Communication method and apparatus, and computer readable storage medium
By sending key information under a serviced RAN architecture to ensure data encryption between the terminal device and the network element node, the business security problem caused by the inability to implement the encryption function of AMF is solved, and data transmission security is achieved without AMF.
Patent Information
- Application Number
- PCT/CN2024/137854
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-14
- Filing Date
- 2024-12-09
- Publication Date
- 2025-06-19
AI Technical Summary
Under the service-based RAN architecture, AMF cannot implement encryption functions, resulting in the service security between the terminal equipment and the core network elements being unable to be guaranteed.
By receiving request information and sending key information, it is ensured that the terminal device and network element nodes can correctly encrypt and decrypt the transmitted data. The key information is used to indicate a first key, which is used to encrypt data transmitted between the network element node and the terminal device.
When the data transmission between the core network elements and terminal devices does not pass through AMF, the data security can still be guaranteed, providing an encryption mechanism suitable for the service-based RAN architecture.
Smart Images

Figure CN2024137854_19062025_PF_FP_ABST
Abstract
Description
Communication method and device, and computer-readable storage medium
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on December 14, 2023, with application number 202311731505.0 and application name “Communication Method and Device, Computer-readable Storage Medium”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to a communication method and device, and a computer-readable storage medium. Background Art
[0003] Currently, the interaction between terminal devices and core network elements needs to be forwarded through the Access and Mobility Management Function (AMF), and security is protected by the AMF's encryption mechanism.
[0004] In the future, there's a strong possibility that a service-based radio access network (RAN) will be introduced. This will break the nested relationship between core network elements and the AMF, allowing end devices to interact directly with core network elements without going through the AMF. In this scenario, the AMF will no longer be able to perform encryption, and the security of services between end devices and core network elements will be compromised. Summary of the Invention
[0005] The technical problem that this application can solve is how to ensure business security under the service-oriented RAN architecture.
[0006] To solve the above technical problems, an embodiment of the present application provides a communication method, including: receiving request information, wherein the request information is used to request a first service; sending key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
[0007] Optionally, sending the key information includes: sending first information to the network element node, where the first information includes the first key.
[0008] Optionally, before sending the first information to the network element node, the method further includes: selecting the network element node from a plurality of candidate network element nodes, where all of the plurality of candidate network element nodes are associated with the first service.
[0009] Optionally, the sending of key information includes: sending second information to the terminal device, where the second information includes input parameters, and the input parameters are used to generate the first key.
[0010] Optionally, the input parameter includes: an identifier of the network element node and / or an address of the network element node.
[0011] Optionally, the request information is received from a server or the terminal device.
[0012] Optionally, the network element node is selected from: a positioning management function node and a perception function node.
[0013] To solve the above technical problems, an embodiment of the present application also provides a communication method, including: receiving key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; using the first key to process the data of the first service and transmit it to the network element node via a wireless access network.
[0014] Optionally, the receiving key information includes: receiving second information, where the second information includes input parameters, and the input parameters are used to generate the first key.
[0015] Optionally, the input parameters include: an identifier of the network element node and / or a network interconnection protocol address of the network element node.
[0016] Optionally, the method further includes: sending request information, where the request information is used to request the first service.
[0017] To solve the above technical problems, an embodiment of the present application also provides a communication method, including: receiving key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; using the first key to process the data of the first service and transmit it to the terminal device via a wireless access network.
[0018] Optionally, receiving key information includes: receiving first information, where the first information includes the first key.
[0019] Optionally, the network element node is selected from: a positioning management function node and a perception function node.
[0020] To solve the above technical problems, an embodiment of the present application also provides a communication device, including: a receiving module for receiving request information, wherein the request information is used to request a first service; a sending module for sending key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
[0021] To solve the above technical problems, an embodiment of the present application also provides a communication device, including: a receiving module for receiving key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; a transmission module for processing the data of the first service using the first key and transmitting it to the network element node via a wireless access network.
[0022] To solve the above technical problems, an embodiment of the present application also provides a communication device, including: a receiving module for receiving key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; a transmission module for processing the data of the first service using the first key and transmitting it to the terminal device via a wireless access network.
[0023] To solve the above technical problems, an embodiment of the present application also provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transient storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps of the above method are executed.
[0024] To solve the above technical problems, an embodiment of the present application further provides a communication device, comprising a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and the processor executes the steps of the above method when running the computer program.
