Wireless communication method and apparatus, and device

By optimizing the interaction process between the terminal and the core network and adopting a combination of encryption and verification information, the problem of low efficiency of terminal access to the network is solved, and efficient network access is achieved.

WO2025214273A1PCT designated stage Publication Date: 2025-10-16VIVO MOBILE COMM CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/087386
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-12
Filing Date
2025-04-07
Publication Date
2025-10-16

AI Technical Summary

Technical Problem

The network access process between the terminal and the core network is inefficient, and existing technologies require multiple steps of interaction, resulting in delays and inefficiencies.

Method used

By optimizing the interaction process between the terminal and the core network, reducing the interaction steps, and adopting a combination of encryption and verification information, efficient communication between the terminal and the core network can be achieved.

Benefits of technology

The efficiency of terminal access to the network is improved, allowing terminal devices to access the network and transmit information through a small number of interactive steps.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025087386_16102025_PF_FP_ABST
    Figure CN2025087386_16102025_PF_FP_ABST
Patent Text Reader

Abstract

The present application belongs to the field of communications, and discloses a wireless communication method and apparatus, and a device. The wireless communication method in the embodiments of the present application comprises: a terminal device sends first information to a first communication node. The first information comprises at least one of the following: second information, third information, and first authentication information. The second information comprises at least one of the following: first challenge information, a first sequence number, and a first authentication management domain. The third information comprises at least one of the following: fourth information and first verification information, and fifth information and second verification information. The fourth information is generated after sixth information is encrypted by a first key. The first verification information is generated on the basis of a second key, the fourth information, or the sixth information. The second verification information is generated on the basis of a third key, the fifth information, or seventh information. The seventh information is information obtained after the fifth information is encrypted.
Need to check novelty before this filing date? Find Prior Art

Description

Wireless communication method, apparatus and device

[0001] The present application claims priority from the Chinese patent application No. 202410443292.X, filed on April 12, 2024, and entitled "Wireless communication method, apparatus and device", the whole content of which is incorporated herein by reference. TECHNICAL FIELD

[0002] The present application relates to the field of communication, and more particularly, to a wireless communication method, apparatus and device. BACKGROUND

[0003] In the related art, the terminal access network process can include:

[0004] 1. A bidirectional authentication process between the terminal and the core network;

[0005] 2. A Security Mode Control (SMC) process at the NAS level.

[0006] Figure 1 is a schematic diagram of a terminal access network process. As shown in Figure 1, the terminal and the unified data management (UDM) have a shared key, i.e., key 1, and a bidirectional authentication NAS procedure between the terminal and the core network includes: S1, the terminal sends an NAS message (msg) 1 to an access and mobility management function (AMF), the msg 1 including: an identifier of the terminal and algorithm information supported by the terminal; S2, the AMF obtains authentication data from the UDM, including: challenge information (such as a random number (RAND)), second sequence number (such as a sequence number (SQN) in an authentication token (AUTN)), authentication management domain (such as AMF information in the AUTN), second authentication information (such as MAC in the AUTN), and third authentication information (XRES); S3, the AMF sends an NAS message (msg) 2 to the terminal, the msg 2 including: the challenge information (RAND) and the AUTN; S4, the terminal verifies the second authentication information (MAC in the AUTN) to authenticate the network side, and if the authentication is successful, the terminal generates first authentication information (RES) based on the key 1 and the challenge information (RAND); S5, the terminal sends an NAS message (msg) 3 to the AMF, the msg 3 including: the first authentication information (RES); S6, the AMF verifies the first authentication information (RES) based on the third authentication information (XRES) to authenticate the terminal, wherein the third authentication information (XRES) is also generated based on the key 1 and the challenge information (RAND).

[0007] An NAS procedure (SMC procedure) between the terminal and the core network that enables NAS security includes: S7, after the AMF successfully authenticates the terminal, the AMF sends an NAS message (msg) 4 to the terminal, the msg 4 including: algorithm information of an encryption algorithm selected by the AMF and algorithm information of an integrity protection algorithm; S8, the terminal verifies the msg 4, and if the verification is successful, the terminal enables confidentiality and integrity protection of NAS messages based on the selected encryption algorithm and integrity protection algorithm; S9, the terminal sends an NAS message (msg) 5 to the AMF, the msg 5 including: cipher text and a message authentication code (MAC); and S10, the AMF decrypts and performs integrity protection verification on the msg 5 based on the selected encryption algorithm and integrity protection algorithm.

[0008] The msg1-msg5 are all NAS messages, and thus it is known that at least 5 steps of interaction are needed between the terminal and the core network, and after that, the terminal can access the network and deliver information. However, due to the large number of interaction steps, the efficiency of the terminal accessing the network is low. SUMMARY

[0009] Embodiments of the present application provide a wireless communication method, device and equipment, which can solve the problem of low efficiency of terminal accessing the network.

[0010] In a first aspect, a wireless communication method is provided, comprising:

[0011] The terminal device sends first information to a first communication node;

[0012] The first information includes at least one of the following: second information, third information and first authentication information;

[0013] The second information includes at least one of the following: first challenge information, first sequence number, first authentication management domain;

[0014] The third information includes at least one of the following:

[0015] Fourth information and first check information;

[0016] Fifth information and second check information;

[0017] The fourth information is generated by encrypting the sixth information by using a first key;

[0018] The first check information is generated based on a second key, the fourth information or the sixth information;

[0019] The second check information is generated based on a third key, the fifth information or the seventh information;

[0020] The seventh information is information obtained by encrypting the fifth information.

[0021] In a second aspect, a wireless communication method is provided, comprising:

[0022] The first communication node receives first information from a terminal device, and the first communication node performs at least one of a first operation and a second operation according to the first information;

[0023] The first information includes at least one of the following: second information, third information and first authentication information;

[0024] The second information includes at least one of the following: first challenge information, first sequence number, first authentication management domain;

[0025] The third information includes at least one of the following:

[0026] The fourth information and the first check information;

[0027] The fifth information and the second check information;

[0028] The fourth information is generated by encrypting the sixth information by using the first key;

[0029] The first check information is generated based on the second key, the fourth information or the sixth information;

[0030] The second check information is generated based on the third key, the fifth information or the seventh information;

[0031] The seventh information is information obtained by encrypting the fifth information;

[0032] The first operation includes checking the first authentication information;

[0033] The second operation includes at least one of the following:

[0034] Decrypting the fourth information based on the first key;

[0035] A third check operation;

[0036] A fourth check operation;

[0037] The third check operation includes checking the first check information based on the second key, the fourth information or the sixth information;

[0038] The fourth check operation includes checking the second check information based on the third key, the fifth information or the seventh information.

[0039] In a third aspect, a wireless communication device is provided, including:

[0040] A transceiver configured to send first information to a first communication node;

[0041] The first information includes at least one of the following: second information, third information and first authentication information;

[0042] The second information includes at least one of the following: first challenge information, first sequence number, first authentication management domain;

[0043] The third information includes at least one of the following:

[0044] The fourth information and the first check information;

[0045] The fifth information and the second check information;

[0046] wherein the fourth information is generated by encrypting the sixth information by the first key;

[0047] wherein the first check information is generated based on the second key, the fourth information or the sixth information;

[0048] wherein the second check information is generated based on the third key, the fifth information or the seventh information;

[0049] wherein the seventh information is information obtained by encrypting the fifth information.

[0050] In a fourth aspect, a wireless communication apparatus is provided, comprising: a transceiver and a processing unit;

[0051] The transceiver is configured to receive first information from a terminal device, and the processing unit is configured to perform at least one of a first operation and a second operation based on the first information;

[0052] wherein the first information comprises at least one of: second information, third information and first authentication information;

[0053] wherein the second information comprises at least one of: first challenge information, first sequence number, first authentication management domain;

[0054] wherein the third information comprises at least one of:

[0055] fourth information and first check information;

[0056] fifth information and second check information;

[0057] wherein the fourth information is generated by encrypting the sixth information by the first key;

[0058] wherein the first check information is generated based on the second key, the fourth information or the sixth information;

[0059] wherein the second check information is generated based on the third key, the fifth information or the seventh information;

[0060] wherein the seventh information is information obtained by encrypting the fifth information.

[0061] wherein the first operation comprises checking the first authentication information;

[0062] wherein the second operation comprises at least one of:

[0063] decrypting the fourth information based on the first key;

[0064] a third check operation;

[0065] a fourth check operation;

[0066] wherein the third verifying operation comprises verifying the first verification information based on the second key, the fourth information or the sixth information;

[0067] wherein the fourth verifying operation comprises verifying the second verification information based on the third key, the fifth information or the seventh information.

[0068] In a fifth aspect, a terminal is provided, which comprises a transceiver, a processor and a memory, the memory storing programs or instructions executable on the processor, and the programs or instructions, when executed by the processor, implement the steps of the method according to the first aspect.

[0069] In a sixth aspect, a terminal is provided, which comprises a processor and a communication interface;

[0070] wherein the communication interface is configured to send the first information to the first communication node;

[0071] wherein the first information comprises at least one of the following: the second information, the third information and the first authentication information;

[0072] wherein the second information comprises at least one of the following: the first challenge information, the first sequence number, the first authentication management domain;

[0073] wherein the third information comprises at least one of the following:

[0074] the fourth information and the first verification information;

[0075] the fifth information and the second verification information;

[0076] wherein the fourth information is generated by encrypting the sixth information by a first key;

[0077] wherein the first verification information is generated based on a second key, the fourth information or the sixth information;

[0078] wherein the second verification information is generated based on a third key, the fifth information or the seventh information;

[0079] wherein the seventh information is information obtained by encrypting the fifth information.

[0080] In a seventh aspect, a first communication node is provided, which comprises a transceiver, a processor and a memory, the memory storing programs or instructions executable on the processor, and the programs or instructions, when executed by the processor, implement the steps of the method according to the second aspect.

[0081] In an eighth aspect, a first communication node is provided, which comprises a processor and a communication interface;

[0082] wherein the communication interface is configured to receive first information from the terminal device, and the processor is configured to perform at least one of a first operation and a second operation based on the first information;

[0083] wherein the first information comprises at least one of: second information, third information, and first authentication information;

[0084] wherein the second information comprises at least one of: first challenge information, a first serial number, a first authentication management domain;

[0085] wherein the third information comprises at least one of:

[0086] fourth information and first verification information;

[0087] fifth information and second verification information;

[0088] wherein the fourth information is generated by encrypting sixth information by a first key;

[0089] wherein the first verification information is generated based on a second key, the fourth information, or the sixth information;

[0090] wherein the second verification information is generated based on a third key, the fifth information, or seventh information;

[0091] wherein the seventh information is information obtained by encrypting the fifth information;

[0092] wherein the first operation comprises verifying the first authentication information;

[0093] wherein the second operation comprises at least one of:

[0094] decrypting the fourth information based on the first key;

[0095] a third verification operation;

[0096] a fourth verification operation;

[0097] wherein the third verification operation comprises verifying the first verification information based on the second key, the fourth information, or the sixth information;

[0098] wherein the fourth verification operation comprises verifying the second verification information based on the third key, the fifth information, or the seventh information.

[0099] In a ninth aspect, a readable storage medium is provided, and the readable storage medium stores a program or instructions, and the program or instructions are executed by a processor to implement steps of the method in the first aspect or implement steps of the method in the second aspect.

[0100] In a tenth aspect, a wireless communication system is provided, including a terminal configured to perform the steps of the method of the first aspect, and a network-side device configured to perform the steps of the method of the second aspect.

[0101] In an eleventh aspect, a chip is provided, including a processor and a communication interface, the communication interface being coupled to the processor, the processor being configured to run programs or instructions to implement the method of the first aspect or the method of the second aspect.

[0102] In a twelfth aspect, a computer program / program product is provided, stored in a storage medium, the program / program product being executed by at least one processor to implement the steps of the wireless communication method of the first aspect or the second aspect.

