Key processing methods, communication device and storage medium
By generating and managing the keys for UE-SAT-UE communications for user equipment and network equipment in the satellite communication system, the problem of lack of end-to-end security protection in satellite communications is solved, and the security improvement of UE-SAT-UE communications and consistency protection of data transmission is achieved.
Patent Information
- Application Number
- PCT/CN2024/073361
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-19
- Publication Date
- 2025-07-24
AI Technical Summary
In satellite communication, the prior art lacks an effective end-to-end security protection mechanism, which makes the communication security between user equipment unable to be guaranteed, especially in locally exchanged user equipment to satellite to user equipment (UE-SAT-UE) communication under satellite coverage, it is difficult to protect the security of user plane data consistently.
By providing a key processing method for user equipment (UE) and network equipment, generating and managing the root key and second key for UE-SAT-UE communication, ensuring end-to-end security protection, including receiving and sending key information, determining the UE's permissions and security policies, activating or not activating the end-to-end security of the user plane, and generating integrity and confidentiality keys using the key generation algorithm.
It realizes end-to-end security protection of UE-SAT-UE communication, improves communication security, ensures consistency protection of user-side data on the transmission link, and prevents malicious tampering.
Smart Images

Figure CN2024073361_24072025_PF_FP_ABST
Abstract
Description
Key processing method, communication device and storage medium Technical Field
[0001] The present disclosure relates to the field of communication technology, and in particular to a key processing method, communication equipment, and storage medium. Background Art
[0002] In satellite-based communication scenarios, where base stations or user plane functions (UPF) are integrated, the communication system can support user equipment (UE)-satellite-UE (UE-SAT-UE) communication. UE-SAT-UE communication involves communication between UEs using local switching within the coverage of one or more satellites, rather than over the user plane (UP).
[0003] Summary of the Invention
[0004] Embodiments of the present disclosure provide a key processing method, a communication device, and a storage medium.
[0005] According to a first aspect of an embodiment of the present disclosure, a key processing method is provided, which is performed by a first user equipment UE, and the method includes: determining a second key based on a first key; the first key is a root key for UE-SAT-UE communication; and the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0006] According to a second aspect of an embodiment of the present disclosure, a key processing method is provided, which is performed by a second network device and includes: determining a first key; the first key is a root key for UE-SAT-UE communication; the first key is used to generate a second key for a first user equipment UE; UE-SAT-UE communication.
[0007] According to a third aspect of an embodiment of the present disclosure, a key processing method is provided, which is performed by a first network device and includes: sending first information to a first user equipment UE; the first information includes at least a first indication; the first indication is used to indicate whether end-to-end security of UE-SAT-UE communication is activated, so that the first UE generates a second key based on the first key; the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0008] According to a fourth aspect of an embodiment of the present disclosure, a key processing method is provided, which is performed by a third network device, and the method includes: receiving a third message from a first user equipment UE; the third message is used to request establishment of a protocol data unit (PDU) session for UE-SAT-UE communication between the first UE and at least one second UE; determining that the first UE has the authority for the UE-SAT-UE communication or has end-to-end security authority for the UE-SAT-UE communication; the first UE has the authority for the UE-SAT-UE communication or has end-to-end security authority for the UE-SAT-UE communication, and determining to agree to establish the PDU session for the UE-SAT-UE communication; agreeing to establish the PDU session for the UE-SAT-UE communication, and sending a PDU session establishment request message to the second network device; the PDU session establishment request message is used by the second network device to provide a first key to the first UE; the first key is a root key for UE-SAT-UE communication; the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0009] According to the fifth aspect of an embodiment of the present disclosure, a first user equipment UE is provided, which includes: a processing module configured to determine a second key based on a first key; the first key is a root key for UE-SAT-UE communication; and the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0010] According to a sixth aspect of an embodiment of the present disclosure, a second network device is provided, comprising: a processing module configured to determine a first key; the first key is a root key for UE-SAT-UE communication; the first key is used to generate a second key for a first user equipment UE; and UE-SAT-UE communication.
[0011] According to a seventh aspect of an embodiment of the present disclosure, a first network device is provided, comprising: a sending module configured to send first information to a first user equipment UE; the first information includes at least a first indication; the first indication is used to indicate whether end-to-end security of UE-SAT-UE communication is activated, so that the first UE generates a second key based on the first key; the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0012] According to an eighth aspect of an embodiment of the present disclosure, a third network device is provided, comprising: a receiving module configured to receive a third message from a first user equipment UE; the third message is used to request establishment of a protocol data unit (PDU) session for UE-SAT-UE communication between the first UE and at least one second UE; a processing module configured to determine whether the first UE has permission for the UE-SAT-UE communication or has end-to-end security permission for the UE-SAT-UE communication; the first UE has permission for the UE-SAT-UE communication or has end-to-end security permission for the UE-SAT-UE communication, and determines to agree to establish the PDU session for the UE-SAT-UE communication; a sending module configured to agree to establish the PDU session for the UE-SAT-UE communication, and send a PDU session establishment request message to the second network device; the PDU session establishment request message is used by the second network device to provide a first key to the first UE; the first key is a root key for UE-SAT-UE communication; the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0013] According to the ninth aspect of the embodiment of the present disclosure, a communication device is provided, wherein the communication device includes: one or more processors; wherein the processor is used to call instructions so that the communication device executes the key processing method provided by any technical solution of the aforementioned first to fourth aspects.
[0014] According to a tenth aspect of an embodiment of the present disclosure, a storage medium is provided, wherein the storage medium stores instructions, which, when the instructions are executed on a communication device, enable the communication device to execute the key processing method provided by any of the first to fourth aspects.
[0015] According to the technical solution provided by the embodiment of the present disclosure, the first UE determines the second key based on the first key. In this way, the subsequent UE-SAT-UE communication between the first UE and the second UE is end-to-end securely protected, thereby improving the security of the UE-SAT-UE communication between the first UE and the second UE.
[0016] It should be understood that the foregoing general description and the following detailed description are merely exemplary and explanatory and are not restrictive of the embodiments of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the present disclosure and, together with the description, serve to explain the principles of the embodiments of the present disclosure.
[0018] FIG1A is a schematic diagram showing an architecture of a communication system according to an exemplary embodiment;
[0019] FIG1B is a schematic diagram showing an architecture of a communication system according to an exemplary embodiment;
[0020] FIG1C is a schematic diagram showing an architecture of a communication system according to an exemplary embodiment;
[0021] FIG2 is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0022] FIG3 is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0023] FIG4 is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0024] FIG5 is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0025] FIG6 is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0026] FIG7A is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0027] FIG7B is a schematic flow chart showing a key processing method according to an exemplary embodiment;
[0028] FIG8A is a schematic structural diagram of a first UE according to an exemplary embodiment;
[0029] FIG8B is a schematic structural diagram of a second network device according to an exemplary embodiment;
[0030] FIG8C is a schematic structural diagram of a first network device according to an exemplary embodiment;
[0031] FIG8D is a schematic structural diagram of a third network device according to an exemplary embodiment;
[0032] FIG9A is a schematic structural diagram of a communication device according to an exemplary embodiment;
[0033] FIG9B is a schematic structural diagram of a chip according to an exemplary embodiment. DETAILED DESCRIPTION
[0034] Embodiments of the present disclosure provide a key processing method, a communication device, and a storage medium.
[0035] A first aspect provides a key processing method, which is performed by a first user equipment UE. The method includes:
[0036] The second key is determined based on the first key; the first key is the root key of UE-SAT-UE communication; the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0037] Based on the above scheme, the first UE will determine the second key based on the first key. In this way, the subsequent UE-SAT-UE communication between the first UE and the second UE is end-to-end securely protected, thereby improving the security of the UE-SAT-UE communication between the first UE and the second UE.
[0038] In some embodiments of the first aspect, the method also includes: receiving first information sent by a first network device; the first information is at least used by the first UE to determine whether to activate user plane UP end-to-end security of UE-SAT-UE communication; determining the second key based on the first key, including: when the end-to-end security of UE-SAT-UE communication is activated, determining the second key based on the first key.
[0039] Based on the above scheme, the first UE can determine whether it is necessary to activate end-to-end security of UE-SAT-UE communication based on the first information, and determine the second key based on the first key, thereby reducing unnecessary key generation when end-to-end security of UE-SAT-UE communication is not required.
[0040] In some embodiments of the first aspect, the first information further includes at least one of the following: a first indication, the first indication being used to indicate whether end-to-end security for UE-SAT-UE communication is activated; and a parameter value, the parameter value and the first key being used together to determine the second key.
[0041] Based on the above solution, the specific content of the first information is limited. The first information may include only the first indication, only the parameter value, or both the first indication and the parameter value. In some cases, the first information may also include other content. In short, the above is only the distance of the first information, and the specific implementation time can be flexibly set as needed.
[0042] In some embodiments of the first aspect, when end-to-end security for UE-SAT-UE communication is activated, determining the second key based on the first key includes at least one of the following: generating the second key based on the first key and a parameter value; or generating the second key based on the first key. Based on the above solution, two optional methods for generating the second key when end-to-end security for UE-SAT-UE communication is activated are defined, which has the advantage of simple implementation.
[0043] In some embodiments of the first aspect, the method includes: sending a first message to a second network device; the first message is related to UE-SAT-UE communication; receiving a second message sent by the second network device; the second message includes the first key.
[0044] The above solution provides a method for the first UE to trigger the second network device to distribute the first key. In specific implementation, the method for the first UE to obtain the first key is not limited to requesting it from the second network device.
[0045] In some embodiments of the first aspect, the first message includes at least one of the following: a registration authorization request message; the registration authorization request information includes capability information of the first UE supporting UE-SAT-UE communication; and a protocol data unit (PDU) session establishment request message for UE-SAT-UE communication.
[0046] Based on the above solution, two optional messages of the first message are provided, both of which reuse messages with other functions, thereby having strong compatibility with related technologies and triggering the second network device to provide the first key to the first UE without setting a new message.
[0047] In some embodiments of the first aspect, the second key comprises at least one of: an integrity key; a confidentiality key.
[0048] Based on the above solution, the end-to-end security protection of the UE-SAT-UE communication here may include integrity protection and / or confidentiality protection, thereby ensuring the end-to-end security of the UE-SAT-UE communication.
[0049] A second aspect provides a key processing method, which is executed by a second network device and includes: determining a first key; the first key is a root key for UE-SAT-UE communication; the first key is used to generate a second key for a first user equipment UE; and UE-SAT-UE communication.
