5g LAN cross-group communication security protection method and system, device, and storage medium
By generating and using integrity keys in 5G LAN communication systems, data security issues in cross-group communication are solved, and data security transmission and delay optimization are achieved.
Patent Information
- Application Number
- PCT/CN2025/073622
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-26
- Filing Date
- 2025-01-21
- Publication Date
- 2025-07-03
AI Technical Summary
The existing 5G LAN communication system does not support cross-group communication, resulting in data security and privacy protection issues and affecting data transmission efficiency.
The initial anchor key is obtained through the 5G terminal, combined with PCC rules and contracted QoS Profile to generate integrity keys, perform PDU session authentication and UPF network element selection, and use integrity keys to protect user-plane data packets to realize secure data transmission across UPF network elements.
It enhances the data security of 5G LAN cross-group communication, realizes the secure data transmission between different 5G LAN groups, and reduces the delay in user-plane data transmission.
Smart Images

Figure CN2025073622_03072025_PF_FP_ABST
Abstract
Description
5G LAN cross-group communication security protection method, system, device and storage medium Technical Field
[0001] The present invention relates to the field of 5G communication technology, and in particular to a 5G LAN cross-group communication security protection method and system, device, and storage medium. Background Art
[0002] Current mobile network standards and applications do not support cross-group communication (e.g., 5G LAN groups), supporting only communication between terminals within a group. However, in some real-world industrial applications (e.g., power communication applications), inter-group communication is required. The mobile core network can control UEs in a 5G LAN to send data to UEs in other 5G LANs, and each 5G LAN supports its own QoS rules to improve data transmission efficiency in 5G network group communications. However, data security and the protection of sensitive information such as privacy in cross-group communications have not yet been considered, impacting the data security of 5G LAN inter-group communications.
[0003] Explanation of terms:
[0004] LAN: local area network.
[0005] UE: user equipment, user equipment.
[0006] QoS: Quality of Service.
[0007] UDM: Unified Data Management, unified user management.
[0008] PDU: protocol data unit.
[0009] SMF: session management function, session management function.
[0010] PCF: policy control function.
[0011] UPF: User Plane Function, user plane function.
[0012] AMF: Access and Mobility Management Function, access mobility management. Summary of the Invention
[0013] The purpose of the present invention is to solve one of the technical problems existing in the prior art to at least a certain extent.
[0014] To this end, an object of an embodiment of the present invention is to provide a 5G LAN cross-group communication security protection method, which enhances the data security of 5G LAN cross-group communication.
[0015] Another object of an embodiment of the present invention is to provide a 5G LAN cross-group communication security protection system.
[0016] In order to achieve the above technical objectives, the technical solutions adopted by the embodiments of the present invention include:
[0017] In one aspect, an embodiment of the present invention provides a 5G LAN cross-group communication security protection method, comprising the following steps:
[0018] Obtain the initial anchor key of the 5G LAN group through the 5G terminal, and initiate a PDU session establishment request to the SMF network element based on the initial anchor key;
[0019] Generate an integrity key through the 5G terminal and the SMF network element according to the initial anchor key and the PCC rule and subscribed QoS Profile of the 5G LAN group, and perform PDU session authentication through the SMF network element. When the PDU session authentication passes, establish a PDU session and select the UPF network element;
[0020] When it is determined that the 5G LAN group crosses UPF network elements, a first authentication key is generated according to the PCC rule and the subscribed QoS Profile, and cross-UPF authentication is performed according to the first authentication key;
[0021] When the cross-UPF authentication is passed, the user plane data packet is obtained through the 5G terminal, and the user plane data packet is integrity protected according to the integrity key to obtain the data packet to be transmitted, and then the data packet to be transmitted is transmitted through the PDU session.
[0022] Furthermore, in one embodiment of the present invention, the step of obtaining the initial anchor key of the 5G LAN group through the 5G terminal and initiating a PDU session establishment request to the SMF according to the initial anchor key specifically includes:
[0023] Generate the initial anchor key according to the user subscription information of the 5G terminal through the UDM network element, and send the initial anchor key to the 5G terminal;
[0024] The 5G terminal generates the PDU session establishment request based on the initial anchor key, and sends the PDU session establishment request to the SMF network element.
