Communication methods, communication device, storage medium and computer program product

WO2025218267A1PCT designated stage Publication Date: 2025-10-23ZTE CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/143682
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-19
Filing Date
2024-12-30
Publication Date
2025-10-23

Smart Images

  • Figure CN2024143682_23102025_PF_FP_ABST
    Figure CN2024143682_23102025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present disclosure are communication methods, a communication device, a storage medium and a computer program product. A method comprises: in response to a parameter update of a terminal, a UDM network element acquiring authentication and key management for application (AKMA) service data and a parameter update reason of the terminal; and in response to the AKMA service data indicating that the terminal subscribes to an AKMA service, and the parameter update reason of the terminal being a routing identifier update, sending initial registration request information of the terminal to an access and mobility management function (AMF) network element, wherein the initial registration request information is used for requesting the terminal to execute initial registration.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device, storage medium, and computer program product

[0001] The present disclosure claims priority to Chinese Patent Application No. 202410483152.5, filed on April 19, 2024, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD

[0002] The present disclosure relates to the field of communication technology, and in particular to a communication method and device, a storage medium, and a computer program product. BACKGROUND

[0003] With the rapid development of communication technology, communication security problems are increasingly valued by users. Currently, a terminal can support an authentication and key management for application (AKMA) service, through which an authenticated communication can be established between the terminal and an application function (AF), and the communication security is improved.

[0004] Based on the AKMA procedure, the terminal side and the network side can each generate an AKMA key and a corresponding AKMA key temporary identifier (A-KID). The A-KID can also be referred to as an authentication and key management-key temporary identifier. SUMMARY

[0005] In a first aspect, the present disclosure provides a communication method applied to a UDM network element. The communication method comprises: in response to parameter update of a terminal, obtaining authentication and key management for application (AKMA) service data and a parameter update reason of the terminal; in response to the AKMA service data indicating that the terminal subscribes to the AKMA service and the parameter update reason of the terminal being route identifier update, sending initial registration request information of the terminal to an access and mobility management function (AMF) network element, the initial registration request information being used to request the terminal to perform initial registration.

[0006] In a second aspect, the present disclosure provides another communication method applied to a terminal. The communication method comprises: receiving initial registration request information sent by an AMF network element, the initial registration request information being sent by a UDM network element in response to parameter update of a terminal, the terminal subscribing to an AKMA service, and the parameter update reason of the terminal being route identifier update; and performing initial registration.

[0007] In a third aspect, the present disclosure provides another communication method applied to an AMF network element. The communication method comprises: in response to parameter update of a terminal, the terminal subscribing to an AKMA service, and the parameter update cause of the terminal being route identifier update, receiving initial registration request information sent by a UDM network element; and sending the initial registration request information to the terminal.

[0008] In a fourth aspect, the present disclosure provides a communication apparatus. The communication apparatus comprises: an obtaining module configured to obtain AKMA service data applied and a parameter update cause of a terminal in response to parameter update of the terminal; and a sending module configured to send initial registration request information of the terminal to an AMF network element in response to the AKMA service data indicating that the terminal subscribes to an AKMA service and the parameter update cause of the terminal being route identifier update, the initial registration request information being used to request the terminal to perform initial registration.

[0009] In a fifth aspect, the present disclosure provides another communication apparatus. The communication apparatus comprises: a receiving module configured to receive initial registration request information sent by an AMF network element, the initial registration request information being sent by a UDM network element in response to parameter update of a terminal, the terminal subscribing to an AKMA service, and the parameter update cause of the terminal being route identifier update; and a processing module configured to perform initial registration.

[0010] In a sixth aspect, the present disclosure provides another communication apparatus. The communication apparatus comprises: a receiving module configured to receive initial registration request information sent by a UDM network element in response to parameter update of a terminal, the terminal subscribing to an AKMA service, and the parameter update cause of the terminal being route identifier update; and a sending module configured to send the initial registration request information to the terminal.

[0011] In a seventh aspect, the present disclosure provides a communication device. The communication device comprises a memory and a processor, the memory and the processor being coupled, the memory being configured to store instructions executable by the processor, and the processor being configured to execute the instructions to perform the communication method provided in any one of the first aspect, the second aspect, or the third aspect.

[0012] In an eighth aspect, the present disclosure provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the computer program is used to perform the communication method provided in any one of the first aspect, the second aspect, or the third aspect.

[0013] In a ninth aspect, the present disclosure provides a computer program product comprising computer instructions. When the computer instructions are executed by a processor, the computer instructions are used to perform the method provided in any one of the first aspect, the second aspect, or the third aspect. BRIEF DESCRIPTION OF DRAWINGS

[0014] The accompanying drawings are used to provide a further understanding of the technical solutions of the present disclosure, and constitute a part of the specification, and are used to explain the technical solutions of the present disclosure together with the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions of the present disclosure.

[0015] FIG. 1 is a schematic diagram of a network architecture of AKMA according to an embodiment of the present disclosure.

[0016] FIG. 2 is a schematic diagram of a process of updating parameters of a terminal through a control plane of a UDM according to an embodiment of the present disclosure.

[0017] FIG. 3 is a schematic diagram of a flow of a communication method according to an embodiment of the present disclosure.

[0018] FIG. 4 is a schematic diagram of another communication method according to an embodiment of the present disclosure.

[0019] FIG. 5 is a schematic diagram of an AKMA key architecture according to an embodiment of the present disclosure.