[0050] In some embodiments of the second aspect, the method further includes: receiving a first message sent by a first UE; the first message is related to UE-SAT-UE; sending a second message to the first UE; the second message includes the first key.
[0051] In some embodiments of the second aspect, the first message is a registration authorization request message; the registration authorization request message includes capability information of the first UE; a second message is sent to the first UE, including; the capability information of the first UE indicates whether the first UE supports UE-SAT-UE communication or whether the first UE supports end-to-end security of UE-SAT-UE communication, and the second message is sent to the first UE.
[0052] In some embodiments of the second aspect, sending a second message to the first UE includes at least one of the following: the first message is a protocol data unit PDU session establishment request message for UE-SAT-UE communication and the second network device determines that the first UE has the authority for UE-SAT-UE communication, and sends the second message to the first UE; the first message is a protocol data unit PDU session establishment request message for UE-SAT-UE communication and the second network device determines that the first UE has end-to-end security authority for UE-SAT-UE communication, and sends the second message to the first UE; the first message is a protocol data unit PDU session establishment request message for UE-SAT-UE communication and the third network device agrees to establish a PDU session for UE-SAT-UE communication for the first UE, and sends the second message to the first UE.
[0053] In some embodiments of the second aspect, the method further includes: determining whether the first UE has signed up for UE-SAT-UE communication based on the contract information of the first UE; and if the first UE has signed up for UE-SAT-UE communication, determining to send a second message to the first UE.
[0054] In some embodiments of the second aspect, the method also includes: determining whether the first UE has signed up for end-to-end security of UE-SAT-UE communication based on the contract information of the first UE; and determining to send a second message to the first UE if the first UE has signed up for end-to-end security of UE-SAT-UE communication.
[0055] In some embodiments of the second aspect, the method further includes: sending a second indication to a first network device to which the first UE is connected, the second indication being used to indicate whether to activate user plane UP end-to-end security of UE-SAT-UE communication of the first UE.
[0056] In some embodiments of the second aspect, sending the second indication to the first network device to which the first UE is connected includes: establishing a PDU session for UE-SAT-UE communication for the first UE, and sending the second indication to the first network device to which the first UE is connected.
[0057] A third aspect provides a key processing method, which is performed by a first network device and includes: sending first information to a first user equipment UE; the first information is at least used to indicate whether end-to-end security of user equipment to satellite to user equipment UE-SAT-UE communication is activated, so that the first UE generates a second key based on the first key; the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0058] In some embodiments of the third aspect, the method includes: receiving a second indication sent by a second network device or a third network device; the second indication is used to indicate whether to activate end-to-end security of UE-SAT-UE communication of the first UE; sending a first indication to the first user equipment UE, including: whether it is necessary to activate end-to-end security protection of UE-SAT-UE communication of the first UE, and sending first information to the first UE.
[0059] In some embodiments of the third aspect, the first information further includes at least one of the following: a first indication, the first indication being used to indicate whether to activate end-to-end security for the UE-SAT-UE communication; and a parameter value, the parameter value and the first key being jointly used to determine the second key.
[0060] A fourth aspect provides a key processing method, wherein the method is performed by a third network device, and the method includes:
[0061] Receive a third message from a first user equipment UE; the third message is used to request establishment of a protocol data unit (PDU) session for UE-SAT-UE communication between the first UE and at least one second UE; determine that the first UE has permission for UE-SAT-UE communication or has end-to-end security permission for UE-SAT-UE communication; the first UE has permission for UE-SAT-UE communication or has end-to-end security permission for UE-SAT-UE communication, and determines to agree to establish a PDU session for UE-SAT-UE communication; agree to establish the PDU session for UE-SAT-UE communication, and send a PDU session establishment request message to a second network device; the PDU session establishment request message is used by the second network device to provide a first key to the first UE; the first key is a root key for UE-SAT-UE communication; the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0062] In some embodiments of the fourth aspect, the method may further include:
[0063] Agree to establish the PDU session of the UE-SAT-UE communication, and send a second indication to the first network device; the second indication is used to indicate whether the end-to-end security of the UE-SAT-UE communication of the first UE is activated.
[0064] The fifth aspect provides a first user equipment UE, which includes: a processing module configured to determine a second key based on a first key; the first key is a root key for UE-SAT-UE communication; and the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0065] The sixth aspect provides a second network device, which includes: a processing module configured to determine a first key; the first key is a root key for UE-SAT-UE communication; the first key is used to generate a second key for a first user equipment UE; UE-SAT-UE communication.
[0066] The seventh aspect provides a first network device, which includes: a sending module configured to send first information to a first user equipment UE; the first information includes at least a first indication; the first indication is used to indicate whether the end-to-end security of UE-SAT-UE communication is activated, so that the first UE generates a second key based on the first key; the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0067] The eighth aspect provides a third network device, which includes: a receiving module, configured to receive a third message from a first user equipment UE; the third message is used to request the establishment of a protocol data unit PDU session for UE-SAT-UE communication between the first UE and at least one second UE; a processing module, configured to determine whether the first UE has the authority for UE-SAT-UE communication or has end-to-end security authority for UE-SAT-UE communication; the first UE has the authority for UE-SAT-UE communication or has end-to-end security authority for UE-SAT-UE communication, and determines to agree to establish the PDU session for UE-SAT-UE communication; a sending module, configured to agree to establish the PDU session for UE-SAT-UE communication, and send a PDU session establishment request message to the second network device; the PDU session establishment request message is used for the second network device to provide a first key to the first UE; the first key is the root key for UE-SAT-UE communication; the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0068] A ninth aspect provides a communication device, the communication device comprising: one or more processors;
[0069] The processor is used to call instructions to enable the communication device to execute the key processing method described in the optional implementation of the first to fourth aspects.
[0070] In the tenth aspect, an embodiment of the present disclosure provides a storage medium, wherein the storage medium stores instructions, which, when the instructions are executed on a communication device, enable the communication device to execute the key processing method described in the optional implementation methods of the first to fourth aspects.
[0071] In an eleventh aspect, an embodiment of the present disclosure provides a program product. When the program product is executed by a communication device, the communication device executes the key processing method described in the optional implementation of the first to fourth aspects.
[0072] In a twelfth aspect, an embodiment of the present disclosure provides a computer program, which, when executed on a computer, enables the computer to execute the key processing method described in the optional implementation of the first to fourth aspects.
[0073] It is understandable that the above-mentioned terminals, network devices, communication systems, program products, and computer programs are all used to execute the methods provided by the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding methods and will not be repeated here.
[0074] The embodiments of the present disclosure propose a key processing method, communication equipment, communication system and storage medium. The embodiments of the present disclosure are not exhaustive, but are only illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0075] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.
[0076] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.
[0077] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "the", "the", etc., can mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article can be understood as a singular expression or a plural expression.
[0078] In the embodiments of the present disclosure, “plurality” refers to two or more.
[0079] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.
[0080] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "in one case A, in another case B," or "in one case A, in another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, and C.
[0081] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.
[0082] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different. For another example, if the description object is "information", then the "first category of information" and the "second category of information" can be the same information or different information, and their contents can be the same or different.
[0083] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0084] In some embodiments, terms such as "...", "determine...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.
[0085] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.
[0086] In some embodiments, devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as "device", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", and "subject" can be used interchangeably.
[0087] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).
[0088] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station" "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like may be used interchangeably.
[0089] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client, etc. can be used interchangeably.
[0090] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it is also possible to set the structure in which the terminal has all or part of the functions of the access network device. In addition, terms such as "uplink" and "downlink" can also be replaced by terms corresponding to communication between terminals (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels, and uplinks, downlinks, etc. can be replaced by side links.
[0091] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the terminal.
[0092] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
[0093] In some embodiments, data, information, etc. may be obtained with the user's consent.
[0094] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.
[0095] FIG1A is a schematic diagram showing the architecture of a communication system according to an embodiment of the present disclosure.
[0096] As shown in Figure 1A, a communication system 100 includes a terminal 101 and a network device 102. The network device 102 may include an access network device and / or a core network device.
[0097] In some embodiments, the terminal 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and at least one of a wireless terminal device in a smart home, but is not limited thereto.
[0098] In some embodiments, the terminal is also referred to as User Equipment (UE).
[0099] In some embodiments, the access network device may be, for example, a node or device that accesses a terminal to a wireless network. The access network device may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a Wi-Fi system, but is not limited thereto.
[0100] In some embodiments, the technical solution of the present disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can be transformed into internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.
[0101] In some embodiments, the access network device can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit. The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.
[0102] In some embodiments, the core network device may be a single device including a first network element, or may be a plurality of devices or a group of devices, each including a first network element. The network element may be virtual or physical. The core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).
[0103] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution provided by the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution provided by the embodiment of the present disclosure is also applicable to similar technical problems.
[0104] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1A , or a portion thereof, but are not limited thereto. The entities shown in FIG1A are illustrative only. The communication system may include all or part of the entities shown in FIG1A , or may include other entities other than those shown in FIG1A . The number and form of the entities may be arbitrary. The connection relationship between the entities is illustrative only. The entities may be connected or disconnected, and the connection may be in any manner, including direct or indirect, wired or wireless.
[0105] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems using configuration methods for other resources, and next-generation systems based on and extending these systems. Furthermore, multiple systems may be combined (for example, LTE and NR).
[0106] Figure 1B shows a network system supporting UE-SAT-UE communication, which may include: UE1, UE2, and a gNB on satellite X. A feedback link exists between the gNB on satellite X and the ground. This feedback link allows the gNB on satellite X to connect to the core network, for example, to the core network's access management function (AMF). The gNB on satellite X forms satellite cell A, which may be adjacent to a terrestrial cell. A terrestrial cell may be formed by a terrestrial base station. The connection between the gNB on satellite X and the Uu interface between UE1 and UE2 is a satellite link. Thus, user plane data can be transmitted between UE1 and UE2 via the base station on satellite X. It is important to note that while Figure 1B uses two UEs to represent UE-SAT-UE communication, this communication can involve more than one UE. The multiple UEs involved in UE-SAT-UE communication can be located in the same cell or in different cells. The number of satellites involved in UE-SAT-UE communication can be one or more. In Figure 1B, the AMF is merely a representative of the core network's network functions. In reality, core network functions are not limited to the AMF and may also include the Session Management Function (SMF). As shown in Figure 1B, the connection between the gNB onboard Satellite (SAT)x and the ground can be used for control plane (CP) signaling exchanges.