[0025] Furthermore, in one embodiment of the present invention, the step of generating an integrity key by the 5G terminal and the SMF network element according to the initial anchor key and the PCC rule and subscribed QoS Profile of the 5G LAN group specifically includes:
[0026] Generate the PCC rule according to the source address and destination address of the cross-group communication and the group information of the corresponding 5G LAN group through the PCF network element, and send the PCC rule to the 5G terminal and the SMF network element;
[0027] Obtain the subscribed QoS Profile of the 5G LAN group through the 5G terminal and the SMF network element, and generate the integrity key according to the initial anchor key, the PCC rule and the subscribed QoS Profile.
[0028] Furthermore, in one embodiment of the present invention, the PDU session authentication is performed by the SMF network element. When the PDU session authentication is passed, the step of establishing a PDU session and performing UPF network element selection specifically includes:
[0029] Parsing the PDU session establishment request through the SMF network element to obtain the initial anchor key;
[0030] Obtain the user subscription information through the SMF network element, and perform PDU session authentication based on the user subscription information and the initial anchor key;
[0031] When the PDU session authentication is passed, the PDU session is established and the UPF network element for the N4 session is selected, and then the N4 session is established synchronously.
[0032] Further, in one embodiment of the present invention, when it is determined that the 5G LAN group crosses the UPF network element, a first authentication key is generated according to the PCC rule and the subscribed QoS Profile, and cross-UPF authentication is performed according to the first authentication key. This step specifically includes:
[0033] When the 5G LAN groups for cross-group communication correspond to different UPF network elements, determining that the 5G LAN groups cross UPF network elements;
[0034] Dynamically generate the first authentication key by each UPF network element according to the PCC rule of the corresponding 5G LAN group and the subscribed QoS Profile;
[0035] Cross-UPF authentication is performed based on the first authentication key corresponding to each of the UPF network elements.
[0036] Furthermore, in one embodiment of the present invention, the step of performing integrity protection on the user plane data packet according to the integrity key to obtain the data packet to be transmitted specifically includes:
[0037] Determining whether the user plane data packet is sensitive to delay;
[0038] When it is determined that the user plane data is sensitive to delay, obtaining a PDCP SDU header of the user plane data packet, performing an information digest on the PDCP SDU header according to the integrity key to obtain first summary data, and adding the first summary data to the end of the user plane data packet to obtain the data packet to be transmitted;
[0039] When it is determined that the user plane data is not sensitive to delay, the user plane data packet is digested according to the integrity key to obtain second summary data, and the second summary data is added to the end of the user plane data packet to obtain the data packet to be transmitted.
[0040] Furthermore, in one embodiment of the present invention, the 5G LAN cross-group communication security protection method further includes the following steps:
[0041] When it is determined that the 5G LAN group crosses SMF network elements, a second authentication key is generated according to the PCC rules, and cross-SMF authentication is performed based on the second authentication key.
[0042] On the other hand, an embodiment of the present invention provides a 5G LAN cross-group communication security protection system, including:
[0043] A PDU session request module is used to obtain the initial anchor key of the 5G LAN group through the 5G terminal, and initiate a PDU session establishment request to the SMF network element based on the initial anchor key;
[0044] A PDU session authentication module is configured to generate an integrity key through the 5G terminal and the SMF network element according to the initial anchor key and the PCC rule and subscribed QoS Profile of the 5G LAN group, and perform PDU session authentication through the SMF network element. When the PDU session authentication passes, a PDU session is established and a UPF network element is selected;
[0045] A cross-UPF authentication module is configured to, when determining that the 5G LAN group crosses UPF network elements, generate a first authentication key according to the PCC rule and the subscribed QoS Profile, and perform cross-UPF authentication according to the first authentication key;
[0046] The integrity protection module is used to obtain the user plane data packet through the 5G terminal when the cross-UPF authentication is passed, and to perform integrity protection on the user plane data packet according to the integrity key to obtain the data packet to be transmitted, and then transmit the data packet to be transmitted through the PDU session.
[0047] On the other hand, an embodiment of the present invention provides an electronic device, which includes a memory, a processor, a program stored on the memory and runnable on the processor, and a data bus for realizing connection communication between the processor and the memory. When the program is executed by the processor, the 5G LAN cross-group communication security protection method as described above is realized.
