Service processing method and apparatus, related device, and storage medium
By using key management between application function (AF) and user plane function (UPF) in 5G networks, the problem that encrypted XR services cannot perform network transmission enhancement processing is solved, and QoS enhancement processing for encrypted XR services is realized, and the end-to-end transmission quality is improved.
Patent Information
- Application Number
- PCT/CN2024/143646
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-05
- Filing Date
- 2024-12-30
- Publication Date
- 2025-07-10
AI Technical Summary
The existing 5G network cannot enhance the network transmission process of encrypted extended reality (XR) services, which limits the scope of application of the QoS enhancement mechanism.
The application function key (KAF) is obtained from the application layer authentication and key management (AKMA) anchor function (AAnF) through the application function (AF), the auxiliary information of the service data packet is encrypted, and the encryption auxiliary information is inserted in the message header expansion part of the application transmission protocol, and sent to the user plane function (UPF). UPF uses KAF to decrypt and perform PDU set classification identification processing.
It realizes QoS enhanced processing of encrypted XR services, improves end-to-end transmission quality, and meets the high security needs of XR services.
Smart Images

Figure CN2024143646_10072025_PF_FP_ABST
Abstract
Description
Business processing method, device, related equipment and storage medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to Chinese patent application No. 202410022890.X filed in China on January 5, 2024, the entire contents of which are incorporated herein by reference. Technical Field
[0003] The present disclosure relates to the field of communication technology, and in particular to a service processing method, apparatus, related equipment, and storage medium. Background Art
[0004] In actual application scenarios, media streaming services such as Extended Reality (XR) services are diverse, and XR services involving sensitive information are encrypted and protected. This greatly limits the scope of application of technologies that enhance Quality of Service (QoS) based on Protocol Data Unit (PDU) sets. In related technologies, for encrypted XR services, the fifth-generation mobile communication technology (5G) network cannot analyze the service data payload (Data Payload) to identify PDU-related information of different data streams, making it impossible to enhance the network transmission process of information. Summary of the Invention
[0005] The embodiments of the present disclosure provide a service processing method, apparatus, related equipment, and storage medium to address the problem in related technologies that encrypted XR services cannot perform enhanced processing on the network transmission process of information.
[0006] To solve the above technical problems, the present disclosure is implemented as follows:
[0007] In a first aspect, an embodiment of the present disclosure provides a service processing method, including:
[0008] The application function AF obtains the application function key K from the application layer authentication and key management AKMA anchor function AAnF AF ;
[0009] The AF determines the auxiliary information of the service data packet to be transmitted, and uses the K AF encrypting the auxiliary information to obtain encrypted auxiliary information;
[0010] The AF inserts the encryption auxiliary information into the message header extension part of the application transmission protocol of the service data packet to obtain the encrypted service data packet;
[0011] The AF sends the encrypted service data packet to the user plane function UPF.
[0012] Optionally, the AF obtains the application function key K from the application layer authentication and key management AKMA anchor function AAnF AF ,include:
[0013] The AF sends a first key request message to the AAnF, wherein the first key request message carries the AKMA key identifier A-KID and the AF identifier AF-ID;
[0014] The AF receives the first key request response message sent by the AAnF, wherein the first key request response message carries the application function key K AF .
[0015] Optionally, the auxiliary information includes at least one of the following:
[0016] Importance level;
[0017] Serial number;
[0018] Data description information;
[0019] Related data description information;
[0020] Latency budget.
[0021] Optionally, before the AF sends the first key request message to the AAnF, the method further includes:
[0022] The AF receives an application layer session establishment request message sent by the UE, where the application layer session establishment request message carries the A-KID.
[0023] In a second aspect, an embodiment of the present disclosure provides a service processing method, including:
[0024] The UPF receives the encrypted service data packet sent by the AF;
[0025] The UPF obtains K from AAnF AF ;
[0026] The UPF utilizes the K AF decrypting the encrypted service data packet to obtain auxiliary information of the service data packet, wherein the auxiliary information is inserted into a message header extension portion of an application transmission protocol of the service data packet;
[0027] The UPF performs protocol data unit (PDU) set classification and identification processing on the service data packet according to the auxiliary information.
[0028] Optionally, the UPF obtains K from AAnF AF ,include:
[0029] The UPF receives the K sent by AAnF AF ;
[0030] Alternatively, the UPF sends a second key request message to the AAnF;
[0031] The UPF receives the second key request response message sent by the AAnF, wherein the second key request response message carries the K AF .
[0032] Optionally, the auxiliary information includes at least one of the following:
[0033] Importance level;
[0034] Serial number;
[0035] Data description information;
[0036] Related data description information;
[0037] Latency budget.
[0038] In a third aspect, an embodiment of the present disclosure provides a service processing method, including:
[0039] AAnF is based on the AKMA anchor key K AKMA Determine K AF ;
[0040] The AAnF sends the K AF , where the K AF The AF is used to encrypt the auxiliary information of the service data packet to be transmitted.
[0041] Optionally, the AAnF sends the K AF Previously, the method also included:
[0042] The AAnF receives a first key request message sent by the AF, wherein the first key request message carries the A-KID and the AF-ID;
[0043] The AAnF sends the K AF ,include:
[0044] The AAnF sends a first key request response message to the AF, wherein the first key request response message carries the K AF .
[0045] Optionally, the method further includes:
[0046] The AAnF sends the K AF ;
[0047] Alternatively, the AAnF receives a second key request message sent by the UPF;
[0048] The AAnF sends a second key request response message to the UPF, wherein the second key request response message carries the K AF .
[0049] Optionally, the auxiliary information includes at least one of the following:
[0050] Importance level;
[0051] Serial number;
[0052] Data description information;
[0053] Related data description information;
[0054] Latency budget.