[0020] FIG. 6 is a schematic diagram of another communication method according to an embodiment of the present disclosure.

[0021] FIG. 7 is a schematic diagram of interactions of a communication method according to an embodiment of the present disclosure.

[0022] FIG. 8 is a schematic diagram of another process of updating parameters of a terminal through a control plane of a UDM according to an embodiment of the present disclosure.

[0023] FIG. 9 is a schematic diagram of a composition of a communication apparatus according to an embodiment of the present disclosure.

[0024] FIG. 10 is a schematic diagram of another composition of a communication apparatus according to an embodiment of the present disclosure.

[0025] FIG. 11 is a schematic diagram of another composition of a communication apparatus according to an embodiment of the present disclosure.

[0026] FIG. 12 is a schematic diagram of a structure of a communication device according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0027] In order for those skilled in the art to better understand the technical solutions of the embodiments of the present disclosure, the technical solutions in the embodiments of the present disclosure will be described clearly and completely below with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present disclosure.

[0028] Unless the context clearly requires otherwise, throughout the description and the claims, the words "comprise", "comprising", and the like are to be construed in an open, inclusive sense, as opposed to a closed, exclusive or exhaustive sense, meaning that a process, method, article, or apparatus that "comprises", "comprising", or "includes" one or more elements or steps have the possibility of including additional elements or steps not only composed of, but also exceeding those listed, unless the context clearly dictates otherwise. Throughout the description and claims of this specification, the words "comprise", "comprising", and the like can have the meaning ascribed to them in U.S. law; i.e., they can mean "include", "including", and the like.

[0029] The terms "first", "second", and the like, do not denote any order, quantity, combination, or importance, but rather are used to identify one feature from another. Therefore, use of such terms can be understood to mean "one or more". In the description of the disclosure, the meaning of "a plurality" is two or more, unless otherwise specified.

[0030] In the description of the disclosure, the words "exemplary" and "for example" are used to illustrate, exemplify, or describe certain embodiments or aspects. Any embodiment or aspect described as "exemplary" or "for example" is not necessarily to be construed as preferred or advantageous over other embodiments or aspects. Rather, use of the words "exemplary" and "for example" is intended to present concepts in a particular manner. In the description of the disclosure, the word "include" is used to indicate that the item included is not exclusive, but can include additional items not listed.

[0031] In addition, the use of "based on" means open and inclusive, as the process, step, calculation, or other action that is "based on" one or more stated conditions or values can be based on additional conditions or values beyond those stated.

[0032] The AKMA service is an important service for ensuring application security and reliability. The service covers various aspects such as user identity verification, access control, and key generation, storage, distribution, update, and destruction. The AKMA service can ensure that only authorized users can access the application by verifying the identity of the user, and can also be used to generate and manage keys for encrypting and decrypting data. In addition, an AKMA anchor function (AAnF) can be introduced in the network architecture to generate session keys between the UE and the AF, as well as the corresponding security context. Since the A-KID is usually generated based on the Routing Indicator (RID), when the RID is updated, the A-KID on the terminal side will change, making it impossible for the network side to correctly locate the AAnF or unified data management (UDM), and unable to find the AKMA security context of the terminal, thereby affecting the AKMA service.

[0033] Therefore, the present disclosure provides a communication method applied to a UDM network element, which comprises: in the case of parameter update of a terminal, obtaining AKMA service data of an application and a parameter update reason of the terminal; in the case that the AKMA service data indicates that the terminal subscribes to the AKMA service and the parameter update reason of the terminal is routing identifier update, sending initial registration request information of the terminal to an access and mobility management function (AMF) network element, the initial registration request information being used to request the terminal to perform initial registration.

[0034] In this way, the terminal can be controlled to perform initial registration when the routing identifier is updated, thereby triggering the update of the AKMA key, so that the authentication context after the change of the A-KID can remain consistent, thereby enabling authentication and key management according to the A-KID, and avoiding interruption or failure of the AKMA service.

[0035] The technical solution provided by the embodiments of the present disclosure can be applied to various mobile communication networks, such as a 5th generation mobile communication technology (5G) communication network, a new radio (NR) mobile communication network using 5G, an internet of things (loT), a narrow band internet of things (NB-loT), a long term evolution (LTE) communication network, a future mobile communication network (such as 6G or a multi-communication fusion system), etc., and the embodiments of the present disclosure are not limited thereto.

[0036] Exemplarily, as shown in FIG. 1, the present disclosure provides a network architecture diagram of AKMA. The network architecture at least includes a terminal, an access network (AN), a core network and a data service network. Compared with the traditional 5th Generation Mobile Networks (5G) architecture, a new network function (NF) network element, AAnF network element, is added in the network architecture. The AAnF can be used to generate a session key between the terminal and the AF network element, and maintain the corresponding security context. For example, the AAnF network element can be used to support AKMA anchor key (K AKMA ), and generate an application key (K AF ). Moreover, the AAnF network element can be a single deployment NF network element, or can be deployed together with other NF network elements. It can be understood that FIG. 1 is only illustrative and does not limit the present disclosure.

[0037] The terminal can be referred to as a terminal device, a user equipment (UE), etc., which is a device with wireless transceiver function, and can communicate with one or more core networks (CNs) through an access network ((Radio) access network (R)AN) access network device. The terminal can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; can also be deployed on water (such as ships, etc.); can also be deployed in the air (such as airplanes, balloons and satellites, etc.). The terminal can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical treatment, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc.