[0103] In the embodiments of the present application, the interaction process between the terminal and the core network is changed, and the interaction steps between the terminal and the core network are reduced, so as to improve the efficiency of the terminal accessing the network. BRIEF DESCRIPTION OF DRAWINGS

[0104] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the description of the embodiments of the present application will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0105] FIG. 1 is a schematic diagram of a terminal accessing a network process provided by the present application.

[0106] FIG. 2 is a schematic diagram of a communication system architecture provided by the embodiments of the present application.

[0107] FIG. 3 is a schematic flowchart of a wireless communication method provided by the embodiments of the present application.

[0108] FIGS. 4 to 6 are schematic flowcharts of wireless communication provided by the embodiments of the present application, respectively.

[0109] FIG. 7 is a schematic block diagram of a wireless communication device provided by the embodiments of the present application.

[0110] FIG. 8 is a schematic block diagram of another wireless communication device provided by the embodiments of the present application.

[0111] FIG. 9 is a schematic block diagram of a communication device provided by the embodiments of the present application.

[0112] FIG. 10 is a schematic diagram of the hardware structure of a terminal provided by the embodiments of the present application.

[0113] FIG. 11 is a schematic block diagram of a network-side device according to an embodiment of the present application.

[0114] FIG. 12 is a schematic block diagram of another network-side device according to an embodiment of the present application. DETAILED DESCRIPTION

[0115] The technical solutions in the embodiments of the present application will be clearly described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all of them. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present application.

[0116] The terms "first", "second", and the like in the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second" are generally a category and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in the present application means at least one of the connected objects. For example, "A or B" covers three schemes, namely, scheme one: including A and not including B; scheme two: including B and not including A; scheme three: including A and including B. The character " / " generally represents that the objects before and after are in an "or" relationship.

[0117] The term "indicate" in the present application can be a direct indication (or explicit indication) or an indirect indication (or implicit indication). Among them, the direct indication can be understood as that the sender explicitly informs the receiver of specific information, operations to be performed or requested results, etc. in the sent indication; the indirect indication can be understood as that the receiver determines the corresponding information according to the indication sent by the sender, or judges and determines the operation to be performed or the requested result according to the judgment result.

[0118] It is worth noting that the technology described in embodiments of the present application is not limited to an Ambient Internet of Things (IoT) system, and can also be used in other wireless communication systems, such as a Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, a Code Division Multiple Access (CDMA) system, a Time Division Multiple Access (TDMA) system, a Frequency Division Multiple Access (FDMA) system, an Orthogonal Frequency Division Multiple Access (OFDMA) system, a Single-carrier Frequency Division Multiple Access (SC-FDMA) system, a Wireless Local Area Networks (WLAN) system, a Wireless Fidelity (WiFi) system, a Bluetooth system, or other systems. The terms "system" and "network" are often used interchangeably in embodiments of the present application, and the technology described can be used in the above-mentioned systems and radio technologies, as well as other systems and radio technologies. The following description describes a New Radio (NR) system for the purpose of example, and NR terminology is used in most of the following description, but the technology can also be applied to systems other than NR systems, such as a 6th Generation (6G) communication system. th

[0119] FIG. 2 shows a block diagram of a wireless communication system to which embodiments of the present application can be applied. Specifically, as shown in FIG. 2, the wireless communication system includes a terminal 21 and a communication node 22.

[0120] ​Optionally, the terminal 21 can be a terminal-side device such as a mobile phone, a Tablet Personal Computer (Tablet PC), a Laptop Computer (Laptop), a notebook computer, a Personal Digital Assistant (PDA), a palm computer, a netbook, an Ultra-mobile Personal Computer (UMPC), a Mobile Internet Device (MID), an Augmented Reality (AR) device, a Virtual Reality (VR) device, a robot, a wearable device, a flight vehicle, a Vehicle User Equipment (VUE), a shipboard device, a Pedestrian User Equipment (PUE), a smart home (a home device with a wireless communication function, such as a refrigerator, a television, a washing machine, or furniture, etc.), a game console, a Personal Computer (PC), a kiosk, or a self-service machine, etc. The wearable device includes a smart watch, a smart bracelet, a smart earphone, smart glasses, smart jewelry (a smart bracelet, a smart necklace, a smart ring, a smart necklace, a smart anklet, a smart necklace, etc.), a smart wristband, smart clothing, etc. The vehicle-mounted device can also be referred to as a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip, or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 21 is not limited in the embodiments of the present application.

[0121] Optionally, the communication node 22 can include at least one of a transit terminal, an access network device, and a core network node.

[0122] Optionally, the transit terminal is a terminal with a transit capability.

[0123] Optionally, the access network device can also be referred to as a radio access network (RAN) device, a radio access network function or a radio access network unit. The access network device can include a base station, a wireless local area network (WLAN) access point (AP) or a wireless fidelity (WiFi) node, etc. Among them, the base station can be referred to as a node B (NB), an evolved node B (eNB), a next generation node B (gNB), a new radio node B (NR node B), an access point, a relay base station (RBS), a serving base station (SBS), a base transceiver station (BTS), a radio base station, a radio transceiver, a basic service set (BSS), an extended service set (ESS), a home node B (HNB), a home evolved node B, a transmission reception point (TRP), or some other appropriate term in the art, as long as the same technical effect is achieved. The base station is not limited to a specific technical term, and it should be noted that in the embodiments of the present application, only the base station in the NR system is taken as an example for introduction, and the specific type of the base station is not limited.

[0124] Optionally, the core network node can include, but is not limited to, at least one of the following: a core network device, a core network function, a Mobility Management Entity (MME), an Access and Mobility Management Function (AMF), a Session Management Function (SMF), a User Plane Function (UPF), a Policy Control Function (PCF), a Policy and Charging Rules Function (PCRF), an Edge Application Server Discovery Function (EASDF), a Unified Data Management (UDM), a Unified Data Repository (UDR), a Home Subscriber Server (HSS), a Centralized network configuration (CNC), a Network Repository Function (NRF), a Network Exposure Function (NEF), a Local NEF (L-NEF), a Binding Support Function (BSF), an Application Function (AF), an Authentication Server Function (AUSF), an Authentication Center (AuC), and the like. It should be noted that only the core network functions in the NR system are taken as examples in the embodiments of the present application, and the specific types of the core network node are not limited.

[0125] It should be noted that based on the above FIG. 1, it can be known that at least 5 steps of interaction are required between the terminal and the core network at present, and the terminal can access the network, and then information can be transmitted. The process of the terminal accessing the network shown in FIG. 1 has more interaction steps, which leads to a lower efficiency of the terminal accessing the network.

[0126] In order to solve the above technical problems, the embodiments of the present application propose to reduce the interaction steps between the terminal and the core network, so as to improve the efficiency of the terminal accessing the network.

[0127] For the purpose of understanding the technical solutions of the embodiments of the present application, the technical solutions of the present application are described in detail below through specific embodiments. The above related technologies can be combined with the technical solutions of the embodiments of the present application in any manner, and all of them belong to the protection scope of the embodiments of the present application. The embodiments of the present application include at least part of the following contents.

[0128] FIG. 3 is a schematic flow chart of a wireless communication method 200 according to an embodiment of the present application. As shown in FIG. 3, the wireless communication method 200 can include at least part of the following contents:

[0129] S210, the terminal device sends first information to a first communication node; wherein the first information includes at least one of the following: second information, third information and first authentication information; wherein the second information includes at least one of the following: first challenge information, first sequence number, first authentication management field; wherein the third information includes at least one of the following: fourth information and first check information; fifth information and second check information; wherein the fourth information is generated by encrypting the sixth information by using a first key; wherein the first check information is generated based on a second key, the fourth information or the sixth information; wherein the second check information is generated based on a third key, the fifth information or seventh information; wherein the seventh information is information obtained by encrypting the fifth information;

[0130] S220, the first communication node receives the first information from the terminal device;

[0131] S230, the first communication node performs at least one of a first operation and a second operation according to the first information; wherein the first operation includes checking the first authentication information; wherein the second operation includes at least one of the following: decrypting the fourth information based on the first key; third check operation; fourth check operation; wherein the third check operation includes checking the first check information based on the second key, the fourth information or the sixth information; wherein the fourth check operation includes checking the second check information based on the third key, the fifth information or the seventh information.

[0132] It should be understood that FIG. 3 shows steps or operations of the wireless communication method 200, but these steps or operations are only examples, and the present application can also perform other operations or variations of each operation in FIG. 3.

[0133] In the embodiments of the present application, the first information can be a NAS message, and the first communication node can determine whether to allow the terminal device to access the network based on the first information. In other words, in the embodiments of the present application, the terminal device can interact with the first communication node only one NAS message, and the terminal device can access the network and deliver information. Since the interaction steps of the terminal device and the core network are reduced, the efficiency of the terminal device accessing the network can be improved.

[0134] The first communication node in the embodiments of the present application can also be referred to as a first communication device, a first communication entity, and the like, and the present application is not limited thereto.

[0135] In some embodiments, the first communication node can include, but is not limited to, at least one of the following:

[0136] AMF, UDM, AUSF, AuC.

[0137] The verification information in the embodiments of the present application can also be referred to as message integrity verification information or message authentication code (MAC), and the embodiments of the present application are not limited thereto.

[0138] In some embodiments, the first challenge information is also referred to as first random information or first random number (RAND1), and the like, but is not limited thereto, such as string information, sequentially increasing or decreasing quantity information, and the like.

[0139] In some embodiments, the fourth information can be understood as ciphertext or encrypted content, and the corresponding plaintext or plaintext content is the sixth information. Exemplarily, the sixth information can be application data or service data sent by the terminal device, but is not limited thereto. The application data can be carried by an application container (AC) field, but is not limited thereto.

[0140] In some embodiments, the fifth information can be understood as plaintext or plaintext content, and the corresponding ciphertext or encrypted content is the seventh information. Exemplarily, the fifth information can be application data or service data sent by the terminal device, but is not limited thereto. The application data can be carried by an application container (AC) field, but is not limited thereto.

[0141] In some embodiments, the second key can be an integrity protection key.

[0142] In some embodiments, the third key can be an integrity protection key.

[0143] In some embodiments, the first authentication information is used for authentication of the terminal device by the first communication node. For example, the first authentication information can be an AUTS or RES generated based on a random number (RAND).

[0144] In some embodiments, the first check information is further generated based on at least one of the first authentication information, part or all of the second information. That is, the terminal device generates the first check information based on at least one of the second key, the fourth information or the sixth information, the first authentication information, part or all of the second information.

[0145] In one implementation, the first check information is generated based on the first authentication information, in which case the first authentication information is not generated based on the first check information.

[0146] In another implementation, the first authentication information is generated based on the first check information, in which case the first check information is not generated based on the first authentication information.

[0147] In some embodiments, the second check information is further generated based on at least one of the first authentication information, part or all of the second information. That is, the terminal device generates the second check information based on at least one of the third key, the fifth information or the seventh information, the first authentication information, part or all of the second information.

[0148] In one implementation, the second check information is generated based on the first authentication information, in which case the first authentication information is not generated based on the second check information.

[0149] In another implementation, the first authentication information is generated based on the second check information, in which case the second check information is not generated based on the first authentication information.

[0150] In some embodiments, before the terminal device sends the first information to the first communication node, the wireless communication method 200 further includes at least one of:

[0151] the terminal device generates the first check information based on at least one of the second key, the fourth information or the sixth information, the first authentication information, part or all of the second information;

[0152] The terminal device generates the second check information according to at least one of the following: the third key, part or all of the fifth information or the seventh information, the first authentication information, and the second information.

[0153] In some embodiments, in the case where the first authentication information is successfully checked, the terminal device can access the network and transmit information.

[0154] In some embodiments, the first operation can be performed based on at least one of the following:

[0155] part or all of the second information;

[0156] The first specific key is known to the terminal device.

[0157] Specifically, the first communication node (such as UDM) can check the first authentication information based on at least one of the following: the first specific key, and part or all of the second information.

