Communication method and apparatus
By enabling the terminal device to generate security context and derive keys in the ATSSS-lite architecture, the problem of data transmission without the participation of N3IWF and TNGF is solved, and fast and secure non-3GPP access data transmission is achieved.
Patent Information
- Application Number
- PCT/CN2025/086859
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-03
- Filing Date
- 2025-04-02
- Publication Date
- 2025-10-09
AI Technical Summary
In the ATSSS scenario, how can the terminal device establish a direct data transmission connection with the core network through non-3GPP access without the participation of N3IWF and TNGF network elements?
When the terminal device registers with the core network via 3GPP access, it generates a security context, derives the first key, and establishes a connection with the user plane network element via non-3GPP access to directly transmit data, avoiding repeated authentication and key negotiation processes.
It realizes fast, secure and low signaling overhead data transmission connection between terminal devices and user plane network elements under the ATSSS-lite architecture.
Smart Images

Figure CN2025086859_09102025_PF_FP_ABST
Abstract
Description
Communication method and device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on April 3, 2024, with application number 202410412899.1 and application name “A Communication Method and Device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communications, and more particularly, to a communication method and apparatus. Background Art
[0003] In access traffic steering, switching, and splitting (ATSSS) scenarios, terminal devices can register with the core network through two paths, namely, 3GPP access and non-3GPP access, and subsequently transmit data through these two paths. In the existing network architecture, untrusted non-3GPP access networks connect to the core network through the non-3GPP interworking function (N3IWF) network element, while trusted 3GPP access networks connect to the core network through the trusted non-3GPP gateway function (TNGF) network element. The registration of terminal devices to the core network through non-3GPP access and the transmission of data between the terminal devices and the core network through non-3GPP access require the participation of N3IWF network elements or TNGF network elements.
[0004] To simplify operations on non-3GPP access paths in ATSSS scenarios, the industry has proposed a new ATSSS network architecture. In this architecture, non-3GPP access networks can provide direct connections between terminal devices and the core network, eliminating the need for intermediate network elements such as the N3IWF and TNGF elements. When the N3IWF and TNGF elements are removed, the challenge remains how terminal devices can establish connections with the core network to transmit data via non-3GPP access. Summary of the Invention
[0005] Embodiments of the present application provide a communication method and apparatus that can establish a connection between a terminal device and a core network via non-3GPP access to transmit data in a network architecture where a non-3GPP access network provides a direct connection between the terminal device and the core network.
[0006] In a first aspect, a communication method is provided, which can be executed by a terminal device, or by a chip or circuit of the terminal device, which is not limited in this application. For ease of description, the following description is based on an example of execution by a terminal device.
[0007] The method includes: generating a security context during registration with a core network through a 3rd Generation Partnership Project 3GPP access network; sending a session establishment request message through the 3GPP access network, the session establishment request message being used to request establishment of a session, the session being used for a terminal device to transmit data with a user plane network element in the core network through the 3GPP access network and a non-3GPP access network; receiving a session establishment response message, the session establishment response message being used to indicate successful session establishment; deriving a first key based on the security context in response to the session establishment response message; and establishing a first connection between the terminal device and the user plane network element based on the first key, the first connection being used for the terminal device to transmit session data with the user plane network element through the non-3GPP access network.
[0008] For the sake of convenience, the network architecture in which a non-3GPP access network provides a direct connection between a terminal device and a core network is referred to as the ASSS-lite architecture.
[0009] Based on this method, after registering with the core network through 3GPP access and successfully establishing a session, the terminal device can derive a first key based on the 3GPP security context and use the first key to directly establish a data transmission connection with the user plane network element through non-3GPP access. This method does not require the participation of the N3IWF network element and the TNGF network element, nor does it require the terminal device to perform repeated authentication and key agreement (AKA) processes with the core network. This helps the terminal device to quickly and easily establish a connection with the user plane network element for data transmission through non-3GPP access under the ATSSS-lite architecture.
[0010] With reference to the first aspect, in certain implementations of the first aspect, the session establishment response message includes first address information on the user plane network element side, where the first address information is used by the terminal device to communicate with the user plane network element via the non-3GPP access network. In this way, the terminal device can obtain the first address information from the session establishment response message, facilitating subsequent communication with the user plane network element via the non-3GPP access network. For example, the terminal device can use the first address information to initiate establishment of a first connection with the user plane network element.
[0011] In combination with the first aspect, in some implementations of the first aspect, deducing the first key according to the security context includes: when the session establishment response message includes the first address information, deducing the first key according to the security context.
[0012] It should be understood that in the prior art, the session establishment response message does not include the first address information. When the session establishment response message includes the first address information, the terminal device can determine that the current architecture is the ATSSS-lite architecture and then derive the first key based on the 3GPP security context. In this way, the first address information can also be used to implicitly trigger the terminal device to derive the first key. This single information can serve multiple purposes, helping to improve communication efficiency.
[0013] In conjunction with the first aspect, in certain implementations of the first aspect, the session establishment response message includes first indication information, where the first indication information is used to indicate that the non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element. The first indication information helps the terminal device accurately determine that the current architecture is the ASSSS-lite architecture.
[0014] In conjunction with the first aspect, in certain implementations of the first aspect, deriving the first key based on the security context includes: when the session establishment response message includes first indication information, deriving the first key based on the security context. For example, the terminal device determines that the current architecture is the ATSSS-lite architecture based on the first indication information, and then derives the first key based on the 3GPP security context. That is, the first indication information can be used to trigger the terminal device to derive the first key.
[0015] In combination with the first aspect, in certain implementations of the first aspect, deducing the first key based on the security context includes: deducing the first key based on the security context, identification information of the session and identification information of the terminal device; or, deducing the first key based on the security context and second address information on the user plane network element side, the second address information being used for the terminal device to communicate with the user plane network element through the 3GPP access network.
[0016] The session identification information and the terminal device identification information can uniquely identify the session requested by the terminal device. The second address information can also uniquely identify the session. The first key obtained by the above method is uniquely bound to the session, which can achieve session-level security isolation and provide higher security. The first key can also be called a session key.
[0017] In conjunction with the first aspect, in certain implementations of the first aspect, deducing the first key according to the security context includes: deducing the first key according to K in the security context AMF , K AUSF , or K SEAF Deducing the first key. K AMF , K AUSF , or K SEAF The key is generated when the terminal device registers to the core network through 3GPP access, and the terminal device shares these keys with the core network. The terminal device uses KAMF , K AUSF , or K SEAF By calculating the first key using the generated key, there is no need to perform the AKA process with the core network, which can reduce the signaling overhead and processing complexity of the terminal device while ensuring security.
[0018] In combination with the first aspect, in certain implementations of the first aspect, establishing a first connection between the terminal device and the user plane network element based on a first key includes: establishing an Internet Protocol Security IPsec connection between the terminal device and the user plane network element based on the first key; when the IPsec connection is successfully established and the first condition is met, establishing a Multipath Fast User Datagram Protocol Internet Connection MPQUIC connection between the terminal device and the user plane network element; wherein the first condition includes: at least one of the one or more ATSSS rules in the session establishment response message indicates the use of the MPQUIC function to guide, switch and split the data of the session. The IPsec connection can improve the security of data transmitted between the terminal device and the user plane network element through the non-3GPP access network. The terminal device and the user plane network element also establish an MPQUIC connection on demand, which can achieve differentiated guidance, switching and splitting of different data.
[0019] In combination with the first aspect, in certain implementations of the first aspect, establishing an IPsec connection between the terminal device and the user plane network element based on the first key includes: establishing the IPsec connection based on the first key when the second condition is met.
[0020] The second condition includes any of the following:
[0021] (1) At least one of the one or more ATSSS rules in the session establishment response message indicates that the multipath transmission control protocol MPTCP function or the ATSSS lower layer ATSSS-LL function is used to guide, switch, and split the session data;
[0022] (2) The session establishment response message includes information indicating that an IPsec connection needs to be established; or
[0023] (3) The session establishment response message does not include information indicating that there is no need to establish an IPsec connection.
[0024] In combination with the first aspect, in certain implementations of the first aspect, establishing an IPsec connection between a terminal device and a user-plane network element based on a first key includes: performing identity authentication with the user-plane network element based on the first key or a second key, the second key being obtained based on the first key. Based on the shared first key or the second key obtained based on the first key, when establishing an IPsec connection between the terminal device and the user-plane network element through non-3GPP access, a shared key message authentication code mode may be used for identity authentication. Compared to the authentication method of the Extensible Authentication Protocol (EAP) adopted in the prior art, this method does not require the participation of a session management network element and an authentication service network element, thereby simplifying the process and reducing signaling overhead.
[0025] In conjunction with the first aspect, in certain implementations of the first aspect, when identity authentication is performed with a user-plane network element based on the second key, the method further includes: obtaining the second key based on the first key and IPsec connection indication information. The IPsec connection indication information helps distinguish the second key from other keys obtained based on the first key and used to establish other connections.
[0026] In combination with the first aspect, in certain implementations of the first aspect, establishing an MPQUIC connection between a terminal device and a user-plane network element includes: performing identity authentication with the user-plane network element based on a first key or a fourth key, the fourth key being obtained based on any one of the following keys: the first key, the second key, or the third key; wherein the second key is used to perform identity authentication with the user-plane network element during the process of establishing an IPsec connection, and the third key is used to securely protect data transmitted through the IPsec connection.
[0027] Based on the shared first key or the fourth key obtained according to the first key, the terminal device and the user-plane network element can use the pre-shared key mode for identity authentication when establishing an MPQUIC connection through non-3GPP access, which simplifies the process and reduces signaling overhead.
[0028] In combination with the first aspect, in some implementations of the first aspect, establishing a first connection between the terminal device and the user plane network element according to the first key includes: establishing an MPQUIC connection between the terminal device and the user plane network element according to the first key.
[0029] For example, the session response message includes indication information for instructing the terminal device to skip the IPsec connection establishment and directly establish the MPQUIC connection, or the session response message includes indication information for indicating that there is no need to establish an IPsec connection, and the terminal device responds to the indication information and establishes the MPQUIC connection according to the first key.
[0030] The terminal device skips the IPsec connection establishment and directly establishes the MPQUIC connection, which helps to avoid the terminal device and the user-plane network element from performing repeated identity authentication during the process of establishing the first connection. It also helps to avoid the terminal device and the user-plane network element from performing redundant security protection on the data transmitted through the MPQUIC connection, and helps to reduce the processing complexity of the terminal device and the user-plane network element.
[0031] With reference to the first aspect, in certain implementations of the first aspect, establishing an MPQUIC connection between a terminal device and a user-plane network element based on the first key includes: authenticating the terminal device with the user-plane network element based on the first key or a fourth key, where the fourth key is derived based on the first key. Based on the shared first key or the fourth key derived based on the first key, the terminal device and the user-plane network element may use a pre-shared key mode for authentication when establishing the MPQUIC connection via a non-3GPP access, thereby simplifying the process and reducing signaling overhead.
[0032] In conjunction with the first aspect, in certain implementations of the first aspect, when identity authentication is performed with a user plane network element based on the fourth key, the method further includes: obtaining the fourth key based on the first key and MPQUIC connection indication information. The MPQUIC connection indication information helps distinguish the second key from other keys obtained based on the first key and used to establish other connections.
[0033] In conjunction with the first aspect, in certain implementations of the first aspect, the session establishment request message includes information indicating that a non-3GPP access network is used to directly connect the terminal device to the user plane network element. This information helps the recipient of the session establishment request message accurately know that the current network architecture is the ASSSS architecture. Exemplarily, this information can trigger the access and mobility management network element to obtain the first key and / or select a session management network element that supports the ASSSS-lite architecture.
[0034] In a second aspect, a communication method is provided, which can be executed by a user plane network element, or by a chip or circuit of the user plane network element, which is not limited in this application. For ease of description, the following description is based on an example of execution by a user plane network element.
[0035] The method includes: receiving a first key during a process of establishing a session between a terminal device and a user-plane network element through a 3GPP access network, where the session is used for the user-plane network element to transmit data with the terminal device through the 3GPP access network and a non-3GPP access network; and establishing a first connection between the user-plane network element and the terminal device based on the first key, where the first connection is used for the user-plane network element to transmit data of the session with the terminal device through the non-3GPP access network.
[0036] Based on this method, the user-plane network element obtains a first key during the process of establishing a session via 3GPP access by a terminal device, and then establishes a data transmission connection with the terminal device based on the first key, so that the terminal device and the user-plane network element can transmit data via a non-3GPP access network. This method does not require the participation of N3IWF network elements and TNGF network elements, enabling the user-plane network element to establish a connection with the terminal device to transmit data via non-3GPP access under the ASSS-lite architecture.
[0037] In combination with the second aspect, in some implementations of the second aspect, establishing a first connection between the user plane network element and the terminal device based on the first key includes: establishing an IPsec connection between the user plane network element and the terminal device based on the first key.
[0038] In combination with the second aspect, in certain implementations of the second aspect, an IPsec connection is established between a user plane network element and a terminal device based on a first key, including: performing identity authentication with the terminal device based on the first key or the second key, and the second key is derived based on the first key.
[0039] In combination with the second aspect, in certain implementations of the second aspect, when identity authentication is performed with the terminal device based on the second key, the method further includes: obtaining the second key based on the first key and the IPsec connection indication information.
[0040] In combination with the second aspect, in some implementations of the second aspect, the method further includes: when the IPsec connection is successfully established, establishing an MPQUIC connection between the user plane network element and the terminal device.
[0041] In combination with the second aspect, in certain implementations of the second aspect, establishing an MPQUIC connection between a user-plane network element and a terminal device includes: authenticating the terminal device based on a first key or a fourth key, the fourth key being obtained based on any one of the following keys: the first key, the second key, or the third key; wherein the second key is used to authenticate the terminal device during the process of establishing an IPsec connection, and the third key is used to securely protect data transmitted through the IPsec connection.
[0042] In combination with the second aspect, in certain implementations of the second aspect, establishing a first connection between a user plane network element and a terminal device according to a first key includes: establishing an MPQUIC connection between the user plane network element and the terminal device according to the first key.
[0043] In combination with the second aspect, in certain implementations of the second aspect, establishing an MPQUIC connection between a user plane network element and a terminal device based on a first key includes: performing identity authentication with the terminal device based on the first key or a fourth key, the fourth key being obtained based on the first key.
[0044] In combination with the second aspect, in certain implementations of the second aspect, when identity authentication is performed with the terminal device based on the fourth key, the method further includes: obtaining the fourth key based on the first key and the MPQUIC connection indication information.
[0045] In combination with the second aspect, in certain implementations of the second aspect, in the process of a terminal device establishing a session with a user plane network element through a 3GPP access network, first address information is allocated, and the first address information is used by the terminal device to communicate with the user plane network element through a non-3GPP access network; the first address information is sent to the session management network element.
[0046] In combination with the second aspect, in certain implementations of the second aspect, the method further includes: receiving second indication information from a session management network element, the second indication information instructing the user plane network element to allocate address information for the terminal device to communicate with the user plane network element through a non-3GPP access network, or the second indication information indicates that the non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element; allocating the first address information, including: allocating the first address information in response to the second indication information.
[0047] In combination with the second aspect, in certain implementations of the second aspect, the method further includes: in the process of the terminal device establishing a session with a user plane network element through a 3GPP access network, establishing a first user plane resource and a second user plane resource, the first user plane resource being used for the user plane network element to transmit session data with the terminal device through the 3GPP access network, and the second user plane resource being used for the user plane network element to transmit session data with the terminal device through a non-3GPP access network.
[0048] In combination with the second aspect, in certain implementations of the second aspect, third indication information is received from a session management network element, the third indication information indicating that a non-3GPP access network is used to provide a direct connection between a terminal device and a user plane network element; establishing a first user plane resource and a second user plane resource includes: establishing the first user plane resource and the second user plane resource in response to the third indication information.
[0049] In combination with the second aspect, in some implementations of the second aspect, the first key is obtained based on a security context, and the security context is generated during the process of the terminal device registering with the core network through the 3GPP access network, and the core network includes a user plane network element.
[0050] In conjunction with the second aspect, in certain implementations of the second aspect, the first key is obtained based on the security context, including:
[0051] The first key is obtained based on the security context, identification information of the session and identification information of the terminal device; or, the first key is obtained based on the security context and second address information on the user plane network element side, and the second address information is used by the terminal device to communicate with the user plane network element through the 3GPP access network.
[0052] In conjunction with the second aspect, in certain implementations of the second aspect, the first key is obtained according to the security context, including: the first key is obtained according to K in the security context AMF , K AUSF , or K SEAF Got it.
[0053] In a third aspect, a communication method is provided. The method may be executed by a session management network element, or by a chip or circuit of the session management network element, which is not limited in this application. For ease of description, the following description is based on an example of execution by a session management network element.