[0038] A (radio) access network ((R)AN) is used to manage radio resources and provide access services for terminals. The access network device (for example, a RAN device or an AN device) provided by the present disclosure is a device that provides wireless communication functions for terminal devices, and can also be referred to as a network device. For example, the access network device can include a next generation node base station (gNB) in a 5G system, an evolved node B (eNB) in a long term evolution (LTE), a radio network controller (RNC), a node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (for example, a home evolved node B, or a home node B, HNB), a base band unit (BBU), a transmitting and receiving point (TRP), a transmitting point (TP), a pico, a mobile switching center, or a network device in a future network, and the like. In systems using different wireless access technologies, the names of devices with access network device functions may be different. The type of the access network device is not limited in the present disclosure.

[0039] An access and mobility management function (AMF) can also be referred to as an AMF network element, an AMF network function or an AMF network function entity, and is used to manage user access to the network. The AMF network element is responsible for non-access stratum (NAS) signaling management, access control and mobility management of terminals to the network, for example, the AMF network element includes functions such as mobile state management, allocation of user temporary identity, authentication and authorization of users, and the like.

[0040] An authentication server function (AUSF) can also be referred to as an AUSF network element, an AUSF network function or an AUSF network function entity, and is used for authentication services, key generation, and implementation of two-way authentication of user equipment, and supports a unified authentication framework. In the embodiments of the present disclosure, the AUSF is mainly used for mutual authentication between the UE and the network, and generates a security key for use in subsequent processes.

[0041] An application function (AF), which can also be referred to as an AF network element, an AF network function, or an AF network function entity, is configured to perform data routing for application influence, access network exposure functions, interact with a policy framework for policy control, and the like.

[0042] A network exposure function (NEF), which can also be referred to as an NEF network element, an NEF network function, or an NEF network function entity, is configured to perform data routing for application influence, access network exposure functions, interact with a policy framework for policy control, and the like.

[0043] A unified data management (UDM), which can also be referred to as a UDM network element, a UDM network function, or a UDM network function entity, can be configured to perform unified management of user data such as user subscription information and security information, as well as related functions such as user identification, access authorization, and mobility management.

[0044] By way of example, FIG. 2 is a schematic diagram of a process for updating parameters of a terminal through a control plane of a UDM. As shown in FIG. 2, the process includes the following Sa1-Sa7:

[0045] Sa1, the UDM network element determines to perform parameter updating of the terminal.

[0046] Sa2, the UDM network element sends an Nudm_SDM_Notification message to an AMF network element.

[0047] The AMF network element is an AMF network element configured to manage the terminal that is to perform parameter updating. The Nudm_SDM_Notification message described above can be understood as a unified data management service data management notification message, i.e., the UDM network element can notify the AMF network element of updating of terminal-related parameters by invoking the Nudm_SDM_Notification service operation.

[0048] In some embodiments, the Nudm_SDM_Notification message can include UDM update data.

[0049] The UDM update data can include UDM update data related to parameter updating of the terminal, indication information of whether the terminal needs to send confirmation information, and indication information of whether the terminal needs to perform re-registration.

[0050] In some embodiments, in the case that the parameter update of the terminal is performed due to the "routing identity update data", and the updated routing identity is not supported by the UDM network element currently registered by the AMF network element, the UDM network element should require the terminal to re-register after the update data. That is, at this time, the UDM update data can include indication information that the terminal needs to re-register.

[0051] Sa3, in the case that the AMF network element determines that the terminal is unreachable, the Nudm_SDM_Info message is sent to the UDM network element.

[0052] The Nudm_SDM_Info message can be understood as a unified data management service data management information request message, that is, the AMF can call the Nudm_SDM_Info service operation to inform the UDM that the transmission of the parameter update data of the terminal is unsuccessful. Further, the UDM can consider this process as a suspension of the UE parameter update process, and skip the subsequent S4-S7.

[0053] Sa4, the AMF network element sends a DL NAS TRANSPORT message to the terminal.

[0054] The terminal is the terminal determined by the UDM network element to need parameter update, and the AMF network element can be used to manage the terminal. The DL NAS TRANSPORT message is a kind of downlink non-access layer transmission message, and the network side can realize the downlink transmission of information by sending the DL NAS TRANSPORT message. The DL NAS TRANSPORT message sent by the above-mentioned AMF network element to the terminal contains the transparent container received from the UDM.

[0055] The above-mentioned transparent container is a data structure, which is used to encapsulate the user subscription data or other related information received from the UDM network element. These data are transparent to the AMF network element, that is, the AMF network element does not analyze or modify the content in the container, but only transmits it as a whole. In some embodiments, the above-mentioned UDM update data can be contained in the transparent container. The AMF network element receives the transparent container from the UDM network element, constructs the DL NAS TRANSPORT message, and sends the transparent container as part of the message to the terminal.

[0056] Thus, the terminal can receive the DL NAS TRANSPORT message. The terminal can verify whether the UDM update data is provided by a HPLMN (Home Public Land Mobile Network), a SNPN (Specific Network Public Land Mobile Network), or a TTP (Trusted Third Party) based on a preset mechanism. Illustratively, the preset mechanism can be based on a mechanism described in TS 33.501

[0015] .

[0057] If the terminal succeeds in the security check of the UDM update data, the terminal can choose to store the information and use the parameters from then on, or forward the information to a universal subscriber identity module (USIM).