[0055] In a fourth aspect, an embodiment of the present disclosure provides an AF, including:
[0056] The first acquisition module is used to obtain the application function key K from the application layer authentication and key management AKMA anchor function AAnF AF ;
[0057] The encryption module is used to determine the auxiliary information of the service data packet to be transmitted, and use the K AF encrypting the auxiliary information to obtain encrypted auxiliary information;
[0058] An inserting module, configured to insert the encrypted auxiliary information into a message header extension portion of an application transmission protocol of the service data packet to obtain the encrypted service data packet;
[0059] The first sending module is used to send the encrypted service data packet to the user plane function UPF.
[0060] Optionally, the first acquisition module includes:
[0061] A first sending unit is configured to send a first key request message to the AAnF, wherein the first key request message carries an AKMA key identifier A-KID and an AF identifier AF-ID;
[0062] The first receiving unit is configured to receive a first key request response message sent by the AAnF, wherein the first key request response message carries the application function key K AF .
[0063] Optionally, the auxiliary information includes at least one of the following:
[0064] Importance level;
[0065] Serial number;
[0066] Data description information;
[0067] Related data description information;
[0068] Latency budget.
[0069] Optionally, the first acquisition module further includes:
[0070] The second receiving unit is configured to receive an application layer session establishment request message sent by the UE, where the application layer session establishment request message carries the A-KID.
[0071] In a fifth aspect, an embodiment of the present disclosure provides a UPF, including:
[0072] A first receiving module, configured to receive an encrypted service data packet sent by the AF;
[0073] The second acquisition module is used to obtain K from AAnF AF ;
[0074] Decryption module, used to use the K AF decrypting the encrypted service data packet to obtain auxiliary information of the service data packet, wherein the auxiliary information is inserted into a message header extension portion of an application transmission protocol of the service data packet;
[0075] The identification module is used to perform protocol data unit (PDU) set classification identification processing on the service data packet according to the auxiliary information.
[0076] Optionally, the second acquisition module includes:
[0077] The third receiving unit is used to receive the K sent by AAnF AF ;
[0078] Alternatively, a second sending unit is configured to send a second key request message to the AAnF;
[0079] The fourth receiving unit is configured to receive a second key request response message sent by the AAnF, wherein the second key request response message carries the K AF .
[0080] Optionally, the auxiliary information includes at least one of the following:
[0081] Importance level;
[0082] Serial number;
[0083] Data description information;
[0084] Related data description information;
[0085] Latency budget.
[0086] In a sixth aspect, an embodiment of the present disclosure provides an AAnF, including:
[0087] Determine module for determining the intermediate key K according to AKMA AKMA Determine K AF ;
[0088] The second sending module is used to send the K AF , where the K AF The AF is used to encrypt the auxiliary information of the service data packet to be transmitted.
[0089] Optionally, the AAnF further includes:
[0090] A second receiving module is configured to receive a first key request message sent by the AF, wherein the first key request message carries the A-KID and the AF-ID;
[0091] The second sending module includes:
[0092] The third sending unit is configured to send a first key request response message to the AF, wherein the first key request response message carries the K AF .
[0093] Optionally, the AAnF further includes:
[0094] The third sending module is used to send the K AF ;
[0095] Alternatively, a third receiving module is configured to receive a second key request message sent by the UPF;
[0096] The fourth sending module is configured to send a second key request response message to the UPF, wherein the second key request response message carries the K AF .
[0097] Optionally, the auxiliary information includes at least one of the following:
[0098] Importance level;
[0099] Serial number;
[0100] Data description information;
[0101] Related data description information;
[0102] Latency budget.
[0103] In a seventh aspect, an embodiment of the present disclosure provides an AF, comprising a transceiver and a processor,
[0104] The transceiver is used to obtain the application function key K from the application layer authentication and key management AKMA anchor function AAnF AF ;
[0105] The processor is used to: determine the auxiliary information of the service data packet to be transmitted, and use the K AF encrypting the auxiliary information to obtain encrypted auxiliary information;
[0106] Inserting the encryption auxiliary information into a message header extension portion of an application transmission protocol of the service data packet to obtain the encrypted service data packet;
[0107] The transceiver is also used to send the encrypted service data packet to the user plane function UPF.
[0108] Optionally, the transceiver is specifically configured to:
[0109] Sending a first key request message to the AAnF, wherein the first key request message carries the AKMA key identifier A-KID and the AF identifier AF-ID;
[0110] Receive the first key request response message sent by the AAnF, wherein the first key request response message carries the application function key K AF .
[0111] Optionally, the auxiliary information includes at least one of the following:
[0112] Importance level;
[0113] Serial number;
[0114] Data description information;
[0115] Related data description information;
[0116] Latency budget.
[0117] Optionally, the transceiver is further configured to:
[0118] An application layer session establishment request message sent by the UE is received, where the application layer session establishment request message carries the A-KID.
[0119] In an eighth aspect, an embodiment of the present disclosure provides a UPF, including a transceiver and a processor, wherein the transceiver is configured to:
[0120] Receive encrypted service data packets sent by AF;
[0121] Get K from AAnF AF ;
[0122] The processor is used to: utilize the K AF decrypting the encrypted service data packet to obtain auxiliary information of the service data packet, wherein the auxiliary information is inserted into a message header extension portion of an application transmission protocol of the service data packet;
[0123] The service data packet is subjected to protocol data unit (PDU) set classification and identification processing according to the auxiliary information.
[0124] Optionally, the transceiver is specifically configured to:
[0125] Receive the K sent by AAnF AF ;
[0126] Alternatively, a second key request message is sent to the AAnF;
[0127] Receive the second key request response message sent by the AAnF, wherein the second key request response message carries the K AF .
[0128] Optionally, the auxiliary information includes at least one of the following:
[0129] Importance level;
[0130] Serial number;
[0131] Data description information;
[0132] Related data description information;
[0133] Latency budget.
[0134] In a ninth aspect, an embodiment of the present disclosure provides an AAnF, comprising a transceiver and a processor,
[0135] The processor is configured to generate an intermediate key K according to the AKMA AKMA Determine K AF ;
[0136] The transceiver is used to send the K AF , where the K AF The AF is used to encrypt the auxiliary information of the service data packet to be transmitted.