[0054] The method includes: receiving a session establishment request message, the session establishment request message is used to request establishment of a session for a terminal device, the session is used for the terminal device to transmit data with a user plane network element through a 3GPP access network and a non-3GPP access network; obtaining a first key according to the session establishment request message; sending the first key to the user plane network element, the first key is used to establish a first connection between the user plane network element and the terminal device, and the first connection is used for the terminal device and the user plane network element to transmit session data through the non-3GPP access network.
[0055] Based on this method, the session management network element obtains the first key in response to the session establishment request message and sends the first key to the user plane network element, so that the user plane network element can subsequently establish a data transmission connection for 3GPP access with the terminal device based on the first key under the ATSSS-lite architecture.
[0056] Optionally, the session management network element may also trigger the first network element to send the first key to the user plane network element according to the third request message.
[0057] In combination with the third aspect, in some implementations of the third aspect, the session establishment request message includes the first key.
[0058] In combination with the third aspect, in certain implementations of the third aspect, obtaining the first key according to the session establishment request message includes: sending a key request message according to the session establishment request message, the key request message being used to request a key for establishing the first connection; and receiving the first key.
[0059] In combination with the third aspect, in certain implementations of the third aspect, the session establishment request message includes fourth indication information, and the fourth indication information indicates that the non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element; sending a key request message according to the session establishment request message includes: sending a key request message according to the fourth indication information.
[0060] In combination with the third aspect, in certain implementations of the third aspect, sending a key request message includes: sending a key request message when the contract information of the terminal device indicates that the terminal device has a first capability, and the first capability includes: transmitting data with a user plane network element when a non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element.
[0061] In combination with the third aspect, in certain implementations of the third aspect, sending a first key to a user plane network element includes: sending a first key to the user plane network element when the contract information of the terminal device indicates that the terminal device has a first capability, and the first capability includes: transmitting data with the user plane network element when a non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element.
[0062] In combination with the third aspect, in certain implementations of the third aspect, the method further includes: receiving first address information from a user plane network element, the first address information being used by the terminal device to communicate with the user plane network element through a non-3GPP access network; and sending the first address information to the terminal device.
[0063] For example, the session management network element sends the first address information to the terminal device via the access and mobility management network element and the 3GPP access network. Exemplarily, the session response message includes the first address information.
[0064] In combination with the third aspect, in certain implementations of the third aspect, before receiving the first address information from the user plane network element, the method also includes: sending second indication information to the user plane network element, the second indication information instructing the user plane network element to allocate address information for the terminal device to communicate with the user plane network element through the non-3GPP access network, or the second indication information instructs the non-3GPP access network to provide a direct connection between the terminal device and the user plane network element.
[0065] In conjunction with the third aspect, in certain implementations of the third aspect, the method further includes: determining one or more ASSSS rules; and when at least one of the one or more ASSSS rules indicates the use of an MPTCP function or an ASSSS lower layer ATSSS-LL function to guide, switch, and split session data, sending information to the terminal device indicating that an IPsec connection needs to be established; or, when one or more ASSSS rules indicate the use of an MPQUIC function to guide, switch, and split session data, sending information to the terminal device indicating that an IPsec connection does not need to be established or instructing the direct establishment of an MPQUIC connection. For example, the above information is included in a session establishment response message.
[0066] In combination with the third aspect, in certain implementations of the third aspect, the method further includes: establishing a first user plane resource and a second user plane resource, the first user plane resource being used for the user plane network element to transmit session data with the terminal device through the 3GPP access network, and the second user plane resource being used for the user plane network element to transmit session data with the terminal device through the non-3GPP access network.
[0067] In combination with the third aspect, in certain implementations of the third aspect, the method further includes: sending a session establishment response message to the terminal device, the session establishment response message is used to indicate that the session establishment is successful, the session establishment response message includes first indication information, and the first indication information is used to indicate that the non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element.
[0068] In combination with the third aspect, in certain implementations of the third aspect, the first key is obtained based on a security context, which is generated during the process of the terminal device registering with the core network through a 3GPP access network, and the core network includes a user plane network element.
[0069] In combination with the third aspect, in certain implementations of the third aspect, the first key is obtained based on the security context, including: the first key is obtained based on the security context, identification information of the session and identification information of the terminal device; or, the first key is obtained based on the security context and second address information on the user plane network element side, and the second address information is used for the terminal device to communicate with the user plane network element through the 3GPP access network.
[0070] In conjunction with the third aspect, in certain implementations of the third aspect, the first key is obtained according to the security context, including: the first key is obtained according to K in the security context AMF , K AUSF , or K SEAF Got it.
[0071] In a fourth aspect, a communication method is provided. The method may be executed by a first network element, or may be executed by a chip or circuit of the first network element, which is not limited in this application. For ease of description, the following description is based on an example of execution by the first network element.
[0072] The method includes: obtaining the security context of the terminal device during the process of the terminal device registering with the core network through the Third Generation Partnership Project 3GPP access network; deducing a first key based on the security context and sending the first key during the process of the terminal device requesting to establish a session through the 3GPP access network; wherein the session is used for the terminal device to transmit data with the user plane network element in the core network through the 3GPP access network and the non-3GPP access network.
[0073] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first key is deduced based on the security context, including: deducing the first key based on the security context, identification information of the session and identification information of the terminal device; or, deducing the first key based on the security context and second address information on the user plane network element side, the second address information is used for the terminal device to communicate with the user plane network element through the 3GPP access network.
[0074] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the first network element is an access and mobility management network element, and deducing the first key according to the security context includes: deducing the first key according to K in the security context AMF Deducing a first key; or, the first network element is an authentication server network element, deducing a first key according to the security context, including: according to the K in the security context AUSF Deducing a first key; or, the first network element is a security anchor network element, deducing a first key according to the security context, including: according to K in the security context SEAF Deducing the first key.
[0075] In combination with the fourth aspect, in certain implementations of the fourth aspect, the method also includes: in the process of the terminal device requesting to establish a session through the 3GPP access network, receiving a session establishment request message from the terminal device, the session establishment request message being used to request to establish a session; deducing a first key based on the security context, including: generating a first key based on the security context in response to the session establishment request message.
[0076] In combination with the fourth aspect, in certain implementations of the fourth aspect, the session establishment request message includes information for indicating that the non-3GPP access network is used to directly connect the terminal device and the user plane network element; in response to the session establishment request message, generating a first key based on the security context, including: in response to the session establishment request message including information for indicating that the non-3GPP access network is used to directly connect the terminal device and the user plane network element, generating the first key based on the security context.
[0077] In combination with the fourth aspect, in some implementations of the fourth aspect, sending the first key includes: sending the first key to a session management network element.
[0078] In combination with the fourth aspect, in certain implementations of the fourth aspect, the method further includes: receiving a key request message in the process of the terminal device requesting to establish a session through the 3GPP access network, the key request message being used to request a key for establishing a first connection, the first connection being used by the terminal device to transmit session data with the user plane network element through the non-3GPP access network; deducing the first key based on the security context, including: deducing the first key based on the security context in response to the key request message.
[0079] In combination with the fourth aspect, in certain implementations of the fourth aspect, sending the first key includes: sending a key response message, where the key response message includes the first key.
[0080] In a fifth aspect, a communication device is provided, which includes a module for implementing the method described in the first aspect or any of its implementations; or, the communication device includes a module for implementing the method described in the second aspect or any of its implementations; or, the communication device includes a module for implementing the method described in the third aspect or any of its implementations; or, the communication device includes a module for implementing the method described in the fourth aspect or any of its implementations.
[0081] In a sixth aspect, a communication device is provided, comprising a processor, a memory, and an optional transceiver, wherein the memory is used to store instructions, and when the instructions are executed by the processor, the processor implements the method described in the first aspect or any of its implementations; or, the processor implements the method described in the second aspect or any of its implementations; or, the processor implements the method described in the third aspect or any of its implementations; or, the processor implements the method described in the fourth aspect or any of its implementations.
[0082] The transceiver is used for receiving and / or sending signals.
[0083] In the seventh aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores instructions, and when the instructions are executed on a computer, the computer executes the method described in the first aspect or any of its implementations; or, the computer executes the method described in the second aspect or any of its implementations; or, the computer executes the method described in the third aspect or any of its implementations; or, the computer executes the method described in the fourth aspect or any of its implementations.
[0084] In an eighth aspect, a computer program product comprising instructions is provided, which, when the instructions are run on a computer, causes the computer to execute the method described in the first aspect or any of its implementations; or, causes the computer to execute the method described in the second aspect or any of its implementations; or, causes the computer to execute the method described in the third aspect or any of its implementations; or, causes the computer to execute the method described in the fourth aspect or any of its implementations.
[0085] In the ninth aspect, a chip is provided, which includes a processor and a communication interface, and the processor reads instructions stored in a memory through the communication interface, and is used to execute the method described in the first aspect or any of its implementations; or, is used to execute the method described in the second aspect or any of its implementations; or, is used to execute the method described in the third aspect or any of its implementations; or, is used to execute the method described in the fourth aspect or any of its implementations.
[0086] Optionally, as an implementation, the chip may further include a memory storing instructions, and the processor is used to execute the instructions stored in the memory. When the instructions are executed, the processor is used to execute the method described in the above-mentioned first aspect or any of its implementations; or, the processor is used to execute the method described in the above-mentioned second aspect or any of its implementations; or, the processor is used to execute the method described in the above-mentioned third aspect or any of its implementations; or, the processor is used to execute the method described in the above-mentioned fourth aspect or any of its implementations.
[0087] In the tenth aspect, a communication system is provided, which includes a first communication device and a second communication device, wherein the first communication device is used to execute the method described in the second aspect or any of its implementations, and the second communication device is used to execute the method described in the third aspect or any of its implementations.
[0088] In combination with the tenth aspect, in certain implementations of the tenth aspect, the communication system includes a third communication device, which is used to execute the method described in the fourth aspect or any implementation thereof.
[0089] The beneficial effects of the above-mentioned second to tenth aspects or any implementation thereof can be referred to the relevant description in the first aspect and its implementation, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0090] FIG1 is a schematic diagram of a network architecture 100 supporting the ATSSS feature.
[0091] FIG2 is a schematic diagram of a network architecture for non-3GPP access.
[0092] FIG3 is a schematic diagram of a simplified ATSSS network architecture 300 applicable to an embodiment of the present application.
[0093] FIG4 is a flow chart of a communication method 400 provided in an embodiment of the present application.
[0094] Figures 5 and 6 are flowchart diagrams of a method for a terminal device and a user-plane network element to establish a first connection based on a first key, as provided in an embodiment of the present application.
[0095] FIG7 is a schematic diagram of a communication device 1000 provided in an embodiment of the present application.
[0096] FIG8 is a schematic diagram of a communication device 2000 provided in an embodiment of the present application.
[0097] FIG9 is a schematic diagram of a chip system 3000 provided in an embodiment of the present application. DETAILED DESCRIPTION
[0098] When the terminal device and the core network support the access traffic steering, switching, splitting (ATSSS) feature, the terminal device can register with the core network through both 3GPP access and non-3GPP access paths, and establish a multiple access protocol data unit (MA PDU) session with the core network. MA PDUs have corresponding user plane resources in both the 3GPP access network and the non-3GPP access network. Based on the MA PDU session, the terminal device and the DN can exchange service data through both the 3GPP access network and the non-3GPP access network.
[0099] Figure 1 is a schematic diagram of a network architecture 100 that supports the ATSSS feature. The network architecture is based on a fifth-generation (5G) mobile communication network based on a service-based architecture (SBA) in a non-roaming scenario of the 3rd Generation Partnership Project (3GPP). The network architecture 100 is briefly introduced below. For parts not described in detail, reference can be made to existing protocols.
[0100] As shown in FIG1 , a network architecture 100 includes a terminal device 110 , a (radio) access network (R)AN) 120 , a core network, and a data network (DN) 140 .
[0101] The terminal device 110 is a device with wireless transceiver capabilities and may also be referred to as user equipment (UE), terminal equipment, access terminal, terminal, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent, or user device. The terminal device 110 may be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; on water, such as on a ship; or in the air, such as on an airplane, balloon, or satellite. The terminal device 110 may be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a smartphone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), or the like. The terminal device 110 may also be a handheld device with wireless communication capabilities, a computing device, or other device connected to a wireless modem, an in-vehicle device, a wearable device, a drone device, or a terminal in the Internet of Things or the Internet of Vehicles, a terminal in any form in a 5G network or a future network (such as a sixth-generation (6G) mobile communication network), or a relay user device. Among them, the relay user device may be, for example, a 5G residential gateway (RG). For example, the terminal device 110 may be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. The embodiments of the present application do not limit the type or category of the terminal device.
[0102] ATSSS-capable terminal devices have one or more of the following sterring functionalities:
[0103] (1) Multipath Transmission Control Protocol (MPTCP) functionality, used to guide, switch, and split Transmission Control Protocol (TCP) traffic flows;
[0104] (2) Multipath Quick User Datagram Protocol Internet Connections (MPQUIC) functionality, which is used to guide, switch, and split User Datagram Protocol (UDP) traffic flows;
[0105] (3) ATSSS lower layer (ATSSS-LL) function, used to guide, switch, and split TCP service flows, UDP service flows, or Ethernet service flows.
[0106] A terminal device equipped with any of the above-mentioned steering functions can realize traffic guidance, switching and splitting between 3GPP access and non-3GPP access based on the ATSSS rule provided by the core network. For example, each ATSSS rule includes information for describing the characteristics of the data flow (which can be called a traffic descriptor), and also includes information for identifying the steering function, indicating that the steering function is used for data flows that meet the characteristics described by the traffic descriptor. The terminal device uses the steering function to guide, switch and split the data flow according to the ATSSS rule.
[0107] DN 140, also known as a packet data network (PDN), is deployed with one or more servers for providing services to terminal device 110. After terminal device 110 accesses the (R)AN and the core network, it can access DN 140 through the (R)AN and the core network to obtain services provided by the servers on DN 140.
[0108] The core network belongs to the operator's network and includes: user plane function (UPF) network element 130, access and mobility management function (AMF) network element 131, session management function (SMF) network element 132, policy control function (PCF) network element 133, unified data management (UDM) network element 134, authentication server function (AUSF) network element 135, and security anchor function (SEAF) network element 136. The following briefly describes the functions of each network element. For details not fully explained, please refer to existing protocols.
[0109] 1. The UPF network element 130 is a user-plane network element and serves as the gateway for communication between the core network and the DN 140. The functions of the UPF network element include packet routing and transmission, packet detection, service usage reporting, quality of service (QoS) processing, legal monitoring, uplink packet detection, and downlink packet storage.
[0110] The UPF network element that supports the ATSSS feature has one or more of the following functions: MPTCP proxy function, MPQUIC proxy function or ATSSS-LL function. The MPTCP function in the terminal device and the associated MPTCP proxy function in the UPF network element can use the MPTCP protocol to communicate through the 3GPP and / or non-3GPP user plane. The MPQUIC function in the terminal device and the associated MPQUIC proxy function in the UPF network element can use the quick user datagram protocol internet connections (QUIC) protocol to communicate through the 3GPP and / or non-3GPP user plane.
[0111] 2. The AMF network element 131 is a control plane network element responsible for access control and mobility management of terminal devices, including managing the mobility status of terminal devices, allocating temporary user identities, authenticating and authorizing terminal devices, and other functions.
[0112] 3. The SMF network element 132 is a control plane network element responsible for managing the protocol data unit (PDU) sessions of terminal devices. A PDU session is a channel for transmitting PDUs, and terminal devices need to use PDU sessions to transfer PDUs to and from the DN. The SMF network element is responsible for establishing, maintaining, and deleting PDU sessions. It is also responsible for maintaining tunnels between the UPF network element and the (R)AN, selecting and controlling the UPF network element, and selecting service and session continuity modes.
[0113] 4. PCF network element 133 is a control plane network element that supports the use of a unified policy framework to govern network behavior and provide policy rules and contract information related to policy decisions to other control function network elements.
[0114] 5. The UDM network element 134 is a control plane network element responsible for storing information such as the subscriber permanent identifier (SUPI), the generic public subscription identifier (GPSI), and credentials of subscribers in the operator's network.
[0115] 6. The AUSF network element 135 is a control plane network element, typically used for authentication between a terminal device (subscriber) and an operator network. After receiving an authentication request from a subscriber, the AUSF network element can authenticate and / or authorize the subscriber using the authentication information and / or authorization information stored in the UDM network element, or generate authentication and / or authorization information for the subscriber through the UDM network element. The AUSF network element can also provide feedback on authentication and / or authorization information to the subscriber.
[0116] 7. The SEAF network element 136 is a control plane network element used for authentication between the terminal device (subscriber) and the operator network, such as completing the operator network side authentication of the terminal device during the authentication and key agreement (AKA) process. Optionally, the SEAF network element can be part of the AMF network element.
[0117] The core network may also include network exposure function (NEF) network elements, unified data repository (UDR) network elements, network repository function (NRF) network elements, authentication repository and processing function (ARPF) network elements, and application function (AF) network elements. These network elements may also be referred to as network functions (NFs).