[0025] Compared with the prior art, the technical solution of the embodiment of the present application has the following beneficial effects:
[0026] On the AMF side, an embodiment of the present application provides a communication method, including: receiving request information, the request information is used to request a first service; sending key information, the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between the network element node and the terminal device.
[0027] Compared to the prior art, where the AMF acts as a transit node to encrypt messages / data when forwarding them between terminal devices and core network elements, the first service covered by this implementation is a service performed within the service-based RAN architecture. Since the AMF does not perform data transit, key information is sent to both communicating parties (e.g., terminal devices and network elements) to ensure that they can correctly encrypt and decrypt transmitted data. This provides a suitable encryption mechanism for the service-based RAN architecture, ensuring security even when data transmission between core network elements and terminal devices does not pass through the AMF.
[0028] On the terminal device side, an embodiment of the present application also provides a communication method, including: receiving key information, the key information is used to indicate a first key, the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; using the first key to process the data of the first service, and transmitting it to the network element node via a wireless access network.
[0029] Compared to the existing technology, where terminal devices only need to send and receive data decrypted by the AMF, this implementation indicates the first key configured on the AMF side to the terminal device, allowing the terminal device to correctly encrypt and decrypt transmitted data during communication between the RAN and the network element node. This provides a suitable encryption mechanism for the service-based RAN architecture, ensuring security even when data transmission between core network elements and terminal devices does not pass through the AMF.
[0030] On the core network side, an embodiment of the present application also provides a communication method, including: receiving key information, the key information is used to indicate a first key, the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; using the first key to process the data of the first service, and transmitting it to the terminal device via a wireless access network.
[0031] Compared to existing techniques where network element nodes only need to send and receive data decrypted by the AMF, this implementation instructs the network element nodes on the first key configured on the AMF side, enabling them to correctly encrypt and decrypt transmitted data during communication with terminal devices over the RAN. This provides a suitable encryption mechanism for the service-based RAN architecture, ensuring security even when data transmission between core network elements and terminal devices does not pass through the AMF. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] FIG1 is a schematic diagram of the architecture of the first service-oriented RAN of the present application;
[0033] FIG2 is a schematic diagram of the architecture of the second service-oriented RAN of the present application;
[0034] FIG3 is a schematic diagram of the architecture of the third service-oriented RAN of the present application;
[0035] FIG4 is a signaling interaction diagram of a communication method according to an embodiment of the present application;
[0036] FIG5 is a schematic structural diagram of a communication device according to an embodiment of the present application;
[0037] FIG6 is a schematic structural diagram of another communication device according to an embodiment of the present application;
[0038] FIG7 is a schematic structural diagram of another communication device according to an embodiment of the present application. DETAILED DESCRIPTION
[0039] As mentioned in the background technology, under the service-oriented RAN architecture, the existing encryption function implemented through AMF is no longer applicable, and the service security between terminal devices and core network elements cannot be guaranteed.
[0040] Specifically, the interaction between existing terminal devices and core network elements is forwarded through AMF. Taking positioning services as an example, there is no direct interface between the positioning management server (also known as the location management function, LMF) and the terminal device. For service security reasons, the data of positioning services (for example, including positioning requests and positioning reports) needs to be encrypted. Since the interaction between the terminal device and LMF must pass through AMF, it can be encrypted through AMF.
[0041] Considering that 6G will introduce a service-based architecture, one option is for the RAN to directly connect to the core network, eliminating forwarding through the AMF. Therefore, a new encryption mechanism needs to be designed for the service-based RAN architecture.
[0042] To solve the above technical problems, an embodiment of the present application provides a communication method, including: receiving request information, wherein the request information is used to request a first service; sending key information, wherein the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
[0043] The first service covered by this implementation is a service within the Service-Based RAN architecture. Since the AMF does not act as a data relay, key information is sent to both communicating parties (e.g., terminal devices and network element nodes) to ensure that they can correctly encrypt and decrypt transmitted data. This provides a suitable encryption mechanism for the Service-Based RAN architecture, ensuring security even when data transmission between core network elements and terminal devices does not pass through the AMF.
[0044] The service-oriented RAN architecture in the embodiment of the present application may be shown in any one of Figures 1 to 3 .