[0158] In some embodiments, the terminal device can know the first specific key through configuration or derivation.

[0159] Alternatively, the first specific key is known to the terminal device, UDM, or AUSF. It should be noted that some core network elements (such as AMF) do not necessarily know the first specific key.

[0160] For example, the first specific key can be a same long-term key (LTK) configured by the UDM or AUSF and the terminal device, or a key (KEY) derived based on the LTK.

[0161] For example, the first specific key can be a shared key between the terminal device and the UDM or AUSF.

[0162] Alternatively, the first specific key belongs to a key known in advance by the terminal device and the UDM or AUSF, for example, can be derived through a key known in advance by one or both parties, or can be pre-configured on both parties.

[0163] In some embodiments, the first operation can also be performed based on the check information (such as XRES or HXRES) received from other network functions. Illustratively, the first communication node can compare and check the first authentication information with the check information (such as XRES or HXRES) received from other network functions. Specifically, if the first authentication information is the same as the check information (such as XRES or HXRES) received from other network functions, the check is passed or successful; if the first authentication information is different from the check information (such as XRES or HXRES) received from other network functions, the check is failed or unsuccessful.

[0164] In some embodiments, in the case where the third check operation is successful, the terminal device can access the network and deliver information.

[0165] In some embodiments, the third check operation is further performed based on at least one of the following: the first authentication information, part or all of the second information. Specifically, the first communication node can check the first check information based on at least one of the following: the second key, the fourth information or the sixth information, the first authentication information, part or all of the second information.

[0166] In some embodiments, in the case where the fourth check operation is successful, the terminal device can access the network and deliver information.

[0167] In some embodiments, the fourth check operation is further performed based on at least one of the following: the first authentication information, part or all of the second information. Specifically, the first communication node can check the second check information based on at least one of the following: the third key, the fifth information or the seventh information, the first authentication information, part or all of the second information.

[0168] In some embodiments, the second information further comprises at least one of the following:

[0169] an identity of the terminal device, first algorithm information;

[0170] The first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a check information generation algorithm, a key derivation algorithm, an authentication information generation algorithm.

[0171] Illustratively, the first algorithm information can be the algorithm information adopted by the terminal device.

[0172] In this embodiment, after obtaining the first algorithm information, the first communication node can know the algorithm information adopted by the terminal device.

[0173] It should be understood that the encryption algorithm is used to encrypt the plaintext.

[0174] It should be understood that the integrity protection algorithm is used to integrity protect the information, for example, can be used to calculate the MAC.

[0175] It should be understood that the check information generation algorithm is used to generate the check information.

[0176] It should be understood that the key derivation algorithm is used to generate the derived key, for example, at least one of the above-mentioned first key, the second key, the above-mentioned third key, and the fourth key and the fifth key to be mentioned below can be generated based on the first specific key and the key derivation algorithm.

[0177] It should be understood that the authentication information generation algorithm is used to generate the authentication information, for example, to generate the first authentication information.

[0178] In some embodiments, before the terminal device sends the first information to the first communication node, the wireless communication method 200 further comprises:

[0179] The terminal device generates the first authentication information according to at least one of the following:

[0180] The first specific key, part or all of the content in the second information.

[0181] In some embodiments, before the terminal device sends the first information to the first communication node, the wireless communication method 200 further comprises:

[0182] The terminal device receives the eighth information;

[0183] Wherein, the eighth information includes second challenge information, or the eighth information includes second challenge information and at least one of the following: second sequence number, second authentication management domain, second authentication information, second algorithm information;

[0184] Wherein, the second authentication information is generated based on the second challenge information, or the second authentication information is generated based on the second challenge information and at least one of the following: the second sequence number, the second authentication management domain, the second algorithm information;

[0185] Wherein, the second algorithm information is used to indicate at least one of the following: encryption algorithm, integrity protection algorithm, check information generation algorithm, key derivation algorithm, authentication information generation algorithm.

[0186] In some embodiments, the second algorithm information can be an algorithm supported, allowed or selected by the first communication node.

[0187] In some embodiments, the second challenge information is also referred to as second random information or second random number (RAND2), etc., but is not limited thereto, such as string information, sequentially increasing or decreasing quantity information, etc.

[0188] In some embodiments, the second authentication information is used for authentication of the terminal device to the first communication node. For example, the second authentication information can be AUTS or RES.

[0189] In some embodiments, the terminal device receives eighth information, including:

[0190] The terminal device receives the eighth information sent by the second communication node; or,

[0191] The terminal device receives the eighth information sent by the first communication node.

[0192] Wherein, the second communication node is an access network node, and the eighth information is received by the terminal device from the second communication node in an idle state.

[0193] In other words, the first communication node sends the eighth information by any one of the following:

[0194] Sends the eighth information to the terminal device;

[0195] Sends the eighth information through the second communication node.

[0196] Exemplarily, the first communication node sends the eighth information to the second communication node, the second communication node forwards or broadcasts the eighth information, and the terminal device receives the eighth information.

[0197] The second communication node described in the embodiments of the present application can also be referred to as a second communication device, a second communication entity, etc., and the present application does not limit this.

[0198] In some embodiments, the second communication node can include, but is not limited to, at least one of the following:

[0199] Base station, transit terminal, TRP, AP.

[0200] In some embodiments, the second communication node can belong to a base station system, and the base station system can include one or more base stations.

[0201] In some embodiments, before the terminal device sends the first information to the first communication node, the wireless communication method 200 further includes:

[0202] The terminal device generates the first authentication information according to at least one of the following:

[0203] the first specific key, the second challenge information, the second serial number, the second authentication management domain, the second authentication information, the second algorithm information.

[0204] In some embodiments, the wireless communication method 200 further includes:

[0205] the terminal device performs a first verification operation;

[0206] wherein the first verification operation includes at least one of:

[0207] verifying the second authentication information based on the second challenge information;

[0208] verifying the second authentication information based on the second challenge information and at least one of: the second serial number, the second authentication management domain, the second algorithm information.

[0209] In some embodiments, the S210 can specifically include:

[0210] in the case where the first verification operation is successful, the terminal device sends the first information to the first communication node.

[0211] In some implementations, in the case where the first verification operation fails, the terminal device does not send the first information to the first communication node.

[0212] In some embodiments, the first operation is performed based on at least one of:

[0213] the first specific key, the second challenge information, the second serial number, the second authentication management domain, the second authentication information, the second algorithm information.

[0214] wherein the first specific key is known by the terminal device and the first communication node (such as UDM or AUSF). It should be noted that some core network elements (such as AMF) do not necessarily know the first specific key.

[0215] Specifically, the first communication node (such as UDM or AUSF) can verify the first authentication information based on at least one of: the first specific key, the second challenge information, the second serial number, the second authentication management domain, the second authentication information, the second algorithm information.

[0216] In some embodiments, the first operation is performed based on at least one of:

[0217] The first specific key, part or all of the second information, the second challenge information, the second sequence number, the second authentication management domain, the second authentication information, the second algorithm information.

[0218] In particular, the first communication node (e.g., UDM or AUSF) can verify the first authentication information based on at least one of the first specific key, part or all of the second information, the second challenge information, the second sequence number, the second authentication management domain, the second authentication information, the second algorithm information.

[0219] In some embodiments, the wireless communication method 200 further includes:

[0220] The terminal device receives ninth information from the first communication node;

[0221] The ninth information includes at least one of the following: tenth information, third challenge information, third sequence number, third authentication management domain, third authentication information, third algorithm information.

[0222] The tenth information includes eleventh information and third verification information.

[0223] The third verification information is generated based on at least one of the following: the tenth information or the eleventh information, part or all of the first information, part or all of the eighth information, the third challenge information, the third sequence number, the third authentication management domain, the third authentication information, the third algorithm information.

[0224] The eleventh information is information decrypted from the tenth information.

[0225] The third authentication information is generated based on at least one of the following: a second specific key, part or all of the second information, the first authentication information, part or all of the eighth information, the third sequence number, the third authentication management domain, and the third algorithm information.

[0226] The third algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, an authentication information generation algorithm.

[0227] In some embodiments, the third verification information or the third authentication information can be generated by the first communication node, in which case, the first communication node is, for example, UDM.

[0228] In some embodiments, the third verification information or the third authentication information can be acquired by the first communication node from other communication nodes, for example, the first communication node is an AMF and the other communication nodes are UDMs.

[0229] In some embodiments, the tenth information can be understood as cipher text or encrypted content, and the corresponding plain text or plain text content is the eleventh information. For example, the tenth information can be application data or service data sent by the first communication node, but is not limited thereto. The application data can be carried by an application container (AC) field, but is not limited thereto.

[0230] In some embodiments, the third algorithm information can be an algorithm supported, allowed or selected by the first communication node.

[0231] It should be noted that the third algorithm information can be the same as or different from the second algorithm information, and the embodiments of the present application are not limited thereto.

[0232] In some embodiments, the third authentication information is used for authentication of the terminal device to the first communication node. For example, the third authentication information can be AUTS or RES.

[0233] In some embodiments, the third challenge information is also referred to as third random information or third random number (RAND3), etc., but is not limited thereto, such as string information, sequentially increasing or decreasing quantity information, etc.

[0234] In some embodiments, the second specific key is known to the terminal device.

[0235] In some embodiments, the terminal device can know the second specific key through configuration or derivation.

[0236] Alternatively, the second specific key is known to the terminal device, UDM or AUSF. It should be noted that some core network elements (such as AMF) can not know the second specific key.

[0237] For example, the second specific key can be a same long-term key (LTK) configured by the UDM or AUSF and the terminal device, or a key (KEY) derived based on the LTK.

[0238] For example, the second specific key can be a shared key between the terminal device and the UDM or AUSF.

[0239] Optionally, the second specific key belongs to a key known in advance by the terminal device and the UDM or the AUSF, for example, can be derived through one or two pre-known keys, or can be pre-configured on both sides.

[0240] It should be noted that the second specific key can be the same as or different from the first specific key, and the embodiments of the present application are not limited thereto.

[0241] In some embodiments, the wireless communication method 200 further includes:

[0242] The terminal device performs at least one of the following:

[0243] Decrypting the tenth information to obtain the eleventh information;

[0244] Performing a second verification operation;

[0245] Generating fourth verification information according to a fourth key and the twelfth information or the thirteenth information;

[0246] Sending the fourteenth information to the first communication node; wherein the fourteenth information includes the twelfth information or the thirteenth information, or the fourteenth information includes the twelfth information or the thirteenth information and the fourth verification information;

[0247] The thirteenth information is generated by encrypting the twelfth information by a fifth key;

[0248] The second verification operation includes at least one of the following:

[0249] Verifying the third verification information based on at least one of the following: part or all of the contents of the tenth information or the eleventh information, part or all of the contents of the first information, part or all of the contents of the eighth information, the third challenge information, the third sequence number, the third authentication management domain, the third authentication information, and the third algorithm information;

[0250] Verifying the third authentication information based on at least one of the following: the second specific key, part or all of the contents of the second information, the first authentication information, part or all of the contents of the eighth information, the tenth information or the eleventh information, the third sequence number, the third authentication management domain, and the third algorithm information.

[0251] In some embodiments, the fourth key can be an integrity protection key.

[0252] In some embodiments, in a case that the second verification operation is successful, the terminal device generates the fourth verification information according to the fourth key and the twelfth information or the thirteenth information, and / or the terminal device sends the fourteenth information to the first communication node; in a case that the second verification operation fails, the terminal device does not generate the fourth verification information according to the fourth key and the twelfth information or the thirteenth information, and / or the terminal device does not send the fourteenth information to the first communication node.

[0253] In some embodiments, before the first communication node sends the ninth information to the terminal device, the wireless communication method 200 further includes at least one of the following:

[0254] The first communication node encrypts the eleventh information to obtain the tenth information.

[0255] The first communication node generates the third verification information based on at least one of the following: the tenth information or the eleventh information, part or all of the content in the first information, part or all of the content in the eighth information, the third challenge information, the third sequence number, the third authentication management domain, the third authentication information, the third algorithm information.