[0118] It should be understood that the above-mentioned network elements can be physical entities in hardware devices, software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (e.g., a cloud platform). In terms of form, the above-mentioned network elements can be independent devices or integrated into the same device to implement different functions.
[0119] It should be noted that the above naming is defined only to facilitate the distinction between different functions and should not constitute any limitation to this application. This application does not exclude the possibility of adopting other naming in 5G networks and future networks. For example, in a 6G mobile communication network, some or all of the above network elements may continue to use the terminology used in 5G, or may adopt other names.
[0120] (R)AN 120 is an implementation system between the core network and the terminal device 110. The terminal device 110 can access the core network through the wireless communication function provided by the (R)AN 120, thereby obtaining services provided by network elements in the core network.
[0121] (R)AN 120 may include a 3GPP access network 121, which may be considered as part of an operator's network. Access network equipment in the 3GPP access network may be one or more of the following devices: a next generation node base station (gNB) in a 5G system, an evolved node B (eNB) in long term evolution (LTE), a radio network controller (RNC), a node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (e.g., home evolved node B, or home node B, HNB), a base band unit (BBU), a transmitting and receiving point (TRP), a transmitting point (TP), a small base station device, a mobile switching center, or network equipment in future networks, etc. The access network equipment may also be a module or unit that performs the functions of a base station, for example, including a centralized unit (CU) and a distributed unit (DU); in one possible network structure, the CU may be used to support communications under protocols such as radio resource control (RRC), packet data convergence protocol (PDCP), and service data adaptation protocol (SDAP); and the DU may be used to support communications under radio link control (RLC) layer protocols, medium access control (MAC) layer protocols, and physical layer protocols. The access type of the terminal device 110 accessing the core network through the 3GPP access network may be referred to as 3GPP access, and the terminal device 110 accessing the core network through the 3GPP access network may also be referred to as the terminal device 110 registering with the core network through 3GPP access.
[0122] (R)AN 120 may include non-3GPP access networks 122, i.e., access networks other than 3GPP access networks, such as wireless local area networks (WLANs), wireless fidelity (Wi-Fi) networks, worldwide interoperability for microwave access (WiMAX), fixed networks, etc. The access type of the terminal device 110 accessing the core network through a non-3GPP access network may be referred to as non-3GPP access.
[0123] If the home operator of the terminal device does not trust the non-3GPP access network, the non-3GPP access network is called an untrusted non-3GPP access network. If the non-3GPP access network is trusted, the non-3GPP access network is called a trusted non-3GPP access network. The trusted non-3GPP access network can be considered as part of the operator's network. As shown in Figure 2, the untrusted non-3GPP access network is connected to other network elements through the non-3GPP interworking function (N3IWF) network element in the core network. The trusted 3GPP access network includes a trusted non-3GPP access point (TNAP) and a trusted non-3GPP gateway function (TNGF) network element. The TNAP is connected to the network elements in the core network through the TNGF network element. The above-mentioned N3IWF network element and TNGF network element can exchange control plane signaling with the AMF network element 131, and can also exchange user plane data with the UPF network element 130.
[0124] Based on the network architecture shown in Figure 2, the terminal device can authenticate with the core network through the N3IWF network element or the TNGF network element, complete the establishment of a security context, and then register with the core network through non-3GPP access. The terminal device can also subsequently transmit user plane data to the core network through the N3IWF network element or the TNGF network element.
[0125] In the ATSSS scenario, the terminal device must register with the core network through 3GPP access and register with the core network through non-3GPP access. These two processes are performed independently. In each process, the terminal device and the core network must perform an authentication and key agreement (AKA), which makes the process complicated. In order to simplify the operations on the non-3GPP access path in the ATSSS scenario, the industry has proposed a new network architecture 300 as shown in Figure 3. Unlike the network architecture shown in Figures 1 and 2, the network architecture 300 removes the N3IWF network element and the TNGF network element. The non-3GPP access network can provide a direct connection between the terminal device and the user plane network element (such as the UPF network element 130). The direct connection can also be called a direct Internet protocol (IP) connection. That is, the data of the terminal device can be directly exchanged between the non-3GPP access network and the user plane network element, and the forwarding of intermediate network elements such as the N3IWF network element and the TNGF network element is no longer required.
[0126] However, when the network architecture no longer includes N3IWF and TNGF network elements, the question of how a terminal device can establish a secure data transmission connection via non-3GPP access is a problem that needs to be solved. To address this problem, embodiments of the present application provide a communication method and apparatus that can establish a connection between a terminal device and a core network for transmitting data via non-3GPP access based on network architecture 300.
[0127] First, the network architecture 300 is further described in detail with reference to Figure 3. The network architecture 300 includes a terminal device, a 3GPP access network, a non-3GPP access network and a core network. The core network includes a user plane network element, an access and mobility network element and a session management network element. The functions and examples of each device or network element can refer to the above description of the terminal device 110, the 3GPP access network 121, the non-3GPP access network 122, the UPF network element 130, the AMF network element 131 and the SMF network element 132, which will not be repeated here. The core network may also include other network elements shown in Figure 1 and described above, which are not limited in the embodiments of the present application. Among them, the non-3GPP access network can be a non-trusted non-3GPP access network or a trusted 3GPP access point. The non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element (such as the UPF network element 130). This type of non-3GPP access network can be called a non-integrated non-3GPP access (NIN3A). The network architecture 300 can be called a lightweight ATSSS architecture, or a simplified ASSSS architecture, hereinafter referred to as ASSSS-lite architecture.
[0128] Figure 4 is a flow chart of a communication method 400 provided in an embodiment of the present application. The communication method 400 can be executed by the terminal device, 3GPP access network, non-3GPP access network, user plane network element, access and mobility network element and session management network element in Figure 3, or it can be executed by modules and / or devices (for example, chips or integrated circuits, etc.) with corresponding functions installed in the terminal device, 3GPP access network, non-3GPP access network, user plane network element, access and mobility network element and session management network element, and the present application is not limited thereto. For ease of description, the following description is based on the terminal device, 3GPP access network, non-3GPP access network, user plane network element, access and mobility network element and session management network element as the execution entities. For parts not fully described, please refer to the above description and existing protocols. As shown in Figure 4, the communication method 400 includes the following multiple steps.
[0129] S410: The terminal device registers with the core network through the 3GPP access network. That is, the terminal device and the core network perform a registration process through the 3GPP access network.
[0130] In this process, the terminal device and the core network generate a security context, which may include a security key shared by the terminal device and the core network element, such as at least one of the following keys: (1) a shared security key between the terminal device and the access and mobility management network element, denoted as the AMF key, which may be the K in the 5G network; AMF (2) A shared security key between the terminal device and the authentication service function network element (such as AUSF network element 135), denoted as AUSF key, which can be K in the 5G network AUSF (3) A shared security key between the terminal device and the security anchor network element (such as SEAF network element 136), denoted as SEAF key, which can be K in the 5G network SEAF . This security context is referred to as the 3GPP security context below.
[0131] Exemplarily, after the primary authentication between the terminal device and the core network is successfully completed, the authentication service function network element can generate an AUSF key and save it locally. The authentication service function network element can also derive a SEAF key based on the AUSF key, and send the SEAF key to the SEAF network element. Correspondingly, the SEAF network element receives the SEAF key from the AUSF network element and saves it locally. The SEAF network element can derive an AMF key based on the SEAF key, and send the AMF key to the AMF network element. Correspondingly, the AMF network element receives the AMF key from the SEAF network element and saves it locally. Similarly, the terminal device can generate a security context on the terminal device side after the primary authentication is successfully completed.
[0132] The specific implementation of step S410 may refer to 3GPP technical specifications (TS) 23.501 and 23.502.
[0133] S420: The terminal device sends a request message #1 to the access and mobility management network element through the 3GPP access network. Correspondingly, the access and mobility management network element receives the request message #1 from the terminal device through the 3GPP access network.
[0134] Among them, request message #1 is used to request the establishment of a session, and may also be referred to as a session establishment request message. For the sake of convenience, the session requested to be established by request message #1 will be referred to as session #1 below. Session #1 is used for the terminal device to transmit data through the 3GPP access network and the non-3GPP access network. For example, the terminal device sends indication information #1 to the AMF network element. Indication information #1 is used to indicate that the type of session #1 is a session for the terminal device to transmit data through the 3GPP access network and the non-3GPP access network. For example, indication information #1 is used to indicate that the type of session #1 is an MA PDU session. Exemplarily, the terminal device sends a non-access stratum (NAS) message to the access and mobility management network element. The NAS message includes request message #1 and a request type. The value of the request type is MA PDU request.
[0135] For convenience of expression, MA PDU session is used below to refer to a session used by a terminal device to transmit data through a 3GPP access network and a non-3GPP access network. That is, the MA PDU session below can be replaced by any session that can be used by a terminal device to transmit data through a 3GPP access network and a non-3GPP access network.
[0136] The request message #1 includes identification information of session #1. The identification information is used to identify session #1 and may be generated or allocated by the terminal device for session #1.
[0137] The request message #1 may also include identification information of the terminal device, where the identification information is used to identify the terminal device. The identification information of the terminal device may be a subscription concealed identifier (SUCI) or a globally unique temporary identifier (GUTI).
[0138] Request message #1 may include indication information #2, which may be used to indicate any of the following: a non-3GPP access network is used to directly connect the terminal device and the user plane network element, the session requested to be established is used for the ATSSS-lite architecture (or ATSSS-lite scenario, described below using the ATSSS-lite architecture as an example), the network architecture in which the terminal device is located is the ATSSS-lite architecture, the session requested to be established is an ATSSS-lite type session, or the terminal device supports the ATSSS-lite feature. The terminal device supporting the ATSSS-lite feature may also be replaced with the terminal device having the ASSSS-lite capability, or the terminal device supporting the establishment of an ATSSS-lite type session, which will be described below using the terminal device supporting the ATSSS-lite feature as an example.
[0139] Exemplarily, when the network architecture in which the terminal device is located is an ATSSS-lite architecture, or when a request is made to establish an ATSSS-lite type session, or when the ATSSS-lite feature is supported, the terminal device sends indication information #2 to the access and mobility management network element. Correspondingly, the access and mobility management network element can determine, based on indication information #2, that the current network architecture is an ATSSS-lite architecture, or that the session requested to be established by the terminal device is an ATSSS-lite type session, or that the terminal device requesting to establish a session supports the ATSSS-lite feature.
[0140] Among them, the ATSSS-lite type session includes the data transmission path between the terminal device, the 3GPP access network and the UPF network element, and also includes the data transmission path between the terminal device, the non-3GPP access network and the UPF network element, and there is no N3IWF network element and TNGF network element between the non-3GPP access network and the UPF network element in the core network, that is, the non-3GPP access network can provide a direct connection between the terminal device and the user plane network element, and the non-3GPP access network and the user plane network element can directly exchange data without the need for N3IWF network element and TNGF network element to forward. It should be noted that the name of the ATSSS-lite type session is only an example, and the session type can also use other names, and the embodiments of the present application do not limit this.
[0141] Among them, the terminal device supporting the ATSSS-lite feature can indicate that the terminal device can deduce a first key based on the 3GPP security context and establish a connection for the terminal device to transmit data with the user plane network element through the non-3GPP access network based on the first key. It can also indicate that the terminal device can establish an ATSSS-lite type session, and can also indicate that the terminal device can transmit data under the ATSSS-lite architecture. It should be noted that the names of ATSSS-lite feature and ATSSS-lite capability are only examples and should not be used as limitations.
[0142] Request message #1 may also include indication information #3, where indication information #3 is used to indicate the redirection function supported by the terminal device. The redirection function supported by the terminal device may include one or more of the following functions: MPTCP function, MPQUIC function, or ATSSS-LL function.
[0143] S430: The access and mobility management network element sends a request message #2 to the session management network element according to the request message #1. Correspondingly, the session management network element receives the request message #2 from the access and mobility management network element.
[0144] Request message #2 is used to request establishment of a session for the terminal device, or request message #2 is used to request establishment of a session management context for session #1, or request message #2 is used to request establishment of an association between an access and mobility management network element and a session management network element to support session #1. Exemplarily, request message #2 may be called a session establishment request message or a session management context establishment request message, and request message #2 may be an Nsmf_PDUSession_CreateSMContext message.
[0145] Before the access and mobility management network element sends request message #2 to the session management network element, communication method 400 may further include: the access and mobility management network element selecting a session management network element. For example, the access and mobility management network element selects a session management network element that supports the ATSSS-lite feature based on indication information #2. A session management network element that supports the ATSSS-lite feature may also be considered a session management network element with ATSSS-lite capabilities or a session management network element that supports establishing ATSSS-lite-type sessions. The functions of this type of session management network element are detailed below.
[0146] Request message #2 may include the identification information of session #1 and the identification information of the terminal device, such as the access and mobility management network element carries the identification information of session #1 and the identification information of the terminal device in request message #1 in request message #2 and sends it to the session management network element.
[0147] Request message #2 may include indication information #4, which may be used to indicate any of the following: a non-3GPP access network is used to directly connect the terminal device with the user plane network element, the session requested to be established is used for the ATSSS-lite architecture, the session requested to be established is an ATSSS-lite type session, or the terminal device supports the ATSSS-lite feature.
[0148] Indication information #4 and indication information #2 can be the same indication information, for example, the access and mobility management network element carries indication information #2 in request message #1 and sends it to the session management network element in request message #2. Indication information #4 and indication information #2 can also be different indication information, for example, the access and mobility management network element generates indication information #4 based on indication information #2. For example, the access and mobility management network element determines that the current network architecture is the ATSSS-lite architecture based on indication information #2, or determines that the terminal device supports the ATSSS-lite feature, and then generates indication information #4.
[0149] The request message #2 may further include indication information #5, where the indication information #5 is used to indicate that the type of session #1 is an MA PDU session. The indication information #5 may be the same as the indication information #1.
[0150] The request message #2 may further include indication information #3 for indicating the redirection function supported by the terminal device.
[0151] In one implementation manner (denoted as implementation manner 1), the request message #2 includes the first key, and the session management network element sends the first key in the request message #2 to the user plane network element.
[0152] The first key is used to establish a first connection between the terminal device and the user plane network element, and the first connection is used for the terminal device and the user plane network element to transmit data of session #1 through the non-3GPP access network. The first key can be called a session key, an end-to-end security key, or an end-to-end security credential.
[0153] For example, the access and mobility management network element obtains the first key in response to request message #1, such as in response to indication information #2, and sends the first key to the session management network element in request message #2. Exemplarily, the access and mobility management network element may obtain the first key through the following method 4-1 or method 4-2.
[0154] Mode 4-1: The access and mobility management network element derives the first key according to the 3GPP security context corresponding to the terminal device.
[0155] For example, after receiving request message #1, the access and mobility management network element, triggered by indication message #2, derives the first key based on the 3GPP security context corresponding to the terminal device. For example, the access and mobility management network element searches for the locally stored 3GPP security context corresponding to the terminal device based on the identification information of the terminal device in request message #1, and then derives the first key based on the 3GPP security context. Derivation of the first key may be replaced by generation of the first key.
[0156] Exemplarily, the 3GPP security context corresponding to the terminal device includes an AMF key, a security key shared by the terminal device and the access and mobility management network element, and the access and mobility management network element derives the first key based on the AMF key.
[0157] Optionally, the access and mobility management network element derives the first key based on the 3GPP security context corresponding to the terminal device, the identification information of session #1, and the identification information of the terminal device. For example, the access and mobility management network element uses the 3GPP security context corresponding to the terminal device, the identification information of session #1, and the identification information of the terminal device as input parameters of a key derivation function (KDF), and the output of the KDF is the first key. Because the combination of the identification information of session #1 and the identification information of the terminal device can uniquely identify session #1, the first key obtained based on the identification information of session #1 and the identification information of the terminal device uniquely corresponds to session #1.
[0158] Based on the 3GPP security context corresponding to the terminal device, the identification information of session #1 and the identification information of the terminal device, the access and mobility management network element can also add other parameters to deduce the first key, such as parameter #1 used to indicate that the access type is non-3GPP access, and / or parameter #2 used to indicate the radio access technology (RAT) type, etc.
[0159] Exemplarily, since the first key is used for non-3GPP access, that is, for the terminal device and the user-plane network element to establish a first connection through non-3GPP access, the access and mobility management network element sets the value of parameter #1 to the value #1 corresponding to the non-3GPP access, and then uses parameter #1 with the value #1 to deduce the first key. In other scenarios, the access and mobility management network element may need to deduce the key for 3GPP access based on the AMF key, the identification information of session #1, and the identification information of the terminal device. In this case, the access and mobility management network element will set the value of parameter #1 to the value #2 corresponding to the 3GPP access, and then use parameter #1 with the value #2 to deduce the key for 3GPP access, where value #1 is different from value #2.