[0045] Figure 1 exemplarily illustrates the network architecture under the full service of the N2 interface, which can realize direct service calls between the access network network function (RAN Network Function, RAN NF) and the core network network function (Core Network NF, CN NF). Specifically, the terminal device (indicated by UE in the figure) can access the bus (i.e., access the core network) through the AMF. Furthermore, the terminal device can also directly access the core network through the RAN, thereby breaking through the existing AMF-only forwarding mechanism. The RAN includes the control plane RAN (indicated by RAN-C in the figure) and the user plane RAN (indicated by RAN-U in the figure). Furthermore, in the architecture shown in Figure 1, the application function (AF), network repository function (NRF), policy control function (PCF), and unified data management function (UDM) on the core network side also directly access the bus. Furthermore, the user plane function (UPF) and data network (DN) can access the bus through the session management function (SMF).
[0046] Figure 2 illustrates a service-oriented network architecture for traditional RAN functions. This architecture decomposes functions (also known as RAN capabilities) into services and further integrates RAN and CN-related functional services and processes to better meet the design principles of high cohesion and loose coupling, streamlining network design. Specifically, a terminal device (denoted as a UE in the figure) can access the bus through the AMF. Furthermore, the terminal device can access the RAN through the radio unit (RU), and directly access the core network via the RAN. The RU is responsible for handling the digital front end (DFE) and some physical (PHY) layer functions. Furthermore, the RAN is decomposed into RAN control plane services (implemented based on the control plane service (CPS)) and RAN user plane services (implemented based on the user plane service (UPS)). Furthermore, a core network user plane service (implemented based on the UPS) is configured to communicate with the RAN and directly access the bus. Furthermore, other core network elements such as the AF, NRF, PCF, and UDM directly access the bus. Furthermore, the SMF also directly accesses the bus. Furthermore, the DN accesses the bus through the core network user plane service.
[0047] Figure 3 illustrates a service-oriented network architecture for the newly added DOICT capabilities. This architecture defines artificial intelligence (AI), computing, and data capabilities as services. DOICT uses communication technology (CT) to simplify field network configuration; uses operational technology (OT) to achieve high reliability through deep collaboration with industrial protocols; uses data technology (DT) to achieve intelligence and a closed-loop guarantee of low latency; and uses information technology (IT) to enable more industrial applications, reduce construction costs, and achieve flexible networking. Specifically, terminal devices access the RAN through the RU and directly access the core network through the RAN. Furthermore, the RAN is split into RAN control plane services (implemented based on the Cyber-Physical System (CPS)), RAN user plane services (implemented based on the User-Physical System (UPS)), and multi-dimensional capability services (including AI services, computing services, and data services). Furthermore, the AMF is connected to the bus and decoupled from the terminal device. Furthermore, other core network elements such as the Network Exposure Function (NEF), AF, NRF, PCF, and UDM directly access the bus. Furthermore, the SMF can also directly access the bus. Furthermore, the DN accesses the bus through the UPF, which communicates with the RAN.
[0048] In an embodiment of the present application, the network element node may be a core network element that performs a function related to the first service. The first service may be a service implemented based on a service-based RAN architecture. For example, the first service may be a positioning service, and the corresponding network element node may be a positioning management function (LMF) node (SMF for short). For another example, the first service may be a synaesthesia (also known as sensing) service, and the corresponding network element node may be a sensing function (SF) node (SF for short).
[0049] In the embodiment of the present application, although AMF no longer forwards data between the terminal device and the network element node, it still plays a management function.
[0050] In order to make the above-mentioned objectives, features and beneficial effects of the present application more obvious and easy to understand, the specific embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0051] FIG4 is a signaling interaction diagram of a communication method according to an embodiment of the present application.
[0052] This implementation scheme can be applied to communication scenarios under the service-oriented RAN architecture. The terminal device directly interacts with the network element node through the RAN to transmit the data of the first service without being transferred through the AMF.
[0053] In a specific implementation, in the communication method provided by the following steps S101 to S102, the steps implemented by the terminal device can be executed by a chip with communication functions in the terminal device, or by a baseband chip in the terminal device; the steps implemented by the AMF can be executed by a chip with communication functions in the AMF, or by a baseband chip in the AMF; the steps implemented by the network element node can be executed by a chip with communication functions in the network element node, or by a baseband chip in the network element node.
[0054] Specifically, referring to FIG4 , the communication method according to this embodiment may include the following steps:
[0055] In step S101, a terminal device sends a request message to an AMF. Accordingly, the AMF receives the request message. The request message is used to request a first service.
[0056] For example, the first service may be a positioning service, and correspondingly, the request information may be positioning request information.
