of the present application, the functional modules of the transmitting device or the receiving device can be divided according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation. The following is an example of dividing each functional module according to each function.

[0474] Figure 10 is a schematic block diagram of a communication device 10 provided in an embodiment of the present application. The device 10 includes a transceiver module 11 and a processing module 12. The transceiver module 11 can implement corresponding communication functions, and the processing module 12 is used to process data. In other words, the transceiver module 11 is used to perform operations related to receiving and sending, while the processing module 12 is used to perform operations other than receiving and sending. The transceiver module 11 can also be referred to as a communication interface or a communication unit.

[0475] Optionally, the device 10 may further include a storage module 13, which may be used to store instructions and / or data. The processing module 12 may read the instructions and / or data in the storage module so that the device implements the actions of the devices in the aforementioned method embodiments.

[0476] In one design, the apparatus 10 may correspond to a core network device (eg, a first core network device or a second core network device) in the above method embodiment, or a component of a core network device (eg, a chip).

[0477] The device 10 can implement the steps or processes executed by the core network device in the above method embodiment, wherein the transceiver module 11 can be used to execute the transceiver-related operations of the core network device in the above method embodiment, and the processing module 12 can be used to execute the processing-related operations of the core network device in the above method embodiment.

[0478] It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.

[0479] In another design, the apparatus 10 may correspond to the access network device in the above method embodiment, or a component (such as a chip) of the access network device.

[0480] The device 10 can implement the steps or processes executed by the access network device in the above method embodiment, wherein the transceiver module 11 can be used to execute the transceiver-related operations of the access network device in the above method embodiment, and the processing module 12 can be used to execute the processing-related operations of the access network device in the above method embodiment.

[0481] It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.

[0482] In another design, the apparatus 10 may correspond to the terminal device in the above method embodiment, or be a component (such as a chip) of the terminal device.

[0483] The device 10 can implement the steps or processes executed by the terminal device in the above method embodiment, wherein the transceiver module 11 can be used to execute the transceiver-related operations of the terminal device in the above method embodiment, and the processing module 12 can be used to execute the processing-related operations of the terminal device in the above method embodiment.

[0484] It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.

[0485] It should also be understood that the device 10 here is embodied in the form of a functional module. The term "module" here may refer to an application specific integrated circuit (ASIC), an electronic circuit, a processor (such as a shared processor, a dedicated processor or a group processor, etc.) and a memory for executing one or more software or firmware programs, a combined logic circuit and / or other suitable components that support the described functions. In an optional example, those skilled in the art will understand that the device 10 may be specifically the access and mobility management network element or the data management network element in the above-mentioned embodiments, which may be used to execute the various processes and / or steps corresponding to the access and mobility management network element or the data management network element in the above-mentioned method embodiments; or, the device 10 may be specifically the access network device in the above-mentioned embodiments, which may be used to execute the various processes and / or steps corresponding to the access network device in the above-mentioned method embodiments. To avoid repetition, they will not be described in detail here; or, the device 10 may be specifically the terminal device in the above-mentioned embodiments, which may be used to execute the various processes and / or steps corresponding to the terminal device in the above-mentioned method embodiments. To avoid repetition, they will not be described in detail here.

[0486] The apparatus 10 of each of the above-mentioned solutions has the function of implementing the corresponding steps performed by the devices (such as core network devices, access network devices, and terminal devices) in the above-mentioned methods. This function can be implemented by hardware, or it can be implemented by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-mentioned functions; for example, the transceiver module can be replaced by a transceiver (for example, the sending unit in the transceiver module can be replaced by a transmitter, and the receiving unit in the transceiver module can be replaced by a receiver), and other units, such as the processing module, can be replaced by a processor to respectively perform the transceiver operations and related processing operations in each method embodiment.

[0487] In addition, the transceiver module 11 may also be a transceiver circuit (for example, may include a receiving circuit and a sending circuit), and the processing module may be a processing circuit.

[0488] Figure 11 is a schematic diagram of another communication device 20 provided in an embodiment of the present application. Device 20 includes a processor 21, which is configured to execute computer programs or instructions stored in memory 22, or read data / signaling stored in memory 22, to perform the methods described in the above method embodiments. Optionally, there may be one or more processors 21.

[0489] Optionally, as shown in FIG11 , the device 20 further includes a memory 22 for storing computer programs or instructions and / or data. The memory 22 may be integrated with the processor 21 or may be separately provided. Optionally, there may be one or more memories 22.

[0490] Optionally, as shown in Figure 11, the device 20 further includes a transceiver 23, which is used to receive and / or send signals. For example, the processor 21 is used to control the transceiver 23 to receive and / or send signals.

[0491] As a solution, the apparatus 20 is used to implement the operations performed by the access network device in each of the above method embodiments.