[0160] Exemplarily, when the non-3GPP access network through which the subsequent terminal device and the user-plane network element establish a first connection is a terrestrial network (TN), i.e., a non-3GPP access network deployed on the surface, the access and mobility management network element sets the value of parameter #2 to value #3 corresponding to TN, and then uses parameter #2 with value #3 to derive the first key. When the non-3GPP access network through which the subsequent terminal device and the user-plane network element establish a first connection is a non-terrestrial network (NTN), such as a non-3GPP access network deployed on a satellite or spacecraft, the access and mobility management network element sets the value of parameter #2 to value #4 corresponding to NTN, and then uses parameter #2 with value #4 to derive the first key. In this implementation, request message #1 also includes information indicating the RAT type, and the access and mobility management network element determines the value of parameter #2 based on this information.
[0161] It should be noted that the parameters used to derive the first key are parameters shared by the terminal device and the access and mobility management network element.
[0162] Mode 4-2: The access and mobility management network element receives the first key from the first network element.
[0163] For example, the access and mobility management network element sends a request message #3 to the first network element based on indication information #2. That is, the access and mobility management network element sends a request message #3 to the first network element under the triggering of indication information #2. Request message #3 is used to request a first key, that is, to request a key for establishing the first connection. Request message #3 can be called a key request message. The key request message can include identification information of the terminal device.
[0164] Correspondingly, the first network element receives request message #3 from the access and mobility management network element. In response to request message #3, the first network element derives the first key based on the 3GPP security context corresponding to the terminal device. For example, the first network element searches for the 3GPP security context corresponding to the terminal device stored locally based on the identification information of the terminal device, and then derives the first key based on the 3GPP security context.
[0165] After the first network element derives the first key, it sends the first key to the access and mobility management network element. For example, the first network element sends a response message #3 to the access and mobility management network element. The response message #3 includes the first key. The response message #3 can be called a key response message.
[0166] For example, the 3GPP security context corresponding to the terminal device includes a security key shared by the first network element and the terminal device, and the first network element derives the first key based on the shared security key. Exemplarily, the first network element is an authentication service network element (such as AUSF network element 135), and the shared security key is an AUSF key; or the first network element is a security anchor point network element (such as SEAF network element 136), and the shared security key is a SEAF key.
[0167] Optionally, if request message #3 also includes the identification information of session #1 and the identification information of the terminal device, the first network element may also derive the first key based on the 3GPP security context corresponding to the terminal device, the identification information of session #1, and the identification information of the terminal device. The first network element may also add other parameters shared with the terminal device to derive the first key, such as parameter #1 and / or parameter #2 described above. For detailed implementation, see the description in Method 4-1.
[0168] In this implementation, the communication method 400 further includes the following step S440.
[0169] S440: The session management network element sends the first key to the user plane network element. Correspondingly, the user plane network element receives the first key from the session management network element.
[0170] For example, the session management network element sends the first key in the request message #2 to the user plane network element.
[0171] Optionally, when the contract information of the terminal device indicates that the terminal device supports the ASSSS-lite feature, the session management network element sends a first key to the user plane network element; otherwise, the session management network element sends a message to the terminal device for indicating refusal to establish a session, wherein the message for indicating refusal to establish a session may also be referred to as a message for indicating failure to establish a session. The following description takes the message for indicating refusal to establish a session as an example.
[0172] For example, the contract information of the terminal device includes the characteristics or capabilities supported by the terminal device. When the characteristics or capabilities supported by the terminal device include the ATSSS-lite characteristic, the session management network element sends a first key to the user plane network element. When the characteristics or capabilities supported by the terminal device do not include the ATSSS-lite characteristic, the session management network element sends a message to the terminal device to indicate the refusal to establish a session.
[0173] For another example, when the contract information of the terminal device includes indication information for indicating that the terminal device supports the ATSSS-lite feature, the session management network element sends a first key to the user plane network element; when the contract information of the terminal device does not include indication information for indicating that the terminal device supports the ATSSS-lite feature, the session management network element sends a message to the terminal device for indicating that establishment of a session is rejected.
[0174] For another example, the contract information of the terminal device includes indication information #6 for indicating whether the terminal device supports the ATSSS-lite feature. When the value of indication information #6 is the first value (such as 1), it indicates that the terminal device supports the ATSSS-lite feature, and the session management network element sends a first key to the user plane network element; when the value of indication information #6 is the second value (such as 0), it indicates that the terminal device does not support the ATSSS-lite feature, and the session management network element sends a message to the terminal device for indicating the refusal to establish a session.
[0175] Exemplarily, the network architecture 300 further includes a unified data management network element, such as the UDM network element 134 in Figure 1. After the session management network element receives the request message #2 and before sending the first key to the user plane network element, the communication method 400 further includes the following steps S441-1 and S442-1 (not shown in the figure).
[0176] S441-1. The session management network element sends a request message #4 to the unified data management network element. Correspondingly, the unified data management network element receives the request message #4 from the session management network element.
[0177] Request message #4 is used to request the terminal device's contract information. Request message #4 may include the terminal device's identification information. For example, the session management network element sends request message #4, along with the terminal device's identification information from request message #2, to the unified data management network element. Request message #4 may also be replaced by a retrieval message or query message to retrieve or query the terminal device's contract information.
[0178] For example, the session management network element sends a request message #4 to the unified data management network element in response to indication information #4 or triggered by the first key.
[0179] S442-1. The unified data management network element sends the contract information of the terminal device to the session management network element. Correspondingly, the session management network element receives the contract information of the terminal device from the unified data management network element.
[0180] For example, the unified data management network element searches for the terminal device's contract information based on the terminal device's identification information, and then sends the terminal device's contract information to the session management network element. For example, the unified data management network element sends a response message #4 to the session management network element, and the response message #4 includes the terminal device's contract information.
[0181] After the session management network element receives the contract information of the terminal device from the unified data management network element, it determines whether the terminal device supports the ATSSS-lite feature based on the contract information of the terminal device, and then sends a first key to the user plane network element or sends a message to the terminal device to indicate that the establishment of a session is rejected.
[0182] The above steps S441-1 and S442-1 can be replaced by steps S441-2 and S442-2 (not shown in the figure).
[0183] S441-2. The session management network element sends a request message #4 to the unified data management network element. Correspondingly, the unified data management network element receives the request message #4 from the session management network element.
[0184] Request message #4 is used to request verification of whether the terminal device supports the ASSSS-lite feature, or to query whether the terminal device supports the ASSSS-lite feature. Request message #4 may include identification information of the terminal device. For example, the session management network element sends request message #4 to the unified data management network element along with the identification information of the terminal device in request message #2. For example, the session management network element sends request message #4 to the unified data management network element based on indication message #4 or triggered by the first key.
[0185] S442-2. The unified data management network element sends a response message #4 to the session management network element. Correspondingly, the session management network element receives the response message #4 from the unified data management network element.
[0186] Among them, response message #4 is used to indicate whether the terminal device supports the ATSSS-lite feature.
[0187] For example, the unified data management network element determines whether the terminal device supports the ATSSS-lite feature based on the contract information of the terminal device. If the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, the response message #4 indicates that the terminal device supports the ATSSS-lite feature. If the contract information of the terminal device indicates that the terminal device does not support the ATSSS-lite feature, or if the contract information of the terminal device does not indicate that the terminal device supports the ATSSS-lite feature, the response message #4 indicates that the terminal device does not support the ATSSS-lite feature. The unified data management network element can search for the contract information of the terminal device based on the identification information of the terminal device.
[0188] When response message #4 indicates that the terminal device supports the ATSSS-lite feature, the session management network element sends a first key to the user plane network element; when response message #4 indicates that the terminal device does not support the ATSSS-lite feature, the session management network element sends a message to the terminal device to indicate that establishment of a session is rejected.
[0189] Before the session management network element sends the first key to the user plane network element, communication method 400 may further include: the session management network element selecting a user plane network element. For example, the session management network element selects a user plane network element that supports the ATSSS-lite feature as the user plane network element serving session #1 based on indication information #4 or the first key in request message #2. Functions of the user plane network element that supports the ATSSS-lite feature are detailed below.
[0190] The session management network element may send identification information of the terminal device to the user plane network element while sending the first key to the user plane network element.
[0191] In another implementation manner (denoted as implementation manner 2), the session management network element obtains the first key from the first network element according to request message #2, such as indication information #4 in request message #2, and then sends the obtained first key to the user plane network element.
[0192] In this implementation, the communication method 400 further includes the following steps S443 to S445 ( FIG. 4 takes the first network element as an access and mobility management network element as an example).
[0193] S443. The session management network element sends a request message #5 to the first network element. Correspondingly, the first network element receives the request message #5 from the session management network element.
[0194] Among them, request message #5 is used to request the first key, that is, request message #5 is used to request the first key for establishing the first connection between the user plane network element and the terminal device. Request message #5 can be a key request message.
[0195] For example, the session management network element, triggered by the request message #2, such as the indication information #4, sends a request message #5 to the first network element.
[0196] Request message #5 may also include identification information of the terminal device and identification information of session #1. For example, the session management network element carries the identification information of the terminal device and identification information of session #1 in request message #2 in request message #5 and sends it to the first network element.
[0197] Request message #5 may also include second address information of the user plane network element. This second address information is used by the terminal device to communicate with the user plane network element via the 3GPP access network. For example, when the terminal device sends uplink data to the user plane network element via the 3GPP access network, the terminal device may set the destination address of the data packet carrying the uplink data to the second address information. The second address information may be the IP address of the user plane network element.
[0198] In the case that the request message #5 includes the second address information of the user plane network element, before step S443, the session management network element may obtain the second address information. Exemplarily, the session management network element may obtain the second address information through the following steps S443-1 and S443-2 (not shown in the figure).
[0199] S443-1. The session management network element sends a message for requesting the second address information to the user plane network element. Correspondingly, the user plane network element receives the message for requesting the second address information from the session management network element.
[0200] The message for requesting the second address information may also be used to request address information for the terminal device to communicate with the user plane network element through the 3GPP access network.
[0201] Before the session management network element requests the second address information from the user plane network element, communication method 400 may further include: the session management network element selecting a user plane network element. For example, based on indication information #2, the session management network element selects a user plane network element that supports the ASSSS-lite feature as the user plane network element serving session #1. The session management network element then requests the second address information from the selected user plane network element.
[0202] S443-2. The user plane network element sends the second address information to the session management network element. Correspondingly, the session management network element receives the second address information from the user plane network element.
[0203] For example, in response to the message for requesting the second address information, the user plane network element allocates the second address information, and then sends the second address information to the session management network element.
[0204] S444: The first network element sends the first key to the session management network element. Correspondingly, the session management network element receives the first key from the first network element.
[0205] For example, in response to request message #5, the first network element derives a first key based on the 3GPP security context corresponding to the terminal device, and then sends the first key to the session management network element. If the first network element sends a response message #5 to the session management network element in response to request message #5, response message #5 includes the first key, and response message #5 can be a key response message.
[0206] For example, the 3GPP security context corresponding to the terminal device includes a security key shared by the first network element and the terminal device, and the first network element derives the first key based on the shared security key. Exemplarily, the first network element is an access and mobility management network element (such as the AMF network element 131), and the shared security key is an AMF key; or, the first network element is an authentication service network element (such as the AUSF network element 135), and the shared security key is an AUSF key; or, the first network element is a security anchor point network element (such as the SEAF network element 136), and the shared security key is a SEAF key.
[0207] When request message #5 includes the terminal device's identification information and session #1's identification information, the first network element may derive the first key based on the terminal device's corresponding 3GPP security context, session #1's identification information, and the terminal device's identification information. The first network element may also add other parameters shared with the terminal device to derive the first key, such as parameter #1 and / or parameter #2. For detailed implementation, see the description in Method 4-1.
[0208] When request message #5 includes the second address information of the user-plane network element, the first network element can derive the first key based on the 3GPP security context corresponding to the terminal device and the second address information of the user-plane network element. If the first network element uses the 3GPP security context and the second address information as KDF input parameters, the output of the KDF is the first key. Because the second address information uniquely identifies session #1, the first key derived from the second address information uniquely corresponds to session #1.
[0209] Based on the 3GPP security context and second address information corresponding to the terminal device, the first network element may also add other parameters shared with the terminal device to deduce the first key, such as the above-mentioned parameter #1 and / or parameter #2. For specific implementation, please refer to the description in method 4-1.
[0210] Optionally, the session management network element sends request message #5 directly to the first network element, and the first network element sends the first key directly to the session management network element; or, the session management network element sends request message #5 to the first network element via another network element, and the first network element sends the first key to the session management network element via the other network element. For example, the first network element is an authentication service network element or a security anchor network element, and the session management network element sends request message #5 to the authentication service network element or the security anchor network element via the access and mobility management network element, and the authentication service network element or the security anchor network element sends the first key to the session management network element via the access and mobility management network element. In this case, after receiving request message #5 from the session management network element, the access and mobility management network element may transparently transmit request message #5 to the authentication service network element or the security anchor network element, process request message #5 and then send it to the authentication service network element or the security anchor network element, or generate another request message for requesting the first key based on request message #5 and send it to the authentication service network element or the security anchor network element. This embodiment of the present application is not limited in this regard.
[0211] S445. The session management network element sends the first key to the user plane network element. Correspondingly, the user plane network element receives the first key from the session management network element.
[0212] For example, the session management network element sends the first key received from the first network element to the user plane network element.
[0213] Before the session management network element sends the first key to the user plane network element, the communication method 400 may also include: the session management network element selects a user plane network element, such as the session management network element selects a user plane network element that supports the ATSSS-lite feature as the user plane network element for service session #1 according to indication information #2 in request message #2.
[0214] In one example, when the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, the session management network element sends a request message #5 to the first network element; otherwise, the session management network element sends a message to the terminal device indicating that session establishment is rejected. For the specific implementation of the terminal device's contract information indicating that the terminal device supports the ATSSS-lite feature, refer to the description in Implementation Method 1.
[0215] For example, the session management network element receives the contract information of the terminal device from the unified data management network element through steps S441-1 and S442-1. If the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, the session management network element executes step S443. Alternatively, the session management network element receives response message #4 from the unified data management network element through steps S441-2 and S442-2. If response message #4 indicates that the terminal device supports the ATSSS-lite feature, the session management network element executes step S443.
[0216] In another example, when the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, the session management network element sends a first key to the user plane network element; otherwise, the session management network element sends a message to the terminal device indicating that the session establishment is rejected. The specific implementation of the contract information of the terminal device indicating that the terminal device supports the ATSSS-lite feature can refer to the description in Implementation Method 1.
[0217] For example, after receiving the first key from the first network element, the session management network element receives the contract information of the terminal device from the unified data management network element through steps S441-1 and S442-1. If the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, the session management network element selects a user plane network element and executes step S445 to send the first key to the selected user plane network element. Alternatively, after receiving the first key from the first network element, the session management network element receives a response message #4 from the unified data management network element through steps S441-2 and S442-2. If the response message #4 indicates that the terminal device supports the ATSSS-lite feature, the session management network element selects a user plane network element and executes step S445 to send the first key to the selected user plane network element. It should be understood that in this example, the session management network element may not determine whether the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature before sending request message #5 to the first network element.
[0218] In yet another implementation manner (denoted as implementation manner 3), the session management network element triggers the first network element to send the first key to the user plane network element according to the request message #2.
[0219] In this implementation, the communication method 400 further includes the following steps S446 and S447 ( FIG. 4 takes the first network element as an access and mobility management network element as an example).
[0220] S446. The session management network element sends a request message #6 to the first network element. Correspondingly, the first network element receives the request message #6 from the session management network element.
[0221] Request message #6 is used to request the first key, that is, request message #6 is used to request the key for establishing the first connection. Request message #6 can be called a key request message.
[0222] For example, the session management network element sends a request message #6 to the first network element according to the request message #2, such as the indication information #2.
[0223] Request message #6 includes information about a user-plane network element used to serve session #1. The information about the user-plane network element may be the NF instance identifier (instance ID), full address domain name (i.e., fully qualified domain name, FQDN), or address information (such as an IP address) of the user-plane network element. The address information of the user-plane network element is the address of the UPF within the 3GPP network. That is, network elements (including the first network element) in the 3GPP network can send messages to the user-plane network element based on the address information. Hereinafter, the address information of the user-plane network element sent by the session management network element to the first network element is referred to as user-plane network element address information #1.
[0224] Before the session management network element sends request message #6 to the first network element, communication method 400 may further include: the session management network element selecting a user plane network element. For example, based on indication information #2, the session management network element selects a user plane network element that supports the ASSSS-lite feature as the user plane network element serving session #1. The session management network element then sends request message #6, along with information about the selected user plane network element, to the first network element.
[0225] Request message #6 may also include identification information of session #1 and identification information of the terminal device. For example, the session management network element carries the identification information of session #1 and identification information of the terminal device in request message #2 in request message #6 and sends it to the first network element.