[0048] On the other hand, an embodiment of the present invention also provides a storage medium, which is a computer-readable storage medium for computer-readable storage, and the storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the 5G LAN cross-group communication security protection method as described above.
[0049] The advantages and benefits of the present invention will be described in part in the following description and will become apparent from the following description or learned through practice of the present invention:
[0050] In an embodiment of the present invention, the initial anchoring key of the 5G LAN group is obtained through the 5G terminal, and a PDU session establishment request is initiated to the SMF network element according to the initial anchoring key. Then, the integrity key is generated according to the initial anchoring key and the PCC rule and the subscribed QoS Profile of the 5G LAN group through the 5G terminal and the SMF network element, and the PDU session authentication is performed through the SMF network element. When the PDU session authentication is passed, the PDU session is established and the UPF network element selection is performed. When it is determined that the 5G LAN group crosses the UPF network element, a first authentication key is generated according to the PCC rule and the subscribed QoS Profile, and cross-UPF authentication is performed according to the first authentication key. When the cross-UPF authentication is passed, the user plane data packet is obtained through the 5G terminal, and the user plane data packet is integrity protected according to the integrity key to obtain the data packet to be transmitted, and then the data packet to be transmitted is transmitted through the PDU session. The embodiment of the present invention generates an integrity key based on the initial anchor key, the PCC rules of the 5G LAN group, and the subscribed QoS profile, and uses the integrity key to protect the integrity of the user plane data of the 5G LAN cross-group communication, thereby realizing the secure transmission of data across UPF network elements between different 5G LAN groups and enhancing the data security of the 5G LAN cross-group communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following introduction is made to the drawings required for use in the embodiments of the present invention. It should be understood that the drawings introduced below are only for the convenience of clearly describing some embodiments of the technical solutions of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative work.
[0052] FIG1 is a flow chart of a 5G LAN cross-group communication security protection method provided by an embodiment of the present invention;
[0053] FIG2 is a flow chart of step S101 provided in an embodiment of the present invention;
[0054] FIG3 is a flow chart of step S102 provided in an embodiment of the present invention;
[0055] FIG4 is another flow chart of step S102 provided in an embodiment of the present invention;
[0056] FIG5 is a flow chart of step S103 provided by an embodiment of the present invention;
[0057] FIG6 is a flow chart of step S104 provided in an embodiment of the present invention;
[0058] FIG7 is another flowchart of a 5G LAN cross-group communication security protection method provided by an embodiment of the present invention;
[0059] FIG8 is a schematic diagram of network element interaction of a 5G LAN cross-group communication security protection method provided by an embodiment of the present invention;
[0060] FIG9 is a schematic diagram of the structure of a 5G LAN cross-group communication security protection system provided by an embodiment of the present invention;
[0061] FIG10 is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0062] The embodiments of the present invention are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements with the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application, and are not to be construed as limitations on the present application. It should be noted that, although the functional modules are divided in the system schematic and the logical order is shown in the flow chart, in some cases, the steps shown or described may be performed in a different order than the module division in the system schematic or the order in the flow chart. For the step numbers in the following embodiments, they are only provided for the convenience of explanation, and no limitation is placed on the order between the steps. The execution order of each step in the embodiment can be adaptively adjusted according to the understanding of those skilled in the art.
[0063] In the description of the present invention, the meaning of "a plurality" is two or more. If there is a description of "first" or "second", it is only used to distinguish technical features and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features or implicitly indicating the order of the indicated technical features. In addition, unless otherwise defined, all technical and scientific terms used in this document have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used in this document are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0064] The 5G LAN cross-group communication security protection method provided in the embodiments of the present application can be applied to a terminal, can also be applied to a server, and can also be software running on a terminal or a server. In some embodiments, the terminal can be a smartphone, tablet computer, laptop computer, desktop computer, set-top box, etc.; the server can be configured as an independent physical server, or as a server cluster or distributed system composed of multiple physical servers, or as a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements the 5G LAN cross-group communication security protection method, etc., but is not limited to the above forms.
[0065] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and the like. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments in which tasks are performed by remote processing devices connected via a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.