[0137] Optionally, the transceiver is further configured to:
[0138] Receive a first key request message sent by the AF, wherein the first key request message carries the A-KID and the AF-ID;
[0139] The transceiver is specifically used for:
[0140] Send a first key request response message to the AF, wherein the first key request response message carries the K AF .
[0141] Optionally, the transceiver is further configured to:
[0142] Send the K to UPF AF ;
[0143] Alternatively, receiving a second key request message sent by the UPF;
[0144] Send a second key request response message to the UPF, wherein the second key request response message carries the K AF .
[0145] Optionally, the auxiliary information includes at least one of the following:
[0146] Importance level;
[0147] Serial number;
[0148] Data description information;
[0149] Related data description information;
[0150] Latency budget.
[0151] In the tenth aspect, an embodiment of the present disclosure provides an electronic device, comprising: a processor, a memory, and a program stored on the memory and runnable on the processor, wherein when the program is executed by the processor, the steps of the business processing method as described in the first aspect are implemented; or, when the program is executed by the processor, the steps of the business processing method as described in the second aspect are implemented; or, when the program is executed by the processor, the steps of the business processing method as described in the third aspect are implemented.
[0152] In the eleventh aspect, an embodiment of the present disclosure provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the computer program implements the steps of the business processing method described in the first aspect above; or, when the computer program is executed by a processor, the computer program implements the steps of the business processing method described in the second aspect above; or, when the computer program is executed by a processor, the computer program implements the steps of the business processing method described in the third aspect above.
[0153] In the twelfth aspect, an embodiment of the present disclosure provides a computer program product, comprising computer instructions, which, when executed by a processor, implement the steps of the business processing method as described in the first aspect above; or, implement the steps of the business processing method as described in the second aspect above; or, implement the steps of the business processing method as described in the third aspect above.
[0154] In the embodiment of the present disclosure, the above service processing method can obtain the auxiliary information of the service data packet to be transmitted through AF, and use the K AF The auxiliary information is encrypted, and then the encrypted auxiliary information is loaded using the message header extension part of the application transmission protocol and sent to the UPF, so that the transmission of service data can meet the high security requirements of the XR service, that is, the original service payload is encrypted and protected, and the auxiliary information loaded into the protocol extension header is also encrypted and protected, thereby ensuring the strong security requirements of the service. In addition, the 5G system can also perform QoS enhancement processing based on the PDU set through the auxiliary information of the protocol extension header, thereby realizing QoS enhancement processing of the encrypted XR service and improving the end-to-end transmission quality of the XR service. BRIEF DESCRIPTION OF THE DRAWINGS
[0155] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the description of the embodiments of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0156] FIG1 is a flowchart of a service processing method according to an embodiment of the present disclosure;
[0157] FIG2 is a second flowchart of a business processing method provided by an embodiment of the present disclosure;
[0158] FIG3 is a third flowchart of a business processing method provided by an embodiment of the present disclosure;
[0159] FIG4 is one of the interaction diagrams of a business processing method provided by an embodiment of the present disclosure;
[0160] FIG5 is a second interactive diagram of a business processing method provided by an embodiment of the present disclosure;
[0161] FIG6 is a schematic diagram of a structure of an AF provided by an embodiment of the present disclosure;
[0162] FIG7 is a structural diagram of a UPF according to an embodiment of the present disclosure;
[0163] FIG8 is a schematic diagram of the structure of an AAnF provided by an embodiment of the present disclosure;
[0164] FIG9 is a second structural diagram of an AF provided by an embodiment of the present disclosure;
[0165] FIG10 is a second structural diagram of a UPF provided in an embodiment of the present disclosure;
[0166] FIG11 is a second structural diagram of an AAnF provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0167] The following will clearly and completely describe the technical solutions in the embodiments of the present disclosure in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present disclosure without making any creative efforts shall fall within the scope of protection of the present disclosure.
[0168] For ease of understanding, some contents involved in the embodiments of the present disclosure are described below:
[0169] To achieve an immersive user experience, XR services place extremely high demands on end-to-end latency and network transmission quality. The 3rd Generation Partnership Project (3GPP) Service and System Aspects SA2 Working Group has studied the network transmission QoS for XR services transmitted over 5G networks. It has proposed methods to improve network transmission QoS through network and service integration. SA2 proposes the concept of PDU sets and corresponding QoS enhancement mechanisms. Specifically, 5G networks analyze and identify the associations and importance of different media data packets based on the QoS requirements of different media streams (visual, auditory, tactile, etc.) in XR services, and make real-time adjustments to XR service data transmission processing based on the real-time network conditions. For example, in case of network congestion, the importance of P-frames or B-frames in video streams with less stringent timing requirements is reduced and can be discarded as needed.
[0170] SA2 operates on the assumption that XR application layer information is unencrypted. Therefore, the 5G network's UPF or RAN can process XR service data based on PDU sets to improve QoS. However, in the real world, XR services are diverse, and those involving sensitive information are encrypted. Furthermore, with increasing awareness and legislation regarding personal data privacy, an increasing number of XR services are encrypted. This significantly limits the applicability of SA2's existing PDU set-based QoS enhancement mechanisms.
[0171] In the embodiments of the present disclosure, a service processing method, apparatus, related equipment, and storage medium are proposed to solve the problem in related technologies that the network transmission process of encrypted XR services cannot be enhanced.
[0172] Referring to FIG. 1 , FIG. 1 is a flowchart of a service processing method provided by an embodiment of the present disclosure. As shown in FIG. 1 , the method includes the following steps:
[0173] Step 101: The application function (AF) obtains the application function key K from the Akma anchor function (AAnF) of the application layer authentication and key management for applications (AKMA). AF .
[0174] Specifically, the above K AF It is the AKMA application layer key.
[0175] Step 102: The AF determines the auxiliary information of the service data packet to be transmitted, and uses the K AF The auxiliary information is encrypted to obtain encrypted auxiliary information.
[0176] Specifically, the service data packet to be transmitted may be an encrypted XR service data packet in the media stream. The auxiliary information may be key information of the service data packet, for example, the importance and relevance of the service data packet.