[0107] As shown in Figure 1C, two UEs performing UE-SAT-UE communication are located in different cells, and different cells correspond to different base stations and / or user plane functions (UPF). At this time, a connection (or link) needs to be established between satellites. There are inter-satellite links (Inter Satellite Link(s), ISL) between satellites. ISL allows satellites to connect to other satellites through ISL, and connect to the ground through other satellites. In this way, ISL can make the connection between satellite and ground available at any time. When the local switching capability involves multiple satellites, UE-SAT-UE communication can be extended to the coverage of one or more satellites.
[0108] The security of the user plane (UP) data flow of the Uu interface is based on the security policy provided by the core network. The security policy can be set by the user data management (UDM) or by the session management function (SMF) based on the specific service requested by the UE. For example, the SMF can set the security policy based on the UP security enhancement information during the PDU session establishment process. The UP security enhancement information may include but is not limited to at least one of the following:
[0109] The subscribed UP security policy, which may be received from UDM and is part of the session management subscription information;
[0110] The UP security policy is a local policy for a single Data Network Name (DNN) and Single Network Slice Selection Assistance Information (S-NSSAI). This local UP security policy can be used when the UDM does not provide a contracted UP security policy.
[0111] The UP security policy indicates whether UP security protection is activated on the Uu interface for this PDU Session. The UP security policy can be used to activate UP confidentiality and / or UP integrity for the PDU Session. Based on the UP security policy provided by the SMF, if the UP security policy indicates "Required," the gNB activates UP security protection on the Uu interface for each Data Radio Bearer (DRB) via RRC signaling. If the policy indicates "Not Needed," the PDU Session is established without protection. If the policy indicates "Preferred," the gNB can decide whether to activate UP security protection on the Uu interface. However, when the UP security policy indicates "Required" or "Not Needed," the gNB cannot overrule the UP security policy received from the SMF.
[0112] For use of existing mechanisms through fifth mobile communications (5 th In traditional UE-to-UE communication over 5G (5th Generation) networks, each UE establishes a separate PDU session with the core network through a potentially separate gNB. The gNB then applies different UP security policies to each UE's PDU session.
[0113] For UE-SAT-UE communications that exchange UP traffic locally without passing through the terrestrial network where the core network functions (e.g., SMF) are located, the existing mechanism can be reused to establish two separate PDU sessions for UE-SAT-UE communications. However, if the communication terminals have different UP security policies, this may result in different security protections being applied to the two Uu ports of a single UE-SAT-UE communication session. In this case, the security protections on the two Uu ports may be inconsistent, and high security protection (e.g., integrity and confidentiality protection) on one Uu port may be masked by low security protection (e.g., only integrity protection, only confidentiality protection, or no protection) on another Uu port.
[0114] Security protection for the Uu interface terminates at the gNB. This means that the transmitting gNB must decode the uplink traffic, and the receiving gNB must encode the downlink traffic. When UP traffic needs to be transmitted between the transmitting and receiving gNBs over an inter-satellite link (ISL), protection of UP traffic over the ISL relies solely on the security applied on the ISL, which may not be controlled by the operator. Therefore, UP traffic carried on both Uu interfaces may not be uniformly protected across the transmission link. In this case, UP traffic may be tampered with by malicious or misbehaving entities (e.g., entities between the inter-satellite links).
[0115] If end-to-end protection is implemented between two communication terminals, consistent protection can be achieved for UP traffic carried by both Uu ports and for the UE-SAT-UE communication transmission link. However, there is currently no end-to-end protection solution for UP services in UE-SAT-UE communication, and further research is needed.
[0116] Ensure that end-to-end protection is applied between the two communication terminals so that the protection of UP traffic carried by the two Uu ports remains consistent on the UE-SAT-UE communication transmission link.
[0117] As shown in FIG2 , an embodiment of the present disclosure provides a key processing method, which is executed by a communication system. The method may include:
[0118] S2101: The first UE sends a first message to the second network device.
[0119] In some embodiments, the second network device may include but is not limited to a core network device. For example, the second network device may be a network function (NF) deployed in the core network.
[0120] In some embodiments, the second network device may be a Policy Control Function (PCF).
[0121] In some embodiments, the first UE sends a first message to the second network device via a base station on a satellite via a serving link as shown in FIG1B and FIG1C . The gNB on the satellite forwards or transparently transmits the first message to the second network device.
[0122] In some embodiments, the first message may be any message sent by the first UE during the registration authorization authentication process.
[0123] In some embodiments, the first message may be an authorization request message.
[0124] In some embodiments, the first message may be an authorization request message for UE-SAT-UE communication.
[0125] In some embodiments, the first message may be a PDU session establishment request message.
[0126] In some embodiments, the first message may be a PDU session modification request message.
[0127] In some embodiments, the first message includes at least:
[0128] identification information of the first UE;
[0129] Capability information of the first UE.
[0130] Service identifier for UE-SAT-UE communication;
[0131] Network information of the data network used for UE-SAT-UE communication;
[0132] Slice information of the network slice used for UE-SAT-UE communication.
[0133] In some embodiments, the identification information of the first UE may include, but is not limited to, an application layer identifier of the first UE (eg, a user information identifier (User Info), a user permanent identifier (SUbscription Permanent Identifier, SUPI), etc.
[0134] In some embodiments, the capability information may indicate at least one of the following:
[0135] a communication type supported by the first UE;
[0136] Services supported by the first UE.
[0137] In some embodiments, after receiving the capability information, the second network device can determine whether the capabilities and / or services supported by the UE are authorized for subscription according to the subscription information of the UE.
[0138] In some embodiments, the capability information may be used to indicate whether the first UE supports UE-SAT-UE communication or whether the first UE supports end-to-end security of UE-SAT-UE communication.
[0139] In some embodiments, UE-SAT-UE communication may be configured with one or more services, and traffic of these services may be transmitted based on the UE-SAT-UE communication.
[0140] In some embodiments, UE-SAT-UE communication may also be referred to as local communication or satellite-based local communication.
[0141] S2102: The second network device obtains the first key.
[0142] In some embodiments, the second network device generates a first key for UE-SAT-UE communication.
[0143] In some embodiments, the second network device receives the first key from an application server providing UE-SAT-UE communication.
[0144] In some embodiments, the second network device receives the first key from a User Data Management (UDM) or a Unified Data Repository (UDR).
[0145] In some embodiments, the first key is a root key for UE-SAT-UE communication.
[0146] In some embodiments, the first key is used to generate the second key.
[0147] In some embodiments, the first key is not limited to the root key, but may also be an intermediate key that generates the second key.
[0148] In some embodiments, the first key is used to generate a second key for UE-SAT-UE communication.
[0149] In some embodiments, the first key is a root key for UE-SAT-UE communication.
[0150] In some embodiments, the second key may include at least one of the following:
[0151] Integrity key, used for integrity protection of UE-SAT-UE communication;
[0152] Confidentiality key, used for confidentiality protection of UE-SAT-UE communication;
[0153] Scrambling key, used for scrambling protection of UE-SAT-UE communication;
[0154] Replay attack protection key, used for replay attack protection of service data in UE-SAT-UE communication.
[0155] In some embodiments, the second network device determines authority of the first UE.
[0156] In some embodiments, the second network device obtains the first key after determining that the first UE has authority.
[0157] In some embodiments, the permission of the first UE may include: the permission of the first UE for UE-SAT-UE communication. For example, the first UE has the permission to sign up for UE-SAT-UE communication.
[0158] In some embodiments, the permissions of the first UE may include: end-to-end security permissions for the first UE to participate in UE-SAT-UE communications. For example, the first UE has end-to-end security permissions to sign up for UE-SAT-UE communications.
[0159] In some embodiments, the second network device determines whether the first UE has the authority for UE-SAT-UE communication based on the capability information and / or subscription information of the first UE.
[0160] In some embodiments, when the second network device determines, based on the capability information of the first UE, that the first UE supports UE-SAT-UE communication, the second network device obtains the first key.
[0161] In some embodiments, when the second network device determines that the first UE does not support UE-SAT-UE communication according to the capability information of the first UE, it is not necessary to obtain the first key.
[0162] In some embodiments, it is determined according to the subscription information of the first UE whether the first UE has the authority to subscribe to UE-SAT-UE communication.
[0163] In some embodiments, it is determined according to the subscription information of the first UE whether the first UE has the authority to subscribe to the end-to-end security of UE-SAT-UE communication.
[0164] In some embodiments, it is determined based on the subscription information of the first UE whether the first UE has the authority to sign up for UE-SAT-UE communication and, if it has the authority to sign up for UE-SAT-UE communication, whether it has the authority to sign up for end-to-end security of UE-SAT-UE communication.
[0165] In some embodiments, when it is determined according to the capability information of the first UE that the first UE supports UE-SAT-UE communication, it is determined according to the subscription information of the first UE whether the first UE has signed up for the permission of UE-SAT-UE communication.
[0166] In some embodiments, if the first UE does not have permission for UE-SAT-UE communication or does not have permission for UE-SAT-UE end-to-end security, the second network device may send a rejection message or a failure message to the first UE while skipping the acquisition of the first key. The rejection message may be used to indicate that the network side rejects PDU session establishment, PDU session update, or registration authorization. The failure message may be used to indicate a PDU session establishment failure, a PDU session update failure, or a registration authorization failure.
[0167] S2103: The second network device sends a second message to the first UE.
[0168] In some embodiments, the second message includes the first key.
[0169] In some embodiments, the second network device may first obtain the first key, and then determine whether the first UE has the authority when receiving the first message from the first UE.
[0170] In some embodiments, the first UE has permission for UE-SAT-UE communication and sends the second message to the first UE. Exemplarily, the second message is sent to an access network device of the first UE and forwarded or transparently transmitted to the first UE by the access network device.
[0171] In some embodiments, the first UE does not have permission for UE-SAT-UE communication, and a rejection message or a failure message is sent to the first UE. The rejection message or the failure message indicates that the first UE does not have permission for UE-SAT-UE communication.
[0172] In some embodiments, if the second network device first determines whether the first UE has permission and the first UE does not have permission, then step S2103 may be optional. In this case, the second network device may send the aforementioned rejection message or failure message to the first UE. In some embodiments, the second network device may not send any message to the first UE. In some embodiments, the second network device may also send a request acceptance message to the first UE without the first key.
[0173] In some embodiments, the rejection message or failure message may also carry a failure reason, which indicates authentication failure, etc. That is, in some embodiments, S2103 may be an optional step.