[0066] It should be noted that in each specific embodiment of the present application, when it comes to the need to perform relevant processing based on data related to the user's identity or characteristics, such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first, and the collection, use, and processing of such data will comply with the relevant laws, regulations, and standards of the relevant countries and regions. In addition, when the embodiment of the present application needs to obtain the user's sensitive personal information, the user's separate permission or consent will be obtained through a pop-up window or by jumping to a confirmation page. After clearly obtaining the user's separate permission or consent, the necessary user-related data for the normal operation of the embodiment of the present application will be obtained.
[0067] FIG1 is a flowchart of a 5G LAN inter-group communication security protection method provided by an embodiment of the present invention. Referring to FIG1 , an embodiment of the present invention provides a 5G LAN inter-group communication security protection method, which specifically includes the following steps:
[0068] S101. Obtain the initial anchor key of the 5G LAN group through the 5G terminal, and initiate a PDU session establishment request to the SMF network element based on the initial anchor key.
[0069] FIG2 is a flowchart of step S101 according to an embodiment of the present invention. Referring to FIG2 , as an optional implementation, the 5G terminal obtains the initial anchor key of the 5G LAN group and initiates a PDU session establishment request to the SMF based on the initial anchor key. The steps specifically include:
[0070] S1011. Generate an initial anchor key based on the user subscription information of the 5G terminal through the UDM network element, and send the initial anchor key to the 5G terminal;
[0071] S1012. The 5G terminal generates a PDU session establishment request based on the initial anchoring key and sends the PDU session establishment request to the SMF network element.
[0072] Specifically, after the UE (5G terminal) successfully accesses the network authentication, the UDM pre - plan generates the 5G LAN initial anchoring key k1 value according to the UE's user subscription information and sends it to the UE; the UE initiates a PDU session establishment request based on the initial anchoring key and saves the <PCC rule, subscribed QoS Profile, k1> information.
[0073] S102. The 5G terminal and the SMF network element generate an integrity key based on the initial anchoring key, the PCC rule of the 5G LAN group, and the subscribed QoS Profile, and the SMF network element performs PDU session authentication. When the PDU session authentication passes, a PDU session is established and the UPF network element is selected.
[0074] Specifically, the UE side and the network side dynamically generate the integrity key k1' according to the <PCC rule, subscribed QoS Profile, k1> information of the 5G LAN group; the SMF network element realizes the response of the PDU session establishment request and radio resource reservation, saves k1', and performs PDU session authentication authorization.
[0075] As shown in Figure 3, it is a flowchart of step S102 provided by an embodiment of the present invention. Referring to Figure 3, as an optional implementation manner, the step of the 5G terminal and the SMF network element generating an integrity key based on the initial anchoring key, the PCC rule of the 5G LAN group, and the subscribed QoS Profile specifically includes:
[0076] S1021. The PCF network element generates a PCC rule according to the source address and destination address of cross - group communication and the group information of the corresponding 5G LAN group, and sends the PCC rule to the 5G terminal and the SMF network element;
[0077] S1022. The 5G terminal and the SMF network element obtain the subscribed QoS Profile of the 5G LAN group, and generate an integrity key according to the initial anchoring key, the PCC rule, and the subscribed QoS Profile.
[0078] Specifically, the PCF network element generates the PCC rule based on the source address, destination address and corresponding group information for cross-group communication, that is, the correspondence between the sending / receiving address and the 5G LAN group information; the integrity key k1' is generated and saved through the 5G terminal and SMF network element based on the initial anchor key, PCC rule and contracted QoS Profile; the integrity key can be generated by a one-way irreversible function based on a preset method through the initial anchor key, PCC rule and contracted QoS Profile.
[0079] FIG4 is another flow chart of step S102 provided in an embodiment of the present invention. Referring to FIG4 , as an optional implementation, PDU session authentication is performed by the SMF network element. When the PDU session authentication is passed, a PDU session is established and the UPF network element selection step is performed, which specifically includes:
[0080] S1023. The PDU session establishment request is parsed and processed by the SMF network element to obtain an initial anchor key.
[0081] S1024. Obtain user contract information through the SMF network element, and perform PDU session authentication based on the user contract information and the initial anchor key;
[0082] S1025. When the PDU session authentication is passed, the PDU session is established and the UPF network element for the N4 session is selected, and then the N4 session is established synchronously.