[0256] The first communication node generates the third authentication information based on at least one of the following: a second specific key, part or all of the content in the second information, the first authentication information, part or all of the content in the eighth information, the third sequence number, the third authentication management domain, and the third algorithm information.

[0257] In some embodiments, the wireless communication method 200 further includes:

[0258] The first communication node receives the fourteenth information from the terminal device.

[0259] The first communication node performs at least one of the following:

[0260] The fifth key is used to decrypt the thirteenth information to obtain the twelfth information.

[0261] The fourth verification information is verified according to the fourth key and the twelfth information or the thirteenth information.

[0262] In some embodiments, the wireless communication method 200 further includes at least one of the following:

[0263] The terminal device derives the first key based on first derived information.

[0264] The terminal device derives the second key based on second derived information;

[0265] The terminal device derives the third key based on third derived information;

[0266] The terminal device derives the fourth key based on fourth derived information;

[0267] The terminal device derives the fifth key based on fifth derived information;

[0268] The first derived information comprises at least one of the following: part or all of the first information, part or all of the eighth information;

[0269] The second derived information comprises at least one of the following: part or all of the first information, part or all of the eighth information;

[0270] The third derived information comprises at least one of the following: part or all of the first information, part or all of the eighth information;

[0271] The fourth derived information comprises at least one of the following: part or all of the first information, part or all of the eighth information, part or all of the ninth information;

[0272] The fifth derived information comprises at least one of the following: part or all of the first information, part or all of the eighth information, part or all of the ninth information.

[0273] In some embodiments, the wireless communication method 200 further comprises at least one of the following:

[0274] The first communication node derives the first key based on first derived information;

[0275] The first communication node derives the second key based on second derived information;

[0276] The first communication node derives the third key based on third derived information;

[0277] The first communication node derives the fourth key based on fourth derived information;

[0278] The first communication node derives the fifth key based on fifth derived information;

[0279] The first derived information comprises at least one of the following: part or all of the first information, part or all of the eighth information;

[0280] The second derivative information includes at least one of the following: part or all of the first information, part or all of the eighth information.

[0281] The third derivative information includes at least one of the following: part or all of the first information, part or all of the eighth information.

[0282] The fourth derivative information includes at least one of the following: part or all of the first information, part or all of the eighth information, part or all of the ninth information.

[0283] The fifth derivative information includes at least one of the following: part or all of the first information, part or all of the eighth information, part or all of the ninth information.

[0284] It should be understood that in the embodiments of the present application, the first key, the second key, the third key, the fourth key and the fifth key are derived in a protocol agreed manner or a pre-configuration manner, therefore, the terminal device and the first communication node do not need to exchange the first key, the second key, the third key, the fourth key and the fifth key.

[0285] Therefore, in the embodiments of the present application, the first information can be a NAS message, and the first communication node can judge whether to allow the terminal device to access the network based on the first information. Specifically, in the embodiments of the present application, the terminal device can only interact with the first communication node a NAS message, and the terminal device can access the network and deliver information. Since the interaction steps between the terminal device and the core network are reduced, the efficiency of the terminal device accessing the network can be improved.

[0286] The core idea of the embodiments of the present application is to reduce the interaction steps between the terminal and the core network to improve the efficiency of the terminal accessing the network. There are various ways to reduce the interaction steps between the terminal and the core network, which will be exemplarily illustrated by embodiments 1 to 3.

[0287] Embodiment 1: In embodiment 1, the terminal device and the first communication node have a shared key, i.e. a first specific key, and the flow of embodiment 1 can be as shown in FIG. 4, which can specifically include part or all of the following S1-1 to S1-4.

[0288] S1-1. The terminal device receives the eighth information from the first communication node.

[0289] The eighth information includes second challenge information, or the eighth information includes second challenge information and at least one of the following: a second serial number, a second authentication management domain, second authentication information, second algorithm information.

[0290] The second authentication information is generated based on the second challenge information, or the second authentication information is generated based on the second challenge information and at least one of the following: the second serial number, the second authentication management domain, and the second algorithm information.

[0291] The second algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a check information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

[0292] Optionally, the first communication node sends the eighth information by any one of the following:

[0293] Sends the eighth information to the terminal device;

[0294] Sends the eighth information through a second communication node.

[0295] The second communication node is an access network node, and the eighth information is received by the terminal device from the second communication node in an idle state.

[0296] S1-2. The terminal device performs a first check operation.

[0297] The first check operation includes at least one of the following:

[0298] The second authentication information is checked based on the second challenge information.

[0299] The second authentication information is checked based on the second challenge information and at least one of the following: the second serial number, the second authentication management domain, and the second algorithm information.

[0300] S1-3. In case that the first check operation is successful, the terminal device sends first information to the first communication node; wherein the first information comprises at least one of the following: second information, third information and first authentication information; wherein the second information comprises at least one of the following: first challenge information, first serial number, first authentication management domain; wherein the third information comprises at least one of the following: fourth information and first check information; fifth information and second check information; wherein the fourth information is generated by encrypting sixth information by a first key; wherein the first check information is generated based on a second key, the fourth information or the sixth information; wherein the second check information is generated based on a third key, the fifth information or seventh information; wherein the seventh information is information obtained by encrypting the fifth information.

[0301] Optionally, the first check information is further generated based on at least one of the following: the first authentication information, part or all of the second information. That is, the terminal device generates the first check information according to at least one of the following: the second key, the fourth information or the sixth information, the first authentication information, part or all of the second information.

[0302] Optionally, the second check information is further generated based on at least one of the following: the first authentication information, part or all of the second information. That is, the terminal device generates the second check information according to at least one of the following: the third key, the fifth information or the seventh information, the first authentication information, part or all of the second information.

[0303] S1-4. The first communication node performs at least one of the following: a first operation and a second operation according to the first information; wherein the first operation comprises checking the first authentication information; wherein the second operation comprises at least one of the following: decrypting the fourth information based on the first key; a third check operation; a fourth check operation; wherein the third check operation comprises checking the first check information based on the second key, the fourth information or the sixth information; wherein the fourth check operation comprises checking the second check information based on the third key, the fifth information or the seventh information.

[0304] Optionally, the first operation can be performed based on at least one of the following:

[0305] a first specific key, part or all of the second information;

[0306] wherein the first specific key is known by the terminal device.

[0307] Optionally, the third checking operation is further based on at least one of the following: the first authentication information, part or all of the second information. Specifically, the first communication node can check the first checking information based on at least one of the following: the second key, the fourth information or the sixth information, the first authentication information, part or all of the second information.

[0308] Optionally, the fourth checking operation is further based on at least one of the following: the first authentication information, part or all of the second information. Specifically, the first communication node can check the second checking information based on at least one of the following: the third key, the fifth information or the seventh information, the first authentication information, part or all of the second information.

[0309] Embodiment 2: In embodiment 2, the terminal device and the UDM have a shared key, i.e., a first specific key, and the flow of embodiment 2 can be as shown in FIG. 5, and can specifically include some or all of the following steps S2-1 to S2-8.

[0310] S2-1. The terminal device sends first information to the UDM; wherein the first information includes at least one of the following: second information, third information and first authentication information; wherein the second information includes at least one of the following: first challenge information, first sequence number, first authentication management domain; wherein the third information includes at least one of the following: fourth information and first checking information; fifth information and second checking information; wherein the fourth information is generated by encrypting the sixth information by a first key; wherein the first checking information is generated based on a second key, the fourth information or the sixth information; wherein the second checking information is generated based on a third key, the fifth information or the seventh information; wherein the seventh information is information obtained by encrypting the fifth information.

[0311] Optionally, the first checking information is further generated based on at least one of the following: the first authentication information, part or all of the second information. That is, the terminal device generates the first checking information according to at least one of the following: the second key, the fourth information or the sixth information, the first authentication information, part or all of the second information.

[0312] Optionally, the second checking information is further generated based on at least one of the following: the first authentication information, part or all of the second information. That is, the terminal device generates the second checking information according to at least one of the following: the third key, the fifth information or the seventh information, the first authentication information, part or all of the second information.

[0313] S2-2. The UDM performs at least one of a first operation and a second operation according to the first information; wherein the first operation comprises verifying the first authentication information; wherein the second operation comprises at least one of: decrypting the fourth information based on the first key; a third verification operation; a fourth verification operation; wherein the third verification operation comprises verifying the first verification information based on the second key, the fourth information, or the sixth information; wherein the fourth verification operation comprises verifying the second verification information based on the third key, the fifth information, or the seventh information.

[0314] Optionally, the first operation is performed based on at least one of:

[0315] part or all of the second information;

[0316] wherein the first specific key is known by the terminal device.

[0317] Optionally, the third verification operation is further performed based on at least one of: the first authentication information, part or all of the second information. Specifically, the UDM can verify the first verification information based on at least one of: the second key, the fourth information, or the sixth information, the first authentication information, part or all of the second information.

[0318] Optionally, the fourth verification operation is further performed based on at least one of: the first authentication information, part or all of the second information. Specifically, the UDM can verify the second verification information based on at least one of: the third key, the fifth information, or the seventh information, the first authentication information, part or all of the second information.

[0319] S2-3. The UDM generates third authentication information and third verification information;

[0320] wherein the third verification information is generated based on at least one of: the tenth information or the eleventh information, part or all of the first information, part or all of the eighth information, third challenge information, third sequence number, third authentication management domain, the third authentication information, third algorithm information.

[0321] wherein the third authentication information is generated based on at least one of: a second specific key, part or all of the second information, the first authentication information, part or all of the eighth information, third sequence number, third authentication management domain, and third algorithm information.

[0322] Optionally, the tenth information comprises eleventh information and third check information, the eleventh information being information after decryption of the tenth information.

[0323] Optionally, the third algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a check information generation algorithm, a key derivation algorithm, an authentication information generation algorithm.

[0324] Optionally, the eighth information comprises second challenge information, or the eighth information comprises second challenge information and at least one of the following: a second sequence number, a second authentication management domain, second authentication information, second algorithm information.

[0325] The second authentication information is generated based on the second challenge information, or the second authentication information is generated based on the second challenge information and at least one of the following: the second sequence number, the second authentication management domain, the second algorithm information.

[0326] The second algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a check information generation algorithm, a key derivation algorithm, an authentication information generation algorithm.

[0327] S2-4. The UDM sends the third authentication information, the third check information, and the third algorithm information (optional) to the AMF.

[0328] S2-5. The AMF sends ninth information to the terminal device.

[0329] The ninth information comprises at least one of the following: the tenth information, the third challenge information, the third sequence number, the third authentication management domain, the third authentication information, and the third algorithm information.

[0330] S2-6. The terminal device performs at least one of the following:

[0331] Decrypts the tenth information to obtain the eleventh information.

[0332] Performs a second check operation.

[0333] Generates fourth check information according to a fourth key and twelfth information or thirteenth information.

[0334] The thirteenth information is generated by encrypting the twelfth information by a fifth key.

[0335] The second check operation comprises at least one of the following:

[0336] verify the third authentication information based on at least one of the second specific key, part or all of the second information, part or all of the first authentication information, part or all of the eighth information, the tenth information or the eleventh information, the third serial number, the third authentication management domain, and the third algorithm information.

[0337] verify the third authentication information based on at least one of the second specific key, part or all of the second information, part or all of the first authentication information, part or all of the eighth information, the tenth information or the eleventh information, the third serial number, the third authentication management domain, and the third algorithm information.

[0338] S2-7. The terminal device sends the fourteenth information to the AMF.

[0339] The fourteenth information includes the twelfth information or the thirteenth information, or the fourteenth information includes the twelfth information or the thirteenth information and the fourth verification information.

[0340] S2-8. The AMF performs at least one of the following:

[0341] decrypt the thirteenth information according to the fifth key to obtain the twelfth information;

[0342] verify the fourth verification information according to the fourth key and the twelfth information or the thirteenth information.