[0058] If the terminal fails in the security check of the UDM update data, the terminal can discard the content of the UDM update data.

[0059] Sa5, the terminal sends an UL NAS TRANSPORT message containing acknowledgment (Ack) information to the AMF network element.

[0060] The UL NAS TRANSPORT message is an uplink non-access layer transmission message. When the terminal needs to perform uplink information transmission, the terminal can achieve uplink transmission of information by sending the UL NAS TRANSPORT message. If the terminal succeeds in the security check of the UDM update data, and the UDM network element requests the terminal to send determination information to the UDM network element. The terminal can transmit the UL NAS TRANSPORT message containing the Ack information to the AMF network element to achieve uplink transmission of the Ack information.

[0061] Sa61, the AMF network element sends an Nudm_SDM_Info request message to the UDM network element.

[0062] The Nudm_SDM_Info request message can contain the Ack information of the terminal.

[0063] In the case that the AMF receives an UL NAS TRANSPORT message carrying a transparent container from the terminal, and the transparent container carries the Ack information of the terminal, the AMF sends an Nudm_SDM_Info request message to the UDM, and includes the transparent container.

[0064] Sa62、 the UDM network element sends the Nudm_SDM_Notification message to the AMF network element.

[0065] If the terminal parameter update is due to the "routing identifier update data", and the UDM registered by the current AMF also supports the updated routing identifier, the UDM network element can require the terminal to send confirmation information, but does not require the terminal to re-register. After the UDM network element receives the transparent container indicating successful reception, the UDM network element should trigger the Nudm_SDM_Notification service operation to update the terminal context in the AMF using the updated routing indicator data.

[0066] In some embodiments, the UDM network element can also indicate other NFs (such as a session management function (SMF) and a short message service function (SMSF)) about the update of the routing identifier assigned to the SUPI (Subscription Permanent Identifier) by invoking the Nudm_SDM_Notification service operation.

[0067] Sa7, if the UDM network element requests the terminal to re-register, the terminal initiates re-registration.

[0068] If the UDM requests the UE to re-register, the terminal can wait until it returns to the radio resource control idle (RRC_IDLE) state, and then initiate a registration procedure. The registration procedure can be the registration procedure described in the relevant standard, such as TS24.501.

[0069] In FIG. 1, Nausf, Nudm, Namf, Nnef, Naanf, Nl, N2, and Ua* are interface sequence numbers, and the meanings of these interface sequence numbers can be found in the meanings defined in the relevant standard protocol, which will not be described one by one here. In addition, only a terminal is exemplarily illustrated as UE in FIG. 1, and the interface names between the network functions in FIG. 1 are also only an example. In actual implementation, the interface names of the system architecture can also be other names, which are not limited by the present disclosure.

[0070] It should be noted that FIG. 1 is only an exemplary framework diagram, and the number of devices or network elements included in FIG. 1, the names of the various devices or network elements are not limited, and in addition to the devices or network elements shown in FIG. 1, other devices or network elements can also be included.

[0071] The application scenarios of the embodiments of the present disclosure are not limited. The system architecture and business scenarios described in the embodiments of the present disclosure are used to more clearly illustrate the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art can know that, with the evolution of network architecture and the appearance of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.

[0072] Some of the methods provided by the present disclosure will be described below with reference to the accompanying drawings.

[0073] As shown in FIG. 3, the present disclosure provides a communication method applied to a UDM network element. The communication method comprises:

[0074] S101, in the case of parameter updating of a terminal, AKMA service data and a parameter updating reason of the terminal are obtained.

[0075] In some embodiments, the AKMA service data can include data for indicating whether the UDM network element corresponds to a terminal that subscribes to the AKMA service, for example, subscription status data, subscriber identifier data, and the like.

[0076] Exemplarily, the AKMA service data can also include one or more of service configuration data, security context, service status data, authentication key data, and the like. The service configuration data can include parameter configurations of the AKMA service, for example, the validity period of the authentication key, the update policy, the used encryption algorithm, and the like. The security context refers to information that can be used to implement security protection (for example, encryption / decryption, and / or integrity protection / verification) of data. Exemplarily, the security context can include an encryption key, an integrity protection password, and the like. The service status data can include the current state of the AKMA service, for example, whether it is activated, whether it is suspended, and the like. The authentication key data can be the key itself and its related attributes for terminal authentication, such as the version number of the key, the generation time, the usage limit, and the like. It should be understood that the above is only an exemplary description of the AKMA service data, and in actual application, the AKMA service data can be different according to the actual business needs of the network architecture, for example, the AKMA service data can also include key update records, service usage records, and the like.

[0077] In some embodiments, the UDM network element can retrieve the AKMA service data from the data storage.

[0078] Exemplarily, the UDM network element will usually maintain a database or data storage system for storing various information related to subscribers, which can include AKMA service data. Thus, when the UDM network element needs to obtain the AKMA service data, the UDM can retrieve the corresponding data from its internal database.

[0079] In some embodiments, the UDM network element can obtain the AKMA service data from other network function network elements (e.g., AMF, SMF, and the like).

[0080] Illustratively, the other network function network elements (e.g., AMF, SMF, and the like) can collect authentication and key information (i.e., AKMA service data) related to the terminal during interaction with the terminal, and thus can forward the collected AKMA service data to the UDM network element.

[0081] In some embodiments, the UDM network element can also obtain the AKMA service data from an authentication server, a key management system, and the like, which are data sources for generating, distributing, and managing authentication keys.