[0057] In some embodiments, the sending of the request information may be actively triggered by the terminal device.
[0058] In some embodiments, the server may trigger the terminal device to send a request message to the AMF. The server may be, for example, an external server for implementing the first service.
[0059] In some embodiments, the server may send the request information directly to the AMF.
[0060] In some embodiments, the requested first service may be an uplink service or a downlink service.
[0061] In some embodiments, the request information may include relevant information for implementing the first service, such as an identifier of the terminal device (used to uniquely identify the terminal device) and quality of service (Quality of Service, QoS for short).
[0062] Still taking the terminal device requesting a positioning service as an example, the positioning request information sent in step S101 may include the terminal device identifier and the positioning QoS (such as positioning accuracy requirements, latency requirements, etc.).
[0063] In one specific implementation, with continued reference to Figure 4 , in response to receiving the request information, the AMF may execute step S102 to send key information to the terminal device and the network element node, respectively. Accordingly, the network element node and the terminal device each receive the key information. The key information indicates a first key used to encrypt data of the first service transmitted between the network element node and the terminal device.
[0064] In some embodiments, for the interaction between the network element node and the AMF, step S102 may specifically include step S1021 and step S1022.
[0065] In step S1021, the AMF selects a network element node from multiple candidate network element nodes, and the multiple candidate network element nodes are all associated with the first service.
[0066] Specifically, the core network may deploy multiple network element nodes for the first service, and these network element nodes serve as candidate network element nodes. After receiving the request information, the AMF selects one from the multiple candidate network element nodes as the network element node to communicate with the terminal device.
[0067] Still taking the positioning request information as an example, the AMF can select a nearby LMF from multiple candidate LMFs and determine it as the LMF that communicates with the terminal device to realize the positioning service.
[0068] For another example, the request information can be used to request a perception service, and the AMF can select one from multiple candidate SFs to determine as the SF that communicates with the terminal device to implement the perception service.
[0069] Further, after determining the network element node, the AMF may continue to perform step S1022 and send the first information to the network element node. Accordingly, the network element node receives the first information. The first information includes the first key.
[0070] Therefore, the AMF directly provides the generated first key to the network element node.
[0071] In some embodiments, the first keys allocated to different candidate network element nodes may not be repeated.
[0072] In one specific implementation, for interaction between the terminal device and the AMF, step S102 may specifically include step S1023, where the AMF sends second information to the terminal device. Accordingly, the terminal device receives the second information. The second information includes input parameters used to generate the first key.
[0073] Specifically, part of the input parameters can be pre-configured by the network or pre-defined by the protocol or determined by the terminal device itself, and the remaining part (for example, parameters related to the network element node) can be indicated to the terminal device by the AMF.
[0074] Still taking the first service as the positioning service as an example, the input parameters required for deriving the LMF key (KLMF) may include:
[0075] -FC=0x6E, used to distinguish different derivation algorithms;
[0076] -P0 = Uplink / Downlink Non-Access Stratum (NAS) count (Uplink / Downlink NAS COUNT), which is the sequence number used when signaling is transmitted between the terminal device and the AMF;
[0077] - L0 = length of uplink / downlink NAS COUNT, for example, 0x00 0x04;
[0078] -P1 = Network function distinguisher, used to distinguish different network functions;
[0079] - L1 = length of the network function distinguisher, for example, 0x000x01.
[0080] In some embodiments, the input parameters carried in the second information may include a P1 parameter. Since the P1 parameter is used to distinguish different network functions, it can also be called an identifier of a network element node (in this example, it can be understood as a type identifier) to distinguish network element nodes with different functions. For example, the P1 value corresponding to LMF is 0x01, and the P1 value corresponding to SF is 0x02.
[0081] In one variation, the content of the P1 parameter may be an identification (ID) of a network element node, used to uniquely identify the candidate network element node. For example, the core network side includes multiple candidate LMFs, each of which is assigned a unique ID. After the AMF selects one of the multiple candidate LMFs, it indicates the ID of the selected LMF to the terminal device via the second message.
[0082] In a variation, the content of the P1 parameter may be replaced with a network function address, and correspondingly, the content of the L1 parameter may be replaced with the length of the network function address.
[0083] The address of the network element node may be, for example, an Internet Protocol (IP) address, or a Media Access Control (MAC) address.