[0226] The request message #6 may also include the second address information of the user plane network element. After the session management network element selects the user plane network element, it obtains the second address information from the selected user plane network element through steps S443-1 and S443-2.
[0227] Optionally, when the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, the session management network element sends a request message #6 to the first network element, or, when the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, the session management network element selects a user plane network element and sends a request message #6 to the first network element; otherwise, the session management network element sends a message to the terminal device to indicate that establishment of a session is rejected.
[0228] For example, the session management network element receives the contract information of the terminal device from the unified data management network element through steps S441-1 and S442-1. If the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, the session management network element executes step S446. Alternatively, the session management network element receives response message #4 from the unified data management network element through steps S441-1 and S442-1. If response message #4 indicates that the terminal device supports the ATSSS-lite feature, the session management network element executes step S446.
[0229] S447. The first network element derives the first key according to the request message #6 and sends the first key to the user plane network element. Correspondingly, the user plane network element receives the first key from the first network element.
[0230] For example, the first network element, triggered by request message #6, derives the first key based on the 3GPP security context corresponding to the terminal device, and then sends the first key to the user plane network element. The specific implementation of the first network element deriving the first key can refer to implementation method 1 and will not be repeated here.
[0231] For example, the first network element sends the first key to the user plane network element according to the information of the user plane network element.
[0232] Optionally, after the first network element sends the first key to the user plane network element, it also sends a response message #6 to the session management network element to respond to the request message #6. The response message #6 is used to indicate that the first key has been successfully deduced, and can also be used to indicate that the first key has been successfully sent to the user plane network element.
[0233] Based on the above implementation manners 1 to 3, the user plane network element receives the first key during the process of the terminal device establishing session #1 with the user plane network element through the 3GPP access network.
[0234] The communication method 400 further includes the following steps S450 to S480 .
[0235] S450. The session management network element sends a request message #7 to the user plane network element. Correspondingly, the user plane network element receives the request message #7 from the session management network element.
[0236] Among them, request message #7 is used to request the first address information of the user plane network element. The first address information is used for the terminal device to communicate with the user plane network element through the non-3GPP access network. For example, when the terminal device sends uplink data to the user plane network element through the non-3GPP access network, the terminal device can set the destination address of the data packet carrying the uplink data to the first address information, so that the non-3GPP access network can send the uplink data to the user plane network element according to the first address information, without the need for intermediate network elements (such as N3IWF network elements or TNGF network elements) to forward it.
[0237] Optionally, request message #7 includes second indication information, and the second indication information may instruct the user plane network element to allocate the first indication information, that is, instruct the user plane network element to allocate address information for the terminal device to communicate with the user plane network element through the non-3GPP access network. The second indication information may also indicate that the non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element, that is, indicate that the architecture in which the terminal device is located is an ATSSS-lite architecture or session #1 is an ATSSS-lite type session.
[0238] There are multiple possible execution orders for step S450 and the above-mentioned steps S440 to S447, as described in Examples 1 to 6 below. It should be understood that Examples 1 to 6 are merely examples, and all execution orders that conform to the internal logical relationship are covered within the scope of protection of the embodiments of this application.
[0239] Example 1: Based on the above implementation method 1, after receiving request message #2, the session management network element sends a request message #7 to the user plane network element when the terminal device's subscription information indicates that the terminal device supports the ATSSS-lite feature. The session management network element can send request message #7 and the first key to the user plane network element in the same message or in different messages. Exemplarily, request message #7 includes the first key.
[0240] Example 2: Based on the above implementation method 2, after receiving request message #2, the session management network element sends request message #5 to the first network element (S443) and receives the first key from the first network element (S444). Then, if the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, the session management network element sends the first key (S445) and request message #7 (S450) to the user plane network element. The session management network element can send request message #7 and the first key through the same message. If request message #7 includes the first key, steps S445 and S450 are the same step. The session management network element can also send request message #7 and the first key to the user plane network element through different messages. In this case, the order of steps S445 and S450 is not limited.
[0241] Example 3: Based on the above implementation method 2, after the session management network element receives request message #2, when the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, it sends a request message #5 (S443) to the first network element. Then, after receiving the first key (S444) from the first network element, the session management network element sends the first key (S445) and request message #7 (S450) to the user plane network element. The session management network element can send request message #7 and the first key through the same message. If request message #7 includes the first key, steps S445 and S450 are the same step. The session management network element can also send request message #7 and the first key to the user plane network element through different messages. In this case, the order of steps S445 and S450 is not limited.
[0242] Example 4: Based on the above-mentioned implementation method 2, after the session management network element receives request message #2, if the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, it sends a request message #5 (S443) to the first network element and sends a request message #7 (S450) to the user plane network element, wherein the order of steps S443 and S450 is not limited. After the subsequent session management network element receives the first key (S444) from the first network element, it sends the first key (S445) to the user plane network element. That is, Example 4 differs from Examples 2 and 3 in that the session management network element receives the first key (S444) only after sending the request message #7 (S450) to the user plane network element.
[0243] Example 5. Based on the above implementation method 3, after the session management network element receives request message #2, if the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, it sends a request message #6 (S446) to the first network element and sends a request message #7 (S450) to the user plane network element, where the order of steps S446 and S450 is not limited.
[0244] Example 6. Based on the above implementation method 3, after the session management network element receives the request message #2, when the contract information of the terminal device indicates that the terminal device supports the ATSSS-lite feature, it sends a request message #6 (S446) to the first network element, and then after receiving the response message #6 indicating the successful derivation of the first key, it sends a request message #7 (S450) to the user plane network element.
[0245] Optionally, the message for requesting the second address information in step S443-1 is the same message as request message #7, i.e., request message #7 is used to request both the first address information and the second address information. It should be understood that, in this implementation, if step S443 or S446 is performed before step S450, request message #5 or request message #6 does not include the second address information; if step S450 is performed before step S443 or S446, request message #5 or request message #6 may include the second address information.
[0246] For example, the session management network element initiates a session establishment process according to request message #2 and sends request message #7 to the user plane network element. Request message #7 may be an N4 session establishment request message, where N4 indicates the interface between the session management network element and the user plane.
[0247] Request message #7 can also be used to request the establishment of user plane resources for 3GPP access and non-3GPP access, or in other words, request message #7 is also used to initiate the establishment of user plane resources on both paths of 3GPP access and non-3GPP access. The user plane resources established for 3GPP access (recorded as first user plane resources) are used for the user plane network element to transmit data of session #1 with the terminal device through the 3GPP access network, and the user plane resources established for non-3GPP access (recorded as second user plane resources) are used for the user plane network element to transmit data of session #1 with the terminal device through the non-3GPP access network. For example, request message #7 includes third indication information, and the third indication information is used to indicate that the non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element, or the third indication information is used to indicate that the user plane network element establishes user plane resources for 3GPP access and non-3GPP access.
[0248] Optionally, the request message #7 also includes one or more ATSSS rules, which are used by the user-side network element to guide, switch and split downlink data to two paths, 3GPP access and non-3GPP access. Each ATSSS rule includes information for identifying or describing a data flow (such as a traffic descriptor), indicating that the ATSSS rule is applied to the data flow identified or described by the information, such as a data flow with characteristics described by the traffic descriptor. Each ATSSS rule also includes information for identifying a steering function, which is applied to the data flow, that is, the steering function is used to guide, switch and split the data flow, and the steering function can be any one of the following: MPTCP function, MPQUIC function or ATSSS-LL function. The one or more ATSSS rules are derived by the session management network element.
[0249] For example, network architecture 300 also includes a policy control network element, such as PCF network element 133 in FIG1 . After receiving request message #2, the session management network element selects a policy control network element and sends a request message #8 to the selected policy control network element. Request message #8 is used to request the establishment of a session management policy association for session #1. Request message #8 may be a session management policy control create request message. Request message #8 may include identification information for session #1 and identification information for the terminal device, and may also include one or more of the following indication information: information indicating that session #1 is an MA PDU session (e.g., an "MA PDU Request" indication), or information indicating that session #1 is an ATSSS-lite type session.
[0250] Correspondingly, the policy control network element sends the policy and charging control (PCC) rules corresponding to session #1 to the session management network element in response to request message #8. The session management network element receives the PCC rules and derives the ATSSS rules based on the PCC rules. The derived ATSSS rules are then sent to the UPF network element via request message #7. The session management network element may also derive the ATSSS rules based on the indication information #3 in request message #2, but this embodiment of the present application does not limit this.
[0251] S460: The user plane network element sends first address information to the session management network element. Correspondingly, the session management network element receives the first address information from the user plane network element.
[0252] For example, in response to request message #7, such as in response to the second indication information in request message #7, the user plane network element allocates the first address information; or, in response to the first key, the user plane network element allocates the first address information. Next, the user plane network element sends the allocated first address information to the session management network element, such as by sending a response message #7 to the session management network element. Response message #7 is used to respond to request message #7, and response message #7 includes the first address information. Response message #7 may be an N4 session establishment response message.
[0253] Optionally, in response to request message #7, such as in response to the third indication information in request message #7, the user plane network element establishes the first user plane resource and the second user plane resource, that is, establishes user plane resources for 3GPP access and non-3GPP access. The specific implementation of the user plane network element establishing the first user plane resource and the second user plane resource can be referenced to the 3GPP protocol and will not be repeated here.
[0254] S470. The session management network element sends a response message #1 to the terminal device. Correspondingly, the terminal device receives the response message #1 from the session management network element.
[0255] The response message #1 is used to indicate that the session #1 is successfully established or to indicate that the establishment of the session #1 is accepted. For example, the response message #1 is a session establishment response message or a PDU session establishment accept message.
[0256] The response message #1 includes the first address information. For example, the session management network element carries the first address information in the response message #7 in the response message #1 and sends it to the terminal device.
[0257] For example, the session management network element sends a response message #1 to the terminal device through the access and mobility management network element and the 3GPP access network. Correspondingly, the terminal device receives the response message #1 from the session management network element through the 3GPP access network and the access and mobility management network element.
[0258] Optionally, response message #1 includes first indication information, and the first indication information is used to indicate permission or acceptance to establish session #1 as an ATSSS-lite type session, or to indicate that session #1 is an ATSSS-lite type session, or to indicate that a non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element.
[0259] Response message #1 may also include one or more ATSSS rules, which are used by the terminal device to guide, switch and split uplink data to two paths, 3GPP access and non-3GPP access. Each ATSSS rule includes information for identifying or describing a data stream (such as a traffic descriptor), indicating that the ATSSS rule is applied to the data stream identified or described by the information, such as a data stream with characteristics described by the traffic descriptor. Each ATSSS rule also includes information for identifying a steering function, which is applied to the data stream, that is, the steering function is used to guide, switch and split the data stream, and the steering function can be any one of the following: MPTCP function, MPQUIC function or ATSSS-LL function. The one or more ATSSS rules are derived by the session management network element.
[0260] The one or more ATSSS rules (referred to as ATSSS rules on the user plane network element side) sent by the session management network element to the user plane network element correspond to the one or more ATSSS rules (referred to as ATSSS rules on the terminal device side) sent to the terminal device. For example, when the ATSSS rules on the user plane network element side include ATSSS rule #1 indicating that the MPTCP proxy function is applied to data stream #1 in the session, the ATSSS rules on the terminal device side include ATSSS rule #2 indicating that the MPTCP function is applied to data stream #1 in the session, so that the MPTCP proxy function in the user plane network element and the MPTCP function in the terminal device transmit data stream #1 according to the MPTCP protocol. Similarly, when the ATSSS rules on the user plane network element side include ATSSS rule #3 indicating the application of the MPQUIC proxy function to data stream #2 in the session, the ATSSS rules on the terminal device side include ATSSS rule #4 indicating the application of the MPQUIC function to data stream #2 in the session, so that the MPQUIC proxy function in the user plane network element and the MPQUIC function in the terminal device transmit data stream #2 according to the MPQUIC protocol.
[0261] Optionally, when at least one of the ATSSS rules on the terminal device side indicates the use of MPTCP function or ASSSS-LL function to guide, switch and split the session data, the response message #1 includes indication information #7, and the indication information #7 is used to indicate the need to establish an Internet protocol security (IPsec) connection.
[0262] Optionally, when the ATSSS rules on the terminal device side all indicate the use of the MPQUIC function to guide, switch and split the session data, the response message #1 includes indication information #8, and the indication information #8 is used to indicate that there is no need to establish an IPsec connection, or to indicate to directly establish an MPQUIC connection, or to indicate to skip IPsec connection establishment.
[0263] S480 . In response to the response message # 1 , the terminal device derives a first key according to the 3GPP security context.
[0264] For example, if response message #1 includes the first address information, or if response message #1 includes the first indication information, the terminal device derives the first key based on the 3GPP security context. That is, after receiving response message #1, the terminal device derives the first key based on the 3GPP security context, triggered by the first address information or the first indication information in the message.
[0265] The method by which the terminal device derives the first key based on the 3GPP security context is the same as the way the first network element derives the first key. For example, when the first network element is an access and mobility management network element, the terminal device derives the first key based on the AMF key; when the first network element is an AUSF network element, the terminal device derives the first key based on the AUSF key; when the first network element is a SEAF network element, the terminal device derives the first key based on the SEAF key. The terminal device can derive the first key based on the 3GPP security context, the identification information of session #1 and the identification information of the terminal device; or, if the response message #1 also includes the second address information, the terminal device can derive the first key based on the 3GPP security context and the second address information. The terminal device can also add the above-mentioned parameters #1 and #2 to derive the first key.
[0266] The method by which the terminal device and the first network element derive the first key may be specified in a protocol or negotiated between the terminal device and the first network element. Exemplarily, the request message #1 includes information indicating the first key derivation methods supported by the terminal device. The first network element selects a method from among the first key derivation methods supported by the terminal device to derive the first key and indicates the selected method to the terminal device via the session management network element. That is, the response message #1 includes information indicating the method used by the first network element to derive the first key. The terminal device derives the first key using the method indicated by the information.
[0267] S490: The terminal device and the user plane network element establish a first connection based on the first key. The first connection is used for the terminal device to transmit session data with the user plane network element through the non-3GPP access network.
[0268] In the above-described communication method 400, the user-plane network element obtains a first key during the process of establishing a session with a terminal device via 3GPP access. The terminal device then derives the first key after the session is successfully established. The first key on the user-plane network element side and the first key on the terminal device side are derived in the same manner based on the 3GPP security context corresponding to the terminal device. That is, the user-plane network element and the terminal device share the first key. Based on this shared first key, the user-plane network element and the terminal device can establish a secure connection for transmitting session data over a non-3GPP access network under the ASSSS-lite architecture.
[0269] The terminal device, access and mobility management network element, session management network element, user plane network element, authentication function network element, and security anchor network element used to implement communication method 400 may be referred to as devices or network elements supporting the ATSSS-lite feature. The functions supported by these devices or network elements are exemplarily described below.
[0270] Exemplarily, a terminal device supporting the ATSSS-lite feature has one or more of the following functions: (1) deriving a first key based on a 3GPP security context; (2) establishing a first connection with a user plane network element based on the first key, such as deriving a second key and / or a fourth key in the process of establishing the first connection; (3) transmitting data with the user plane network element when a non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element.
[0271] Exemplarily, an access and mobility management network element supporting the ATSSS-lite feature has one or more of the following functions: (1) deriving a first key based on a 3GPP security context; or, requesting a first key from a first network element; (2) selecting a session management network element supporting the ATSSS-lite feature.
[0272] Exemplarily, a session management network element supporting the ATSSS-lite feature has one or more of the following functions: (1) obtaining a first key based on a session establishment request message and sending it to a user plane network element, or triggering the first network element to deduce the first key and then sending it to the user plane network element; (2) requesting first address information from the user plane network element and sending the first address information to the terminal device; (3) initiating the establishment of a first user plane resource and a second user plane resource during the process of establishing a session through 3GPP access by the terminal device; (4) determining whether the terminal device supports the ATSSS-lite feature based on the contract information of the terminal device; (4) deriving an ASSSS rule, and sending indication information #7, indication information #8 or indication information #9 to the terminal device according to the ASSSS rule.
[0273] Exemplarily, a user plane network element supporting the ATSSS-lite feature has one or more of the following functions: (1) establishing a first connection with a terminal device based on a first key, such as deducing a second key and / or a fourth key during the process of establishing the first connection; (2) transmitting data with a terminal device when a non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element; (3) allocating first address information during the process of establishing a session via 3GPP access by the terminal device; (4) establishing a first user plane resource and a second user plane resource during the process of establishing a session via 3GPP access by the terminal device.
[0274] The implementation of step S490 is exemplarily described below with reference to FIG. 5 to FIG. 7 .
[0275] As shown in FIG5 , in one implementation, the process of establishing a first connection between the terminal device and the user-plane network element according to the first key (step S490 ) includes the following steps S510 and S520 .
[0276] S510: The terminal device and the user-plane network element establish an IPsec connection based on the first key. The IPsec connection may also be called an IPsec tunnel.