[0492] As another solution, the device 20 is used to implement the operations performed by the core network device in the above various method embodiments.

[0493] As another solution, the apparatus 20 is used to implement the operations performed by the terminal device in the above various method embodiments.

[0494] It should be understood that the processor mentioned in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0495] It should also be understood that the memory mentioned in the embodiments of the present application may be a volatile memory and / or a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes the following forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0496] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) can be integrated into the processor.

[0497] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0498] 12 is a schematic diagram of a chip system 30 according to an embodiment of the present application. The chip system 30 (or also referred to as a processing system) includes a logic circuit 31 and an input / output interface 32.

[0499] The logic circuit 31 may be a processing circuit in the chip system 30. The logic circuit 31 may be coupled to a storage unit and call instructions in the storage unit so that the chip system 30 can implement the methods and functions of the various embodiments of the present application. The input / output interface 32 may be an input / output circuit in the chip system 30, outputting information processed by the chip system 30 or inputting data or signaling information to be processed into the chip system 30 for processing.

[0500] As a solution, the chip system 30 is used to implement the operations performed by the core network device, the access network device and the terminal device in the above method embodiments.

[0501] For example, the logic circuit 31 is used to implement the processing-related operations performed by the core network device, access network device and terminal device in the above method embodiment; the input / output interface 32 is used to implement the sending and / or receiving-related operations performed by the core network device, access network device and terminal device in the above method embodiment.

[0502] An embodiment of the present application also provides a computer-readable storage medium on which computer instructions are stored for implementing the methods executed by the core network device, access network device and terminal device in the above-mentioned method embodiments.

[0503] For example, when the computer program is executed by a computer, the computer can implement the methods performed by the core network device, the access network device, and the terminal device in each embodiment of the above method.

[0504] An embodiment of the present application also provides a computer program product comprising instructions, which, when executed by a computer, implement the methods performed by the core network device, the access network device, and the terminal device in the above-mentioned method embodiments.

[0505] An embodiment of the present application also provides a communication system, including the aforementioned core network device, access network device and terminal device.

[0506] The explanation of the relevant contents and beneficial effects of any of the above-mentioned devices can be referred to the corresponding method embodiments provided above, which will not be repeated here.

[0507] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0508] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. For example, the computer can be a personal computer, a server, or a network device, etc. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state disk (SSD)). For example, the aforementioned available medium includes, but is not limited to, various media that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0509] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A communication method, characterized in that: include: The network device receives first indication information, where the first indication information indicates the length of a first key, where the first key is a key of the terminal device; The network device determines a first security algorithm based on the length of the first key, the length of the input key of the first security algorithm being less than or equal to the length of the first key; The network device transmits a message with the terminal device, where the message is a message that is security protected based on the first security algorithm.

2. The method according to claim 1, characterized in that The network device is a first core network device, and the network device receives first indication information, including: The network device receives the first indication information from the second core network device and / or the terminal device.

3. The method according to claim 1, characterized in that The network device is an access network device, and the network device receives first indication information, including: The network device receives the first indication information from the first core network device and / or the terminal device.

4. The method according to any one of claims 1 to 3, characterized in that The network device determines a first security algorithm based on the length of the first key, including: The network device determines the first security algorithm based on the length of the first key, the security capability information of the terminal device and an algorithm priority list, wherein the security capability information of the terminal device indicates the security algorithms supported by the terminal device, and the algorithm priority list is used to indicate the priority of the security algorithms supported by the network side.

5. The method according to claim 4, characterized in that The first security algorithm is one of the security algorithms supported by the terminal device, the priority of the first security algorithm is higher than the priority of the second security algorithm in the algorithm priority list, and the second security algorithm includes security algorithms supported by the terminal device except the first security algorithm and the length of the input key is less than or equal to the length of the first key.

6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: The network device determines the length of a security key according to the first security algorithm, the security key is a key used by the security algorithm, and the length of the security key is the same as the length of an input key of the first security algorithm.

7. The method according to any one of claims 1 to 6, characterized in that The method further comprises: The network device sends second indication information to the terminal device, where the second indication information indicates the length of the first key, where the length of the first key is used to determine the length of the key output by the key derivation algorithm, where the output key is used to generate a security key, which is a key used by the security algorithm.

8. A communication method, characterized in that: include: Sending first indication information to the network device, where the first indication information indicates the length of a first key, where the first key is a key of a terminal device, where the length of the first key is used by the first core network device to determine the length of an input key of a first security algorithm, where the length of the input key of the first security algorithm is less than or equal to the length of the first key; Transmitting a message with the network device, wherein the message is a message that is security-protected based on the first security algorithm.

9. The method according to claim 8, characterized in that Before sending the first indication information to the network device, the method further includes: The length of the first key is obtained from the user identity module.