[0084] In another variation, in addition to the P1 parameter, the input parameters required for derivation of the LMF key (KLMF) may also include P2 = network function address and L2 = length of the network function address. Furthermore, the second information may include the P1 parameter and the P2 parameter.
[0085] In one specific implementation, the AMF indicates in the second information the identifier (including type identifier and / or identity identifier) and / or address of the network element node associated with the first service, so that the terminal device generates a first key for interacting with the network element node.
[0086] For example, in response to receiving the second information, the terminal device calculates KAMF based on the K value configured in the Universal Subscriber Identity Module (USIM) and the dynamic parameters provided by the network. Furthermore, the first key is calculated based on the input parameters (including the content carried in the second information (such as P1 and / or P2) and the content determined by the terminal device itself).
[0087] In some embodiments, the action of sending the second information to the terminal device (corresponding to step S1023) can be performed before / after / simultaneously with the action of sending the first information to the network element node (corresponding to step S1021 and step S1022).
[0088] In a specific implementation, in response to receiving the first information and the second information respectively, the network element node and the terminal device may use the first key to communicate directly via the RAN.
[0089] Specifically, in response to receiving the second information, the terminal device may execute step S103 to process the data of the first service using the first key and transmit the data to the network element node via the RAN.
[0090] Similarly, in response to receiving the first information, the network element node may execute step S104 to process the data of the first service using the first key and transmit the data to the terminal device via the RAN.
[0091] In one variation, step S101 may be omitted, and the AMF may proactively send key information to the terminal device upon access. Furthermore, the AMF may proactively send key information to the network element node corresponding to the first service that the terminal device needs to implement.
[0092] In one variation, step S102 may be omitted. For example, if there is only one network element node associated with the first service, the AMF may directly execute step S103 to send the key information to the network element node.
[0093] From the above, AMF ensures that the communicating parties can correctly encrypt and decrypt the transmitted data by sending key information to both communicating parties (for example, the terminal device and the network element node). In response to receiving the key information (for example, the second information), the terminal device can correctly encrypt and decrypt the transmitted data during the communication between the RAN and the network element node. In response to receiving the key information (for example, the first information), the network element node can correctly encrypt and decrypt the transmitted data during the communication between the RAN and the terminal device. Thus, a suitable encryption mechanism is provided for the service-based RAN architecture, and security can still be guaranteed when the data transmission between the core network network element and the terminal device does not pass through the AMF.
[0094] FIG5 is a schematic diagram of the structure of a communication device 2 according to an embodiment of the present application. Those skilled in the art will appreciate that the communication device 2 according to this embodiment can be used to implement the method and technical solutions described in the embodiments described in FIG1 to FIG4 above.
[0095] Specifically, the communication device 2 described in this embodiment may include: a receiving module 21, used to receive request information, the request information is used to request a first service; a sending module 22, used to send key information, the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between the network element node and the terminal device.
[0096] For more details about the working principle and working mode of the communication device 2, please refer to the relevant descriptions in Figures 1 to 4 above, which will not be repeated here.
[0097] In a specific implementation, the communication device 2 may correspond to a chip with communication functionality in a network device, or to a chip with data processing functionality, such as a system-on-a-chip (SOC) or a baseband chip; or to a chip module in a network device that includes a chip with communication functionality; or to a chip module with a chip with data processing functionality, or to a network device. In this example, the network device may be, for example, an AMF.
[0098] Figure 6 is a schematic diagram of the structure of another communication device 3 according to an embodiment of the present application. Those skilled in the art will appreciate that the communication device 3 described in this embodiment can be used to implement the method and technical solutions described in the embodiments described in Figures 1 to 4 above.
[0099] Specifically, referring to Figure 6, the communication device 3 described in this embodiment may include: a receiving module 31, used to receive key information, the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between the network element node and the terminal device; a transmission module 32, used to use the first key to process the data of the first service and transmit it to the network element node via the wireless access network.
[0100] For more details about the working principle and working mode of the communication device 3, please refer to the relevant descriptions in Figures 1 to 4 above, which will not be repeated here.
[0101] In a specific implementation, the above-mentioned communication device 3 can correspond to a chip with communication function in the terminal equipment, or to a chip with data processing function, such as a system-on-a-chip (SOC), a baseband chip, etc.; or to a chip module in the terminal equipment that includes a chip with communication function; or to a chip module with a chip with data processing function, or to a terminal equipment.