[0083] Specifically, the SMF network element determines whether the UE has successfully accessed the network based on the parsed initial anchor key and the UE's user subscription information, thereby completing the PDU session authentication; in the process of establishing the PDU session, an N4 session, also known as a PFCP session, will be established simultaneously, using PFCP (Packet Forwarding Control Protocol), which is used to define a series of actions of the UPF on the PDU; while establishing the N4 session, the UPF network element is selected.
[0084] S103. When it is determined that the 5G LAN group crosses UPF network elements, a first authentication key is generated according to the PCC rules and the subscribed QoS Profile, and cross-UPF authentication is performed based on the first authentication key.
[0085] Specifically, after UPF selection, if it is across UPFs, the first authentication key K2 is dynamically generated based on the contracted QoS Profile information and PCC rules of different 5G LAN groups for cross-UPF authentication.
[0086] FIG5 is a flowchart of step S103 provided in an embodiment of the present invention. Referring to FIG5 , as an optional implementation, when it is determined that the 5G LAN group crosses UPF network elements, a first authentication key is generated according to the PCC rule and the subscribed QoS Profile, and cross-UPF authentication is performed according to the first authentication key. The step specifically includes:
[0087] S1031. When the 5G LAN groups for cross-group communication correspond to different UPF network elements, determine that the 5G LAN group crosses the UPF network element;
[0088] S1032. Dynamically generate a first authentication key through each UPF network element according to the PCC rules and subscribed QoS Profile of the corresponding 5G LAN group;
[0089] S1033. Perform cross-UPF authentication based on the first authentication key corresponding to each UPF network element.
[0090] Specifically, when the 5G LAN groups communicating across groups belong to different UPFs, the UPFs need to dynamically generate a first authentication key K2 value for authentication based on the contracted QoS Profile information and PCC rules of different 5G LAN groups.
[0091] S104. When the cross-UPF authentication is passed, the user plane data packet is obtained through the 5G terminal, and the user plane data packet is integrity protected according to the integrity key to obtain the data packet to be transmitted, and then the data packet to be transmitted is transmitted through the PDU session.
[0092] Specifically, for a user plane data packet, the user plane data packet is identified, and according to the service information mapping relationship, a data packet to be transmitted is adaptively generated based on the integrity key k1' for the user plane data packet, and is securely transmitted through a PDU session.
[0093] FIG6 is a flow chart of step S104 according to an embodiment of the present invention. Referring to FIG6 , as an optional implementation, the step of performing integrity protection on the user plane data packet according to the integrity key to obtain the data packet to be transmitted specifically includes:
[0094] S1041. Determine whether the user plane data packet is sensitive to delay;
[0095] S1042: When it is determined that the user plane data is sensitive to delay, obtain a PDCP SDU header of the user plane data packet, perform an information digest on the PDCP SDU header according to the integrity key to obtain first summary data, and append the first summary data to the end of the user plane data packet to obtain a data packet to be transmitted;
[0096] S1043. When it is determined that the user plane data is insensitive to latency, an information digest is obtained for the user plane data packet according to the integrity key to obtain second digest data, and the second digest data is added to the tail of the user plane data packet to obtain a data packet to be transmitted.
[0097] Specifically, for some service information with high latency requirements, based on an adaptive algorithm, the packet header and cascaded partial service information parameters in the PDCP SDU of the user plane data packet are used as the MESSAGE of the integrity protection function, and a MAC-I is generated through the integrity protection function, and the generated MAC-I is added to the tail of the user plane data packet; for service information insensitive to latency, integrity protection is performed based on cascading all information.
[0098] As shown in FIG. 7, it is another flowchart of the 5G LAN cross-group communication security protection method provided by the embodiment of the present invention. Referring to FIG. 7, as a further optional implementation manner, the 5G LAN cross-group communication security protection method further includes the following steps:
[0099] S105. When it is determined that the 5G LAN group crosses the SMF network element, a second authentication key is generated according to the PCC rule, and cross-SMF authentication is performed according to the second authentication key.
[0100] Specifically, when performing SMF network element selection and PDU session authentication, if the 5G LAN group crosses the SMF network element, a second authentication key K3 value is dynamically generated according to the subscribed PCC rule of the 5G LAN group, and cross-SMF authentication is performed.