[0082] It should be noted that the process of obtaining AKMA service data by the UDM network element can vary due to differences in network architecture and standards. In actual applications, the UDM network element can select a suitable implementation to obtain AKMA service data according to the actual network architecture.

[0083] In some embodiments, the UDM can determine whether the terminal needs to perform parameter update by evaluating data such as network status, device performance, and security requirements of the terminal. That is, the reason for parameter update of the terminal can include reasons such as network status, device performance, and security requirements.

[0084] Illustratively, taking the network status as an example of the reason for parameter update of the terminal, for example, route identity update. In the case of route identity update, the UDM can determine that the terminal needs to perform corresponding parameter update to ensure that it can correctly communicate with the network. Route identity is one of the key parameters in the network, which is used to identify and locate the routing path in the network. When the route identity is updated, the UDM network element can receive a route identity update notification and determine that the relevant terminal affected by this route identity update needs to perform parameter update.

[0085] In some embodiments, before obtaining the AKMA service data and the reason for parameter update of the terminal, the UDM network element can also receive a notification message of an update position unit (UPU) updating the route identity of the terminal, and determine to perform parameter update of the terminal according to the notification message.

[0086] Exemplarily, when the routing identifier is updated, a corresponding routing identifier update notification can be generated and sent to a related network entity or network element, such as a UDM network element, through a corresponding signaling protocol or message passing mechanism. Thus, the UDM network element can receive the routing identifier update notification and can parse and process the routing identifier update notification, for example, verify the validity of the notification and determine the related terminal affected by the routing identifier update. Further, the UDM network element can determine that the related terminal needs to perform parameter update.

[0087] S102, in the case that the AKMA service data indicates that the terminal subscribes to the AKMA service and the parameter update cause of the terminal is routing identifier update, the initial registration request information of the terminal is sent to the AMF network element.

[0088] In some embodiments, the UDM network element can determine whether the terminal subscribes to the AKMA service according to the AKMA service data.

[0089] Exemplarily, the UDM network element can determine whether the terminal subscribes to the AKMA service according to data in the AKMA service data, such as subscription state data, subscriber identifier data, and the like, which can indicate whether the terminal subscribes to the AKMA service.

[0090] In some embodiments, the UDM network element can also determine whether the parameter update cause of the terminal is routing identifier update according to the obtained parameter update cause of the terminal.

[0091] Thus, in the case that the AKMA service data indicates that the terminal subscribes to the AKMA service and the parameter update cause of the terminal is routing identifier update, the UDM network element can send the initial registration request information of the terminal to the AMF network element.

[0092] The initial registration request information is used to request the terminal to perform initial registration. Thus, the terminal can perform primary authentication and update the AKMA key.

[0093] In some embodiments, the UDM network element can also send the UDM update data related to the parameter update of the terminal to the AMF network element to trigger the terminal to perform parameter update.

[0094] Based on the technical solution provided in the disclosure, in the case that the terminal subscribes to AKMA and the parameter update of the terminal is caused by routing identifier update, the terminal can perform initial registration, thereby triggering the update of AKMA key. The A-KID on the terminal side will also change due to the routing identifier update, thereby affecting the AKMA service. Based on the technical solution of the disclosure, the terminal can be controlled to perform initial registration when the routing identifier update is determined, thereby triggering the update of AKMA key. In this way, the authentication context after the change of A-KID can remain consistent, thereby enabling the authentication and key management according to A-KID, avoiding the interruption or failure of AKMA service, and improving the reliability of AKMA service.

[0095] In some embodiments, the disclosure also provides another communication method applied to a terminal. As shown in FIG. 4, the communication method comprises:

[0096] S201, receiving initial registration request information sent by an AMF network element, wherein the initial registration request information is sent by a UDM network element in the case that the parameter update of the terminal, the terminal subscribes to AKMA service, and the parameter update of the terminal is caused by routing identifier update.

[0097] S202, performing initial registration.

[0098] In some embodiments, the terminal can first perform deregistration, and then perform initial registration after completing the deregistration process.

[0099] For example, the terminal can perform deregistration and delete its 5G globally unique temporary identifier (5G-GUTI). The 5G-GUTI is a temporary identity of the terminal in the network. It should be understood that the terminal can delete its old 5G-GUTI when performing deregistration, and obtain a new 5G-GUTI when performing initial registration again.

[0100] Further, the terminal can perform initial registration. In the process of initial registration, the terminal side can establish a new registration state with the network side to verify the identity of the terminal, enable the terminal to obtain network access permission, and obtain a new temporary identity, etc. The process of initial registration includes the primary authentication process of the terminal, and can trigger the update of AKMA key.

[0101] Exemplarily, FIG. 5 is an AKMA key architecture diagram provided by an embodiment of the present disclosure, as shown in FIG. 5, the terminal side and the network side complete the primary authentication, and a security key can be generated for use in subsequent processes. In some embodiments, the primary authentication can also involve network elements such as AMF / SEAF (Security Anchor Function), AUSF, and UDM of the network side. In the primary authentication process, a security key K AUSF can be generated, which is a shared key of the AUSF network element and the terminal. Further, the terminal and the AUSF network element can also generate AKMA keys K AKMA , so that the terminal and the AF network element perform traffic protection between them according to K AKMA generated by K AF . The terminal and the AUSF network element can obtain K AKMA and KID, respectively, KID being the corresponding unique key identifier of K AKMA . In this way, the terminal can complete the primary authentication between the terminal side and the network side by performing the initial registration, and new AKMA keys can be generated in the primary authentication process.