[0174] In some embodiments, if the first message is a PDU session establishment request message, the second message is a PDU session establishment response message. Exemplarily, the second message may be a PDU session establishment success message. The corresponding rejection message or failure message may be a PDU session establishment failure message.
[0175] In some embodiments, if the first message is a PDU session update request message, the second message is a PDU session update response message. Exemplarily, the second message may be a PDU session update success message. The corresponding rejection message or failure message may be a PDU session update failure message.
[0176] In some embodiments, if the first message is a registration authorization request message, the second message may be a registration authorization response message. For example, the second message may be a registration authorization success message. The corresponding rejection message or failure message may be a registration authorization failure message.
[0177] In some embodiments, determining whether the first UE has permission may be performed by a third network device. Exemplarily, the third network device may be a Session Management Function (SMF). If the third network device determines whether the first UE has permission, the third network device may notify the second network device that the first UE has permission. For example, the third network device may notify the second network device that the first UE has permission for UE-SAT-UE communication.
[0178] In some embodiments, if the third network device determines that the first UE has permission for UE-SAT-UE communication or the first UE has permission for end-to-end security of UE-SAT-UE communication, the third network device transparently transmits or forwards the first message to the second network device. At this time, upon receiving the first message, the second network device assumes that the first UE has the corresponding permission.
[0179] For example, if the first message is a PDU session establishment request message or a PDU session update message, the first message will pass through the base station to the third network device. After receiving the first message, the third network device will determine whether the first UE has the corresponding authority based on the capability information and / or subscription information of the first UE. Only when the first UE has the corresponding authority will the first message be forwarded or transparently transmitted to the second network device.
[0180] S2104: The second network device sends a second indication to the first network device of the first UE.
[0181] In some embodiments, the second indication may be sent by a third network device to the first UE. For example, during the PDU session establishment process, the third network device may send the second indication to the first network device of the first UE based on whether end-to-end security for UE-SAT-UE communication of the first UE is activated. Exemplarily, the first network device of the first UE may be a serving base station or an anchor base station of the first UE. In some embodiments, the third network device of the first UE may be an SMF of the first UE, for example.
[0182] If the first message is a registration authorization request message, the first UE may subsequently initiate a PDU session request during communication. For example, the PDU session request may include a service identifier related to UE-SAT-UE communication. The PDU session request may be used to request the transmission of service data corresponding to the service identifier based on UE-SAT-UE communication.
[0183] The PDU session request is used by the first UE to request a PDU session.
[0184] In some embodiments, the second network device or the third network device sends a second indication to the first network device when the first UE requests a PDU session.
[0185] In some embodiments, when the first UE requests a PDU session, the second network device or the third network device determines that the first key will be provided to the first UE and sends a second indication to the first network device; otherwise, the second indication may not be provided to the first network device.
[0186] In some embodiments, if the first message is a PDU session establishment request or a PDU session update request, the second network device provides a second indication to the first network device.
[0187] In some embodiments, if the first message is a PDU session establishment request or a PDU session update request and it is determined to provide the first key to the first UE, the second network device or the third network device provides a second indication to the first network device; otherwise, the second indication may not be provided to the second network device.
[0188] In some embodiments, the second indication is used by the first network device to determine whether end-to-end security for UE-SAT-UE communication of the first UE needs to be activated.
[0189] In some embodiments, end-to-end security may include: UP end-to-end security and / or control plane (CP) end-to-end security.
[0190] In some embodiments, the second indication is used by the first network device to determine whether it is necessary to activate user plane UP end-to-end security of UE-SAT-UE communication of the first UE.
[0191] In some embodiments, the second indication may be a specific indication to activate the end-to-end security of the UE-SAT-UE communication of the first UE. After receiving the second indication, the second network device knows that the end-to-end security of the UE-SAT-UE communication of the first UE needs to be activated.
[0192] In some embodiments, if all PDU sessions using the first UE's UE-SAT-UE communication require UP security to be activated, the second network device may send a second indication to the first device specifically instructing the activation of end-to-end security for the first UE's UE-SAT-UE communication.
[0193] In some embodiments, the second indication may be used to indicate whether end-to-end security of UE-SAT-UE communication of the first UE is required. The first network device determines whether end-to-end security of UE-SAT-UE communication of the first UE needs to be activated based on the indication content of the second indication. For example, based on operator policy, some services based on UE-SAT-UE communication of the first UE may require activation of UP security, while some services using UE-SAT-UE communication of the first UE do not require activation of UP security. In this case, the second network device needs to determine whether to issue the second indication or the indication content of the second indication based on the service.
[0194] In some embodiments, S2104 may be an optional step. For example, the UE and the base station may determine whether UP security needs to be activated during UE-SAT-UE communication based on a pre-configuration method such as a protocol agreement. In this case, this step may be an optional step.
[0195] In some embodiments, when the first UE has the authority to conduct the PDU session based on UE-SAT-UE communication, the second network device sends a second indication to the first network device.
[0196] In some embodiments, the second network device receives information related to PDU session establishment sent or forwarded by the third network device. For example, the third network device sends information to the second network device only after determining that the first UE has the authority to conduct a PDU session based on UE-SAT-UE communication. After receiving the information sent by the third network device, the second network device deems that the first UE has the authority to conduct a PDU session based on UE-SAT-UE communication and sends a second indication to the first network device.
[0197] In some embodiments, the second network device receives information related to PDU session establishment sent or forwarded by the third network device. For example, the third network device sends information to the second network device only after determining that the first UE has the authority to conduct a PDU session based on UE-SAT-UE communication. After receiving the information sent by the third network device, the second network device deems that the first UE has the authority to conduct a PDU session based on UE-SAT-UE communication and sends a second indication to the first network device.
[0198] S2105: The first network device sends first information to the first UE.
[0199] In some embodiments, the first network device sends the first information to the first UE according to the second indication.
[0200] In some embodiments, the second indication is used to indicate whether to activate user plane UP end-to-end security of UE-SAT-UE communication of the first UE.
[0201] In some embodiments, the second indication indicates activation of end-to-end security for UE-SAT-UE communications of the first UE.
[0202] In some embodiments, the second indication indicates activation of UE end-to-end security for UE-SAT-UE communication of the first UE.
[0203] In some embodiments, when the second indication indicates activation of UP end-to-end security for UE-SAT-UE communication of the first UE, the first network device sends first information to the first UE.
[0204] In some embodiments, when the second indication indicates that UP end-to-end security for UE-SAT-UE communication of the first UE is not activated, the first network device does not send the first information to the first UE.
[0205] In some embodiments, when the second indication indicates activation of UP end-to-end security for UE-SAT-UE communication of the first UE, the first network device sends first information indicating activation of UP end-to-end security for UE-SAT-UE communication to the first UE.
[0206] In some embodiments, when the second indication indicates that UP end-to-end security for UE-SAT-UE communication of the first UE is not activated, the first network device sends first information indicating that UP end-to-end security for UE-SAT-UE communication is not activated to the first UE.
[0207] In some embodiments, the first information includes at least one of the following:
[0208] The first indication is used to indicate whether user plane UP end-to-end security of UE-SAT-UE communication is activated.
[0209] A parameter value, wherein the parameter value and the first key are used together to determine the second key.
[0210] If the parameter value and the first key are used together to generate the second key, the parameter value and the first key are used together as inputs of a key derivation function (KDF) to obtain the second key output by the KDF.
[0211] In some embodiments, the first indication may be optional content. For example, the first information includes a parameter value, which is equivalent to the first network device implicitly indicating activation of user plane UP end-to-end security of UE-SAT-UE communication through the parameter value.
[0212] In some embodiments, the parameter value may be optional. For example, the first UE may not use the parameter value when determining (generating) the second key based on the first key.
[0213] Exemplarily, the parameter value may be a count value of a specific counter of the first network device, a timing value of a specific timer, a random number, or a fresh value maintained by the first network device.
[0214] S2106: The first UE determines the second key based on the first key.
[0215] In some embodiments, the first UE determines the second key based on the first key and the parameter value.
[0216] In some embodiments, the first key is a root key for UE-SAT-UE communication.
[0217] In some embodiments, the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0218] In some embodiments, when the first indication is used to indicate activation of user plane UP end-to-end security for UE-SAT-UE communication, the second key is determined based on the first key.
[0219] In some embodiments, when the first indication is used to indicate that user plane UP end-to-end security for UE-SAT-UE communication is not activated, the second key does not need to be determined based on the first key.
[0220] In some embodiments, the first key may be a root key that can be used for one or more uses of the second key.
[0221] For example, one second key may be used for one PDU session.
[0222] For another example, a second key can be used for one business communication.
[0223] Of course, in some embodiments, the second key may be set with a validity period, and the second key may be used for one or more UE-SAT-UE communications within the validity period.
[0224] In some embodiments, transactions of different UE-SAT-UE communications may have different second keys.
[0225] In some embodiments, one service of UE-SAT-UE communication may have one second key.
[0226] In some embodiments, the second key comprises at least one of: an integrity key; a confidentiality key.
[0227] In some embodiments, if the first network device sends the first information to the first UE, the first UE determines the second key based on the first key after receiving the first information.
[0228] In some embodiments, if sending the first information by the first network device is an optional step, for example, the first UE defaults to UE-SAT-UE UP end-to-end security activation and does not need to receive parameter values from the first network device, then the first UE directly determines the second key based on the first key.
[0229] In some embodiments, the first UE determining the second key based on the first key may include at least one of the following:
[0230] Input the first key into KDF to obtain the second key output by KDF;
[0231] Input the first key and the length of the first key into the KDF to obtain the second key output by the KDF;
[0232] Input the first key and the parameter value into the KDF to obtain the second key output by the KDF;
[0233] The first key, the length of the first key, the parameter value, and the length of the parameter value are input into the KDF to obtain the second key output by the KDF.
[0234] In some embodiments, the second key can also be generated based on the type of the second key according to the algorithm type distinguisher and the first key; or, the second key can be generated based on the algorithm type distinguisher, the first key and the parameter value corresponding to the type of the second key.
[0235] For example, the algorithm type specifiers corresponding to the integrity key and / or confidentiality key are different.
[0236] As shown in FIG3 , an embodiment of the present disclosure provides a key processing method, which is performed by a first UE. The method may include:
[0237] S3101: Send the first message.
[0238] In some embodiments, the first message is related to UE-SAT-UE communication.