[0101] As shown in FIG. 8, it is a schematic diagram of network element interaction of the 5G LAN cross-group communication security protection method provided by the embodiment of the present invention. Referring to FIG. 8, a specific implementation process of the embodiment of the present invention is as follows: The 5G terminal accesses the network, requests user subscribed information, and based on the UE DNN, the UDM generates an anchoring key k1 for the 5G LAN group; the 5G terminal saves <PCC rule, subscribed QoS Profile, k1>, where the PCC rule is generated by the PCF according to the source / destination address of the cross-group communication and the corresponding group information, and the PCF sends the corresponding PCC rule to the SMF; if the 5G LAN crosses the SMF, the subscribed PCC rule of the 5G LAN group dynamically generates a K3 value and performs authentication; a PDU session context establishment request and response (k1'), the SMF saves k1', PDU session authentication authorization, after the UPF is selected, if it crosses the UPF, then a K2 authentication is dynamically generated according to the subscribed QoS Profile information and PCC rule of different 5G LAN groups, and the UPF saves k1'; for the user plane data packet, the user plane data packet is identified, and according to the service information mapping relationship, a user plane data packet MAC-I is adaptively generated for the PDCP SDU.
[0102] The above describes the method steps of the embodiment of the present invention. It can be understood that the embodiment of the present invention generates an integrity key based on the initial anchor key and the PCC rules and contracted QoS Profile of the 5G LAN group, and uses the integrity key to perform integrity protection on the user-plane data of the 5G LAN cross-group communication, thereby realizing the secure transmission of data across UPF network elements between different 5G LAN groups and enhancing the data security of the 5G LAN cross-group communication. In addition, the embodiment of the present invention generates a user-plane security key based on the 5G LAN cross-group communication, and uses the security key to implement adaptive integrity protection of the user-plane transmission data of the 5G LAN cross-group communication in different business environments, which can reduce the initial configuration, reduce the computing load, and greatly reduce the delay of the user-plane data transmission, and has a certain degree of practicality.
[0103] FIG9 is a schematic diagram of a 5G LAN inter-group communication security protection system according to an embodiment of the present invention. Referring to FIG9 , an embodiment of the present invention provides a 5G LAN inter-group communication security protection system, including:
[0104] The PDU session request module is used to obtain the initial anchor key of the 5G LAN group through the 5G terminal, and initiate a PDU session establishment request to the SMF network element based on the initial anchor key;
[0105] The PDU session authentication module is used to generate an integrity key through the 5G terminal and SMF network element according to the initial anchor key, the PCC rule of the 5G LAN group, and the subscribed QoS Profile, and perform PDU session authentication through the SMF network element. When the PDU session authentication is successful, the PDU session is established and the UPF network element is selected;
[0106] The cross-UPF authentication module is used to generate a first authentication key according to the PCC rule and the subscribed QoS Profile when determining that the 5G LAN group crosses the UPF network element, and perform cross-UPF authentication based on the first authentication key;
[0107] The integrity protection module is used to obtain user-plane data packets through the 5G terminal when cross-UPF authentication is passed, and to perform integrity protection on the user-plane data packets according to the integrity key to obtain the data packets to be transmitted, and then transmit the data packets to be transmitted through the PDU session.
[0108] The contents of the above method embodiments are all applicable to the present system embodiments. The functions specifically implemented by the present system embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0109] An embodiment of the present invention further provides an electronic device comprising: a memory, a processor, a program stored in the memory and executable on the processor, and a data bus for enabling communication between the processor and the memory. When the program is executed by the processor, the aforementioned 5G LAN cross-group communication security protection method is implemented. The electronic device can be any smart terminal, including a tablet computer and an in-vehicle computer.
[0110] FIG10 is a schematic diagram of the hardware structure of an electronic device provided by an embodiment of the present invention. Referring to FIG10 , an embodiment of the present invention provides an electronic device, including:
[0111] The processor 1001 may be implemented as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is configured to execute relevant programs to implement the technical solutions provided by the embodiments of the present invention.
[0112] The memory 1002 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1002 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 1002, and the processor 1001 calls and executes the 5GLAN cross-group communication security protection method of the embodiment of the present invention;
[0113] Input / output interface 1003, used to implement information input and output;
[0114] Communication interface 1004, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);
[0115] Bus 1005 , which transmits information between various components of the device (e.g., processor 1001 , memory 1002 , input / output interface 1003 , and communication interface 1004 );
[0116] The processor 1001 , the memory 1002 , the input / output interface 1003 and the communication interface 1004 are connected to each other in communication within the device via a bus 1005 .