[0277] S520: If the IPsec connection is successfully established and the first condition is met, the terminal device and the user-plane network element establish an MPQUIC connection. The first condition includes: at least one ASSSS rule on the terminal device side indicates that the MPQUIC function should be used to guide, switch, and split the data of session #1. The first condition can also be understood as requiring the MPQUIC function to be used to guide, switch, and split the data of session #1.
[0278] It should be understood that if the first condition is not met, the terminal device and the user-plane network element do not need to establish an MPQUIC connection.
[0279] Step S510 includes: the terminal device and the user plane network element perform identity authentication based on the first key or the second key, where the second key is obtained based on the first key. Whether the terminal device and the user plane network element perform identity authentication based on the first key or the second key may be specified by the protocol or negotiated between the terminal device and the user plane network element, and this embodiment of the application does not limit this.
[0280] For example, the terminal device derives the second key based on the first key and one or more of the following information: session #1 identification information, terminal device identification information, first address information, or IPsec connection indication information. For example, the terminal device inputs the one or more of the above information into a KDF, and the output of the KDF is the second key.
[0281] The IPsec connection indication information can distinguish the second key from a key derived from the first key and used to establish other connections (such as an MPQUIC connection). It can also be considered that the IPsec connection indication information can be used to limit the second key to only being used to establish an IPsec connection, and not to establish other connections.
[0282] In one example, the terminal device derives the second key based on the first key, identification information of session #1 and identification information of the terminal device; in another example, the terminal device derives the second key based on the first key and first address information; in yet another example, the terminal device derives the second key based on the first key and IPsec connection indication information.
[0283] Optionally, the user plane network element derives the second key in the same manner as the terminal device; or, the user plane network element receives the second key before establishing an IPsec connection with the terminal device.
[0284] For example, in the above-mentioned implementation method 1, request message #2 also includes a second key. After receiving request message #2, the session management network element sends the second key to the user plane network element. For example, the session management network element can send the first key and the second key to the user plane network element through the same message. Exemplarily, based on method 4-1, after the access and mobility management network element derives the first key in response to request message #1, it also derives the second key based on the first key. Alternatively, based on method 4-2, the access and mobility management network element also requests the second key from the first network element, that is, requests a key for identity authentication during the process of establishing an IPsec connection; in response to the request of the access and mobility management network element, after deriving the first key, the first network element derives the second key based on the first key and sends the second key to the access and mobility management network element. After obtaining the second key, the access and mobility management network element sends the second key to the session management network element through request message #2.
[0285] For example, in the aforementioned implementation 2, the session management network element further obtains a second key from the first network element based on request message #2, and then sends the obtained first key to the user plane network element. Exemplarily, the session management network element also requests the second key from the first network element, i.e., requests a key used for identity authentication during the IPsec connection establishment process. In response to the session management network element's request, the first network element derives the second key from the first key after deriving the first key, and sends the second key to the session management network element. After obtaining the second key, the session management network element sends the second key to the user plane network element.
[0286] For example, in the above implementation 3, the session management network element further triggers the first network element to send the second key to the user plane network element based on request message #2. Exemplarily, the session management network element further requests the second key from the first network element, i.e., requests the key used for identity authentication during the IPsec connection establishment process. In response to the request from the session management network element, the first network element derives the second key based on the first key after deriving the first key, and sends the second key to the user plane network element.
[0287] The manner in which the access and mobility management network element and the first network element deduce the second key based on the first key is the same as the deduction manner on the terminal device side.
[0288] When the user plane network element receives the second key, the user plane network element can also receive usage indication information #1, which is used to indicate that the second key is used for establishing an IPsec connection, or to indicate that the second key is used for identity authentication during the process of establishing an IPsec connection.
[0289] Optionally, the user-plane network element saves the correspondence between the second key and the identification information of the terminal device, the identification information of session #1, and the usage indication information #1, so that the second key can be subsequently searched based on the identification information of the terminal device, the identification information of session #1, and the usage indication information #1; or the user-plane network element saves the correspondence between the second key and the first address information and the usage indication information #1, so that the second key can be subsequently searched based on the first address information and the usage indication information #1.
[0290] Exemplarily, the terminal device and the user-plane network element establish an IPsec connection according to the IPsec protocol, then step 510 includes the following multiple steps as shown in Figure 5. In the following description, it is assumed that the terminal device and the user-plane network element perform identity authentication based on the second key, and the implementation method of the terminal device and the user-plane network element performing identity authentication based on the first key is similar. For matters not fully explained, please refer to the protocol: Internet Engineering Task Force (IETF) RFC 7296.
[0291] S511. The terminal device sends an Internet key exchange security association initiate message to the user plane network element, which is recorded as IKE_SA_INIT message #1. Correspondingly, the user plane network element receives the IKE_SA_INIT message #1 from the terminal device.
[0292] For example, the terminal device sends IKE_SA_INIT message #1 to the user plane network element based on the first address information in response message #1. For example, the source address of IKE_SA_INIT message #1 is the address information of the terminal device, and the destination address is the first address information. The address information of the terminal device may be allocated to the terminal device by the non-3GPP access network. Exemplarily, prior to step S511, the terminal device is connected to the non-3GPP access network, and the non-3GPP access network allocates address information to the terminal device and sends the allocated address information to the terminal device.
[0293] For example, when the terminal device decides to register or attach to the core network through non-3GPP access, the terminal device initiates an Internet key exchange (IKE) initial exchange and sends an IKE_SA_INIT message #1 to the user plane network element.
[0294] S512: The user plane network element sends an IKE_SA_INIT message #2 to the terminal device. Correspondingly, the terminal device receives the IKE_SA_INIT message #2 from the user plane network element.
[0295] For example, the user-plane network element sends an IKE_SA_INIT message #2 to the terminal device in response to the IKE_SA_INIT message #1.
[0296] IKE_SA_INIT message #2 does not include the CERTREQ parameter, indicating that identity authentication is not performed using a digital signature.
[0297] For the formats and included parameters of IKE_SA_INIT message #1 and IKE_SA_INIT message #2, refer to RFC 7296.
[0298] S513: The terminal device sends an IKE authentication request message (referred to as IKE_AUTH request message) to the user plane network element. Correspondingly, the user plane network element receives the IKE authentication request message from the terminal device.
[0299] For example, the terminal device initiates an IKE authentication exchange and sends an IKE authentication request message to the user plane network element.
[0300] The IKE authentication request message is used to indicate that a shared key message authentication code (KMAC) method is used for identity authentication. For example, the authentication method (eg, Auth Method) field in the IKE authentication request message has a value of 2.
[0301] The IKE authentication request message includes a message authentication code (MAC), denoted as MAC#1. MAC#1 is generated by the terminal device based on the second key. For example, the terminal device uses the second key to calculate the hash value of one or more messages in the IKE_SA_INIT message#1, IKE_SA_INIT message#2, or IKE_AUTH request message to obtain MAC#1.
[0302] S514. The user plane network element authenticates MAC#1 according to the second key and sends an IKE authentication response message (referred to as IKE_AUTH response message) to the terminal device. Correspondingly, the terminal device receives the IKE authentication response message from the user plane network element.
[0303] For example, after the user plane network element receives the IKE authentication response message, it authenticates MAC#1 according to the second key, and sends an IKE authentication response message to the terminal device according to the authentication result. The IKE authentication response message is used to indicate whether the authentication is successful, that is, whether the user plane network element successfully authenticates the terminal device.
[0304] For example, the user-plane network element generates MAC#2 based on the second key and, depending on whether MAC#1 and MAC#2 are identical, sends an IKE authentication response message to the terminal device. If MAC#1 and MAC#2 are different, the user-plane network element sends an IKE authentication response message to the terminal device, indicating that authentication failed. For another example, if MAC#1 and MAC#2 are identical, the user-plane network element sends an IKE authentication response message to the terminal device, indicating that authentication succeeded.
[0305] Among them, the way in which the user plane network element generates MAC#2 is the same as the way in which the terminal device generates MAC#1. The specific method may be specified by the protocol, or negotiated by the terminal device and the user plane network element, or pre-configured in the terminal device and the user plane network element. The embodiment of the present application does not limit this.
[0306] Exemplarily, the terminal device uses the first key to calculate the hash value of IKE_SA_INIT message #1, IKE_SA_INIT message #2 and IKE_AUTH request message to obtain MAC#1, and the user-plane network element also uses the first key to calculate the hash value of IKE_SA_INIT message #1, IKE_SA_INIT message #2 and IKE_AUTH request message to obtain MAC#2.
[0307] Optionally, before authenticating MAC#1 using the second key, the user-plane network element further derives the second key based on the first key. For example, the user-plane network element derives the second key based on the first key when triggered by IKE_SA_INIT message#1 or an IKE authentication request message. When the information from which the second key is derived includes IPsec connection indication information, the user-plane network element can determine, based on the IKE_SA_INIT message#1 or the IKE authentication request message, that the terminal device desires to establish an IPsec connection, thereby determining the IPsec connection indication information.
[0308] Optionally, before authenticating MAC#1 according to the second key, the user plane network element also searches for the second key from the locally stored keys according to the IKE_SA_INIT message #1 and / or the IKE authentication request message. Exemplarily, the user plane network element determines that the terminal device expects to establish an IPsec connection according to the IKE_SA_INIT message #1 and / or the IKE authentication request message, thereby determining that the key range to be searched is the key used to establish the IPsec connection (that is, the usage indication information indicates that the key is used to establish the IPsec connection), and then searches for the key corresponding to the first address information within the range, which is the second key. The first address information can also be replaced with the identification information of session #1 and the identification information of the terminal device. The user plane network element can obtain the first address information, the identification information of session #1 and the identification information of the terminal device according to the IKE_SA_INIT message #1 and / or the IKE authentication request message.
[0309] If authentication is successful (i.e., MAC#1 and MAC#2 are identical), the IKE authentication response message also includes MAC#3, which is generated by the user-plane network element based on the second key. For example, the user-plane network element uses the second key to calculate the hash value of one or more of the following messages: IKE_SA_INIT message#1, IKE_SA_INIT message#2, IKE_AUTH request message, or IKE_AUTH response message to obtain MAC#3.
[0310] If the IKE authentication response message indicates that the authentication has failed, the terminal device confirms that it cannot register or attach to the core network through non-3GPP access, and the process ends.
[0311] In the case that the IKE authentication response message indicates that the authentication is successful, the communication method 400 further includes the following step S515.
[0312] S515. The terminal device authenticates MAC#3 according to the second key.
[0313] For example, the terminal device generates MAC#4 based on the second key and determines whether authentication is successful based on whether MAC#3 and MAC#4 are identical. In other words, it determines whether authentication of the terminal device to the user-plane network element is successful. If MAC#3 and MAC#4 are identical, authentication is successful; if MAC#3 and MAC#4 are different, authentication fails.
[0314] Among them, the way in which the terminal device generates MAC#4 is the same as the way in which the user-plane network element generates MAC#3. The specific method may be specified by the protocol, or negotiated by the terminal device and the user-plane network element, or pre-configured in the terminal device and the user-plane network element. The embodiment of the present application does not impose any restrictions on this.
[0315] When the authentication is successful, the IPsec security association (SA) between the terminal device and the user plane network element is established, that is, the IPsec connection between the terminal device and the user plane network element is established, and the terminal device and the user plane network element negotiate a third key. The terminal device and the user plane network element can subsequently use the third key to securely protect the data of session #1 and transmit the securely protected data through the IPse connection, thereby improving the security of data transmission. The security protection in the embodiments of the present application may include encryption and / or integrity protection.
[0316] Optionally, after the terminal device authenticates MAC#3, the terminal device sends a message indicating the authentication result to the user plane network element. For example, when MAC#3 and MAC#4 are the same, the terminal device sends a message indicating successful authentication, or a message indicating successful IPsec connection establishment, or a message indicating successful IPsec SA establishment to the user plane network element; when MAC#3 and MAC#4 are different, the terminal device sends a message indicating failed authentication, or a message indicating failed IPsec connection establishment, or a message indicating failed IPsec SA establishment to the user plane network element.
[0317] Step S520 includes: the terminal device and the user-plane network element performing identity authentication using the first key or the fourth key, where the fourth key is derived based on any of the following keys: the first key, the second key, or the third key. Whether the terminal device and the user-plane network element perform identity authentication based on the first key or the fourth key during the process of establishing the MPQUIC connection may be specified by the protocol or negotiated between the terminal device and the user-plane network element, and this embodiment of the application does not limit this.
[0318] The following description uses the example of a terminal device deriving the fourth key from the first key. The method used by the terminal device to derive the fourth key based on the second or third key is similar. For example, the terminal device derives the fourth key based on the first key and one or more of the following information: session #1 identification information, terminal device identification information, first address information, or MPQUIC connection indication information. For example, the terminal device inputs one or more of these information into a KDF, and the KDF output is the fourth key.
[0319] The MPQUIC connection indication information can distinguish the fourth key from keys derived from the first key and used to establish other connections, such as the second key described above. It can also be considered that the MPQUIC connection indication information can be used to limit the fourth key to establishing only MPQUIC connections and not other connections.
[0320] It should be noted that when the second key and the fourth key are both derived based on the first key, the IPsec connection indication information needs to be used when deducing the second key, and the MPQUIC connection indication information needs to be used when deducing the fourth key, and the values of the MPQUIC connection indication information and the IPsec connection indication information are different to ensure that the second key is different from the fourth key.
[0321] In one example, the terminal device derives the fourth key based on the first key, the identification information of session #1, and the identification information of the terminal device; in another example, the terminal device derives the fourth key based on the first key and the first address information; in yet another example, the terminal device derives the fourth key based on the first key and the MPQUIC connection indication information.
[0322] Optionally, the user plane network element derives the fourth key in the same manner as the terminal device; or, when the fourth key is obtained based on the first key, the user plane network element receives the fourth key before establishing an MPQUIC connection with the terminal device.
[0323] The implementation method for the user plane network element to receive the fourth key can refer to the above-mentioned method for receiving the second key, and will not be repeated here. In the case where the user plane network element receives the fourth key, the user plane network element may also receive usage indication information #2, where usage indication information #2 is used to indicate that the fourth key is used for MPQUIC connection establishment, or is used to indicate that the fourth key is used for identity authentication during the process of establishing the MPQUIC connection.
[0324] Optionally, the user-plane network element saves the correspondence between the fourth key and the identification information of the terminal device, the identification information of session #1, and the usage indication information #2, so that the fourth key can be subsequently searched based on the identification information of the terminal device, the identification information of session #1, and the usage indication information #2; or the user-plane network element saves the correspondence between the fourth key and the first address information and the usage indication information #2, so that the fourth key can be subsequently searched based on the first address information and the usage indication information #2.
[0325] Exemplarily, the terminal device and the user-plane network element establish an MPQUIC connection according to the transport layer security protocol (TLS), then step S520 includes the following steps S521 to S524. In the following description, it is assumed that the terminal device and the user-plane network element perform identity authentication based on the fourth key. The implementation method of identity authentication based on the first key is similar. For matters not fully described, please refer to the protocol IETF RFC 8446.
[0326] S521. The terminal device sends message #1 to the user plane network element. Correspondingly, the user plane network element receives message #1 from the terminal device.
[0327] Message #1 includes information indicating that a pre-shared key (PSK) mode is used for key negotiation, and message #1 also includes identification information indicating a fourth key. Exemplarily, message #1 is a ClientHello message, wherein the psk_key_share_modes field indicates that the PSK mode is used for key negotiation, and the pre_shared_key field includes identification information indicating the fourth key.
[0328] For example, when the IPsec connection is successfully established, the terminal device determines whether the first condition is met based on the ATSSS rule in the response message #1. If the first condition is met, the terminal device initiates the establishment of the MPQUIC connection and sends message #1 to the user plane network element.
[0329] S522. The user plane network element sends message #2 to the terminal device. Correspondingly, the terminal device receives message #2 from the user plane network element.
[0330] Message #2 includes identification information indicating the fourth key and MAC #5 generated by the user plane network element based on the fourth key. For example, the user plane network element calculates MAC #5 based on the fourth key and the hash value of message #1. Exemplarily, message #2 includes a ServerHello message, the pre_shared_key field includes identification information indicating the fourth key, and a Finished message includes MAC #5.
[0331] Before generating MAC#5 based on the fourth key, the user plane network element may derive the fourth key. Exemplarily, the user plane network element derives the fourth key under the triggering of message #1. When the information used to derive the fourth key includes MPQUIC connection indication information, the user plane network element may determine, based on message #1, that the terminal device is requesting to establish an MPQUIC connection, thereby determining the MPQUIC connection indication information. Before generating MAC#5 based on the fourth key, the user plane network element may also, under the triggering of message #1, search for the fourth key from locally stored keys. For specific implementation methods, refer to the above description of the user plane network element searching for the second key.