[0239] In some embodiments, the first message may be any NAS message.
[0240] In some embodiments, the registration authorization request message includes capability information of the first UE supporting UE-SAT-UE communication.
[0241] In some embodiments, the first message is a PDU session establishment request message for UE-SAT-UE communication.
[0242] In some embodiments, the first message may be a PDU session update request message for UE-SAT-UE communication.
[0243] In some embodiments, the first message may be used by the first UE to request the first key from the network side.
[0244] In some embodiments, the optional steps of S3101 may be referred to S2101 of the corresponding embodiment in Figure 2 .
[0245] In some embodiments, the first key may be pre-configured in a device or a subscriber identity module (SIM) of the first UE. In this case, the first UE does not need to request the first key through the first message.
[0246] S3102: Receive the second message.
[0247] In some embodiments, the first UE receives a second message sent by the second network device.
[0248] In some embodiments, the first UE receives the second message sent by the second network device when the first UE has authority.
[0249] In some embodiments, the relevant content of the second message may be referred to the embodiment of FIG. 2 and will not be repeated here.
[0250] It is worth noting that, for example, if the first UE does not send the first message requesting the first key, then S3102 can be omitted. For another example, if the second network device determines that the first UE does not have permission, then the first UE will not receive the second message either, and S3102 can also be omitted.
[0251] S3103: Receive the first information.
[0252] In some embodiments, the first information is used by the first UE to determine whether user plane UP end-to-end security of UE-SAT-UE communication is activated.
[0253] In some embodiments, the first information includes a first indication and / or parameter value.
[0254] The first indication is used to indicate whether to activate user plane UP end-to-end security for UE-SAT-UE communication.
[0255] In some embodiments, the first indication is used to indicate whether user plane UP end-to-end security of UE-SAT-UE communication is activated. In some embodiments, the first UE receives the first indication sent by the first network device.
[0256] In some embodiments, the description of the parameter value and the first indication can refer to the embodiment corresponding to FIG2 .
[0257] In some embodiments, S3103 may be an optional step. For example, if the first UE activates UP end-to-end security for UE-SAT-UE communication by default, there is no need to receive the first indication from the network side. For another example, if the first UE does not need to use a parameter value when generating the second key based on the first key, and does not need to obtain the parameter value from any network-side device such as the first network device, S3103 may be omitted.
[0258] S3104: Determine the second key based on the first key.
[0259] In some embodiments, the first key may be pre-configured on the first UE or a SIM of the first UE.
[0260] In some embodiments, the first key may also be agreed upon in advance by a protocol.
[0261] In some embodiments, the first key may be a root key for all UE-SAT-UE communications. In this case, the root key may be a key known to all UEs supporting UE-SAT-UE communication or UEs with UE-SAT-UE communication authority.
[0262] In some embodiments, the first key may be a root key for a service of UE-SAT-UE communication. In this case, the root key may be a key known to all UEs supporting the corresponding service of UE-SAT-UE communication or UEs with permission for the corresponding service of UE-SAT-UE communication.
[0263] In some embodiments, the first key may also be a key at the PDU session granularity or a key at the UE group granularity. For example, the UE group may be all UEs in a UE-SAT-UE communication. A key at the PDU session granularity indicates that the first key can be used for a single PDU session.
[0264] In some embodiments, the specific operation of S3104 can be found in S2106 of the corresponding embodiment of FIG. 2 .
[0265] It is worth noting that in some embodiments, S3104 can be performed separately. For example, if the first UE is pre-configured with the first key, S3104 can be performed separately, and S3101 to S3102 are optional steps. If the first UE defaults to UP end-to-end security activation for UE-SAT-UE communication and does not require the network to provide parameter values, S3103 can be omitted.
[0266] Some embodiments include: S3101, S3102 and S3104 can be performed in combination, that is, S3103 is an optional step.
[0267] Some embodiments include: S3103 and S3104 can be performed in combination.
[0268] As shown in FIG4 , an embodiment of the present disclosure provides a key processing method, which is executed by a first network device. The method may include:
[0269] S4101: Receive the second instruction.
[0270] In some embodiments, the first network device may be a base station.
[0271] In some embodiments, the first network device may be a satellite-borne base station.
[0272] In some embodiments, the first network device receives a second indication sent by the second network device.
[0273] In some embodiments, the second network device may be a core network device.
[0274] In some embodiments, the second network device may be a PCF or the like.
[0275] In some embodiments, the second indication is used to indicate whether to activate user plane UP end-to-end security of UE-SAT-UE communication of the first UE.
[0276] In some embodiments, the first network device receives a second indication sent by the second network device or the third network device.
[0277] In some embodiments, the second indication is received from the second network device or the third network device during the network registration of the first UE, the PDU session establishment process of the first UE, or the PDU session update process of the first UE.
[0278] S4102: Send the first message.
[0279] In some embodiments, the first network device sends first information to the first UE.
[0280] In some embodiments, the first network device determines that UP end-to-end security of UE-SAT-UE of the first UE needs to be activated, and sends first information to the first UE.
[0281] In some embodiments, the first network device determines that it is not necessary to activate UP end-to-end security for UE-SAT-UE communication of the first UE, and sends the first information to the first UE.
[0282] In some embodiments, the first network device determines whether to activate UP end-to-end security for UE-SAT-UE communication of the first UE based on the second indication. For example, the second indication is used to indicate activation of user plane UP end-to-end security for UE-SAT-UE communication of the first UE, thereby determining activation of UP end-to-end security for UE-SAT-UE communication of the first UE. For another example, the second indication is used to indicate deactivation of UP end-to-end security for UE-SAT-UE communication of the first UE, thereby determining deactivation of UP end-to-end security for UE-SAT-UE communication of the first UE.
[0283] In some embodiments, the first network device may also determine whether it is necessary to activate UP end-to-end security for the UE-SAT-UE communication of the first UE based on local configuration and in combination with one or more parameters such as the UE type of the first UE and / or the services involved in the requested UE-SAT-UE communication.
[0284] In some embodiments, if the first network device does not receive the second indication, it may determine whether to activate UP end-to-end security for UE-SAT-UE communication for the first UE based on the local configuration. If the first network device receives the second indication, the first network device determines whether to activate UP end-to-end security for UE-SAT-UE communication for the first UE based on the second indication. That is, the priority of the second indication is higher than the priority of the local configuration of the first network device.
[0285] In some embodiments, the first network device determines whether to send the first information according to the second indication.
[0286] In some embodiments, the first information includes at least one of the following:
[0287] A first indication, the first indication is used to indicate whether to activate user plane UP end-to-end security of UE-SAT-UE communication;
[0288] The parameter value and the first key are used together to determine the second key.
[0289] In some embodiments, the first information may include the first indication alone.
[0290] In some embodiments, the first information may include parameter values alone.
[0291] In some embodiments, the first information may include a first indication and a parameter value.
[0292] It is worth noting that: for the first information, reference can be made to the relevant description of the embodiment corresponding to FIG2 .
[0293] In some embodiments, S4101 may be an optional step. For example, the first network device may determine whether to activate UP end-to-end security for UE-SAT-UE communication of the first UE based on local configuration. That is, S4102 may be implemented separately or in combination.
[0294] As shown in FIG5 , an embodiment of the present disclosure provides a key processing method, which is performed by a second network device and includes:
[0295] S5101: Receive the first message.
[0296] In some embodiments, the second network device receives the first message from the first UE.
[0297] In some embodiments, the second network device receives the first message forwarded or transparently transmitted by the first network device and / or the third network device.
[0298] In some embodiments, the first message is related to UE-SAT-UE communication.
[0299] In some embodiments, the first message includes at least one of the following:
[0300] Registration authorization request message; the registration authorization request message includes capability information of the first UE supporting UE-SAT-UE communication;
[0301] PDU session establishment request message for UE-SAT-UE communication.
[0302] In some embodiments, for the relevant description of the first message, please refer to the relevant description of the embodiment corresponding to Figure 2.
[0303] S5102: Send the second message.
[0304] In some embodiments, the second message includes the first key.
[0305] The first key is the root key for UE-SAT-UE communication.
[0306] In some embodiments, the first key is used by the first UE to generate the second key.
[0307] In some embodiments, the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0308] In some embodiments, the second network device determines that the first UE is a legitimate terminal, for example, a UE that has signed a contract with a communication operator, and then sends a second message to the first UE.
[0309] In some other embodiments, it is determined whether the first UE has the authority, and if it is determined that the first UE has the authority, a second message is sent to the first UE.
[0310] In some embodiments, determining whether the first UE has permission may include at least one of the following:
[0311] determining whether the first UE has permission for UE-SAT-UE communication;
[0312] Determining whether the first UE has permission for UP end-to-end security of UE-SAT-UE communication.
[0313] In some embodiments, determining whether the first UE has the authority may include: determining whether the first UE has the authority based on capability information and / or subscription data of the first UE.
[0314] When the first UE has permission, a second message is sent to the first UE. The second message may be forwarded or transparently transmitted to the first UE by one or more network devices.
[0315] When the first UE does not have the authority, the second message is not sent to the first UE.
[0316] In some embodiments, when the first UE does not have permission, a rejection message or a failure message is sent to the first UE.
[0317] In some embodiments, there is no need to verify whether the first UE has permission, so after receiving the first message, the second message can be sent directly to the first UE.
[0318] In some embodiments, determining whether the first UE has the authority may be performed by a third network device. In this case, the second network device may receive information or a message indicating whether the first UE has the authority from the third network device.
[0319] It is worth noting that: for the specific implementation of S5102, please refer to S2103.
[0320] In some embodiments, if the second network device determines to send a second message to the first UE, it will also send a second indication to the first network device of the first UE. The second indication is used to indicate whether to activate the end-to-end security of the UE-SAT-UE communication of the first UE. Exemplarily, the second indication is used to indicate whether to activate the UP end-to-end security of the UE-SAT-UE communication of the first UE. It is worth noting that the step of the second network device sending the second indication is an optional step. For example, when the end-to-end security of the UE-SAT-UE communication is activated by default, or when the end-to-end security of the UE-SAT-UE communication does not need to be activated, the step of the second network device sending the second indication can be omitted. In some embodiments, the second indication can also be sent by a third network device to the first network device of the first UE, in which case the step of the second network device sending the second indication can also be omitted.
[0321] As shown in FIG6 , an embodiment of the present disclosure provides a key processing method, which is performed by a third network device and includes:
[0322] S6101: Receive the third message.