[0117] An embodiment of the present invention also provides a storage medium, which is a computer-readable storage medium for computer-readable storage. The storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the above-mentioned 5G LAN cross-group communication security protection method.
[0118] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0119] Embodiments of the present invention further disclose a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer instructions from the computer-readable storage medium and execute the computer instructions, causing the computer device to perform the method shown in FIG1 .
[0120] In some optional embodiments, the function / operation mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the function / operation involved, the two boxes shown in succession can actually be executed substantially simultaneously or the above-mentioned boxes can sometimes be executed in reverse order. In addition, the embodiment presented and described in the flow chart of the present invention is provided in an exemplary manner for the purpose of providing a more comprehensive understanding of the technology. The disclosed method is not limited to the operation and logic flow presented herein. Optional embodiments are contemplated in which the order of the various operations is changed and the sub-operations described as a part of a larger operation are performed independently.
[0121] In addition, although the present invention is described in the context of functional modules, it should be understood that, unless otherwise stated, one or more of the above-mentioned functions and / or features can be integrated into a single physical device and / or software module, or one or more functions and / or features can be implemented in separate physical devices or software modules. It is also understood that a detailed discussion of the actual implementation of each module is not necessary for understanding the present invention. More specifically, given the properties, functions, and internal relationships of the various functional modules in the devices disclosed herein, the actual implementation of the module will be understood within the routine skills of an engineer. Therefore, a person skilled in the art can implement the present invention set forth in the claims using ordinary skills without undue experimentation. It is also understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present invention, which is determined by the full scope of the appended claims and their equivalents.
[0122] If the above functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the above methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program code.
[0123] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0124] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable media on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.
[0125] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0126] In the above description of this specification, reference to the terms "one embodiment / example," "another embodiment / example," or "certain embodiments / examples" means that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.
[0127] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to the embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the claims and their equivalents.
[0128] The above is a specific description of the preferred implementation of the present invention, but the present invention is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or substitutions without violating the spirit of the present invention. These equivalent modifications or substitutions are all included in the scope defined by the claims of this application.
Claims
1. A 5G LAN cross-group communication security protection method, characterized in that, It includes the following steps: Obtain the initial anchoring key of the 5G LAN group through a 5G terminal, and initiate a PDU session establishment request to the SMF network element according to the initial anchoring key; Generate an integrity key by the 5G terminal and the SMF network element according to the initial anchoring key, the PCC rules of the 5G LAN group, and the subscribed QoS Profile, and perform PDU session authentication through the SMF network element. When the PDU session authentication is passed, establish a PDU session and perform UPF network element selection; When it is determined that the 5G LAN group spans UPF network elements, generate a first authentication key according to the PCC rules and the subscribed QoS Profile, and perform cross-UPF authentication according to the first authentication key; When the cross-UPF authentication is passed, obtain the user plane data packet through the 5G terminal, perform integrity protection on the user plane data packet according to the integrity key to obtain the data packet to be transmitted, and then transmit the data packet to be transmitted through the PDU session.
2. The 5G LAN cross-group communication security protection method according to claim 1, characterized in that The step of obtaining the initial anchoring key of the 5G LAN group through the 5G terminal and initiating a PDU session establishment request to the SMF according to the initial anchoring key specifically includes: Generate the initial anchoring key by the UDM network element according to the user subscription information of the 5G terminal, and send the initial anchoring key to the 5G terminal; Generate the PDU session establishment request by the 5G terminal according to the initial anchoring key, and send the PDU session establishment request to the SMF network element.
3. A 5G LAN cross-group communication security protection method according to claim 1, characterized in that, The step of generating the integrity key by the 5G terminal and the SMF network element according to the initial anchoring key, the PCC rules of the 5G LAN group, and the subscribed QoS Profile specifically includes: Generate the PCC rules by the PCF network element according to the source address and destination address of cross-group communication and the group information of the corresponding 5G LAN group, and send the PCC rules to the 5G terminal and the SMF network element; The 5G terminal and the SMF network element obtain the subscribed QoS Profile of the 5G LAN group, and generate the integrity key according to the initial anchoring key, the PCC rules, and the subscribed QoS Profile.