[0343] Embodiment 3: In embodiment 3, the terminal device and the UDM have a shared key, i.e., the first specific key. The flow of embodiment 3 can be as shown in FIG. 6, and can specifically include some or all of the steps in S3-1 to S3-5.

[0344] S3-1. The terminal device sends the first information to the AMF; wherein the first information includes at least one of the following: the second information, the third information, and the first authentication information; wherein the second information includes at least one of the following: the first challenge information, the first serial number, the first authentication management domain; wherein the third information includes at least one of the following: the fourth information and the first verification information; the fifth information and the second verification information; wherein the fourth information is generated by encrypting the sixth information by the first key; wherein the first verification information is generated based on the second key, the fourth information or the sixth information; wherein the second verification information is generated based on the third key, the fifth information or the seventh information; wherein the seventh information is information obtained by encrypting the fifth information.

[0345] Optionally, the first check information is further generated based on at least one of: the first authentication information, part or all of the second information. That is, the terminal device generates the first check information according to at least one of: the second key, the fourth information or the sixth information, the first authentication information, part or all of the second information.

[0346] Optionally, the second check information is further generated based on at least one of: the first authentication information, part or all of the second information. That is, the terminal device generates the second check information according to at least one of: the third key, the fifth information or the seventh information, the first authentication information, part or all of the second information.

[0347] S3-2. The AMF sends part or all of the first information to the UDM;

[0348] S3-3. The UDM performs a first operation according to the first information; wherein the first operation comprises checking the first authentication information.

[0349] Optionally, the first operation can be performed based on at least one of:

[0350] a first specific key, part or all of the second information;

[0351] wherein the first specific key is known to the terminal device.

[0352] It should be noted that S3-3 is an optional step.

[0353] S3-4. The UDM sends the first key or the second key to the AMF.

[0354] S3-5. The AMF performs a second operation according to the first information;

[0355] wherein the second operation comprises at least one of: decrypting the fourth information based on the first key; a third check operation; a fourth check operation; wherein the third check operation comprises: checking the first check information based on the second key, the fourth information or the sixth information; wherein the fourth check operation comprises: checking the second check information based on the third key, the fifth information or the seventh information.

[0356] Optionally, the third checking operation is further based on at least one of the first authentication information and part or all of the second information. Specifically, the UDM can check the first checking information based on at least one of the second key, the fourth information or the sixth information, the first authentication information, and part or all of the second information.

[0357] Optionally, the fourth checking operation is further based on at least one of the first authentication information and part or all of the second information. Specifically, the UDM can check the second checking information based on at least one of the third key, the fifth information or the seventh information, the first authentication information, and part or all of the second information.

[0358] The wireless communication method provided in the embodiments of the present application can be executed by a wireless communication device or a processing unit in the wireless communication device for executing the wireless communication method. In the embodiments of the present application, the wireless communication device is taken as an example to illustrate the wireless communication device provided in the embodiments of the present application.

[0359] FIG. 7 shows a schematic block diagram of a wireless communication device 300 according to an embodiment of the present application. As shown in FIG. 7, the wireless communication device 300 includes:

[0360] a transceiver 310, configured to send first information to a first communication node;

[0361] The first information includes at least one of the following: second information, third information, and first authentication information.

[0362] The second information includes at least one of the following: first challenge information, a first sequence number, and a first authentication management domain.

[0363] The third information includes at least one of the following:

[0364] fourth information and first checking information.

[0365] fifth information and second checking information.

[0366] The fourth information is generated by encrypting the sixth information by using a first key.

[0367] The first checking information is generated based on a second key, the fourth information, or the sixth information.

[0368] The second checking information is generated based on a third key, the fifth information, or seventh information.

[0369] The seventh information is information obtained by encrypting the fifth information.

[0370] In some embodiments, the first check information is further generated based on at least one of the following: the first authentication information, part or all of the second information; or,

[0371] The second check information is further generated based on at least one of the following: the first authentication information, part or all of the second information.

[0372] In some embodiments, before the wireless communication device 300 sends the first information to the first communication node, the wireless communication device 300 further comprises a processing unit 320;

[0373] The processing unit 320 is configured to perform at least one of the following:

[0374] The first check information is generated based on at least one of the following: the second key, the fourth information or the sixth information, the first authentication information, part or all of the second information;

[0375] The second check information is generated based on at least one of the following: the third key, the fifth information or the seventh information, the first authentication information, part or all of the second information.

[0376] In some embodiments, the second information further comprises at least one of the following:

[0377] An identity of the wireless communication device 300, first algorithm information;

[0378] The first algorithm information is configured to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a check information generation algorithm, a key derivation algorithm, an authentication information generation algorithm.

[0379] In some embodiments, before the wireless communication device 300 sends the first information to the first communication node, the wireless communication device 300 further comprises a processing unit 320;

[0380] The processing unit 320 is configured to generate the first authentication information based on at least one of the following:

[0381] A first specific key, part or all of the second information.

[0382] In some embodiments, before the wireless communication device 300 sends the first information to the first communication node, the transceiver 310 is further configured to receive an eighth information;

[0383] The eighth information includes second challenge information, or the eighth information includes second challenge information and at least one of the following: second serial number, second authentication management domain, second authentication information, second algorithm information.

[0384] The second authentication information is generated based on the second challenge information, or the second authentication information is generated based on the second challenge information and at least one of the following: the second serial number, the second authentication management domain, the second algorithm information.

[0385] The second algorithm information is used to indicate at least one of the following: encryption algorithm, integrity protection algorithm, check information generation algorithm, key derivation algorithm, authentication information generation algorithm.

[0386] In some embodiments, the transceiver 310 is specifically configured to:

[0387] receive the eighth information sent by the second communication node; or

[0388] receive the eighth information sent by the first communication node;

[0389] The second communication node is an access network node, and the eighth information is received by the wireless communication device 300 from the second communication node in an idle state.

[0390] In some embodiments, before the wireless communication device 300 sends the first information to the first communication node, the wireless communication device 300 further includes a processing unit 320.

[0391] The processing unit 320 is configured to generate the first authentication information according to at least one of the following:

[0392] The first specific key, the second challenge information, the second serial number, the second authentication management domain, the second authentication information, and the second algorithm information.

[0393] In some embodiments, the wireless communication device 300 further includes a processing unit 320.

[0394] The processing unit 320 is configured to perform a first check operation.

[0395] The first check operation includes at least one of the following:

[0396] Check the second authentication information based on the second challenge information;

[0397] Check the second authentication information based on the second challenge information and at least one of the following: the second serial number, the second authentication management domain, and the second algorithm information.

[0398] In some embodiments, the transceiver 310 is specifically configured to:

[0399] In the case that the first check operation is successful, the first information is sent to the first communication node.

[0400] In some embodiments, the transceiver 310 is further configured to receive ninth information from the first communication node;

[0401] The ninth information comprises at least one of the following: tenth information, third challenge information, third sequence number, third authentication management domain, third authentication information, third algorithm information.

[0402] The tenth information comprises eleventh information and third check information.

[0403] The third check information is generated based on at least one of the following: the tenth information or the eleventh information, part or all of the content in the first information, part or all of the content in the eighth information, the third challenge information, the third sequence number, the third authentication management domain, the third authentication information, the third algorithm information.

[0404] The eleventh information is information after decryption of the tenth information.

[0405] The third authentication information is generated based on at least one of the following: second specific key, part or all of the content in the second information, the first authentication information, part or all of the content in the eighth information, the third sequence number, the third authentication management domain, and the third algorithm information.

[0406] The third algorithm information is used to indicate at least one of the following: encryption algorithm, integrity protection algorithm, check information generation algorithm, key derivation algorithm, authentication information generation algorithm.

[0407] In some embodiments, the wireless communication device 300 further comprises a processing unit 320.

[0408] The processing unit 320 is configured to perform at least one of the following:

[0409] Decrypt the tenth information to obtain the eleventh information.

[0410] Perform a second check operation.

[0411] Generate fourth check information according to a fourth key and the twelfth information or the thirteenth information.

[0412] sending a fourteenth information to the first communication node; wherein the fourteenth information comprises the twelfth information or the thirteenth information, or the fourteenth information comprises the twelfth information or the thirteenth information and the fourth check information;

[0413] wherein the thirteenth information is generated by encrypting the twelfth information by a fifth key;

[0414] wherein the second check operation comprises at least one of:

[0415] checking the third check information based on at least one of: the tenth information or the eleventh information, part or all of the first information, part or all of the eighth information, the third challenge information, the third sequence number, the third authentication management domain, the third authentication information, the third algorithm information;

[0416] checking the third authentication information based on at least one of: the second specific key, part or all of the second information, the first authentication information, part or all of the eighth information, the tenth information or the eleventh information, the third sequence number, the third authentication management domain, and the third algorithm information.

[0417] In some embodiments, the wireless communication device 300 further comprises: a processing unit 320;

[0418] the processing unit 320 is configured to perform at least one of:

[0419] deriving the first key based on first derivation information;

[0420] deriving the second key based on second derivation information;

[0421] deriving the third key based on third derivation information;

[0422] deriving the fourth key based on fourth derivation information;

[0423] deriving the fifth key based on fifth derivation information;

[0424] wherein the first derivation information comprises at least one of: part or all of the first information, part or all of the eighth information;

[0425] wherein the second derivation information comprises at least one of: part or all of the first information, part or all of the eighth information;

[0426] wherein the third derivation information comprises at least one of: part or all of the first information, part or all of the eighth information;

[0427] The fourth derivative information includes at least one of the following: part or all of the first information, part or all of the eighth information, and part or all of the ninth information.

[0428] The fifth derivative information includes at least one of the following: part or all of the first information, part or all of the eighth information, and part or all of the ninth information.

[0429] In some embodiments, the transceiver 310 described above can be a communication interface or a transceiver, or an input / output interface of a communication chip or a system on chip. The processing unit 320 described above can be embedded in a processor of the terminal device in the form of hardware or independent of the processor.

[0430] It should be understood that the wireless communication apparatus 300 according to the embodiments of the present application can correspond to the terminal device in the method embodiments of the present application, and each unit in the wireless communication apparatus 300 is respectively used to implement the corresponding process of the terminal device in the method 200 shown in FIG. 3, and for brevity, details are not described herein.

[0431] Therefore, in the embodiments of the present application, the first information can be a NAS message, and the first communication node can determine whether to allow the terminal device to access the network based on the first information. Specifically, in the embodiments of the present application, the terminal device can interact with the first communication node only one NAS message, and the terminal device can access the network and deliver information. Since the interaction steps of the terminal device and the core network are reduced, the efficiency of the terminal device accessing the network can be improved.

[0432] FIG. 8 shows a schematic block diagram of a wireless communication apparatus 400 according to an embodiment of the present application. As shown in FIG. 8, the wireless communication apparatus 400 includes a transceiver 410 and a processing unit 420;

[0433] The transceiver 410 is configured to receive first information from a terminal device, and the processing unit 420 is configured to perform at least one of a first operation and a second operation according to the first information.

[0434] The first information includes at least one of the following: second information, third information, and first authentication information.

[0435] The second information includes at least one of the following: first challenge information, a first sequence number, and a first authentication management domain.

[0436] The third information includes at least one of the following:

[0437] Fourth information and first check information.

[0438] the fifth information and the second verification information;

[0439] wherein the fourth information is generated by encrypting the sixth information by using the first key;

[0440] wherein the first verification information is generated based on the second key, the fourth information or the sixth information;

[0441] wherein the second verification information is generated based on the third key, the fifth information or the seventh information;

[0442] wherein the seventh information is information obtained by encrypting the fifth information;

[0443] wherein the first operation comprises verifying the first authentication information;

[0444] wherein the second operation comprises at least one of:

[0445] decrypting the fourth information based on the first key;

[0446] a third verification operation;

[0447] a fourth verification operation;

[0448] wherein the third verification operation comprises verifying the first verification information based on the second key, the fourth information or the sixth information;

[0449] wherein the fourth verification operation comprises verifying the second verification information based on the third key, the fifth information or the seventh information.