[0323] In some embodiments, the third network device may be an SMF, etc.
[0324] In some embodiments, the third message is used to request establishment of a PDU session for UE-SAT-UE communication between the first UE and at least one second UE.
[0325] In some embodiments, the third message may be any message for the first UE to request establishment of a PDU session.
[0326] S6102: Determine whether the first UE has permission.
[0327] In some embodiments, after receiving the third message, it is determined whether the first UE has authority.
[0328] In some embodiments, it is determined whether the first UE has permission for UE-SAT-UE communication.
[0329] In some embodiments, it is determined whether the first UE has end-to-end security authority for UE-SAT-UE communications.
[0330] In some embodiments, whether the first UE has permission is determined based on capability information and / or subscription information of the first UE.
[0331] In some embodiments, determining whether the first UE has permission based on the capability information and / or subscription information of the first UE may include but is not limited to at least one of the following:
[0332] The capability information of the first UE indicates that the first UE supports UE-SAT-UE communication and determines, based on the subscription information, whether the first UE has permission to subscribe to the UE-SAT-UE communication;
[0333] The capability information of the first UE indicates that the first UE does not support UE-SAT-UE communication and according to the subscription information, it is determined that the first UE does not have the authority.
[0334] In some embodiments, determining whether the first UE has permission to subscribe to UE-SAT-UE communication based on the subscription information may include, but is not limited to, at least one of the following:
[0335] Determining, based on the contract information, whether the first UE has permission to sign up for UE-SAT-UE communication;
[0336] According to the subscription information, it is determined whether the first UE has subscribed to the end-to-end security of UE-SAT-UE communication.
[0337] S6103: Determine whether to agree to establish a PDU session for UE-SAT-UE communication.
[0338] In some embodiments, whether to agree to establish a PDU session for UE-SAT-UE communication is determined based on whether the first UE has permission.
[0339] In some embodiments, the first UE has authority to determine and agree to establish a PDU session for UE-SAT-UE communication.
[0340] In some embodiments, the first UE does not have the authority and determines not to agree to establish a PDU session for UE-SAT-UE communication.
[0341] In some embodiments, the first UE has subscribed to UE-SAT-UE communication and determines to agree to establish a PDU session for UE-SAT-UE communication.
[0342] In some embodiments, the first UE has not subscribed to the UE-SAT-UE communication and determines not to agree to establish a PDU session for the UE-SAT-UE communication.
[0343] In some embodiments, the first UE has subscribed to end-to-end security for UE-SAT-UE communication and determines to agree to establish a PDU session for UE-SAT-UE communication.
[0344] In some embodiments, the first UE has not subscribed to the end-to-end security of the UE-SAT-UE communication and determines that it does not agree to establish the PDU session of the UE-SAT-UE communication.
[0345] In some embodiments, the first UE does not have the authority and determines not to agree to establish a PDU session for UE-SAT-UE communication.
[0346] S6104: Agree to establish a PDU session for UE-SAT-UE communication and send a PDU session establishment request message.
[0347] In some embodiments, the third network device agrees to establish a PDU session for UE-SAT-UE communication and sends a PDU session establishment request message to the second network device.
[0348] In some embodiments, the PDU session establishment request message causes the second network device to send a first key to the first UE. The first key is used by the first UE to determine the second key. In the embodiments of the present disclosure, for descriptions of the second network device, the first key, the second key, etc., please refer to the description of the embodiment corresponding to FIG. 2 .
[0349] In some embodiments, if the establishment of the PDU session for UE-SAT-UE communication is not agreed, no PDU session establishment request message is sent to the second network device, and the PDU session establishment fails.
[0350] In some embodiments, the method may further include:
[0351] Send a second instruction.
[0352] In some embodiments, the third network device sends a second indication to the first network device of the first UE.
[0353] In some embodiments, the second indication is used to indicate whether end-to-end security of UE-SAT-UE communication of the first UE is activated.
[0354] In some embodiments, the third network device agrees to establish the PDU session of the UE-SAT-UE communication and sends a second indication to the first network device; the second indication is used to indicate whether the end-to-end security of the UE-SAT-UE communication of the first UE is activated.
[0355] In some embodiments, the step of the third network device sending the second indication is optional. For example, the second indication may be sent by the second network device, or the step of the third network device sending the second indication may be omitted in scenarios where end-to-end security for UE-SAT-UE communication is activated by default or end-to-end security for UE-SAT-UE communication does not need to be activated.
[0356] It is worth noting that: if the second indication is sent by a third network device, the end-to-end security of the UE-SAT-UE communication can be reactivated each time the first UE establishes a PDU session, and the first UE will regenerate a second key. At this time, the validity period of the second key is equivalent to the duration of the corresponding PDU session. In this way, different PDU sessions of the first UE may have different second keys. In view of this, the embodiment of the present disclosure provides a key processing method that can improve the security of UE-SAT-UT communication. For example, UE1 and / or UE2 initiates a service authorization (Service Authorization and Provisioning) process to the core network, and the PCF sends it to UE1 and / or UE2 through AMF1 / AMF2 based on the contract information of UE1 and / or UE2. PCF can query the root key (K E2E ).
[0357] For example, the contract information may indicate that the UE has signed a contract with the operator for the root key (K E2E ).
[0358] UE1 and / or UE2 initiates a PDU session establishment procedure with the core network. During this procedure, the core network sends a first end-to-end indication of UE-SAT-UE communication to the gNB. For example, SMF1 / SMF2 determines end-to-end security protection for UE-SAT-UE communication based on session management subscription information or session management information.
[0359] When activating Uu interface UP security for UE1 and UE2 respectively, the gNB sends the first end-to-end indication of UE-SAT-UE communication to UE1 and UE2.
[0360] When activating Uu interface UP security for UE1 and UE2 respectively, the gNB sends the first end-to-end indication of UE-SAT-UE communication to UE1 and UE2. After receiving the first end-to-end indication of UE-SAT-UE communication from the gNB, UE1 and / or UE2 receive the root key (K) from the core network in step #1. E2E ) derives the key for end-to-end security protection of UP traffic.
[0361] The UP traffic exchanged between UE1 and UE2 via the gNB may be protected by a key for end-to-end security protection derived by UE1 and UE2. This key may be the aforementioned second key. For example, the second key may be a key for UP security protection. In some embodiments, the second key may also be a key for CP security protection. For example, the second key may include K UP_E2E_int and K UP_E2E_enc . K UP_E2E_intK is the integrity key of UP. UP_E2E_enc It is the confidentiality key of UP.
[0362] When the K E2E When deriving the key for end-to-end security protection of the UE-SAT-UE communication UP service, the following parameters are required to form the string S:
[0363] FC = To Be Determined (TBD);
[0364] P0 = algorithm type distinguisher;
[0365] L0 = length of algorithm type distinguisher;
[0366] P1 = algorithm identity;
[0367] L1 = length of algorithm identity;
[0368] For the E2E-UP encryption algorithm, the algorithm type identifier is E2E-UP-enc-alg;
[0369] For the E2E-UP integrity protection algorithm, the algorithm type identifier is E2E-UP-int-alg.
[0370] When setting the algorithm type specifier, 0x07 to 0xf0 are reserved for future use, and 0xf1 to 0xff are reserved for private use. Therefore, the values of E2E-UP-enc-alg and E2E-UP-int-alg are undetermined and range from 0x07 to 0xf0.
[0371] For the integrity key (K UP_E2E_int ) and the encryption key (K UP_E2E_enc ) is generated (i.e. derived), the input key should be the 256-bit K provided by the core network (such as PCF) E2E Alternatively, the root key (K E2E ) can be provided by the PCF to UE1 and / or UE2 via the SMF during the PDU session establishment process. The input key is the aforementioned first key.
[0372] During the service authorization and information issuance process, the core network function (NF) (such as PCF) should be able to send the root key (K E2E ).
[0373] The NF (e.g. PCF) should be able to send the root key (K E2E ).
[0374] The NF (e.g. SMF and / or PCF) shall be able to send a first indication to the gNB during PDU session establishment to activate end-to-end security for UE-SAT-UE communication.
[0375] The gNB shall be able to receive an indication from the core network to activate end-to-end security for UE-SAT-UE communication.
[0376] When Uu security is activated for a UE, the gNB shall be able to send an indication to the UE of end-to-end security for UE-SAT-UE communication.
[0377] The UE should be able to receive the root key (K) for end-to-end security of UE-SAT-UE communication from the core network (such as PCF). E2E ).
[0378] The UE needs to be able to obtain the root key (K E2E ) to derive the key for end-to-end security protection of UP.
[0379] As shown in FIG7A , an embodiment of the present disclosure provides a key processing method, which may include:
[0380] 1a. Authorization and authentication of UE1, during which the network device issues the root key for UE-SAT-UE communication.
[0381] 1b. Authorization and authentication of UE2, during which the network device issues the root key for UE-SAT-UE communication.
[0382] 2a. Establish a PDU session for UE1 and send an end-to-end security indication for UE-SAT-UE communication to the base station.
[0383] 2a. Establish a PDU session for UE2 and send an end-to-end security indication for UE-SAT-UE communication to the base station.
[0384] 3a. UP security activation for UE1.
[0385] 3b. UP security activation for UE2.
[0386] 4a.UE1 based on the root key (KE2E ) derive the UP key (K UP_E2E ).
[0387] 4b.UE2 based on the root key (K E2E ) derive the UP key (K UP_E2E ).
[0388] 5. Use K UP_E2E Protect UP traffic.
[0389] As shown in FIG7B , an embodiment of the present disclosure provides a key processing method, which may include:
[0390] 1. Establish a PDU session for UE1, send an end-to-end security indication for UE-SAT-UE communication to the base station, and send the root key (K E2E ).
[0391] 2. Establish a PDU session for UE2, send an end-to-end security indication for UE-SAT-UE communication to the base station, and send the root key (K E2E ).
[0392] 3a. UP security activation for UE1.
[0393] 3b. UP security activation for UE2.
[0394] 4a.UE1 based on the root key (K E2E ) derive the UP key (K UP_E2E ).
[0395] 4b.UE2 based on the root key (K E2E ) derive the UP key (K UP_E2E ).
[0396] 5. Use K UP_E2E Protect UP traffic.
[0397] In the embodiments of the present disclosure, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations of other embodiments.
[0398] In the embodiments of the present disclosure, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations of other embodiments.