[0177] Step 103: The AF inserts the encryption auxiliary information into the message header extension portion of the application transmission protocol of the service data packet to obtain the encrypted service data packet.
[0178] Specifically, the above-mentioned application transmission protocol can be a protocol that supports traffic transmission at the XR application layer. It should be noted that the above-mentioned application transmission protocol needs to support inserting information in the extended part of the message header, such as the Real-time Transport Protocol (RTP), the User Datagram Protocol (UDP), and the Quick UDP Internet Connections (QUIC).
[0179] Step 104: The AF sends the encrypted service data packet to a user plane function (UPF).
[0180] In the embodiment of the present disclosure, the above service processing method can obtain the auxiliary information of the service data packet to be transmitted through AF, and use the K AF The auxiliary information is encrypted, and then the encrypted auxiliary information is loaded using the message header extension part of the application transmission protocol and sent to the UPF, so that the transmission of service data can meet the high security requirements of the XR service, that is, the original service payload is encrypted and protected, and the auxiliary information loaded into the protocol extension header is also encrypted and protected, thereby ensuring the strong security requirements of the service. In addition, the 5G system can also perform QoS enhancement processing based on the PDU set through the auxiliary information of the protocol extension header, thereby realizing QoS enhancement processing of the encrypted XR service and improving the end-to-end transmission quality of the XR service.
[0181] Optionally, the AF obtains the application function key K from the application layer authentication and key management AKMA anchor function AAnF AF ,include:
[0182] The AF sends a first key request message to the AAnF, wherein the first key request message carries an AKMA key identifier (AKMA Key ID, A-KID) and an AF identifier AF-ID;
[0183] The AF receives the first key request response message sent by the AAnF, wherein the first key request response message carries the application function key K AF .
[0184] Specifically, the AF-ID can be the UE's primary authentication. AUSF The derivation is consistent with the K AF Corresponding.
[0185] It should be noted that the first key request response message may also include K AFThe life cycle is used to indicate K AF to further improve the security of business processing.
[0186] In this embodiment, the above service processing method can obtain the K by sending a first key request message to the AAnF. AF The auxiliary information is encrypted.
[0187] Optionally, the auxiliary information includes at least one of the following:
[0188] Importance level;
[0189] Serial number;
[0190] Data description information;
[0191] Related data description information;
[0192] Latency budget.
[0193] Specifically, the importance level may be obtained by evaluating the importance level of a service data packet according to a preset standard, the sequence number may be an identification code of the service data packet, such as the sequence number of the data packet in a PDU set, the data description information may be description information of the service data packet, such as a predicted frame (P Frame), the dependent data description information may be an intra coded frame (I frame), and the delay budget may be the maximum delay allowed during end-to-end data transmission.
[0194] It should be noted that the auxiliary information may also include other information in addition to the information listed above, which is not limited in this disclosure.
[0195] Optionally, before the AF sends the first key request message to the AAnF, the method further includes:
[0196] The AF receives an application layer session establishment request message sent by the UE, where the application layer session establishment request message carries the A-KID.
[0197] Specifically, after the UE completes the primary authentication, it sends an application layer session establishment request message to the AF and carries the A-KID. In this implementation, the above service processing method can receive the application layer session establishment request message sent by the UE. Since the application layer session establishment request message carries the A-KID, it can obtain the KID from the AAnF. AF Carry the A-KID when you are ready to quickly obtain the K AF , thereby improving processing efficiency.
[0198] Referring to FIG. 2 , FIG. 2 is a second flowchart of a service processing method provided by an embodiment of the present disclosure. As shown in FIG. 2 , the method includes the following steps:
[0199] Step 201: UPF receives the encrypted service data packet sent by AF.
[0200] Step 202: The UPF obtains K from the AAnF. AF .
[0201] Step 203: The UPF uses the K AF The encrypted service data packet is decrypted to obtain auxiliary information of the service data packet, wherein the auxiliary information is inserted into a message header extension portion of an application transmission protocol of the service data packet.
[0202] Step 204: The UPF performs protocol data unit (PDU) set classification and identification processing on the service data packet according to the auxiliary information.
[0203] Specifically, the UPF performs protocol data unit (PDU) set classification and identification processing on the service data packets based on the auxiliary information. That is, the UPF identifies the service data packets based on the auxiliary information to achieve classification. For example, if the auxiliary information includes importance levels, data packets with the same importance level can be classified into the same category and marked accordingly.
[0204] It should be noted that the number of categories of auxiliary information required for classification and identification processing is not limited in this disclosure. Classification and identification can be performed based on one category of auxiliary information, or based on multiple categories of auxiliary information after multi-dimensional consideration.
[0205] In the embodiment of the present disclosure, the above service processing method can receive the encrypted service data packet sent by AF through UPF, and obtain K from AAnF. AFThe encrypted business data packet is decrypted to obtain auxiliary information, and then the business data packet can be subjected to protocol data unit PDU set classification identification processing according to the auxiliary information, so that in subsequent business processing, the corresponding strategy can be applied to process the data packet based on the classification information of the PDU set, thereby realizing enhanced QoS processing based on the PDU set, thereby improving the end-to-end transmission quality of the XR business.
[0206] Optionally, the UPF obtains K from AAnF AF ,include:
[0207] The UPF receives the K sent by AAnF AF ;
[0208] Alternatively, the UPF sends a second key request message to the AAnF;
[0209] The UPF receives the second key request response message sent by the AAnF, wherein the second key request response message carries the K AF .
[0210] In this embodiment, the UPF obtains the K AF It can be that the AAnF generates K AF Afterwards, the K AF Send to the UPF, or the UPF may send a request message to the AAnF to obtain the K AF .
[0211] Optionally, the auxiliary information includes at least one of the following:
[0212] Importance level;
[0213] Serial number;
[0214] Data description information;
[0215] Related data description information;
[0216] Latency budget.
[0217] For the above optional implementation manner, reference may be made to the relevant description in the embodiment shown in FIG1 . To avoid repeated description, this embodiment will not be described in detail.