[0102] In some embodiments, the terminal can receive the UDM update data sent by the AMF network element for the terminal to perform parameter update related to the UDM. Further, according to the UDM update data, the parameter update is performed.

[0103] Based on the technical solutions provided by the present disclosure, the terminal can receive the initial registration request information sent by the UDM network element in the case that the parameter update of the terminal, the terminal subscribes to the AKMA service, and the parameter update of the terminal is caused by the routing identifier update, and perform the initial registration. In this way, in the case that the A-KID changes due to the routing identifier update, the primary authentication between the terminal and the network side can be completed by performing the initial registration, and new AKMA keys can be generated in the primary authentication process, thereby avoiding the interruption or failure of the AKMA service and improving the reliability of the AKMA service.

[0104] In some embodiments, the present disclosure also provides another communication method, which is applied to an AMF network element, as shown in FIG. 6, the method comprises:

[0105] S301, in the case that the parameter update of the terminal, the terminal subscribes to the AKMA service, and the parameter update of the terminal is caused by the routing identifier update, receiving the initial registration request information sent by the UDM network element.

[0106] S302, sending the initial registration request information to the terminal.

[0107] It should be understood that the AMF network element sends the initial registration request information to the terminal, which can trigger the terminal to perform the initial registration, so that the main authentication between the terminal side and the network side can be completed, and a new AKMA key can be generated in the main authentication process.

[0108] In some embodiments, the AMF network element can receive the UDM network element update data related to the parameter update of the terminal sent by the UDM network element, and send the UDM update data related to the parameter update of the terminal to the terminal to trigger the parameter update of the terminal.

[0109] In addition, the detailed description of S301-S302 can also refer to the related description of S101-S102 and S201-S202 described above, which will not be repeated here.

[0110] Based on the technical solutions provided in the present disclosure, the AMF network element can receive the initial registration request information sent by the UDM network element in the case that the terminal subscribes to the AKMA service and the parameter update reason of the terminal is route identifier update, and send the initial registration request information to the terminal to trigger the terminal to perform the initial registration. Therefore, the terminal can complete the main authentication process to generate a new AKMA key, thereby avoiding the interruption or failure of the AKMA service and improving the reliability of the AKMA service.

[0111] As shown in FIG. 7, it is an interaction diagram of the communication method provided in the present disclosure, which will be described below in combination with FIG. 7:

[0112] S401, in the case of parameter update of the terminal, the UDM network element obtains AKMA service data and the parameter update reason of the terminal.

[0113] S402, the UDM network element sends the initial registration request information of the terminal to the AMF network element.

[0114] Correspondingly, the AMF network element receives the initial registration request information.

[0115] The initial registration request information is sent by the UDM network element in the case that the AKMA service data indicates that the terminal subscribes to the AKMA service and the parameter update reason of the terminal is route identifier update.

[0116] S403, the AMF network element sends the initial registration request information to the terminal.

[0117] Correspondingly, the terminal can receive the initial registration request information.

[0118] S404, the terminal performs the initial registration.

[0119] In some embodiments, the UDM network element can also send terminal parameter update related UDM update data to the AMF network element. Accordingly, the AMF network element can receive the terminal parameter update related UDM network element update data sent by the UDM network element.

[0120] Further, the AMF network element can send the terminal parameter update related UDM update data to the terminal. The terminal receives the UDM update data and performs parameter update.

[0121] In some embodiments, in combination with the above-mentioned embodiments, the present disclosure also provides a process for updating the parameters of a terminal through the control plane of a UDM, as shown in FIG. 8, which includes the following Sb1-Sb8:

[0122] Sb1, the UDM network element determines to perform parameter update of the terminal.

[0123] Sb2, the UDM network element determines whether the terminal subscribes to the AKMA service.

[0124] Exemplarily, the UDM network element can obtain AKMA service data, and determine whether the terminal subscribes to the AKMA service through the AKMA service data.

[0125] Sb3, the UDM network element sends an Nudm_SDM_Notification message to the AMF network element.

[0126] In the case of performing parameter update of the terminal due to "routing identifier update data", and the updated routing identifier is not supported by the UDM currently registered by the AMF, the UDM should require the terminal to re-register after the update data. That is, at this time, the UDM update data can include indication information that the terminal needs to re-register.

[0127] In some embodiments, in the case of performing parameter update of the terminal due to "routing identifier update data", and the terminal has subscribed to the AKMA service, the UDM network element can request the terminal to re-register after the update data. That is, at this time, the UDM update data can include indication information that the terminal needs to re-register.

[0128] Sb4, in the case where the AMF network element determines that the terminal is unreachable, an Nudm_SDM_Info message is sent to the UDM network element.

[0129] Sb5, the AMF network element sends a DL NAS TRANSPORT message to the terminal.

[0130] The terminal is the terminal determined by the UDM to need to perform parameter update, and the AMF can be used to manage the terminal. The DL NAS TRANSPORT message contains a transparent container received from the UDM.

[0131] Sb6, the terminal sends an UL NAS TRANSPORT message containing acknowledgment (Ack) information to the AMF network element.

[0132] If the security check of the terminal on the UDM updating data is successful, and the UDM requests the terminal to send determination information to the UDM. The terminal can transmit an UL NAS TRANSPORT message containing Ack information to the AMF.

[0133] Sb71, the AMF network element sends an Nudm_SDM_Info request message to the UDM.