[0102] Figure 7 is a schematic diagram of the structure of another communication device 4 according to an embodiment of the present application. Those skilled in the art will appreciate that the communication device 4 described in this embodiment can be used to implement the method and technical solutions described in the embodiments described in Figures 1 to 4 above.
[0103] Specifically, referring to Figure 7, the communication device 4 described in this embodiment may include: a receiving module 41, used to receive key information, the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between the network element node and the terminal device; a transmission module 42, used to use the first key to process the data of the first service and transmit it to the terminal device via the wireless access network.
[0104] For more details about the working principle and working mode of the communication device 4, please refer to the relevant descriptions in Figures 1 to 4 above, which will not be repeated here.
[0105] In a specific implementation, the communication device 4 may correspond to a chip with communication functionality in a network device, or to a chip with data processing functionality, such as a system-on-a-chip (SOC) or a baseband chip; or to a chip module in a network device that includes a chip with communication functionality; or to a chip module with a chip with data processing functionality, or to a network device. In this example, the network device may be, for example, a core network element (i.e., a network element node).
[0106] In specific implementations, the modules / units included in the various devices and products described in the above embodiments may be software modules / units or hardware modules / units, or may be partially software modules / units and partially hardware modules / units.
[0107] For example, for each device or product applied to or integrated into a chip, each module / unit contained therein may be implemented in the form of hardware such as circuits, or at least some of the modules / units may be implemented in the form of software programs, which run on a processor integrated inside the chip, and the remaining (if any) modules / units may be implemented in the form of hardware such as circuits; for each device or product applied to or integrated into a chip module, each module / unit contained therein may be implemented in the form of hardware such as circuits, and different modules / units may be located in the same component (such as a chip, circuit module, etc.) or different components of the chip module, or at least some of the modules / units may be implemented in the form of software programs. The element can be implemented in the form of a software program, which runs on the processor integrated inside the chip module, and the remaining (if any) modules / units can be implemented in the form of hardware such as circuits; for various devices and products applied to or integrated in the terminal, the various modules / units contained therein can be implemented in the form of hardware such as circuits, and different modules / units can be located in the same component (for example, chip, circuit module, etc.) or different components in the terminal, or, at least some modules / units can be implemented in the form of a software program, which runs on the processor integrated inside the terminal, and the remaining (if any) modules / units can be implemented in the form of hardware such as circuits.
[0108] The embodiment of the present application further provides a computer-readable storage medium, which is a non-volatile storage medium or a non-transitory storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the communication method provided in any of the above embodiments are executed. Preferably, the storage medium may include a computer-readable storage medium such as a non-volatile memory or a non-transitory memory. The storage medium may include ROM, RAM, a magnetic disk, or an optical disk, etc.
[0109] The present application also provides another communication device, including a memory and a processor. The memory stores a computer program executable on the processor, and when the processor executes the computer program, it executes the steps of the communication method provided in the embodiment corresponding to FIG. 4 . The communication device can be integrated into a terminal / network device, or the communication device can be, for example, a terminal / network device.
[0110] The technical solution of the present application can be applied to the fifth generation (5G) communication system, as well as the fourth generation (4G) and third generation (3G) communication systems. It can also be applied to various new communication systems in the future, such as the sixth generation (6G) and seventh generation (7G), etc. The embodiments of the present application are not limited to this.
[0111] The technical solution of this application is also applicable to different network architectures, including but not limited to relay network architecture, dual-link architecture, vehicle-to-everything (V2X) architecture, device-to-device (D2D) architecture, and other architectures.
[0112] The devices in the embodiments of the present application include network devices and terminal devices.
[0113] The network devices in the embodiments of the present application include base stations and base station controllers of the access network, and may also include terminal devices.
[0114] The base station (BS) in the embodiments of the present application, which may also be referred to as a base station device, is a device deployed in a radio access network (RAN) to provide wireless communication functions. For example, the device providing base station functions in a 2G network includes a base transceiver station (BTS), the device providing base station functions in a 3G network includes a node B (NodeB), the device providing base station functions in a 4G network includes an evolved node B (eNB), and in wireless local area networks (WLANs), the device providing base station functions is an access point (AP). The device providing base station functions in 5G New Radio (NR) is a gNB, and an evolved node B (ng-eNB). The gNB and terminal devices communicate using NR technology, and the ng-eNB and terminal devices communicate using Evolved Universal Terrestrial Radio Access (E-UTRA) technology. Both the gNB and the ng-eNB can be connected to the 5G core network. The base station in the embodiment of the present application also includes equipment that provides base station functions in future new communication systems, etc.