[0332] Optionally, when the user-plane network element sends message #2 to the terminal device, it may also determine whether to accept the terminal device from establishing an MPQUIC connection based on the ATSSS rules on the user-plane network element side. For example, when at least one of the ATSSS rules on the user-plane network element side indicates the use of the MPQUIC proxy function to guide, switch, and split the data of session #1, the user-plane network element sends message #2 to the terminal device, indicating that it accepts the terminal device from establishing an MPQUIC connection; when there is no ATSSS rule on the user-plane network element side that indicates the use of the MPQUIC proxy function to guide, switch, and split the data of session #1, the user-plane network element sends a message to the terminal device to indicate the rejection of the MPQUIC connection establishment, or sends a message to indicate the failure of the MPQUIC connection establishment.
[0333] S523: The terminal device verifies MAC #5 according to the fourth key, and sends message #3 to the user plane network element. Correspondingly, the user plane network element receives message #3 from the terminal device.
[0334] For example, the terminal device generates MAC#6 based on the fourth key and determines whether verification is successful based on whether MAC#5 and MAC#6 are identical. In other words, it determines whether the terminal device successfully authenticates the user-plane network element. If MAC#5 and MAC#6 are identical, verification is successful; if MAC#5 and MAC#6 are different, verification fails.
[0335] Among them, the way in which the terminal device generates MAC#6 is the same as the way in which the user-plane network element generates MAC#5. The specific method may be specified by the protocol, or negotiated by the terminal device and the user-plane network element, or pre-configured in the terminal device and the user-plane network element. The embodiment of the present application does not impose any restrictions on this.
[0336] If verification succeeds (i.e., MAC#5 and MAC#6 are identical), the terminal device generates MAC#7 based on the fourth key. For example, the terminal device calculates MAC#7 based on the fourth key and a hash value of at least one of the following messages: Message#1 or Message#2. The terminal device then sends Message#3 to the user plane network element, where Message#3 includes MAC#7.
[0337] S524. The user plane network element verifies MAC#7 according to the fourth key.
[0338] For example, the user plane network element generates MAC#8 based on the fourth key and determines whether the verification is successful based on whether MAC#7 and MAC#8 are the same. In other words, it determines whether the user plane network element successfully authenticates the terminal device. If MAC#7 and MAC#8 are the same, the verification is successful. If MAC#7 and MAC#8 are different, the verification fails.
[0339] Among them, the way in which the terminal device generates MAC#7 is the same as the way in which the user-plane network element generates MAC#8. The specific method may be specified by the protocol, or negotiated by the terminal device and the user-plane network element, or pre-configured in the terminal device and the user-plane network element. The embodiment of the present application does not impose any restrictions on this.
[0340] When the verification is successful, the MPQUIC connection between the terminal device and the user-plane network element is successfully established. The terminal device and the user-plane network element can deduce the fifth key based on the first key. The terminal device and the user-plane network element can subsequently use the fifth key to securely protect the data of session #1 and transmit the securely protected data through the MPQUIC connection, thereby improving the security of data transmission.
[0341] It should be noted that the messages exchanged between the terminal device and the user-plane network element in steps S511 to S524 and the data subsequently transmitted between the terminal device and the user-plane network element through an IPsec connection or an MPQUIC connection are all via the non-3GPP access network, that is, in steps S511 to S524, the terminal device and the user-plane network element establish an IPsec connection and an MPQUIC connection via the non-3GPP access network, and subsequently the terminal device and the user-plane network element transmit data through an IPsec connection or an MPQUIC connection via the non-3GPP access network.
[0342] In another implementation, the terminal device and the user-plane network element establish a first connection according to the first key (step S490) including: the terminal device and the user-plane network element establish an MPQUIC connection according to the first key.
[0343] The terminal device and the user plane network element establishing an MPQUIC connection according to the first key includes: the terminal device and the user plane network element performing identity authentication according to the first key or the fourth key, wherein the fourth key is obtained according to the first key.
[0344] The implementation method for the terminal device to derive the fourth key from the first key can refer to the description above. The user plane network element derives the fourth key in the same manner as the terminal device; alternatively, the user plane network element receives the fourth key before establishing an MPQUIC connection with the terminal device. The implementation method for the user plane network element to receive the fourth key can refer to the above-mentioned method for receiving the second key.
[0345] Exemplarily, the terminal device and the user-plane network element establish an MPQUIC connection according to the transport layer security (TLS) protocol, including the above steps S521 to S524. For any details not described, reference may be made to the existing protocol.
[0346] As shown in FIG6 , in another implementation, the terminal device and the user plane network element establish a first connection according to the first key (step S490) including:
[0347] When the second condition is met, the terminal device and the user-plane network element establish an IPsec connection based on the first key. Then, when the IPsec connection is successfully established and the first condition is met, the terminal device and the user-plane network element establish an MPQUIC connection. When the second condition is not met, the terminal device and the user-plane network element establish an MPQUIC connection based on the first key. That is, when the second condition is not met, the terminal device and the user-plane network element do not need to establish an IPsec connection, that is, they skip the IPsec connection establishment and directly establish the MPQUIC connection.
[0348] The second condition includes any of the following:
[0349] (1) At least one of the ATSSS rules on the terminal device side indicates that the data of session #1 should be guided, switched, and split using the MPTCP function or the ATSSS-LL function. That is, the data of session #1 needs to be guided, switched, and split using the MPTCP function or the ATSSS-LL function.
[0350] (2) Response message #1 includes information indicating that an IPsec connection needs to be established, such as response message #1 including indication information #7;
[0351] (3) Response message #1 does not include information indicating that an IPsec connection does not need to be established, or does not include information indicating that IPsec connection establishment is skipped, or does not include information indicating that an MPQUIC connection is directly established, such as response message #1 does not include indication information #8.
[0352] Exemplarily, the terminal device determines whether the second condition is met based on the response message #1. If the second condition is met, the terminal device initiates IPsec connection establishment and performs the above steps S510 and S520 with the user plane network element. Optionally, in step S512, the user plane network element may determine whether to accept the IPsec connection establishment request of the terminal device. For example, when at least one of the ATSSS rules on the user plane network element side indicates the use of the MPTCP function or the ASSSS-LL function to guide, switch and split the data of session #1, the user plane network element sends an IKE_SA_INIT message #2 to the terminal device according to step S512, and the terminal device and the user plane network element continue to perform subsequent steps. When there is no ATSSS rule on the user plane network element side that indicates the use of the MPTCP function or the ASSSS-LL function to guide, switch and split the data of session #1, the user plane network element sends a message to the terminal device to indicate the rejection of the IPsec connection establishment request, and the process ends.
[0353] When the second condition is not met, the terminal device initiates MPQUIC connection establishment, and directly executes step S520 with the user-plane network element, skipping step S510. Optionally, in step S522, the user-plane network element may determine whether the terminal device is allowed to skip the IPsec connection establishment and directly establish the MPQUIC connection. For example, when there is no ATSSS rule on the user-plane network element side that indicates the use of the MPTCP function or the ASSSS-LL function to guide, switch, and split the data of session #1, the user-plane network element sends message #2 to the terminal device in accordance with step S522, and the terminal device and the user-plane network element continue to execute subsequent steps. When there is at least one ASSSS rule on the user-plane network element side that indicates the use of the MPTCP function or the ASSSS-LL function to guide, switch, and split the data of session #1, the user-plane network element sends a message to the terminal device to indicate the rejection of the MPQUIC connection establishment. The message may also indicate that the reason for the rejection is that an IPsec connection needs to be established first, and the process ends.
[0354] Alternatively, establishing the first connection between the terminal device and the user plane network element according to the first key (step S490) includes:
[0355] If the fourth condition is met, the terminal device and the user-plane network element establish an MPQUIC connection based on the first key. That is, if the fourth condition is met, the terminal device and the user-plane network element do not need to establish an IPsec connection, that is, they skip establishing the IPsec connection and directly establish the MPQUIC connection. If the fourth condition is not met, the terminal device and the user-plane network element establish an IPsec connection based on the first key. Then, if the IPsec connection is successfully established and the first condition is met, the terminal device and the user-plane network element establish an MPQUIC connection.
[0356] The fourth condition includes any of the following:
[0357] (1) The ATSSS rules on the terminal device side all indicate that the MPQUIC function is used to guide, switch, and split the data of session #1. That is, the data of session #1 is all guided, switched, and split using the MPQUIC function;
[0358] (2) Response message #1 does not include information indicating that an IPsec connection needs to be established, such as response message #1 does not include indication information #7;
[0359] (3) Response message #1 includes information indicating that an IPsec connection does not need to be established, or includes information indicating that IPsec connection establishment is skipped, or includes information indicating that an MPQUIC connection is directly established, such as response message #1 includes indication information #8.
[0360] Exemplarily, the terminal device determines whether the fourth condition is met based on the response message #1. If the fourth condition is met, the terminal device initiates MPQUIC connection establishment, and directly executes step S520 with the user-plane network element, skipping step S510; if the fourth condition is not met, the terminal device initiates IPsec connection establishment, and executes the above steps S510 and S520 with the user-plane network element.
[0361] It should be noted that, when the terminal device and the user-plane network element skip step S510 and directly execute step S520, the fourth key is derived based on the first key.
[0362] In the prior art, the terminal device and the user-plane network element can only establish an MPQUIC connection if the IPsec connection is successfully established. Moreover, even if the terminal device and the user-plane network element have successfully authenticated each other during the IPsec connection establishment process, the terminal device and the user-plane network element still need to authenticate each other again when establishing the MPQUIC connection, which makes the process complicated and cumbersome. In addition, the prior art also has the problem of security redundancy. Taking the session between the terminal device and the user-plane network element as a protocol data unit (PDU) session, the terminal device sends a PDU data packet to the user-plane network element as an example. When the PDU data packet passes through the MPQUIC layer, the MPQUIC layer will perform TLS security protection on the PDU data packet (such as security protection according to the above-mentioned fifth key) to obtain the PDU data packet after TLS security protection. Subsequently, the PDU data packet after TLS encryption is encapsulated as a UDP data packet via the user datagram protocol (UDP) layer and reaches the IP layer. The IP layer performs IPsec security protection on the UDP data packet (such as security protection based on the third key mentioned above) to obtain the IP packet after IPsec security protection. The terminal device then transmits the IP packet to the user-plane network element via the access network. From the above process, it can be seen that the data transmitted through the MPQUIC connection has undergone two layers of security protection, one of which is the MPQUIC layer security protection based on TLS technology, and the other is the IPsec security protection at the IP layer. Correspondingly, the user-plane network element needs to undergo two layers of integrity verification and / or decryption at the IP layer and the MPQUIC layer to obtain the real PDU data packet. Double-layer security protection leads to security redundancy and also leads to excessive processing complexity at both ends of data transmission and reception.
[0363] In contrast, based on the implementation shown in Figure 6, when the second condition is not met, or when the third condition is met, the terminal device and the user-plane network element can directly establish an MPQUIC connection without establishing an IPsec connection. In this way, the terminal device and the user-plane network element only need to perform identity authentication once, which can simplify the process and save network transmission resources. Moreover, the data sending end only needs to perform security protection on the data based on TLS technology at the MPQUIC layer. Correspondingly, the data sending end only needs to perform integrity verification and / or decryption on the data based on TLS technology at the MPQUIC layer. This can reduce the processing complexity of both the data sending and receiving ends without reducing the security of data transmission.
[0364] Figure 7 is a schematic diagram of the structure of a communication device 1000 provided in an embodiment of the present application. As shown in Figure 7, the device 1000 may include a transceiver unit 1010 and a processing unit 1020. The transceiver unit 1010 can implement corresponding communication functions, and the processing unit 1020 is used to perform data processing, or in other words, the transceiver unit 1010 is used to perform operations related to receiving and sending, and the processing unit 1020 is used to perform other operations in addition to receiving and sending. The transceiver unit 1010 can also be referred to as a communication interface or a communication unit.
[0365] In one possible design, the communication device 1000 may correspond to the terminal device in the above method embodiment, or be a component (such as a chip) of the terminal device.
[0366] The communication device 1000 can implement the steps or processes executed by the terminal device in the above method embodiment, wherein the transceiver unit 1010 can be used to perform the transceiver-related operations of the terminal device in the above method embodiment, and the processing unit 1020 can be used to perform the internal processing-related operations of the terminal device in the above method embodiment.
[0367] Exemplarily, the processing unit 1020 is used to generate a security context during the process of registering to the core network through the Third Generation Partnership Project 3GPP access network; the transceiver unit 1010 is used to send a session establishment request message through the 3GPP access network, the session establishment request message is used to request to establish a session, and the session is used for the terminal device to transmit data with the user plane network element in the core network through the 3GPP access network and the non-3GPP access network; the transceiver unit 1010 is also used to receive a session establishment response message, and the session establishment response message is used to indicate that the session establishment is successful; the processing unit 1020 is also used to deduce a first key according to the security context in response to the session establishment response message; the processing unit 1020 is also used to establish a first connection between the terminal device and the user plane network element based on the first key, and the first connection is used for the terminal device to transmit session data with the user plane network element through the non-3GPP access network.
[0368] In which, when the device 1000 is used to execute the method in Figure 4, the transceiver unit 1010 can be used to execute the steps of sending and receiving information in the method, such as steps S420, S470, or S490; the processing unit 1020 can be used to execute the internal processing steps in the method, such as steps S410, S480, or S490.
[0369] In which, when the device 1000 is used to execute the method in Figure 5, the transceiver unit 1010 can be used to execute the steps of sending and receiving information in the method, such as steps S511 to S514, or S521 to S523; the processing unit 1020 can be used to execute the internal processing steps in the method, such as steps S515 or S523.
[0370] It should be understood that the specific process of each unit executing the above steps can be found in the description of the above embodiment and will not be repeated here.
[0371] In another possible design, the communication device 1000 may correspond to the user plane network element in the above method embodiment, or a component of the user plane network element (such as a chip).
[0372] The communication device 1000 can implement the steps or processes executed by the user plane network element in the above method embodiment, wherein the transceiver unit 1010 can be used to perform operations related to the transmission and reception of the user plane network element in the above method embodiment, and the processing unit 1020 can be used to perform operations related to the internal processing of the user plane network element in the above method embodiment.
[0373] Exemplarily, the transceiver unit 1010 is used to receive a first key during a process in which the terminal device establishes a session with a user plane network element through a 3GPP access network, and the session is used for the user plane network element to transmit data with the terminal device through the 3GPP access network and the non-3GPP access network; the processing unit 1020 is used to establish a first connection between the user plane network element and the terminal device based on the first key, and the first connection is used for the user plane network element to transmit session data with the terminal device through the non-3GPP access network.
[0374] In which, when the device 1000 is used to execute the method in Figure 4, the transceiver unit 1010 can be used to execute the steps of sending and receiving information in the method, such as steps S440, S445, S447, S450, S460, or S490; the processing unit 1020 can be used to execute the internal processing steps in the method, such as step S490.
[0375] In which, when the device 1000 is used to execute the method in Figure 5, the transceiver unit 1010 can be used to execute the steps of sending and receiving information in the method, such as steps S511 to S514, or S521 to S523; the processing unit 1020 can be used to execute the internal processing steps in the method, such as step S514, or S524.
[0376] It should be understood that the specific process of each unit executing the above steps can be found in the description of the above embodiment and will not be repeated here.
[0377] In another possible design, the communication device 1000 may correspond to the session management network element in the above method embodiment, or a component (such as a chip) of the session management network element.
[0378] The communication device 1000 can implement the steps or processes executed by the session management network element in the above method embodiment, wherein the transceiver unit 1010 can be used to perform operations related to sending and receiving of the session management network element in the above method embodiment, and the processing unit 1020 can be used to perform operations related to internal processing of the session management network element in the above method embodiment.
[0379] Exemplarily, the transceiver unit 1010 is used to receive a session establishment request message, which is used to request establishment of a session for a terminal device, and the session is used for the terminal device to transmit data with a user plane network element through a 3GPP access network and a non-3GPP access network; the processing unit 1020 is used to obtain a first key based on the session establishment request message; the transceiver unit 1010 is also used to send a first key to the user plane network element, and the first key is used to establish a first connection between the user plane network element and the terminal device, and the first connection is used for the terminal device and the user plane network element to transmit session data through a non-3GPP access network.
[0380] In which, when the device 1000 is used to execute the method in Figure 4, the transceiver unit 1010 can be used to execute the steps of sending and receiving information in the method, such as steps S430, S443, S444, S440, S445, S446, S447, S450, S460, and S470; the processing unit 1020 can be used to execute the internal processing steps in the method.
[0381] In another possible design, the communication device 1000 may correspond to the first network element in the above method embodiment, or a component of the first network element (such as a chip).
[0382] The communication device 1000 can implement the steps or processes corresponding to those executed by the first network element in the above method embodiment, wherein the transceiver unit 1010 can be used to perform operations related to the transmission and reception of the first network element in the above method embodiment, and the processing unit 1020 can be used to perform operations related to the internal processing of the first network element in the above method embodiment.