10. The method according to claim 8 or 9, characterized in that: Before transmitting the message with the network device, the method further includes: The length of the key output by the key derivation algorithm is determined according to the length of the first key. The key output by the key derivation algorithm is used to generate a security key, and the security key is the key used by the first security algorithm.

11. A communication method, characterized in that: include: Determining the length of a first key of a terminal device; A first indication message is sent to a first core network device, where the first indication message indicates the length of a first key, where the length of the first key is used to determine the length of a key input to a first security algorithm, where the length of the input key of the first security algorithm is less than or equal to the length of the first key, and where the first security algorithm is used to perform security protection on messages transmitted to the terminal device.

12. The method according to claim 11, characterized in that The determining the length of the first key of the terminal device includes: Receiving identification information of the terminal device from the first core network device; The length of the first key is determined according to the identification information of the terminal device.

13. The method according to claim 11 or 12, characterized in that: The method further comprises: The length of the key output by the key derivation algorithm is determined according to the length of the first key, and the output key is used to generate a security key, and the security key is a key used by the security algorithm.

14. A communication method, characterized in that: include: Sending security capability information of a terminal device to a network device, the security capability information indicating a security algorithm supported by the terminal device, the length of an input key of the security algorithm supported by the terminal device being less than or equal to the length of a first key, the first key being a key of the terminal device, and the security capability information of the terminal device being used by a first core network device to determine a first security algorithm; Transmitting a message with the network device, wherein the message is a message that is security-protected based on the first security algorithm.

15. The method according to claim 14, characterized in that Before sending the security capability information of the terminal device to the network device, the method further includes: The length of the first key is obtained from the user identity module.

16. The method according to claim 14 or 15, characterized in that Before transmitting the message with the network device, the method further includes: The security capability information of the terminal device to be sent to the network device is determined according to the length of the first key and the security capability information configured in the terminal device.

17. The method according to any one of claims 14 to 16, characterized in that Before transmitting the message with the network device, the method further includes: The length of the key output by the key derivation algorithm is determined according to the length of the first key. The key output by the key derivation algorithm is used to generate a security key, and the security key is the key used by the first security algorithm.

18. A communication method, characterized in that: include: Receiving security capability information of a terminal device, the security capability information indicating a security algorithm supported by the terminal device, the length of an input key of the security algorithm supported by the terminal device being less than or equal to the length of a first key, and the first key being a key of the terminal device; A message is transmitted to the terminal device, where the message is a message that is security-protected based on a first security algorithm, and the first security algorithm is one of the security algorithms supported by the terminal device.

19. The method according to claim 18, characterized in that Before transmitting a message to the terminal device, the method further includes: The algorithm priority list determines the first security algorithm according to the security capability information of the terminal device, and the priority of the first security algorithm is higher than the security algorithms supported by the terminal device included in the algorithm priority list except the first security algorithm.

20. The method according to claim 18 or 19, characterized in that The method further comprises: The length of a security key is determined according to the first security algorithm, where the security key is a key used by the security algorithm and the length of the security key is the same as the length of an input key of the first security algorithm.

21. A communication device, characterized in that: include: One or more functional modules for executing the method as claimed in any one of claims 1 to 7, or one or more functional modules for executing the method as claimed in any one of claims 8 to 10, or one or more functional modules for executing the method as claimed in any one of claims 11 to 13, or one or more functional modules for executing the method as claimed in any one of claims 14 to 17, or one or more functional modules for executing the method as claimed in any one of claims 18 to 20.

22. A communication device, characterized in that: include: A processor, configured to execute a computer program stored in a memory so that the apparatus performs the method as claimed in any one of claims 1 to 7, or so that the apparatus performs the method as claimed in any one of claims 8 to 10, or for performing the method as claimed in any one of claims 11 to 13, or for performing the method as claimed in any one of claims 14 to 17, or for performing the method as claimed in any one of claims 18 to 20.

23. A computer-readable storage medium, characterized in that: include: The computer-readable storage medium stores a computer program; when the computer program is executed on a computer, the computer is caused to perform the method according to any one of claims 1 to 20.

24. A chip, characterized in that: The chip is installed in a communication device, and the chip includes a processor and a communication interface. When the processor reads instructions through the communication interface and runs, the communication device executes the method as described in any one of claims 1 to 20.

25. A computer program product, characterized in that The computer program product comprises a computer program code, and when the computer program code is executed by a communication device, the method according to any one of claims 1 to 20 is implemented.

Citation Information

Patent Citations

  • Communication method and communication device

    CN120050653A

  • Enhanced encryption and integrity protection method

    CN101860863A

  • Security negotiation method, terminal equipment and network equipment

    CN110366175A

  • Security negotiation method, terminal device and network device

    CN113423104A

  • Method of communication terminal, communication terminal, method of core network apparatus, and core network apparatus

    US20230262456A1