[0450] In some embodiments, the first operation is performed based on at least one of:

[0451] a first specific key, or part or all of the second information;

[0452] wherein the first specific key is known to the terminal device.

[0453] In some embodiments, the third verification operation is further performed based on at least one of: the first authentication information, or part or all of the second information; or

[0454] the fourth verification operation is further performed based on at least one of: the first authentication information, or part or all of the second information.

[0455] In some embodiments, the second information further comprises at least one of:

[0456] an identity of the terminal device, or first algorithm information.

[0457] The first algorithm information is used for indicating at least one of the following: an encryption algorithm, an integrity protection algorithm, a check information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

[0458] In some embodiments, before the wireless communication device 400 receives the first information from the terminal device, the transceiver 410 is further configured to send eighth information by any one of the following:

[0459] sending the eighth information to the terminal device;

[0460] sending the eighth information through a second communication node;

[0461] The eighth information includes second challenge information, or the eighth information includes second challenge information and at least one of the following: a second serial number, a second authentication management domain, second authentication information, and second algorithm information.

[0462] The second authentication information is generated based on the second challenge information, or the second authentication information is generated based on the second challenge information and at least one of the following: the second serial number, the second authentication management domain, and the second algorithm information.

[0463] The second algorithm information is used for indicating at least one of the following: an encryption algorithm, an integrity protection algorithm, a check information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

[0464] The second communication node is an access network node.

[0465] In some embodiments, the first operation is performed based on at least one of the following:

[0466] a first specific key, the second challenge information, the second serial number, the second authentication management domain, the second authentication information, and the second algorithm information.

[0467] The first specific key is known to the terminal device.

[0468] In some embodiments, the transceiver 410 is further configured to send ninth information to the terminal device;

[0469] The ninth information includes at least one of the following: tenth information, third challenge information, a third serial number, a third authentication management domain, third authentication information, and third algorithm information.

[0470] The tenth information includes eleventh information and third check information.

[0471] The third verification information is generated based on at least one of the tenth information or the eleventh information, part or all of the first information, part or all of the eighth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, or the third algorithm information.

[0472] The eleventh information is information obtained by decrypting the tenth information.

[0473] The third authentication information is generated based on at least one of a second specific key, part or all of the second information, the first authentication information, part or all of the eighth information, the third serial number, the third authentication management domain, or the third algorithm information.

[0474] The second specific key is known to the terminal device.

[0475] The third algorithm information indicates at least one of an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, or an authentication information generation algorithm.

[0476] In some embodiments, before the wireless communication device 400 sends the ninth information to the terminal device, the processing unit 420 is further configured to perform at least one of the following:

[0477] The eleventh information is encrypted to obtain the tenth information.

[0478] The third verification information is generated based on at least one of the tenth information or the eleventh information, part or all of the first information, part or all of the eighth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, or the third algorithm information.

[0479] The third authentication information is generated based on at least one of a second specific key, part or all of the second information, the first authentication information, part or all of the eighth information, the third serial number, the third authentication management domain, or the third algorithm information.

[0480] In some embodiments, the transceiver 410 is further configured to receive fourteenth information from the terminal device; wherein the fourteenth information includes the twelfth information or the thirteenth information, or the fourteenth information includes the twelfth information or the thirteenth information and fourth verification information.

[0481] The processing unit 420 is further configured to perform at least one of the following:

[0482] decrypt the thirteenth information according to the fifth key to obtain the twelfth information;

[0483] verify the fourth check information according to the fourth key and the twelfth information or the thirteenth information.

[0484] In some embodiments, the processing unit 420 is further configured to perform at least one of the following:

[0485] derive the first key based on first derivative information;

[0486] derive the second key based on second derivative information;

[0487] derive the third key based on third derivative information;

[0488] derive the fourth key based on fourth derivative information;

[0489] derive the fifth key based on fifth derivative information;

[0490] The first derivative information includes at least one of the following: part or all of the first information, part or all of the eighth information;

[0491] The second derivative information includes at least one of the following: part or all of the first information, part or all of the eighth information;

[0492] The third derivative information includes at least one of the following: part or all of the first information, part or all of the eighth information;

[0493] The fourth derivative information includes at least one of the following: part or all of the first information, part or all of the eighth information, part or all of the ninth information;

[0494] The fifth derivative information includes at least one of the following: part or all of the first information, part or all of the eighth information, part or all of the ninth information.

[0495] In some embodiments, the transceiver 410 described above can be a communication interface or a transceiver, or an input / output interface of a communication chip or a system on chip. The processing unit 420 can be embedded in the form of hardware in the processor of the first communication node or independent of the processor.

[0496] It should be understood that the wireless communication apparatus 400 according to the embodiments of the present application can correspond to the first communication node in the method embodiments of the present application, and each unit in the wireless communication apparatus 400 is respectively used to implement the corresponding process of the first communication node in the method 200 shown in FIG. 3. For brevity, details are not described herein again.

[0497] Therefore, in the embodiments of the present application, the first information can be a NAS message, and the first communication node can determine whether to allow the terminal device to access the network based on the first information. Specifically, in the embodiments of the present application, the terminal device can interact with the first communication node only one NAS message, and the terminal device can access the network and deliver information. Since the interaction steps of the terminal device and the core network are reduced, the efficiency of the terminal device accessing the network can be improved.

[0498] The wireless communication apparatus in the embodiments of the present application can be an electronic device, for example, an electronic device with an operating system, or a component in the electronic device, for example, an integrated circuit or a chip. The electronic device can be a terminal or a communication node, or other devices except the terminal or the communication node. For example, the terminal can include but is not limited to the types of the terminal 21 listed above, the communication node can include but is not limited to the types of the communication node 22 listed above, and the other devices can be a server, a network attached storage (NAS), etc., which are not limited in the embodiments of the present application.

[0499] The wireless communication apparatus provided by the embodiments of the present application can implement the processes of the method embodiments of FIG. 3 and achieve the same technical effects. To avoid repetition, details are not described herein again.

[0500] As shown in FIG. 9, the embodiments of the present application further provide a communication device 500, which includes a processor 501 and a memory 502, and the memory 502 stores programs or instructions executable on the processor 501.

[0501] For example, when the communication device 500 is a terminal device, the programs or instructions are executed by the processor 501 to implement the steps performed by the terminal device in the wireless communication method embodiments described above, and the same technical effects can be achieved. To avoid repetition, details are not described herein again.

[0502] For another example, when the communication device 500 is a first communication node, the programs or instructions are executed by the processor 501 to implement the steps performed by the first communication node in the wireless communication method embodiments described above, and the same technical effects can be achieved. To avoid repetition, details are not described herein again.

[0503] The embodiment of the present application further provides a terminal, comprising a processor and a communication interface, the communication interface is coupled with the processor, and the processor is used for running programs or instructions to realize the steps performed by the terminal device in the method embodiment shown in FIG. 3. The terminal embodiment corresponds to the terminal-side method embodiment described above, and each implementation process and implementation manner of the method embodiment can be applied to the terminal embodiment, and the same technical effects can be achieved. Specifically, FIG. 10 is a schematic diagram of the hardware structure of a terminal for implementing the embodiment of the present application.

[0504] The terminal 600 includes, but is not limited to, at least part of components such as a radio frequency unit 601, a network module 602, an audio output unit 603, an input unit 604, a sensor 605, a display unit 606, a user input unit 607, an interface unit 608, a memory 609, and a processor 610.

[0505] Those skilled in the art can understand that the terminal 600 can further include a power supply (such as a battery) for supplying power to each component, and the power supply can be logically connected with the processor 610 through a power management system, so as to realize functions such as management of charging, discharging, and power consumption management through the power management system. The terminal structure shown in FIG. 10 does not constitute a limitation on the terminal, and the terminal can include more or fewer components than those shown, or combine certain components, or different component arrangements, which will not be described here.

[0506] It should be understood that in the embodiment of the present application, the input unit 604 can include a graphics processing unit (GPU) 6041 and a microphone 6042. The graphics processor 6041 processes image data of a still picture or a video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 606 can include a display panel 6061, which can be configured in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit 607 includes at least one of a touch panel 6071 and other input devices 6072. The touch panel 6071 is also called a touch screen. The touch panel 6071 can include two parts of a touch detection device and a touch controller. The other input devices 6072 can include, but are not limited to, a physical keyboard, function keys (such as volume control keys, on-off keys, etc.), a trackball, a mouse, a joystick, etc., which will not be described here.

[0507] In the embodiment of the present application, the radio frequency unit 601 can transmit the downlink data received from the network side device to the processor 610 for processing. In addition, the radio frequency unit 601 can send uplink data to the network side device. Generally, the radio frequency unit 601 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, etc.

[0508] The memory 609 can be used to store software programs or instructions and various data. The memory 609 can mainly include a first storage area storing programs or instructions and a second storage area storing data, wherein the first storage area can store an operating system, application programs or instructions required by at least one function (such as a sound playing function, an image playing function, etc.), and the like. In addition, the memory 609 can include a volatile memory or a non-volatile memory. The non-volatile memory can be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically EPROM (EEPROM), or a flash memory. The volatile memory can be a Random Access Memory (RAM), a Static RAM (SRAM), a Dynamic RAM (DRAM), a Synchronous DRAM (SDRAM), a Double Data Rate SDRAM (DDR SDRAM), an Enhanced SDRAM (ESDRAM), a Synch link DRAM (SLDRAM), and a Direct Rambus RAM (DRRAM). The memory 609 in the embodiments of the present application includes but is not limited to these and any other suitable types of memory.

[0509] The processor 610 can include at least one processing unit; optionally, the processor 610 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and an application program, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 610.

[0510] In some embodiments, the radio frequency unit 601 is configured to send first information to the first communication node; wherein the first information comprises at least one of the following: second information, third information and first authentication information; wherein the second information comprises at least one of the following: first challenge information, first sequence number, first authentication management domain; wherein the third information comprises at least one of the following: fourth information and first check information; fifth information and second check information; wherein the fourth information is generated by encrypting sixth information by using a first key; wherein the first check information is generated based on a second key, the fourth information or the sixth information; wherein the second check information is generated based on a third key, the fifth information or seventh information; wherein the seventh information is information obtained by encrypting the fifth information.

[0511] It can be understood that the implementation processes of the implementation manners mentioned in the embodiments can refer to the related descriptions of the method embodiments and achieve the same or corresponding technical effects. To avoid repetition, they will not be described here again.

[0512] The embodiments of the present application also provide a network side device, which comprises a processor and a communication interface, the communication interface is coupled with the processor, and the processor is configured to run programs or instructions to implement the steps performed by the first communication node in the method embodiments shown in FIG. 3. The network side device embodiments correspond to the above-mentioned first communication node side method embodiments. The implementation processes and implementation manners of the above-mentioned method embodiments can be applied to the network side device embodiments and can achieve the same technical effects. To be brief, they will not be described here again.

[0513] Specifically, the embodiments of the present application also provide a network side device. As shown in FIG. 11, the network side device 700 comprises an antenna 71, a radio frequency device 72, a baseband device 73, a processor 74 and a memory 75. The antenna 71 is connected with the radio frequency device 72. In the uplink direction, the radio frequency device 72 receives information through the antenna 71 and sends the received information to the baseband device 73 for processing. In the downlink direction, the baseband device 73 processes the information to be sent and sends it to the radio frequency device 72. The radio frequency device 72 processes the received information and sends it out through the antenna 71.

[0514] The method performed by the first communication node in the above embodiments can be implemented in the baseband device 73, which comprises a baseband processor.

[0515] The baseband device 73 may, for example, comprise at least one baseband board, and at least two chips are arranged on the baseband board, as shown in FIG. 11. One of the chips is, for example, a baseband processor, which is connected with the memory 75 through a bus interface to call the programs in the memory 75 and perform the operations of the first communication node shown in the above method embodiments.