4. A 5G LAN cross-group communication security protection method according to claim 2, characterized in that, The step of performing PDU session authentication through the SMF network element. When the PDU session authentication is passed, establish a PDU session and perform UPF network element selection specifically includes: The SMF network element parses and processes the PDU session establishment request to obtain the initial anchoring key; The SMF network element obtains the user subscription information, and performs PDU session authentication according to the user subscription information and the initial anchoring key; When the PDU session authentication is passed, establish a PDU session and select a UPF network element for the N4 session, and then synchronously establish an N4 session.
5. A 5G LAN cross-group communication security protection method according to claim 1, characterized in that The step of, when it is determined that the 5G LAN group crosses the UPF network element, generating a first authentication key according to the PCC rule and the subscribed QoS Profile, and performing cross-UPF authentication according to the first authentication key, specifically includes: When the 5G LAN groups for cross-group communication correspond to different UPF network elements, determine that the 5G LAN group crosses the UPF network element; Dynamically generate the first authentication key by each of the UPF network elements according to the PCC rule and the subscribed QoS Profile of the corresponding 5G LAN group; Perform cross-UPF authentication according to the first authentication key corresponding to each of the UPF network elements.
6. A 5G LAN cross-group communication security protection method according to claim 1, characterized in that, The step of, when performing integrity protection on the user plane data packet according to the integrity key to obtain the packet to be transmitted, specifically includes: Determine whether the user plane data packet is sensitive to latency; When it is determined that the user plane data is sensitive to latency, obtain the PDCP SDU header of the user plane data packet, perform a message digest on the PDCP SDU header according to the integrity key to obtain first digest data, and add the first digest data to the tail of the user plane data packet to obtain the packet to be transmitted; When it is determined that the user plane data is not sensitive to latency, perform a message digest on the user plane data packet according to the integrity key to obtain second digest data, and add the second digest data to the tail of the user plane data packet to obtain the packet to be transmitted.
7. A 5G LAN cross-group communication security protection method according to any one of claims 1 to 6, characterized in that The 5G LAN cross-group communication security protection method further includes the following steps: When it is determined that the 5G LAN group crosses the SMF network element, generate a second authentication key according to the PCC rule, and perform cross-SMF authentication according to the second authentication key.
8. A 5G LAN cross-group communication security protection system, characterized in that, Including: A PDU session request module, configured to obtain an initial anchoring key of a 5G LAN group through a 5G terminal, and initiate a PDU session establishment request to the SMF network element according to the initial anchoring key; A PDU session authentication module, configured to generate an integrity key through the 5G terminal and the SMF network element according to the initial anchoring key, the PCC rule of the 5G LAN group, and the subscribed QoS Profile, and perform PDU session authentication through the SMF network element. When the PDU session authentication is passed, establish a PDU session and perform UPF network element selection; A cross-UPF authentication module, configured to, when it is determined that the 5G LAN group crosses the UPF network element, generate a first authentication key according to the PCC rule and the subscribed QoS Profile, and perform cross-UPF authentication according to the first authentication key; An integrity protection module, configured to, when the cross-UPF authentication is passed, obtain a user plane data packet through the 5G terminal, perform integrity protection on the user plane data packet according to the integrity key to obtain a packet to be transmitted, and then transmit the packet to be transmitted through the PDU session.
9. An electronic device, characterized in that, The electronic device includes a memory, a processor, a program stored on the memory and executable on the processor, and a data bus for implementing connection communication between the processor and the memory. When the program is executed by the processor, it implements the steps of the 5G LAN cross-group communication security protection method according to any one of claims 1 to 7.
10. A storage medium, the storage medium being a computer-readable storage medium for computer-readable storage, characterized in that, The storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the steps of the 5G LAN cross-group communication security protection method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Strategy-based data safety transmission implementation method
CN112738799A
Cross-user-plane forwarding method and system and computer readable storage medium
CN114285787A
Method for cross-group communication, SMF, system and storage medium
CN116828402A
5G LAN cross-group communication security protection method and system, equipment and storage medium
CN117692901A
Securing the User Plane Path for a Group Communication Session based on a Security Policy Common to All Devices in the Group
US20220124488A1