[0399] The embodiments of the present disclosure also provide an apparatus for implementing any of the above methods. For example, an apparatus is provided, comprising units or modules for implementing each step performed by a terminal in any of the above methods. For another example, another apparatus is provided, comprising units or modules for implementing each step performed by a network device (e.g., an access network device or a core network device) in any of the above methods.
[0400] It should be understood that the division of the various units or modules in the above devices is merely a division of logical functions. In actual implementation, they may be fully or partially integrated into a physical entity, or they may be physically separated. In addition, the units or modules in the device may be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above devices, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), which realizes the functions of some or all of the above units or modules by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.
[0401] In the embodiments of the present disclosure, a processor is a circuit with signal processing capabilities. In one implementation, the processor may be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of a hardware circuit. The logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration file to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DLP), or a similar hardware circuit. Unit, DPU) etc.
[0402] As shown in FIG8A , an embodiment of the present disclosure provides a first UE, including:
[0403] The processing module 7101 is configured to determine a second key based on the first key; the first key is a root key for UE-SAT-UE communication; and the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0404] In some embodiments, the processing module may be used for the first UE to execute information processing related steps in any key processing method.
[0405] In some embodiments, the first UE may further include: a sending module and / or a receiving module.
[0406] In some embodiments, the sending module and / or the receiving module may correspond to a network interface and / or a transceiver antenna of the first UE.
[0407] In some embodiments, the sending module may be used by the first UE to execute steps related to information sending in any key processing method.
[0408] In some embodiments, the receiving module may be used by the first UE to execute steps related to information sending in any key processing method.
[0409] A receiving module configured to receive first information sent by a first network device; the first information is used by the first UE to determine whether to activate user plane UP end-to-end security of UE-SAT-UE communication;
[0410] Determining the second key according to the first key includes: determining the second key according to the first key when UP end-to-end security is activated.
[0411] In some embodiments, the first information further includes at least one of the following:
[0412] A first indication, the first indication is used to indicate whether to activate user plane UP end-to-end security of UE-SAT-UE communication;
[0413] The parameter value and the first key are used together to determine the second key.
[0414] In some embodiments, the processing module is configured to perform at least one of the following:
[0415] generating a second key based on the first key and the parameter value;
[0416] A second key is generated based on the first key.
[0417] In some embodiments, the sending module is configured to send a first message to the second network device; the first message is related to UE-SAT-UE communication;
[0418] The receiving module is configured to receive a second message sent by the second network device; the second message includes the first key.
[0419] In some embodiments, the first message includes at least one of the following:
[0420] Registration authorization request message; the registration authorization request message includes capability information of the first UE supporting UE-SAT-UE communication;
[0421] PDU session establishment request message for UE-SAT-UE communication.
[0422] In some embodiments, the second key includes at least one of the following:
[0423] Integrity key;
[0424] Confidentiality key.
[0425] FIG8B is a second network device provided by an embodiment of the present disclosure, including:
[0426] The processing module 7201 is configured to determine a first key; the first key is a root key for UE-SAT-UE communication; the first key is used by the first UE to generate a second key; UE-SAT-UE communication.
[0427] In some embodiments, the second network device may further include a sending module and / or a receiving module.
[0428] In some embodiments, the processing module may be configured to execute any steps related to information processing in the key processing method executed by the second network device.
[0429] In some embodiments, the sending module and / or the receiving module may correspond to a network interface and / or a transceiver antenna of the second network device.
[0430] In some embodiments, the receiving module is configured to receive a first message sent by a first UE; the first message is related to UE-SAT-UE;
[0431] The sending module is configured to send a second message to the first UE; the second message includes the first key.
[0432] The first message is a registration authorization request message; the registration authorization request message includes capability information of the first UE; the sending module is also configured to send a second message to the first UE based on the capability information of the first UE indicating whether the first UE supports UE-SAT-UE communication or whether the first UE supports end-to-end security of UE-SAT-UE communication.
[0433] In some embodiments, the sending module is configured to perform at least one of the following:
[0434] The first message is a PDU session establishment request message for UE-SAT-UE communication, and the second network device determines that the first UE has permission for UE-SAT-UE communication, and sends a second message to the first UE;
[0435] The first message is a PDU session establishment request message for UE-SAT-UE communication, and the second network device determines that it has end-to-end security authority for UE-SAT-UE communication, and sends a second message to the first UE;
[0436] The first message is a PDU session establishment request message for UE-SAT-UE communication, and the third network device agrees to establish a PDU session for UE-SAT-UE communication for the first UE, and sends a second message to the first UE.
[0437] In some embodiments, the processing module is configured to determine whether the first UE has signed up for UE-SAT-UE communication based on the contract information of the first UE; if the first UE has signed up for UE-SAT-UE communication, determine to send a second message to the first UE.
[0438] In some embodiments, the processing module is configured to determine, based on the subscription information of the first UE, whether the first UE has subscribed to the end-to-end security of UE-SAT-UE communication;
[0439] The first UE subscribes to the end-to-end security of UE-SAT-UE communication and determines to send a second message to the first UE.
[0440] In some embodiments, the sending module is configured to send a second indication to the first network device connected to the first UE, where the second indication is used to indicate whether to activate user plane UP end-to-end security of UE-SAT-UE communication of the first UE.
[0441] In some embodiments, the sending module is configured to establish a PDU session for UE-SAT-UE communication for the first UE, and send a second indication to a first network device accessed by the first UE.
[0442] As shown in FIG8C , an embodiment of the present disclosure provides a first network device, including:
[0443] The sending module 7301 is configured to send first information to a first user equipment UE; the first information includes at least first information; the first information is at least used to indicate whether end-to-end security of user equipment to satellite to user equipment UE-SAT-UE communication is activated, so that the first UE generates a second key based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and at least one second UE.
[0444] In some embodiments, the first network device may further include a receiving module and / or a processing module.
[0445] In some embodiments, the processing module may be configured to execute any steps related to information processing in the key processing method executed by the first network device.
[0446] In some embodiments, the sending module and / or the receiving module may correspond to a network interface and / or a transceiver antenna of the first network device.
[0447] In some embodiments, the receiving module is configured to receive a second indication sent by a second network device or a third network device; the second indication is used to indicate whether end-to-end security of UE-SAT-UE communication of the first UE is activated; the sending module is configured to send first information to the first UE to determine whether user plane UP end-to-end security protection of UE-SAT-UE communication of the first UE needs to be activated. In some embodiments, the first information further includes at least one of the following:
[0448] a first indication, where the first indication is used to indicate whether to activate end-to-end security of the UE-SAT-UE communication;
[0449] A parameter value, wherein the parameter value and the first key are used together to determine the second key.
[0450] As shown in FIG8D , an embodiment of the present disclosure provides a third network device, comprising:
[0451] The receiving module 7401 is configured to receive a third message from the first UE; the third message is used to request establishment of a PDU session for UE-SAT-UE communication between the first UE and at least one second UE;
[0452] The processing module 7402 is configured to determine whether the first UE has permission for UE-SAT-UE communication or has end-to-end security permission for UE-SAT-UE communication; the first UE has permission for UE-SAT-UE communication or has end-to-end security permission for UE-SAT-UE communication, and determine to agree to establish a PDU session for UE-SAT-UE communication;
[0453] The sending module 7403 is configured to agree to establish a PDU session for UE-SAT-UE communication and send a PDU session establishment request message to the second network device; the PDU session establishment request message is used by the second network device to provide a first key to the first UE; the first key is the root key for UE-SAT-UE communication; the second key is used for end-to-end security protection of UE-SAT-UE communication between the first UE and at least one second UE.
[0454] In some embodiments, the third network device may further include a receiving module and / or a processing module.
[0455] In some embodiments, the processing module may be configured to execute any steps related to information processing in the key processing method executed by the third network device.
[0456] In some embodiments, the sending module and / or the receiving module may correspond to a network interface and / or a transceiver antenna of a third network device.
[0457] In some embodiments, the sending module is further configured to agree to establish the PDU session of the UE-SAT-UE communication and send a second indication to the first network device; the second indication is used to indicate whether the end-to-end security of the UE-SAT-UE communication of the first UE is activated.
[0458] An embodiment of the present disclosure further provides a communication device, which may include: one or more processors; wherein the processor is used to call instructions to enable the communication device to execute a key processing method that can be implemented in any of the aforementioned embodiments.
[0459] 9A and / or 9B , the communication device 8100 further includes one or more memories 8102 for storing instructions. Alternatively, all or part of the memories 8102 may be located outside the communication device 8100.
[0460] The communication device may be the aforementioned terminal and network device. In some embodiments, the network device may be a master node and / or an auxiliary node.
[0461] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the communication steps such as sending and receiving in the above method are performed by the transceiver 8103, and the other steps are performed by the processor 8101.
[0462] In some embodiments, a transceiver may include a receiver and a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, and transceiver circuit may be used interchangeably; the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be used interchangeably; and the terms receiver, receiving unit, receiver, and receiving circuit may be used interchangeably.
[0463] Optionally, the communication device 8100 further includes one or more interface circuits 8104, which are connected to the memory 8102. The interface circuits 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuits 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0464] The communication device 8100 in the above embodiment description may be a network device or a terminal, but the scope of the communication device 8100 described in this disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 9A. The communication device may be a stand-alone device or may be part of a larger device. For example, the communication device can be: (1) an independent integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs. Optionally, the above-mentioned IC collection can also include storage components for storing data and programs; (3) ASIC, such as modulation Demodulator (Modem); (4) Modules that can be embedded in other equipment; (5) Receivers, terminal equipment, intelligent terminal equipment, cellular phones, wireless equipment, handheld machines, mobile units, vehicle-mounted equipment, network equipment, cloud equipment, artificial intelligence equipment, etc.; (6) Others, etc.
[0465] 9B is a schematic diagram of the structure of the chip 8200 provided in an embodiment of the present disclosure. If the communication device 8100 can be a chip or a chip system, please refer to the schematic diagram of the structure of the chip 8200 shown in FIG9B , but the present disclosure is not limited thereto.
[0466] The chip 8200 includes one or more processors 8201, and the processor 8201 is used to call instructions to enable the chip 8200 to execute any of the above key processing methods.
[0467] In some embodiments, the chip 8200 also includes one or more interface circuits 8202. The interface circuit 8202 is connected to the memory 8203. The interface circuit 8202 can be used to receive signals from the memory 8203 or other devices. The interface circuit 8202 can be used to send signals to the memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201. Optionally, terms such as interface circuit, interface, transceiver pin, and transceiver may be interchanged.