[0516] The network side device can further include a network interface 76, for example, a Common Public Radio Interface (CPRI).

[0517] Specifically, the network side device 700 according to the embodiments of the present application further includes instructions or programs stored in the memory 75 and executable on the processor 74, and the processor 74 invokes the instructions or programs in the memory 75 to execute the method performed by the units shown in FIG. 8 and achieve the same technical effects. To avoid repetition, details are not described herein.

[0518] The embodiments of the present application further provide a network side device. As shown in FIG. 12, the network side device 800 includes a processor 801, a network interface 802 and a memory 803. The network interface 802 is, for example, a common public radio interface (CPRI).

[0519] Specifically, the network side device 800 according to the embodiments of the present application further includes instructions or programs stored in the memory 803 and executable on the processor 801, and the processor 801 invokes the instructions or programs in the memory 803 to execute the method performed by the units shown in FIG. 8 and achieve the same technical effects. To avoid repetition, details are not described herein.

[0520] The embodiments of the present application further provide a readable storage medium, which stores programs or instructions. When the programs or instructions are executed by a processor, each process of the above-mentioned wireless communication method embodiments is implemented, and the same technical effects can be achieved. To avoid repetition, details are not described herein.

[0521] Optionally, the processor is the processor in the terminal or the network side device according to the above-mentioned embodiments. The readable storage medium includes a computer readable storage medium, such as a computer readable only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc. In some examples, the readable storage medium can be a non-transitory readable storage medium.

[0522] The embodiments of the present application further provide a chip, which includes a processor and a communication interface. The communication interface is coupled with the processor, and the processor is configured to execute programs or instructions to implement each process of the above-mentioned wireless communication method embodiments and achieve the same technical effects. To avoid repetition, details are not described herein.

[0523] It should be understood that the chip mentioned in the embodiments of the present application can also be referred to as a system chip, a system on chip (SoC), a chip system or a system on chip (SoC) chip, etc.

[0524] The embodiment of the present application further provides a computer program / program product stored in a storage medium, which is executed by at least one processor to implement the processes of the wireless communication method embodiment, and achieves the same technical effects. To avoid repetition, details are not described herein.

[0525] The embodiment of the present application further provides a communication system, comprising: a terminal device and a first communication node, wherein the terminal device is configured to perform the steps performed by the terminal device in the wireless communication method described above, and the first communication node is configured to perform the steps performed by the first communication node in the wireless communication method described above.

[0526] The embodiment of the present application further provides a communication system, comprising: a terminal device, a first communication node and a second communication node, wherein the terminal device is configured to perform the steps performed by the terminal device in the wireless communication method described above, the first communication node is configured to perform the steps performed by the first communication node in the wireless communication method described above, and the second communication node is configured to perform the steps performed by the second communication node in the wireless communication method described above.

[0527] It should be noted that, in this document, the terms "comprising", "including", or any other variant thereof are intended to cover non-exclusive inclusion, so that processes, methods, articles or devices that include a series of elements not only include those elements, but also include other elements not explicitly listed, or inherent to such processes, methods, articles or devices. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to the order of performing functions as shown or discussed, but can also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved, for example, the described method can be performed in an order different from the described order, and various steps can also be added, omitted or combined. In addition, the features described with reference to certain examples can be combined in other examples.

[0528] From the above description of the embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment method can be realized by means of computer software product and general hardware platform, of course, it can also be realized by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.), which includes a plurality of instructions for making the terminal or network side device execute the method described in each embodiment of the present application.

[0529] The embodiments of the present application are described above with reference to the accompanying drawings, but the present application is not limited to the above-described specific embodiments, and the above-described specific embodiments are merely illustrative, but not restrictive, and a person of ordinary skill in the art can make many forms of embodiments under the inspiration of the present application without departing from the purpose of the present application and the scope protected by the claims, and these embodiments all belong to the protection of the present application.

Claims

1. A wireless communication method, wherein: include: The terminal device sends first information to the first communication node; Wherein, the first information includes at least one of the following: second information, third information and first authentication information; The second information includes at least one of the following: first challenge information, first serial number, first authentication management domain; The third information includes at least one of the following: The fourth information and the first verification information; fifth information and second verification information; The fourth information is generated by encrypting the sixth information with the first key; Wherein, the first verification information is generated based on the second key, the fourth information or the sixth information; The second verification information is generated based on the third key, the fifth information or the seventh information; The seventh information is information obtained by encrypting the fifth information.

2. The method according to claim 1, wherein The first verification information is further generated based on at least one of the following: part or all of the first authentication information and the second information; or The second verification information is also generated based on at least one of the following: the first authentication information, part or all of the content in the second information.

3. The method according to claim 1 or 2, wherein: Before the terminal device sends the first information to the first communication node, the method further includes at least one of the following: The terminal device generates the first verification information according to at least one of the following: the second key, the fourth information or the sixth information, the first authentication information, and part or all of the second information; The terminal device generates the second verification information based on at least one of the following: the third key, the fifth information or the seventh information, the first authentication information, and part or all of the second information.

4. The method according to any one of claims 1 to 3, wherein The second information further includes at least one of the following: The identifier of the terminal device and the first algorithm information; The first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

5. The method according to any one of claims 1 to 4, wherein Before the terminal device sends the first information to the first communication node, the method further includes: The terminal device generates the first authentication information according to at least one of the following: The first specific key, part or all of the content in the second information.

6. The method according to any one of claims 1 to 5, wherein Before the terminal device sends the first information to the first communication node, the method further includes: The terminal device receives eighth information; The eighth information includes the second challenge information, or the eighth information includes the second challenge information and at least one of the following: a second serial number, a second authentication management domain, second authentication information, and second algorithm information; The second authentication information is generated based on the second challenge information, or the second authentication information is generated based on the second challenge information and at least one of the following: the second serial number, the second authentication management domain, and the second algorithm information; The second algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

7. The method according to claim 6, wherein: The terminal device receives the eighth information, including: The terminal device receives the eighth information sent by the second communication node; or, The terminal device receives the eighth information sent by the first communication node; The second communication node is an access network node, and the eighth information is received by the terminal device from the second communication node in an idle state.

8. The method according to claim 6 or 7, wherein: Before the terminal device sends the first information to the first communication node, the method further includes: The terminal device generates the first authentication information according to at least one of the following: A first specific key, the second challenge information, the second serial number, the second authentication management domain, the second authentication information, and the second algorithm information.

9. The method according to any one of claims 6 to 8, wherein The method further comprises: The terminal device performs a first verification operation; The first verification operation includes at least one of the following: verifying the second authentication information based on the second challenge information; The second authentication information is verified based on the second challenge information and at least one of the following: the second serial number, the second authentication management domain, and the second algorithm information.

10. The method according to claim 9, wherein: The terminal device sending first information to the first communication node includes: In case the first verification operation is successful, the terminal device sends the first information to the first communication node.

11. The method according to any one of claims 1 to 10, wherein The method further comprises: The terminal device receives ninth information from the first communication node; The ninth information includes at least one of the following: the tenth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, and the third algorithm information; The tenth information includes the eleventh information and the third verification information; The third verification information is generated based on at least one of the following: the tenth information or the eleventh information, part or all of the content in the first information, part or all of the content in the eighth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, and the third algorithm information; The eleventh information is the decrypted information of the tenth information; The third authentication information is generated based on at least one of a second specific key, part or all of the second information, the first authentication information, part or all of the eighth information, the third serial number, the third authentication management domain, and the third algorithm information; The third algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

12. The method according to claim 11, wherein The method further comprises: The terminal device performs at least one of the following: decrypting the tenth information to obtain the eleventh information; performing a second verification operation; generating fourth verification information according to the fourth key and the twelfth information or the thirteenth information; Sending fourteenth information to the first communication node; wherein the fourteenth information includes the twelfth information or the thirteenth information, or the fourteenth information includes the twelfth information or the thirteenth information and the fourth verification information; The thirteenth information is generated by encrypting the twelfth information with the fifth key; The second verification operation includes at least one of the following: verifying the third verification information based on at least one of the following: the tenth information or the eleventh information, part or all of the first information, part or all of the eighth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, and the third algorithm information; The third authentication information is verified based on a second specific key, part or all of the content in the second information, the first authentication information, part or all of the content in the eighth information, the tenth information or the eleventh information, the third serial number, the third authentication management domain and at least one of the third algorithm information.

13. The method according to any one of claims 1 to 12, wherein The method further comprises at least one of the following: The terminal device derives the first key based on the first derivative information; The terminal device derives the second key based on the second derivative information; The terminal device derives the third key based on the third derivative information; The terminal device derives the fourth key based on the fourth derivative information; The terminal device derives the fifth key based on the fifth derivative information; The first derivative information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The second derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The third derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The fourth derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information, and part or all of the content in the ninth information; The fifth derivative information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information, and part or all of the content in the ninth information.

14. A wireless communication method, wherein: include: A first communication node receives first information from a terminal device, and the first communication node performs at least one of a first operation and a second operation according to the first information; Wherein, the first information includes at least one of the following: second information, third information and first authentication information; The second information includes at least one of the following: first challenge information, first serial number, first authentication management domain; The third information includes at least one of the following: The fourth information and the first verification information; fifth information and second verification information; The fourth information is generated by encrypting the sixth information with the first key; Wherein, the first verification information is generated based on the second key, the fourth information or the sixth information; The second verification information is generated based on the third key, the fifth information or the seventh information; The seventh information is information obtained by encrypting the fifth information; Wherein, the first operation includes verifying the first authentication information; The second operation includes at least one of the following: decrypting the fourth information based on the first key; The third verification operation: Fourth verification operation; The third verification operation includes: verifying the first verification information based on the second key, the fourth information, or the sixth information; The fourth verification operation includes: verifying the second verification information based on the third key, the fifth information or the seventh information.

15. The method according to claim 14, wherein The first operation is performed based on at least one of the following: A first specific key, part or all of the second information; The first specific key is known by the terminal device.

16. The method according to claim 14 or 15, wherein: The third verification operation is further performed based on at least one of the following: part or all of the first authentication information and the second information; or The fourth verification operation is also performed based on at least one of the following: part or all of the content in the first authentication information and the second information.

17. The method according to any one of claims 14 to 16, wherein The second information further includes at least one of the following: The identifier of the terminal device and the first algorithm information; The first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

18. The method according to any one of claims 14 to 17, wherein Before the first communication node receives the first information from the terminal device, the method further includes: The first communication node sends the eighth information by any one of the following: sending the eighth information to the terminal device; Sending the eighth information through the second communication node; The eighth information includes the second challenge information, or the eighth information includes the second challenge information and at least one of the following: a second serial number, a second authentication management domain, second authentication information, and second algorithm information; The second authentication information is generated based on the second challenge information, or the second authentication information is generated based on the second challenge information and at least one of the following: the second serial number, the second authentication management domain, and the second algorithm information; The second algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm; The second communication node is an access network node.

19. The method according to claim 18, wherein The first operation is performed based on at least one of the following: a first specific key, the second challenge information, the second serial number, the second authentication management domain, the second authentication information, and the second algorithm information; The first specific key is known by the terminal device.

20. The method according to any one of claims 14 to 19, wherein The method further comprises: The first communication node sends ninth information to the terminal device; The ninth information includes at least one of the following: the tenth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, and the third algorithm information; The tenth information includes the eleventh information and the third verification information; The third verification information is generated based on at least one of the following: the tenth information or the eleventh information, part or all of the content in the first information, part or all of the content in the eighth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, and the third algorithm information; The eleventh information is the decrypted information of the tenth information; The third authentication information is generated based on at least one of a second specific key, part or all of the second information, the first authentication information, part or all of the eighth information, the third serial number, the third authentication management domain, and the third algorithm information; wherein the second specific key is known by the terminal device; The third algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

21. The method according to claim 20, wherein Before the first communication node sends the ninth information to the terminal device, the method further includes at least one of the following: The first communication node encrypts the eleventh information to obtain the tenth information; The first communication node generates the third verification information based on at least one of the following: the tenth information or the eleventh information, part or all of the first information, part or all of the eighth information, the third challenge information, the third sequence number, the third authentication management domain, the third authentication information, and the third algorithm information; The first communication node generates the third authentication information based on a second specific key, part or all of the content in the second information, the first authentication information, part or all of the content in the eighth information, the third serial number, the third authentication management domain and at least one of the third algorithm information.