[0218] 3 , which is a flowchart of a third service processing method provided by an embodiment of the present disclosure. As shown in FIG3 , the method includes the following steps:
[0219] Step 301: AAnF uses the AKMA anchor key K AKMA Determine K AF .
[0220] Specifically, the above K AKMA After the UE completes the main authentication, the UE uses the intermediate key K AUSF The above is derived from K AKMA Determine K AF It can be K AKMA and AF_ID as parameters to calculate K AF .
[0221] Step 302: The AAnF sends the K AF , where the K AF The AF is used to encrypt the auxiliary information of the service data packet to be transmitted.
[0222] It should be noted that this embodiment is an implementation of AAnF corresponding to the embodiment shown in FIG1 . For its specific implementation, please refer to the relevant description in the embodiment shown in FIG1 . To avoid repeated description, this embodiment will not be described again.
[0223] Optionally, the AAnF sends the K AF Previously, the method also included:
[0224] The AAnF receives a first key request message sent by the AF, wherein the first key request message carries the A-KID and the AF-ID;
[0225] The AAnF sends the K AF ,include:
[0226] The AAnF sends a first key request response message to the AF, wherein the first key request response message carries the K AF .
[0227] It should be noted that the first key request response message may also include K AF The life cycle is used to indicate K AF to further improve the security of business processing.
[0228] For the above optional implementation manner, reference may be made to the relevant description in the embodiment shown in FIG1 . To avoid repeated description, this embodiment will not be described in detail.
[0229] Optionally, the method further includes:
[0230] The AAnF sends the K AF ;
[0231] Alternatively, the AAnF receives a second key request message sent by the UPF;
[0232] The AAnF sends a second key request response message to the UPF, wherein the second key request response message carries the K AF .
[0233] It should be noted that the AAnF sends the K AF The A-KID can also be sent to the UPF at the same time.
[0234] For the above optional implementation manner, reference may be made to the relevant description in the embodiment shown in FIG2 . To avoid repeated description, this embodiment will not be described in detail.
[0235] Optionally, the auxiliary information includes at least one of the following:
[0236] Importance level;
[0237] Serial number;
[0238] Data description information;
[0239] Related data description information;
[0240] Latency budget.
[0241] For the above optional implementation manner, reference may be made to the relevant description in the embodiment shown in FIG1 . To avoid repeated description, this embodiment will not be described in detail.
[0242] For example, FIG4 is one of the interaction diagrams of a business processing method provided by an embodiment of the present disclosure, as shown in FIG4 :
[0243] In step 0, before the UE communicates with the application system (AS), the 5GC needs to negotiate the XR service security and QoS policy with the XR AS. The AF indicates the negotiated XR policy to the PCF.
[0244] Step 1: UE completes the primary authentication and obtains AUSF Derived K AKMA ;
[0245] Step 2: The Session Management Function (SMF) detects the dynamic Policy and Charging Control rule (PCC rule) (for example, during PDU session establishment). The PCC rule contains the negotiated XR policy and generates XR policy enforcement information. The SMF selects the UPF and sends the policy enforcement information to the UPF and UE via the network control plane.
[0246] Step 3: If the policy implementation indication is "Encryption required (AKMA-based)", it means that AF agrees to encrypt service data with the AKMA key provided by the 5G network; AAnF AKMA Generate K AF , send the key to AF and UE. The header extension of the XR data packet consists of K AF After encryption, it is sent from AS to UPF, and UPF uses K AF After decrypting the data packet, the PDU set mark is performed and the marked data packet is sent to the Radio Access Network (RAN);
[0247] Step 4: RAN performs PDU set-based processing.
[0248] For example, FIG5 is a second interactive diagram of a business processing method provided by an embodiment of the present disclosure, as shown in FIG5 :
[0249] Step 1: UE completes the primary authentication and obtains AUSF Derived K AKMA and A-KID;
[0250] Step 2: The UE sends an application layer session establishment request to the AF, carrying the A-KID.
[0251] Step 3: AF sends Naanf_AKMA_ApplicationKey_Get message to AAnF to request the UE's K AF , the message carries A-KID and AF_ID. If it is an external AF, it can request AAnF through NEF;
[0252] Step 4, if AAnF does not have K AF If K is used, then AAnF derives the AKMA application key (KAF) from KAKMA. AKMA and AF_ID as parameters to calculate the key K AF ;
[0253] Step 5: AAnF sends Naanf_AKMA_ApplicationKey_Get Response message to AF, and the response message carries K AF and K AF life cycle;
[0254] Step 6, optionally, AAnF converts K AF and A-KID directly to UPF;
[0255] Step 7, AS uses K to extend the auxiliary information in the header AF After encryption, the entire data packet is sent downstream to the UPF;
[0256] Step 8, if UPF does not obtain K from step 6 AF , UPF requests AAnF to send K AF ;
[0257] Step 9, UPF uses K AF Decrypt the header extension of the data packet and perform PDU set classification and identification on the service data packet based on the auxiliary information therein.
[0258] Referring to FIG. 6 , FIG. 6 is a schematic diagram of a structure of an AF provided by an embodiment of the present disclosure. As shown in FIG. 6 , the AF 600 includes:
[0259] The first acquisition module 601 is used to obtain the application function key K from the application layer authentication and key management AKMA anchor function AAnF AF ;
[0260] The encryption module 602 is used to determine the auxiliary information of the service data packet to be transmitted, and use the K AF encrypting the auxiliary information to obtain encrypted auxiliary information;
[0261] Inserting module 603, configured to insert the encryption auxiliary information into the message header extension portion of the application transmission protocol of the service data packet to obtain the encrypted service data packet;
[0262] The first sending module 604 is configured to send the encrypted service data packet to the user plane function UPF.
[0263] Optionally, the first obtaining module 601 includes:
[0264] A first sending unit is configured to send a first key request message to the AAnF, wherein the first key request message carries an AKMA key identifier A-KID and an AF identifier AF-ID;
[0265] The first receiving unit is configured to receive a first key request response message sent by the AAnF, wherein the first key request response message carries the application function key K AF .