[0468] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Alternatively, all or part of the memories 8203 may be outside the chip 8200.
[0469] The present disclosure also provides a storage medium. Instructions are stored on the storage medium. When the instructions are run on the communication device 8100, the communication device 8100 is caused to perform any of the above methods. Optionally, the above storage medium is an electronic storage medium. Optionally, the above-mentioned storage medium is a computer-readable storage medium, but it may also be a storage medium readable by other devices. Optionally, the above storage medium may be a non-transitory storage medium, but may also be a transitory storage medium.
[0470] The present disclosure further provides a program product, which, when executed by the communication device 8100, enables the communication device 8100 to perform any of the above key processing methods. Optionally, the program product is a computer program product.
[0471] The present disclosure also provides a computer program, which, when executed on a computer, enables the computer to execute any one of the above key processing methods.
[0472] Other embodiments of the presently disclosed embodiments will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the presently disclosed embodiments that follow the general principles of the presently disclosed embodiments and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered as exemplary only, with the true scope and spirit of the presently disclosed embodiments being indicated by the following claims.
[0473] It should be understood that the embodiments of the present disclosure are not limited to the precise structures described above and shown in the drawings, and various modifications and changes can be made without departing from the scope thereof. The scope of the embodiments of the present disclosure is limited only by the appended claims.
Claims
1. A key processing method, wherein, Performed by a first user equipment UE, the method includes: Determine a second key according to a first key; the first key is the root key for user equipment to satellite to user equipment UE-SAT-UE communication; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and at least one second UE.
2. The method according to claim 1, wherein, The method further includes: Receive first information sent by a first network device; the first information is at least used for the first UE to determine whether to activate the end-to-end security of the UE-SAT-UE communication. The determining the second key according to the first key includes: when the end-to-end security of the UE-SAT-UE communication is activated, determining the second key according to the first key.
3. The method according to claim 2, wherein The first information further includes at least one of the following: A first indication, the first indication is used to indicate whether to activate the end-to-end security of the UE-SAT-UE communication. A parameter value, the parameter value and the first key are jointly used to determine the second key.
4. The method according to claim 3, wherein The determining the second key according to the first key when the end-to-end security of the UE-SAT-UE communication is activated includes at least one of the following: Generate the second key according to the first key and the parameter value. Generate the second key according to the first key.
5. The method according to any one of claims 1 to 4, wherein, The method includes: Send a first message to a second network device; the first message is related to the UE-SAT-UE communication. Receive a second message sent by the second network device; the second message includes the first key.
6. The method according to claim 5, wherein, The first message includes at least one of the following: A registration authorization request message; the registration authorization request information includes the capability information of the first UE supporting UE-SAT-UE communication. A protocol data unit PDU session establishment request message of the UE-SAT-UE communication.
7. The method according to any one of claims 1 to 6, wherein The second key includes at least one of the following: An integrity key. A confidentiality key.
8. A key processing method, wherein, Performed by a second network device, the method includes: Determine a first key; the first key is the root key for user equipment to satellite to user equipment UE-SAT-UE communication; the first key is used for a first user equipment UE to generate a second key; user equipment to satellite to user equipment UE-SAT-UE communication.
9. The method according to claim 8, wherein, The method further includes: Receive the first message sent by the first UE; the first message is related to the UE-SAT-UE. Send a second message to the first UE; the second message includes the first key.
10. The method according to claim 9, wherein The first message is a registration authorization request message; the registration authorization request message includes the capability information of the first UE; the sending the second message to the first UE includes: If the capability information of the first UE indicates whether the first UE supports the UE-SAT-UE communication or whether the first UE supports the end-to-end security of the UE-SAT-UE communication, send a second message including to the first UE.
11. The method according to claim 9, wherein, The sending the second message to the first UE includes at least one of the following; The first message is a protocol data unit (PDU) session establishment request message for the UE-SAT-UE communication, and when the second network device determines that the first UE has the permission for the UE-SAT-UE communication, the second network device sends the second message to the first UE; The first message is a protocol data unit (PDU) session establishment request message for the UE-SAT-UE communication, and when the second network device determines that the first UE has the end-to-end security permission for the UE-SAT-UE communication, the second network device sends the second message to the first UE; The first message is a protocol data unit (PDU) session establishment request message for the UE-SAT-UE communication, and when the third network device agrees to establish a PDU session for the UE-SAT-UE communication for the first UE, the third network device sends the second message to the first UE.
12. The method according to claim 9 or 10, wherein The method further includes: Determining whether the first UE subscribes to the UE-SAT-UE communication according to the subscription information of the first UE; When the first UE subscribes to the UE-SAT-UE communication, determining to send the second message to the first UE.
13. The method according to claim 9 or 10, wherein, The method further includes: Determining whether the first UE subscribes to the end-to-end security of the UE-SAT-UE communication according to the subscription information of the first UE; When the first UE subscribes to the end-to-end security of the UE-SAT-UE communication, determining to send the second message to the first UE.
14. The method according to any one of claims 7 to 13, wherein The method further includes: Sending a second indication to a first network device connected to the first UE, where the second indication is used to indicate whether to activate the user plane (UP) end-to-end security of the UE-SAT-UE communication of the first UE.
15. The method according to claim 12, wherein, The sending the second indication to a first network device connected to the first UE includes: Establishing a PDU session for the UE-SAT-UE communication for the first UE, and sending the second indication to the first network device accessed by the first UE.
16. A key processing method, wherein, Executed by a first network device, the method includes: Sending first information to a first user equipment (UE); the first information at least includes first information; the first information is at least used to indicate whether the end-to-end security of the user equipment to satellite to user equipment (UE-SAT-UE) communication is activated, so that the first UE generates a second key according to a first key; the second key is used for the end-to-end security protection between the first UE and at least one second UE for the user equipment to satellite to user equipment (UE-SAT-UE) communication.
17. The method according to claim 16, wherein, The method includes: Receiving a second indication sent by a second network device or a third network device; the second indication is used to indicate whether the end-to-end security of the UE-SAT-UE communication of the first UE is activated; The sending the first information to a first user equipment (UE) includes: According to whether it is necessary to activate the end-to-end security protection of the UE-SAT-UE communication of the first UE, sending the first information to the first UE.
18. The method according to claim 16 or 17, wherein The first information further includes at least one of the following: A first indication, where the first indication is used to indicate whether to activate the end-to-end security of the UE-SAT-UE communication; A parameter value, which is used together with the first key to determine the second key.
19. A key processing method, wherein, Performed by a third network device, the method includes: Receiving a third message from a first user equipment (UE); the third message is used to request the establishment of a protocol data unit (PDU) session for user equipment to satellite to user equipment (UE-SAT-UE) communication between the first UE and at least one second UE; Determining that the first UE has the permission for UE-SAT-UE communication or has the end-to-end security permission for UE-SAT-UE communication; Based on the fact that the first UE has the permission for UE-SAT-UE communication or has the end-to-end security permission for UE-SAT-UE communication, determining to consent to establish the PDU session for UE-SAT-UE communication; Consenting to establish the PDU session for UE-SAT-UE communication, and sending a PDU session establishment request message to a second network device; the PDU session establishment request message is used for the second network device to provide a first key to the first UE; the first key is the root key for user equipment to satellite to user equipment (UE-SAT-UE) communication; the second key is used for the end-to-end security protection of user equipment to satellite to user equipment (UE-SAT-UE) communication between the first UE and at least one second UE.
20. The method according to claim 19, wherein, The method further includes: Consenting to establish the PDU session for UE-SAT-UE communication, and sending a second indication to a first network device; the second indication is used to indicate whether the end-to-end security of the UE-SAT-UE communication of the first UE is activated.
21. A first user equipment UE, wherein, Includes: A processing module, configured to determine a second key according to a first key; The first key is the root key for user equipment to satellite to user equipment (UE-SAT-UE) communication; The second key is used for the end-to-end security protection of user equipment to satellite to user equipment (UE-SAT-UE) communication between the first UE and at least one second UE.
22. A second network device, wherein, Includes: A processing module, configured to determine a first key; The first key is the root key for user equipment to satellite to user equipment (UE-SAT-UE) communication; The first key is used for a first user equipment (UE) to generate a second key; for user equipment to satellite to user equipment (UE-SAT-UE) communication.
23. A first network device, wherein, Includes: A sending module, configured to send first information to a first user equipment (UE); The first information at least includes a first indication; The first indication is used to indicate whether the end-to-end security of user equipment to satellite to user equipment (UE-SAT-UE) communication is activated, so that the first UE generates a second key according to the first key; The second key is used for the end-to-end security protection of user equipment to satellite to user equipment (UE-SAT-UE) communication between the first UE and at least one second UE.
24. A third network device, wherein, Includes: A receiving module, configured to receive a third message from a first user equipment (UE); The third message is used to request the establishment of a protocol data unit (PDU) session for user equipment to satellite to user equipment (UE-SAT-UE) communication between the first UE and at least one second UE; A processing module, configured to determine that the first UE has the permission for the UE-SAT-UE communication or has the end-to-end security permission for the UE-SAT-UE communication; when the first UE has the permission for the UE-SAT-UE communication or has the end-to-end security permission for the UE-SAT-UE communication, determine to consent to establish a PDU session for the UE-SAT-UE communication. A sending module, configured to consent to establish a PDU session for the UE-SAT-UE communication and send a PDU session establishment request message to a second network device. The PDU session establishment request message is used for the second network device to provide a first key to the first UE; the first key is the root key for the user equipment to satellite to user equipment (UE-SAT-UE) communication. The second key is used for end-to-end security protection of the user equipment to satellite to user equipment (UE-SAT-UE) communication between the first UE and at least one second UE.
25. A communication device, wherein, The communication device includes: One or more processors; Wherein, the processor is used to call instructions to cause the communication device to execute the transmission method of the downlink control information (DCI) described in any one of claims 1 to 7, 8 to 15, 16 to 18, and / or claims 19 to 20.
26. A storage medium, wherein, The storage medium stores instructions, which, when running on the communication device, cause the communication device to execute the transmission method of the downlink control information (DCI) described in any one of claims 1 to 7, 8 to 15, 16 to 18, and / or claims 19 to 20.
Citation Information
Patent Citations
Satellite communication system, authentication method and device
CN115776673A
Beidou short message encryption communication system based on quantum key
CN117098123A
Satellite navigation signal credible authentication protocol and terminal credible positioning method and device
CN117310755A
Authentication of satellite navigation system receiver
US20180372878A1