[0115] The base station controller in the embodiment of the present application, which may also be referred to as a base station controller device, is a device for managing base stations, such as a base station controller (BSC) in a 2G network, a radio network controller (RNC) in a 3G network, and may also refer to a device for controlling and managing base stations in future new communication systems.
[0116] The terminal device in the embodiments of the present application may also be referred to as a terminal, and may refer to various forms of user equipment (UE), access terminal equipment, user unit, user station, mobile station, mobile station (MS), remote station, remote terminal equipment, mobile device, user terminal equipment, wireless communication equipment, user agent or user device. The terminal device may also be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA), a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, an in-vehicle device, a wearable device, a terminal device in a future 5G network, or a terminal device in a future evolved Public Land Mobile Network (PLMN), etc., and the embodiments of the present application are not limited to this.
[0117] Although the present application is disclosed as above, the present application is not limited thereto. Any person skilled in the art may make various changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be based on the scope defined by the claims.
Claims
1. A communication method, characterized in that: include: receiving request information, where the request information is used to request a first service; Send key information, where the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
2. The method according to claim 1, characterized in that The sending key information includes: Sending first information to the network element node, where the first information includes the first key.
3. The method according to claim 2, characterized in that Before sending the first information to the network element node, the method further includes: The network element node is obtained by selecting from a plurality of candidate network element nodes, and the plurality of candidate network element nodes are all associated with the first service.
4. The method according to any one of claims 1 to 3, characterized in that The sending key information includes: Sending second information to the terminal device, where the second information includes input parameters, and the input parameters are used to generate the first key.
5. The method according to claim 4, characterized in that The input parameter includes: an identifier of the network element node and / or an address of the network element node.
6. The method according to any one of claims 1 to 5, characterized in that The request information is received from the server or the terminal device.
7. The method according to any one of claims 1 to 5, characterized in that The network element node is selected from: a positioning management function node and a perception function node.
8. A communication method, characterized in that: include: Receiving key information, where the key information is used to indicate a first key, where the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; The data of the first service is processed using the first key, and the data is transmitted to the network element node via a wireless access network.
9. The method according to claim 8, characterized in that The received key information includes: Second information is received, where the second information includes input parameters, and the input parameters are used to generate the first key.
10. The method according to claim 9, characterized in that The input parameters include: an identifier of the network element node and / or a network interconnection protocol address of the network element node.
11. The method according to any one of claims 8 to 10, characterized in that Also includes: Send request information, where the request information is used to request a first service.
12. A communication method, characterized in that: include: Receiving key information, where the key information is used to indicate a first key, where the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; The data of the first service is processed using the first key and transmitted to the terminal device via a wireless access network.
13. The method according to claim 12, characterized in that The received key information includes: First information is received, the first information including the first key.
14. The method according to claim 12 or 13, characterized in that The network element node is selected from: a positioning management function node and a perception function node.
15. A communication device, characterized in that: include: A receiving module, used for receiving request information, where the request information is used for requesting a first service; A sending module is used to send key information, where the key information is used to indicate a first key, and the first key is used to encrypt data of the first service transmitted between a network element node and a terminal device.
16. A communication device, characterized in that: include: A receiving module, used to receive key information, where the key information is used to indicate a first key, where the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; A transmission module is used to process the data of the first service using the first key, and transmit the data to the network element node via a wireless access network.
17. A communication device, characterized in that: include: A receiving module, used to receive key information, where the key information is used to indicate a first key, where the first key is used to encrypt data of a first service transmitted between a network element node and a terminal device; A transmission module is used to process the data of the first service using the first key and transmit the data to the terminal device via a wireless access network.
18. A computer-readable storage medium, wherein the computer-readable storage medium is a non-volatile storage medium or a non-transient storage medium, and a computer program is stored thereon, wherein: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 14 are performed.
19. A communication device, comprising a memory and a processor, wherein the memory stores a computer program that can be run on the processor, characterized in that: When the processor runs the computer program, the steps of the method according to any one of claims 1 to 14 are performed.
Citation Information
Patent Citations
Communication method and device and computer readable storage medium
CN120201421A
Secure session method and device
CN110830991A
Core network system
CN114867004A
DIRECT SMF CONTROL PLANE WITH gNB
US20230018399A1
Security for distributed non-access stratum protocol in a mobile system
WO2023224915A1