[0266] Optionally, the auxiliary information includes at least one of the following:
[0267] Importance level;
[0268] Serial number;
[0269] Data description information;
[0270] Related data description information;
[0271] Latency budget.
[0272] Optionally, the first obtaining module 601 further includes:
[0273] The second receiving unit is configured to receive an application layer session establishment request message sent by the UE, where the application layer session establishment request message carries the A-KID.
[0274] AF600 can implement each process implemented by AF in the method embodiment shown in Figure 1 and can achieve the same beneficial effects. To avoid repetition, it will not be described here.
[0275] Referring to FIG. 7 , FIG. 7 is a schematic diagram of a structure of a UPF provided by an embodiment of the present disclosure. As shown in FIG. 7 , a UPF 700 includes:
[0276] The first receiving module 701 is configured to receive an encrypted service data packet sent by the AF;
[0277] The second acquisition module 702 is used to obtain K from AAnF AF ;
[0278] Decryption module 703, used to use the K AF decrypting the encrypted service data packet to obtain auxiliary information of the service data packet, wherein the auxiliary information is inserted into a message header extension portion of an application transmission protocol of the service data packet;
[0279] The identification module 704 is configured to perform protocol data unit (PDU) set classification and identification processing on the service data packet according to the auxiliary information.
[0280] Optionally, the second obtaining module 702 includes:
[0281] The third receiving unit is used to receive the K sent by AAnF AF ;
[0282] Alternatively, a second sending unit is configured to send a second key request message to the AAnF;
[0283] The fourth receiving unit is configured to receive a second key request response message sent by the AAnF, wherein the second key request response message carries the K AF .
[0284] Optionally, the auxiliary information includes at least one of the following:
[0285] Importance level;
[0286] Serial number;
[0287] Data description information;
[0288] Related data description information;
[0289] Latency budget.
[0290] UPF700 can implement each process implemented by UPF in the method embodiment shown in Figure 2 and can achieve the same beneficial effects. To avoid repetition, it will not be described here.
[0291] Referring to FIG8 , FIG8 is a schematic diagram of a structure of an AAnF provided by an embodiment of the present disclosure. As shown in FIG8 , the AAnF 800 includes:
[0292] Determining module 801, configured to determine the intermediate key K according to the AKMA AKMA Determine K AF ;
[0293] The second sending module 802 is used to send the K AF , where the K AF The AF is used to encrypt the auxiliary information of the service data packet to be transmitted.
[0294] Optionally, the AAnF further includes:
[0295] A second receiving module is configured to receive a first key request message sent by the AF, wherein the first key request message carries the A-KID and the AF-ID;
[0296] The second sending module includes:
[0297] The third sending unit is configured to send a first key request response message to the AF, wherein the first key request response message carries the K AF .
[0298] Optionally, the AAnF further includes:
[0299] The third sending module is used to send the K AF ;
[0300] Alternatively, a third receiving module is configured to receive a second key request message sent by the UPF;
[0301] The fourth sending module is configured to send a second key request response message to the UPF, wherein the second key request response message carries the K AF .
[0302] Optionally, the auxiliary information includes at least one of the following:
[0303] Importance level;
[0304] Serial number;
[0305] Data description information;
[0306] Related data description information;
[0307] Latency budget.
[0308] AAnF800 can implement each process implemented by AAnF in the method embodiment shown in FIG3 and can achieve the same beneficial effects. To avoid repetition, details are not given here.
[0309] Specifically, as shown in FIG9 , an embodiment of the present disclosure further provides an AF, including a bus 901 , a transceiver 902 , an antenna 903 , a bus interface 904 , a processor 905 and a memory 906 .
[0310] The transceiver 902 is used to obtain the application function key K from the application layer authentication and key management AKMA anchor function AAnF AF ;
[0311] Furthermore, the processor 905 is configured to: determine the auxiliary information of the service data packet to be transmitted, and use the K AF encrypting the auxiliary information to obtain encrypted auxiliary information;
[0312] Inserting the encryption auxiliary information into a message header extension portion of an application transmission protocol of the service data packet to obtain the encrypted service data packet;
[0313] The transceiver 902 is further configured to send the encrypted service data packet to the user plane function UPF.
[0314] In Figure 9, a bus architecture (represented by bus 901) is shown. Bus 901 may include any number of interconnected buses and bridges. Bus 901 links various circuits together, including one or more processors represented by processor 905 and memory represented by memory 906. Bus 901 may also link various other circuits together, such as peripheral devices, voltage regulators, and power management circuits, all of which are well known in the art and, therefore, will not be described further herein. Bus interface 904 provides an interface between bus 901 and transceiver 902. Transceiver 902 may be a single component or multiple components, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by processor 905 is transmitted over a wireless medium via antenna 903. Antenna 903 also receives data and transmits it to processor 905.
[0315] The processor 905 is responsible for managing the bus 901 and general processing, and may also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. The memory 906 may be used to store data used by the processor 905 when performing operations.
[0316] Optionally, the processor 905 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or a complex programmable logic device (CPLD).
[0317] Optionally, the transceiver 902 is specifically configured to:
[0318] Sending a first key request message to the AAnF, wherein the first key request message carries the AKMA key identifier A-KID and the AF identifier AF-ID;
[0319] Receive the first key request response message sent by the AAnF, wherein the first key request response message carries the application function key K AF .
[0320] Optionally, the auxiliary information includes at least one of the following:
[0321] Importance level;
[0322] Serial number;
[0323] Data description information;
[0324] Related data description information;
[0325] Latency budget.
[0326] Optionally, the transceiver 902 is further configured to:
[0327] An application layer session establishment request message sent by the UE is received, where the application layer session establishment request message carries the A-KID.
[0328] Specifically, as shown in FIG10 , an embodiment of the present disclosure further provides a UPF, including a bus 1001 , a transceiver 1002 , an antenna 1003 , a bus interface 1004 , a processor 1005 and a memory 1006 .