22. The method according to claim 20 or 21, wherein The method further comprises: The first communication node receives fourteenth information from the terminal device; wherein the fourteenth information includes the twelfth information or the thirteenth information, or the fourteenth information includes the twelfth information or the thirteenth information and fourth verification information; The first communication node performs at least one of the following: decrypting the thirteenth information according to the fifth key to obtain the twelfth information; The fourth verification information is verified according to the fourth key and the twelfth information or the thirteenth information.

23. The method according to any one of claims 14 to 22, wherein The method further comprises at least one of the following: The first communication node derives the first key based on first derivation information; The first communication node derives the second key based on second derivation information; The first communication node derives the third key based on third derivation information; The first communication node derives the fourth key based on fourth derivation information; The first communication node derives the fifth key based on fifth derivation information; The first derivative information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The second derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The third derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The fourth derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information, and part or all of the content in the ninth information; The fifth derivative information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information, and part or all of the content in the ninth information.

24. A wireless communication device, wherein: include: a transceiver unit, configured to send first information to the first communication node; Wherein, the first information includes at least one of the following: second information, third information and first authentication information; The second information includes at least one of the following: first challenge information, first serial number, first authentication management domain; The third information includes at least one of the following: The fourth information and the first verification information; fifth information and second verification information; The fourth information is generated by encrypting the sixth information with the first key; Wherein, the first verification information is generated based on the second key, the fourth information or the sixth information; The second verification information is generated based on the third key, the fifth information or the seventh information; The seventh information is information obtained by encrypting the fifth information.

25. The apparatus according to claim 24, wherein The first verification information is further generated based on at least one of the following: part or all of the first authentication information and the second information; or The second verification information is also generated based on at least one of the following: the first authentication information, part or all of the content in the second information.

26. The device according to claim 24 or 25, wherein Before the wireless communication apparatus sends the first information to the first communication node, the wireless communication apparatus further includes a processing unit, wherein the processing unit is configured to perform at least one of the following: generating the first verification information according to at least one of the following: the second key, the fourth information or the sixth information, the first authentication information, and part or all of the second information; The second verification information is generated according to at least one of the following: the third key, the fifth information or the seventh information, the first authentication information, and part or all of the second information.

27. The device according to any one of claims 24 to 26, wherein The second information further includes at least one of the following: an identifier of the wireless communication device, and first algorithm information; The first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

28. The device according to any one of claims 24 to 27, wherein Before the wireless communication apparatus sends the first information to the first communication node, the wireless communication apparatus further includes: a processing unit, configured to generate the first authentication information according to at least one of the following: The first specific key, part or all of the content in the second information.

29. The device according to any one of claims 24 to 28, wherein Before the wireless communication device sends the first information to the first communication node, the transceiver unit is further configured to receive eighth information; The eighth information includes the second challenge information, or the eighth information includes the second challenge information and at least one of the following: a second serial number, a second authentication management domain, second authentication information, and second algorithm information; The second authentication information is generated based on the second challenge information, or the second authentication information is generated based on the second challenge information and at least one of the following: the second serial number, the second authentication management domain, and the second algorithm information; The second algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

30. The apparatus according to claim 29, wherein Before the wireless communication apparatus sends the first information to the first communication node, the wireless communication apparatus further includes: a processing unit, configured to generate the first authentication information according to at least one of the following: A first specific key, the second challenge information, the second serial number, the second authentication management domain, the second authentication information, and the second algorithm information.

31. The apparatus according to claim 29 or 30, wherein The wireless communication device further includes: a processing unit, configured to perform a first verification operation; The first verification operation includes at least one of the following: verifying the second authentication information based on the second challenge information; The second authentication information is verified based on the second challenge information and at least one of the following: the second serial number, the second authentication management domain, and the second algorithm information.

32. The device according to any one of claims 24 to 31, wherein The transceiver unit is further configured to receive ninth information from the first communication node; The ninth information includes at least one of the following: the tenth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, and the third algorithm information; The tenth information includes the eleventh information and the third verification information; The third verification information is generated based on at least one of the following: the tenth information or the eleventh information, part or all of the content in the first information, part or all of the content in the eighth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, and the third algorithm information; The eleventh information is the decrypted information of the tenth information; The third authentication information is generated based on at least one of a second specific key, part or all of the second information, the first authentication information, part or all of the eighth information, the third serial number, the third authentication management domain, and the third algorithm information; The third algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

33. The apparatus according to claim 32, wherein The wireless communication device further includes: A processing unit configured to perform at least one of the following: decrypting the tenth information to obtain the eleventh information; performing a second verification operation; generating fourth verification information according to the fourth key and the twelfth information or the thirteenth information; Sending fourteenth information to the first communication node; wherein the fourteenth information includes the twelfth information or the thirteenth information, or the fourteenth information includes the twelfth information or the thirteenth information and the fourth verification information; The thirteenth information is generated by encrypting the twelfth information with the fifth key; The second verification operation includes at least one of the following: verifying the third verification information based on at least one of the following: the tenth information or the eleventh information, part or all of the first information, part or all of the eighth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, and the third algorithm information; The third authentication information is verified based on a second specific key, part or all of the content in the second information, the first authentication information, part or all of the content in the eighth information, the tenth information or the eleventh information, the third serial number, the third authentication management domain and at least one of the third algorithm information.

34. The device according to any one of claims 24 to 33, wherein The wireless communication device further includes a processing unit; The processing unit is configured to perform at least one of the following: deriving the first key based on the first derivative information; deriving the second key based on the second derivative information; deriving the third key based on the third derivative information; deriving the fourth key based on the fourth derivative information; deriving the fifth key based on the fifth derivative information; The first derivative information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The second derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The third derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The fourth derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information, and part or all of the content in the ninth information; The fifth derivative information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information, and part or all of the content in the ninth information.

35. A wireless communication device, wherein: include: transceiver unit and processing unit; The transceiver unit is configured to receive first information from a terminal device, and the processing unit is configured to perform at least one of a first operation and a second operation according to the first information; Wherein, the first information includes at least one of the following: second information, third information and first authentication information; The second information includes at least one of the following: first challenge information, first serial number, first authentication management domain; The third information includes at least one of the following: The fourth information and the first verification information; fifth information and second verification information; The fourth information is generated by encrypting the sixth information with the first key; Wherein, the first verification information is generated based on the second key, the fourth information or the sixth information; The second verification information is generated based on the third key, the fifth information or the seventh information; The seventh information is information obtained by encrypting the fifth information; Wherein, the first operation includes verifying the first authentication information; The second operation includes at least one of the following: decrypting the fourth information based on the first key; The third verification operation: Fourth verification operation; The third verification operation includes: verifying the first verification information based on the second key, the fourth information, or the sixth information; The fourth verification operation includes: verifying the second verification information based on the third key, the fifth information or the seventh information.

36. The apparatus of claim 35, wherein: The first operation is performed based on at least one of the following: A first specific key, part or all of the second information; The first specific key is known by the terminal device.

37. The apparatus according to claim 35 or 36, wherein The third verification operation is further performed based on at least one of the following: part or all of the first authentication information and the second information; or The fourth verification operation is also performed based on at least one of the following: part or all of the content in the first authentication information and the second information.

38. The device according to any one of claims 35 to 37, wherein The second information further includes at least one of the following: The identifier of the terminal device and the first algorithm information; The first algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

39. The device according to any one of claims 35 to 38, wherein Before the wireless communication apparatus receives the first information from the terminal device, the transceiver unit is further configured to send eighth information by any one of the following: sending the eighth information to the terminal device; Sending the eighth information through the second communication node; The eighth information includes the second challenge information, or the eighth information includes the second challenge information and at least one of the following: a second serial number, a second authentication management domain, second authentication information, and second algorithm information; The second authentication information is generated based on the second challenge information, or the second authentication information is generated based on the second challenge information and at least one of the following: the second serial number, the second authentication management domain, and the second algorithm information; The second algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm; The second communication node is an access network node.

40. The apparatus of claim 39, wherein The first operation is performed based on at least one of the following: a first specific key, the second challenge information, the second serial number, the second authentication management domain, the second authentication information, and the second algorithm information; The first specific key is known by the terminal device.

41. The device according to any one of claims 35 to 40, wherein The transceiver unit is further configured to send ninth information to the terminal device; The ninth information includes at least one of the following: the tenth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, and the third algorithm information; The tenth information includes the eleventh information and the third verification information; The third verification information is generated based on at least one of the following: the tenth information or the eleventh information, part or all of the content in the first information, part or all of the content in the eighth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, and the third algorithm information; The eleventh information is the decrypted information of the tenth information; The third authentication information is generated based on at least one of a second specific key, part or all of the second information, the first authentication information, part or all of the eighth information, the third serial number, the third authentication management domain, and the third algorithm information; wherein the second specific key is known by the terminal device; The third algorithm information is used to indicate at least one of the following: an encryption algorithm, an integrity protection algorithm, a verification information generation algorithm, a key derivation algorithm, and an authentication information generation algorithm.

42. The apparatus according to claim 41, wherein Before the wireless communication apparatus sends the ninth information to the terminal device, the processing unit is further configured to perform at least one of the following: encrypting the eleventh information to obtain the tenth information; The third verification information is generated based on at least one of the following: the tenth information or the eleventh information, part or all of the first information, part or all of the eighth information, the third challenge information, the third serial number, the third authentication management domain, the third authentication information, and the third algorithm information; The third authentication information is generated based on at least one of a second specific key, part or all of the content in the second information, the first authentication information, part or all of the content in the eighth information, the third serial number, the third authentication management domain and the third algorithm information.

43. The apparatus according to claim 41 or 42, wherein The transceiver unit is further configured to receive fourteenth information from the terminal device; wherein the fourteenth information includes the twelfth information or the thirteenth information, or the fourteenth information includes the twelfth information or the thirteenth information and fourth verification information; The processing unit is further configured to perform at least one of the following: decrypting the thirteenth information according to the fifth key to obtain the twelfth information; The fourth verification information is verified according to the fourth key and the twelfth information or the thirteenth information.

44. The device according to any one of claims 35 to 43, wherein The processing unit is further configured to perform at least one of the following: deriving the first key based on the first derivative information; deriving the second key based on the second derivative information; deriving the third key based on the third derivative information; deriving the fourth key based on the fourth derivative information; deriving the fifth key based on the fifth derivative information; The first derivative information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The second derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The third derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information; The fourth derived information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information, and part or all of the content in the ninth information; The fifth derivative information includes at least one of the following: part or all of the content in the first information, part or all of the content in the eighth information, and part or all of the content in the ninth information.

45. A terminal device, wherein: The wireless communication device comprises a transceiver, a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the wireless communication method according to any one of claims 1 to 13 are implemented.

46. ​​A first communication node, wherein: The wireless communication device comprises a transceiver, a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the wireless communication method according to any one of claims 14 to 23 are implemented.

47. A readable storage medium, wherein: The readable storage medium stores a program or instruction, and when the program or instruction is executed by the processor, the steps of the wireless communication method according to any one of claims 1 to 13 are implemented, or the steps of the wireless communication method according to any one of claims 14 to 23 are implemented.

Citation Information

Patent Citations

  • Method, system and device for binding mobile terminal and smart card in mobile network

    CN102892102A

  • Method and system for authenticating UE during interoperation from EPS to 5GS

    CN111212424A

  • Methods and apparatus relating to authentication of a wireless device

    CN113615124A

  • Method and apparatus to manage nssaa procedure in wireless communication network

    US20230067830A1