[0383] Exemplarily, the processing unit 1020 is used to obtain the security context of the terminal device during the process of the terminal device registering to the core network through the Third Generation Partnership Project 3GPP access network; the processing unit 1020 is also used to derive a first key based on the security context during the process of the terminal device requesting to establish a session through the 3GPP access network; the transceiver unit 1010 is used to send the first key; wherein, the session is used for the terminal device to transmit data with the user plane network element in the core network through the 3GPP access network and the non-3GPP access network.
[0384] When the device 1000 is used to execute the method in FIG. 4 , the transceiver unit 1010 may be used to execute the steps of sending and receiving information in the method, such as steps S420 , S430 , S443 , S444 , S446 , S447 , or S470 .
[0385] It should be understood that the device 1000 here is embodied in the form of a functional unit. The term "unit" here can refer to an application specific integrated circuit (ASIC), an electronic circuit, a processor (such as a shared processor, a dedicated processor or a group processor, etc.) and a memory for executing one or more software or firmware programs, a combined logic circuit and / or other suitable components that support the described functions. In an optional example, the above-mentioned transceiver unit 1010 can also be a transceiver circuit (for example, it can include a receiving circuit and a transmitting circuit), and the processing unit 1020 can be a processing circuit.
[0386] The apparatus 1000 of each of the above-mentioned solutions has the function of implementing the corresponding steps performed by the network element (such as a terminal device, a user plane network element, a session management network element, or a first network element) in the above-mentioned method. This function can be implemented by hardware, or it can be implemented by hardware executing the corresponding software. The hardware or software includes one or more modules corresponding to the above-mentioned functions; for example, the transceiver module can be replaced by a transceiver (for example, the sending unit in the transceiver module can be replaced by a transmitter, and the receiving unit in the transceiver module can be replaced by a receiver), and other units, such as the processing module, can be replaced by a processor to respectively perform the transceiver operations and related processing operations in each method embodiment.
[0387] Figure 8 is a schematic diagram of another communication device 2000 provided in an embodiment of the present application. The device 2000 includes one or more processors 2010 and one or more memories 2020. The processor 2010 is configured to execute computer programs or instructions stored in the memory 2020, or to read data / signaling stored in the memory 2020, to perform the methods described in the above method embodiments. The memory 2020 is configured to store computer programs or instructions and / or data. The memory 2020 may be integrated with the processor 2010, or may be provided separately.
[0388] Optionally, as shown in Figure 8, the apparatus 2000 further includes a transceiver 2030, which is configured to receive and / or transmit signals. For example, the processor 2010 is configured to control the transceiver 2030 to receive and / or transmit signals.
[0389] As a solution, the device 2000 is used to implement the operations performed by the terminal device in the above various method embodiments.
[0390] As another solution, the apparatus 2000 is used to implement the operations performed by the user plane network element in each of the above method embodiments.
[0391] As another solution, the apparatus 2000 is used to implement the operations performed by the session management network element in each of the above method embodiments.
[0392] As another solution, the device 2000 is used to implement the operations performed by the first network element in the above method embodiments.
[0393] It should be understood that the processor mentioned in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0394] It should also be understood that the memory mentioned in the embodiments of the present application may be a volatile memory and / or a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes the following forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0395] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor. It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0396] 9 is a schematic diagram of a chip system 3000 according to an embodiment of the present application. The chip system 3000 (or also referred to as a processing system) includes a logic circuit 3010 and an input / output interface 1002 .
[0397] Logic circuit 3010 may be a processing circuit in chip system 3000. Logic circuit 3010 may be coupled to a storage unit and call instructions in the storage unit, so that chip system 3000 can implement the methods and functions of various embodiments of the present application. Input / output interface 3020 may be an input / output circuit in chip system 3000, outputting information processed by chip system 3000 or inputting data or signaling information to be processed into chip system 3000 for processing.
[0398] As a solution, the chip system 3000 is used to implement the operations performed by the terminal device, user plane network element, session management network element, or first network element in each of the above method embodiments. For example, the logic circuit 3010 is used to implement the internal processing-related operations performed by the terminal device, user plane network element, session management network element, or first network element in the above method embodiments; and the input / output interface 3020 is used to implement the sending and / or receiving-related operations performed by the terminal device, user plane network element, session management network element, or first network element in the above method embodiments.
[0399] The explanation of the relevant contents and beneficial effects of any of the above-mentioned devices can be referred to the corresponding method embodiments provided above, which will not be repeated here.
[0400] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0401] An embodiment of the present application further provides a communications system, including a user plane network element and a session management network element, wherein the user plane network element is configured to implement the operations performed by the user plane network element in each of the above method embodiments, and the session management network element is configured to implement the operations performed by the session management network element in each of the above method embodiments. Optionally, the communications system further includes a first network element, wherein the first network element is configured to implement the operations performed by the first network element in each of the above method embodiments.
[0402] The present application also provides a computer-readable storage medium storing computer instructions for implementing the methods performed by a terminal device, a user plane network element, a session management network element, or a first network element in each of the above-described method embodiments. For example, when the computer program is executed by a computer, the computer can implement the methods performed by the terminal device, the user plane network element, the session management network element, or the first network element in each of the above-described method embodiments.
[0403] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. For example, the computer can be a personal computer, a server, or a network device, etc. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state disk (SSD)). For example, the available medium includes, but is not limited to, various media that can store program code, such as a USB flash drive, a mobile hard disk, ROM, RAM, a magnetic disk, or an optical disk.
[0404] In order to facilitate understanding of the embodiments of the present application, the following explanations are made.
[0405] First, in the various embodiments of the present application, unless otherwise specified or logically conflicting, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0406] Second, in the embodiments of this application, "plurality" refers to two or more. "And / or" describes the relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the associated objects are in an "or" relationship.
[0407] Third, in the embodiments of the present application, "first," "second," and various numerical references (e.g., #1, #2, etc.) are used to distinguish between different messages for ease of description and are not intended to limit the scope of the embodiments of the present application. For example, they are used to distinguish between different messages, rather than to describe a specific order or precedence. It should be understood that the objects described in this manner can be interchanged where appropriate to describe scenarios other than the embodiments of the present application.
[0408] Fourth, in the embodiments of the present application, descriptions such as "when...", "in the case of...", and "if" all mean that the device will perform corresponding processing under certain objective circumstances. It does not limit the time, nor does it require the device to perform judgment actions when implemented, nor does it mean that there are other limitations.
[0409] Fifth, in the embodiments of the present application, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or apparatus that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products or apparatuses.
[0410] Sixth, in the embodiments of the present application, "used for indication" may include direct indication and indirect indication. When describing that a certain indication information is used to indicate A, it may include that the indication information directly indicates A or indirectly indicates A, and does not necessarily mean that the indication information carries A.
[0411] The indication methods involved in the embodiments of this application should be understood to encompass various methods that enable the party to be indicated to obtain information to be indicated. The information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately. The transmission period and / or timing of these sub-information can be the same or different. This application does not limit the specific transmission method.
[0412] In the embodiments of the present application, the "indication information" may be an explicit indication, i.e., a direct indication via signaling, or may be obtained based on parameters indicated by the signaling, in combination with other rules, other parameters, or by deduction. It may also be an implicit indication, i.e., based on a rule or relationship, or based on other parameters, or by deduction. This application does not impose specific limitations on this.
[0413] Seventh, in the embodiments of the present application, "storage" may refer to storage in one or more memories. The one or more memories may be provided separately or integrated into an encoder or decoder, a processor, or a communication device. The one or more memories may also be partially provided separately and partially integrated into a decoder, a processor, or a communication device. The type of memory may be any form of storage medium and is not limited by this application.
[0414] Eighth, in the embodiments of the present application, "communication" can also be described as "data transmission", "information transmission", "data processing", etc. "Transmission" includes "sending" and "receiving", which is not limited in the present application.
[0415] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A communication method, characterized in that: include: Generate a security context during the registration process with the core network through the 3rd Generation Partnership Project 3GPP access network; Sending a session establishment request message through the 3GPP access network, wherein the session establishment request message is used to request establishment of a session, wherein the session is used for a terminal device to transmit data with a user plane network element in the core network through the 3GPP access network and a non-3GPP access network; receiving a session establishment response message, where the session establishment response message is used to indicate that the session establishment is successful; In response to the session establishment response message, deriving a first key according to the security context; A first connection is established between the terminal device and the user plane network element according to the first key, where the first connection is used for the terminal device to transmit data of the session with the user plane network element through the non-3GPP access network.
2. The method according to claim 1, characterized in that The session establishment response message includes first address information of the user plane network element side, where the first address information is used by the terminal device to communicate with the user plane network element through the non-3GPP access network; The deducing a first key according to the security context includes: In a case where the session establishment response message includes the first address information, the first key is deduced according to the security context.
3. The method according to claim 1, characterized in that The session establishment response message includes first indication information, where the first indication information is used to indicate that the non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element.
4. The method according to claim 3, characterized in that The deducing a first key according to the security context includes: In a case where the session establishment response message includes the first indication information, the first key is deduced according to the security context.
5. The method according to any one of claims 1 to 4, characterized in that The deducing the first key according to the security context includes: Deducing the first key based on the security context, the identification information of the session, and the identification information of the terminal device; or, The first key is deduced based on the security context and second address information on the user plane network element side, where the second address information is used by the terminal device to communicate with the user plane network element through the 3GPP access network.
6. The method according to any one of claims 1 to 5, characterized in that The deducing a first key according to the security context includes: According to the K in the security context AMF , K AUSF , or K SEAF The first key is derived.
7. The method according to any one of claims 1 to 6, characterized in that The establishing a first connection between the terminal device and the user plane network element according to the first key includes: establishing an Internet Protocol security (IPsec) connection between the terminal device and the user plane network element according to the first key; If the IPsec connection is successfully established and the first condition is met, establishing a Multipath Fast User Datagram Protocol Internet Connection (MPQUIC) connection between the terminal device and the user plane network element; The first condition includes: at least one ASSS rule among the one or more ASSS rules in the session establishment response message indicates the use of the MPQUIC function to guide, switch and split the data of the session.
8. The method according to claim 7, characterized in that The establishing an IPsec connection between the terminal device and the user plane network element according to the first key includes: When a second condition is met, the IPsec connection is established according to the first key, where the second condition includes any one of the following: At least one of the one or more ATSSS rules in the session establishment response message indicates that the multipath transmission control protocol MPTCP function or the ATSSS lower layer ATSSS-LL function is used to guide, switch and split the data of the session; The session establishment response message includes information indicating that an IPsec connection needs to be established; or The session establishment response message does not include information indicating that the IPsec connection does not need to be established.
9. The method according to claim 7 or 8, characterized in that The establishing an IPsec connection between the terminal device and the user plane network element according to the first key includes: Identity authentication is performed with the user plane network element according to the first key or the second key, where the second key is obtained according to the first key.
10. The method according to claim 9, characterized in that In the case where identity authentication is performed with the user plane network element according to the second key, the method further includes: The second key is obtained according to the first key and the IPsec connection indication information.
11. The method according to any one of claims 7 to 10, characterized in that: The establishing the MPQUIC connection between the terminal device and the user plane network element includes: Perform identity authentication with the user plane network element according to the first key or the fourth key, where the fourth key is obtained according to any one of the following keys: the first key, the second key, or the third key; The second key is used to perform identity authentication with the user plane network element during the process of establishing the IPsec connection, and the third key is used to securely protect data transmitted through the IPsec connection.
12. The method according to any one of claims 1 to 6, characterized in that The establishing of the first connection between the terminal device and the user plane network element according to the first key includes: An MPQUIC connection is established between the terminal device and the user plane network element according to the first key.
13. The method according to claim 12, characterized in that The establishing the MPQUIC connection between the terminal device and the user plane network element according to the first key includes: Identity authentication is performed with the user plane network element according to the first key or the fourth key, where the fourth key is obtained according to the first key.
14. The method according to claim 11 or 13, characterized in that In the case where identity authentication is performed with the user plane network element according to the fourth key, the method further includes: The fourth key is obtained according to the first key and the MPQUIC connection indication information.
15. A communication method, characterized in that: include: receiving a first key during a process of establishing a session between a terminal device and a user plane network element through a 3GPP access network, wherein the session is used for the user plane network element to transmit data with the terminal device through the 3GPP access network and a non-3GPP access network; A first connection is established between the user plane network element and the terminal device according to the first key, where the first connection is used for the user plane network element to transmit data of the session with the terminal device through the non-3GPP access network.
16. The method according to claim 15, characterized in that The establishing a first connection between the user plane network element and the terminal device according to the first key includes: An IPsec connection is established between the user plane network element and the terminal device according to the first key.
17. The method according to claim 16, characterized in that The establishing an IPsec connection between the user plane network element and the terminal device according to the first key includes: Identity authentication is performed with the terminal device according to the first key or the second key, where the second key is derived according to the first key.
18. The method according to claim 17, characterized in that In the case of performing identity authentication with the terminal device according to the second key, the method further includes: The second key is obtained according to the first key and the IPsec connection indication information.
19. The method according to any one of claims 16 to 18, characterized in that: The method further comprises: When the IPsec connection is successfully established, an MPQUIC connection is established between the user plane network element and the terminal device.
20. The method according to claim 19, characterized in that The establishing the MPQUIC connection between the user plane network element and the terminal device includes: Performing identity authentication with the terminal device according to a first key or a fourth key, wherein the fourth key is obtained according to any one of the following keys: the first key, the second key, or the third key; The second key is used to perform identity authentication with the terminal device during the process of establishing the IPsec connection, and the third key is used to securely protect data transmitted through the IPsec connection.
21. The method according to claim 15, wherein The establishing a first connection between the user plane network element and the terminal device according to the first key includes: An MPQUIC connection is established between the user plane network element and the terminal device according to the first key.
22. The method according to claim 21, characterized in that The establishing the MPQUIC connection between the user plane network element and the terminal device according to the first key includes: Identity authentication is performed with the terminal device according to the first key or the fourth key, where the fourth key is obtained according to the first key.
23. The method according to claim 20 or 22, characterized in that In the case of performing identity authentication with the terminal device according to the fourth key, the method further includes: The fourth key is obtained according to the first key and the MPQUIC connection indication information.
24. A communication method, characterized in that: include: receiving a session establishment request message, wherein the session establishment request message is used to request establishment of a session for a terminal device, wherein the session is used for the terminal device to transmit data with a user plane network element through a 3GPP access network and a non-3GPP access network; Obtaining a first key according to the session establishment request message; The first key is sent to the user plane network element, where the first key is used to establish a first connection between the user plane network element and the terminal device, and the first connection is used for the terminal device and the user plane network element to transmit data of the session through the non-3GPP access network.
25. The method according to claim 24, characterized in that The session establishment request message includes the first key.
26. The method according to claim 24, characterized in that The acquiring the first key according to the session establishment request message includes: Sending a key request message according to the session establishment request message, where the key request message is used to request: a key for establishing the first connection; The first key is received.
27. The method according to claim 26, characterized in that The session establishment request message includes fourth indication information, where the fourth indication information indicates that the non-3GPP access network is used to provide a direct connection between the terminal device and the user plane network element; The sending of a key request message according to the session establishment request message includes: Send the key request message according to the fourth indication information.
28. A communication device, characterized in that: The method comprises a module for executing the method according to any one of claims 1 to 27.
29. A communication device, characterized in that: The communication device comprises a processor and a memory, wherein the memory is used to store instructions, and when the instructions are executed by the processor, the communication device causes the communication device to execute the method according to any one of claims 1 to 27.
30. A computer program product comprising instructions, characterized in that When the instructions are executed on a computer, the computer is caused to perform the method according to any one of claims 1 to 27.
31. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, and when the instructions are executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 27.
32. A communication system, characterized in that: The communication system includes a first communication device and a second communication device, wherein the first communication device is used to execute the method according to any one of claims 15 to 23, and the second communication device is used to execute the method according to any one of claims 24 to 27.
33. A communication method, characterized in that: include: The session management network element receives a session establishment request message, where the session establishment request message is used to request establishment of a session for the terminal device, where the session is used for the terminal device to transmit data with a user plane network element through a 3GPP access network and a non-3GPP access network; The session management network element obtains a first key according to the session establishment request message; The session management network element sends the first key to the user plane network element; The user plane network element establishes a first connection between the user plane network element and the terminal device according to the first key, where the first connection is used for the user plane network element to transmit data of the session with the terminal device through the non-3GPP access network.
Citation Information
Patent Citations
Communication method and device
CN116866881A
Multi-path processing method for edge shunt flow and related equipment
CN116963186A
Access method, access system and related equipment
CN117715175A
Methods and apparatus relating to communication of path switching capability information between a network device and a UE device to enable efficient switching of multi-access (MA) traffic between non-3GPP access paths
WO2023211763A1
Multiple access networks with non-integrated aggregation
WO2024039961A1