[0329] The transceiver 1002 is configured to:
[0330] Receive encrypted service data packets sent by AF;
[0331] Get K from AAnF AF ;
[0332] Furthermore, the processor 1005 is configured to: utilize the K AF decrypting the encrypted service data packet to obtain auxiliary information of the service data packet, wherein the auxiliary information is inserted into a message header extension portion of an application transmission protocol of the service data packet;
[0333] The service data packet is subjected to protocol data unit (PDU) set classification and identification processing according to the auxiliary information.
[0334] In Figure 10, a bus architecture (represented by bus 1001) is shown. Bus 1001 may include any number of interconnected buses and bridges. Bus 1001 links various circuits together, including one or more processors represented by processor 1005 and memory represented by memory 1006. Bus 1001 may also link various other circuits together, such as peripheral devices, voltage regulators, and power management circuits, all of which are well known in the art and, therefore, will not be described further herein. Bus interface 1004 provides an interface between bus 1001 and transceiver 1002. Transceiver 1002 may be a single component or multiple components, such as multiple receivers and transmitters, providing a means for communicating with various other devices over a transmission medium. Data processed by processor 1005 is transmitted over a wireless medium via antenna 1003. Antenna 1003 also receives data and transmits it to processor 1005.
[0335] The processor 1005 is responsible for managing the bus 1001 and general processing, and may also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. The memory 1006 may be used to store data used by the processor 1005 when performing operations.
[0336] Optionally, the processor 1005 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or a complex programmable logic device (CPLD).
[0337] Optionally, the transceiver 1002 is specifically configured to:
[0338] Receive the K sent by AAnF AF ;
[0339] Alternatively, a second key request message is sent to the AAnF;
[0340] Receive the second key request response message sent by the AAnF, wherein the second key request response message carries the K AF .
[0341] Optionally, the auxiliary information includes at least one of the following:
[0342] Importance level;
[0343] Serial number;
[0344] Data description information;
[0345] Related data description information;
[0346] Latency budget.
[0347] Specifically, as shown in FIG11 , an embodiment of the present disclosure further provides an AAnF, including a bus 1101 , a transceiver 1102 , an antenna 1103 , a bus interface 1104 , a processor 1105 and a memory 1106 .
[0348] The processor 1105 is configured to: AKMA Determine K AF ;
[0349] Furthermore, the transceiver 1102 is used to send the K AF , where the K AF The AF is used to encrypt the auxiliary information of the service data packet to be transmitted.
[0350] In Figure 11, a bus architecture (represented by bus 1101) is shown. Bus 1101 may include any number of interconnected buses and bridges. Bus 1101 links various circuits together, including one or more processors represented by processor 1105 and memory represented by memory 1106. Bus 1101 may also link various other circuits together, such as peripheral devices, voltage regulators, and power management circuits, all of which are well known in the art and, therefore, will not be described further herein. Bus interface 1104 provides an interface between bus 1101 and transceiver 1102. Transceiver 1102 may be a single component or multiple components, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by processor 1105 is transmitted over a wireless medium via antenna 1103. Antenna 1103 also receives data and transmits it to processor 1105.
[0351] The processor 1105 is responsible for managing the bus 1101 and general processing, and may also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. The memory 1106 may be used to store data used by the processor 1105 when performing operations.
[0352] Optionally, the processor 1105 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or a complex programmable logic device (CPLD).
[0353] Optionally, the transceiver 1102 is further configured to:
[0354] Receive a first key request message sent by the AF, wherein the first key request message carries the A-KID and the AF-ID;
[0355] The transceiver 1102 is specifically configured to: send a first key request response message to the AF, wherein the first key request response message carries the K AF .
[0356] Optionally, the transceiver 1102 is further configured to:
[0357] Send the K to UPF AF ;
[0358] Alternatively, receiving a second key request message sent by the UPF;
[0359] Send a second key request response message to the UPF, wherein the second key request response message carries the K AF .
[0360] Optionally, the auxiliary information includes at least one of the following:
[0361] Importance level;
[0362] Serial number;
[0363] Data description information;
[0364] Related data description information;
[0365] Latency budget.
[0366] An embodiment of the present disclosure also provides an electronic device, comprising: a processor, a memory, and a program stored in the memory and executable on the processor. When the program is executed by the processor, the various processes of the above-mentioned business processing method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be described here.
[0367] The present disclosure also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the computer program implements the various processes of the above-mentioned business processing method embodiment and can achieve the same technical effect. To avoid repetition, the details are not described here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0368] The embodiment of the present disclosure also provides a computer program product, including computer instructions. When the computer instructions are executed by a processor, the various processes of the above-mentioned business processing method embodiment are implemented and can achieve the same technical effect. To avoid repetition, they are not repeated here.
[0369] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.
[0370] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the relevant technology, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present disclosure.
[0371] The embodiments of the present disclosure are described above in conjunction with the accompanying drawings, but the present disclosure is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present disclosure, ordinary technicians in this field can also make many forms without departing from the scope of protection of the purpose of the present disclosure and the claims, all of which are protected by the present disclosure.
Claims
1. A service processing method, comprising: The application function AF obtains the application function key K from the application layer authentication and key management AKMA anchor function AAnF AF ; The AF determines auxiliary information of the service data packet to be transmitted, and uses the K AF to encrypt the auxiliary information to obtain encrypted auxiliary information; The AF inserts the encryption auxiliary information into the header extension part of the application transport protocol of the service data packet to obtain the encrypted service data packet; The AF sends the encrypted service data packet to the user plane function UPF.
2. The method according to claim 1, wherein The AF obtains the application function key K from the Application Layer Authentication and Key Management AKMA Anchor Function AAnF AF , including: The AF sends a first key request message to the AAnF, where the first key request message carries the AKMA key identifier A-KID and the AF identifier AF-ID; The AF receives the first key request response message sent by the AAnF, where the application function key K is carried in the first key request response message AF .
3. The method according to claim 1, wherein, The auxiliary information includes at least one of the following: Importance level; Sequence number; Data description information; Related data description information; Delay budget.