[0134] The Nudm_SDM_Info request message can contain Ack information carrying the terminal.

[0135] Sb72, the UDM network element sends an Nudm_SDM_Notification message to the AMF network element.

[0136] Sb8, if the UDM requests the terminal to re-register, the terminal initiates re-registration.

[0137] If the UDM requests the UE to re-register, the terminal can wait until it returns to a radio resource control idle (RRC_IDLE) state, and then the terminal can first perform deregistration, delete its 5G-GUTI, and then initiate a registration procedure. The registration procedure can be a registration procedure described in a related standard, such as TS 24.501.

[0138] In addition, the detailed description of Sb1-Sb8 can also refer to the related description of Sa1-Sa7 described above, which will not be repeated here.

[0139] The above mainly introduces the scheme provided by the present disclosure from the perspective of interaction between each device or network element. It can be understood that each device or network element contains a hardware structure and / or software module for executing each function in order to achieve the above functions. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiments disclosed in the present text, the present disclosure can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present disclosure.

[0140] Figure 9 shows a schematic diagram of a communication device according to an embodiment of the present disclosure. As shown in Figure 9, the communication device 900, which can be applied to a UDM network element, comprises an obtaining module 901 and a sending module 902. In some embodiments, the communication device 900 can further comprise a determining module 903.

[0141] The obtaining module 901 is configured to, in the case of parameter update of the terminal, obtain AKMA service data applied and a parameter update reason of the terminal.

[0142] The sending module 902 is configured to, in the case that the AKMA service data indicates that the terminal subscribes to the AKMA service and the parameter update reason of the terminal is a routing identifier update, send initial registration request information of the terminal to an access and mobility management function (AMF) network element, the initial registration request information being used to request the terminal to perform initial registration.

[0143] In some embodiments, the sending module 902 is further configured to send UDM update data related to the parameter update of the terminal to the AMF network element, so as to trigger the terminal to perform the parameter update.

[0144] In some embodiments, the obtaining module 901 is further configured to receive a notification message that a UPU updates the routing identifier of the terminal. The determining module 903 is configured to determine to perform the parameter update of the terminal according to the notification message.

[0145] For more details of the obtaining module 901, the sending module 902, the determining module 903, and more details of the technical features and beneficial effects thereof, please refer to the corresponding method embodiments described above, which will not be repeated here.

[0146] Figure 10 shows a schematic diagram of a communication device according to an embodiment of the present disclosure. As shown in Figure 10, the communication device 1000, which can be applied to a terminal, comprises a receiving module 1001 and a processing module 1002.

[0147] The receiving module 1001 is configured to receive initial registration request information sent by an AMF network element, the initial registration request information being sent by a UDM network element in the case of parameter update of the terminal, the terminal subscribing to AKMA service, and the parameter update reason of the terminal being a routing identifier update.

[0148] The processing module 1002 is configured to perform initial registration.

[0149] In some embodiments, the receiving module 1001 is further configured to receive UDM update data related to the parameter update of the terminal sent by the AMF network element. The processing module 1002 is further configured to perform the parameter update according to the UDM update data.

[0150] In some embodiments, the processing module 1002 is further configured to perform deregistration before performing the initial registration.

[0151] For more details of the receiving module 1001 and the processing module 1002, and the more detailed description of each technical feature therein, and the description of the beneficial effects, etc., please refer to the corresponding method embodiment part above, which will not be repeated here.

[0152] FIG. 11 shows a constituent schematic diagram of a communication apparatus provided by an embodiment of the present disclosure. As shown in FIG. 11, the communication apparatus 1100, which can be applied to an AMF network element, includes a receiving module 1101 and a sending module 1102.

[0153] The receiving module 1101 is configured to receive initial registration request information sent by a UDM network element in the case that a terminal performs parameter update, the terminal subscribes to an AKMA service, and the cause of the parameter update of the terminal is route identifier update.

[0154] The sending module 1102 is configured to send the initial registration request information to the terminal.

[0155] In some embodiments, the receiving module 1101 is further configured to receive UDM network element update data related to parameter update of the terminal sent by the UDM network element. The sending module 1102 is further configured to send the UDM update data related to the parameter update of the terminal to the terminal to trigger the terminal to perform parameter update.

[0156] For more details of the receiving module 1101 and the sending module 1102, and the more detailed description of each technical feature therein, and the description of the beneficial effects, etc., please refer to the corresponding method embodiment part above, which will not be repeated here.

[0157] It should be noted that the modules in FIG. 9, FIG. 10 or FIG. 11 can also be referred to as units, for example, the sending module can be referred to as a sending unit. In addition, in the embodiments shown in FIG. 9, FIG. 10 or FIG. 11, the name of each module can not be the name shown in the figure, for example, the sending module can also be referred to as a communication module, and the receiving module can also be referred to as a communication module.

[0158] Each unit or module in FIG. 9, FIG. 10 or FIG. 11, if implemented in the form of a software functional module and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present disclosure, essentially or partially, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a number of instructions for causing a computer device (such as a personal computer, a server, or a network device, etc.) or a processor (or a plurality of processors) to perform all or part of the steps of the methods in the embodiments of the present disclosure. The storage medium storing the computer software product includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and the like.