4. The method according to claim 2, wherein Before the AF sends the first key request message to the AAnF, the method further includes: The AF receives an application layer session establishment request message sent by the UE, and the A-KID is carried in the application layer session establishment request message.
5. A service processing method, comprising: The UPF receives the encrypted service data packet sent by the AF; The UPF obtains K from the AAnF AF ; The UPF uses the K AF to decrypt the encrypted service data packet to obtain auxiliary information of the service data packet, where the auxiliary information is inserted in the header extension part of the application transport protocol of the service data packet; The UPF performs protocol data unit PDU set classification and identification processing on the service data packet according to the auxiliary information.
6. The method according to claim 5, wherein, The UPF obtains K from the AAnF AF , including: The UPF receives the K sent by the AAnF AF ; Alternatively, the UPF sends a second key request message to the AAnF; The UPF receives the second key request response message sent by the AAnF, where the second key request response message carries the K AF .
7. The method according to claim 5, wherein, The auxiliary information includes at least one of the following: Importance level; Sequence number; Data description information; Related data description information; Delay budget.
8. A service processing method, comprising: Determine K according to the AKMA anchor key K AKMA Determine K AF ; The AAnF sends the K to the AF AF , where the K AF is used for the AF to encrypt the auxiliary information of the service data packet to be transmitted.
9. The method according to claim 8, wherein The AAnF sends the K to the AF AF Before that, the method further includes: The AAnF receives the first key request message sent by the AF, where the first key request message carries the A-KID and the AF-ID; The AAnF sends the K to the AF AF , including: The AAnF sends a first key request response message to the AF, where the first key request response message carries the K AF .
10. According to the method described in claim 9, the method further includes: The AAnF sends the K to the UPF AF ; Alternatively, the AAnF receives the second key request message sent by the UPF; The AAnF sends a second key request response message to the UPF, where the second key request response message carries the K AF .
11. The method according to claim 8, wherein The auxiliary information includes at least one of the following: Importance level; Sequence number; Data description information; Related data description information; Delay budget.
12. An AF, comprising: The first acquisition module is used to obtain the application function key K from the application layer authentication and key management AKMA anchor function AAnF AF ; An encryption module, configured to determine auxiliary information of a service data packet to be transmitted, and use the K AF to encrypt the auxiliary information to obtain encrypted auxiliary information; An insertion module, configured to insert the encryption auxiliary information into the header extension part of the application transport protocol of the service data packet to obtain the encrypted service data packet; A first sending module, configured to send the encrypted service data packet to the user plane function UPF.
13. A UPF, comprising: A first receiving module, configured to receive the encrypted service data packet sent by the AF; The second acquisition module is used to acquire K from AAnF AF ; A decryption module, configured to use the K AF to decrypt the encrypted service data packet and obtain auxiliary information of the service data packet, where the auxiliary information is inserted into an extended part of a header of an application transmission protocol of the service data packet; An identification module, configured to perform protocol data unit PDU set classification and identification processing on the service data packet according to the auxiliary information.
14. An AAnF, comprising: Determination module, for determining K according to the AKMA intermediate key K AKMA Determine K AF ; A second sending module, configured to send the K to the AF AF , where the K AF is used for the AF to encrypt the auxiliary information of the service data packet to be transmitted.
15. An AF, comprising a transceiver and a processor, The transceiver is used to obtain the application function key K from the application layer authentication and key management AKMA anchor function AAnF AF ; The processor is configured to: determine auxiliary information of a service data packet to be transmitted, and use the K AF encrypt the auxiliary information to obtain encrypted auxiliary information; Insert the encryption auxiliary information into the header extension part of the application transport protocol of the service data packet to obtain the encrypted service data packet; The transceiver is further configured to send the encrypted service data packet to the user plane function UPF.
16. A UPF, comprising a transceiver and a processor, and the transceiver is configured to: Receive the encrypted service data packet sent by the AF; Obtain K from AAnF AF ; The processor is configured to: utilize the K AF decrypt the encrypted service data packet to obtain auxiliary information of the service data packet, wherein The auxiliary information is inserted into the header extension part of the application transport protocol of the service data packet; Perform protocol data unit PDU set classification and identification processing on the service data packet according to the auxiliary information.
17. An AAnF, comprising a transceiver and a processor, The processor is configured to determine K based on the AKMA intermediate key K AKMA ; AF ; The transceiver is used to send the K to the AF AF , wherein The said K AF is used to encrypt the auxiliary information of the service data packet to be transmitted by the said AF.
18. An electronic device, comprising: A processor, a memory, and a program stored on the memory and executable on the processor, wherein when the program is executed by the processor, the steps of the service processing method according to any one of claims 1 to 4 are implemented; or, when the program is executed by the processor, the steps of the service processing method according to any one of claims 5 to 7 are implemented; or, when the program is executed by the processor, the steps of the service processing method according to any one of claims 8 to 11 are implemented.
19. A computer-readable storage medium, on which a computer program is stored, wherein when the computer program is executed by a processor, the steps of the service processing method according to any one of claims 1 to 4 are implemented; or, when the computer program is executed by the processor, the steps of the service processing method according to any one of claims 5 to 7 are implemented; or, when the computer program is executed by the processor, the steps of the service processing method according to any one of claims 8 to 11 are implemented.
20. A computer program product, including computer instructions, wherein when the computer instructions are executed by a processor, the steps of the service processing method according to any one of claims 1 to 4 are implemented; or, when the computer instructions are executed by the processor, the steps of the service processing method according to any one of claims 5 to 7 are implemented; or, when the computer instructions are executed by the processor, the steps of the service processing method according to any one of claims 8 to 11 are implemented.
Citation Information
Patent Citations
Method and system for establishment and authentication of secure connections for edge computing services
CN116368833A
Key generation method and apparatus, and network device
CN117082504A
Method and apparatus for configuring temporary user equipment (UE) external identifier in wireless communication system
US20220322067A1
Secure communications for a client device involving authentication and key management for applications (AKMA)
US20230115314A1
Enhanced ranging and positioning services in wireless networks
WO2023161242A1