[0159] In the case of implementing the functions of the above-mentioned integrated modules in the form of hardware, the embodiments of the present disclosure provide a structural diagram of a communication device, which can include the above-mentioned communication apparatus 900, the communication apparatus 1000 or the communication apparatus 1100. As shown in FIG. 12, the communication device 1200 includes a memory 1201, a processor 1202, a communication interface 1203 and a bus 1204.

[0160] The memory 1201 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, can be a random access memory (RAM) or other type of dynamic storage device that can store dynamic information and instructions, can be an electrically erasable programmable read-only memory (EEPROM), a magnetic disk storage medium or other magnetic storage device, or can be any other medium capable of carrying or storing desired program codes in the form of instructions or data structures and capable of being accessed by a computer, but is not limited to this.

[0161] The processor 1202 can be a logical grouping of a logical block, a module, and a circuit that implements or executes the various exemplary methods described in connection with the present disclosure. The processor 1202 can be a central processing unit, a general purpose processor, a digital signal processor, an application specific integrated circuit, a field programmable gate array, or other programmable logic device, transistor logic, hardware component, or any combination thereof. The processor 1202 can also implement or execute the various exemplary logical blocks, modules, and circuits described in connection with the present disclosure. The processor 1202 can also be a combination of computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.

[0162] The communication interface 1203 is configured to connect with other devices through a communication network. The communication network can be an Ethernet, a wireless access network, a wireless local area network (WLAN), and the like.

[0163] In some embodiments, the memory 1201 can exist independently of the processor 1202, and the memory 1201 can be connected to the processor 1202 through the bus 1204, for storing instructions or program codes. When the processor 1202 invokes and executes the instructions or program codes stored in the memory 1201, the method provided by the embodiments of the present disclosure can be implemented.

[0164] In some embodiments, the memory 1201 can also be integrated with the processor 1202.

[0165] The bus 1204 can be an extended industry standard architecture (EISA) bus or the like. The bus 1204 can be divided into an address bus, a data bus, a control bus, and the like. For the sake of brevity and conciseness, only one thick line is used to represent the bus 1204 in FIG. 12, but it does not mean that there is only one bus or only one type of bus.

[0166] From the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of brevity and conciseness, only the division of the above functional modules is exemplified, and in actual applications, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device or apparatus is divided into different functional modules to complete all or part of the functions described above.

[0167] The present disclosure also provides a computer-readable storage medium. All or part of the processes in the above-mentioned method embodiments can be completed by computer instructions to the relevant hardware, and the program can be stored in the above-mentioned computer-readable storage medium. When the program is executed, it may include the processes of the above-mentioned method embodiments. The computer-readable storage medium can be an internal storage unit of the device or apparatus of any of the above-mentioned embodiments, such as a hard disk or memory of a computer device. The above-mentioned computer-readable storage medium can also be an external storage device of the above-mentioned device or apparatus, for example, a plug-in hard disk, a smart memory card (smart media card, SMC), a secure digital (secure digital, SD) card, a flash card (flash card), etc. equipped on the above-mentioned device or apparatus. Further, the above-mentioned computer-readable storage medium can also include both the internal storage unit of the above-mentioned device or apparatus and an external storage device. The above-mentioned computer-readable storage medium is used to store the above-mentioned computer program and other programs and data required by the above-mentioned device or apparatus. The above-mentioned computer-readable storage medium can also be used to temporarily store data that has been output or is to be output. The above-mentioned computer-readable storage medium includes a non-transitory computer-readable storage medium.

[0168] The embodiments of the present disclosure further provide a computer program product, which includes a computer program. When the computer program product is run on a computer, the computer is enabled to execute any one of the methods provided in the above embodiments.

[0169] Although the present disclosure is described herein in conjunction with various embodiments, in the process of implementing the disclosure for which protection is sought, those skilled in the art may understand and implement other variations of the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "one" or "an" does not exclude multiple components. A single processor or other unit may implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0170] Although the present disclosure has been described with reference to certain features and embodiments thereof, it will be apparent that various modifications and combinations may be made thereto without departing from the spirit and scope of the present disclosure. Accordingly, this specification and the drawings are merely illustrative of the present disclosure as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present disclosure. Obviously, those skilled in the art may make various modifications and variations to the present disclosure without departing from the scope of the present disclosure. Thus, the present disclosure is intended to encompass such modifications and variations if they fall within the scope of the claims of the present disclosure and their equivalents.

[0171] The above merely provides the specific implementation of the present disclosure, but the protection scope of the present disclosure is not limited thereto, any change or replacement within the technical scope disclosed by the present disclosure should be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.

Claims

1. A communication method applied to a unified data management function (UDM) network element, wherein, The method comprises: in response to parameter update of the terminal, obtaining authentication and key management, AKMA, service data of an application and a parameter update cause of the terminal; in response to the AKMA service data indicating that the terminal subscribes to AKMA service and the parameter update cause of the terminal being route identifier update, sending initial registration request information of the terminal to an access and mobility management function, AMF, network element, the initial registration request information being used to request the terminal to perform initial registration.

2. The method of claim 1, further comprising: sending UDM update data related to the parameter update of the terminal to the AMF network element to trigger the parameter update of the terminal.

3. The method of claim 1, wherein, Before the obtaining of the AKMA service data and the parameter update cause of the terminal, the method further comprises: receiving a notification message that a UPU updates the route identifier of the terminal; determining to perform the parameter update of the terminal according to the notification message.

4. A communication method applied to a terminal, wherein, The method comprises: receiving initial registration request information sent by an access and mobility management function, AMF, network element, the initial registration request information being sent by a unified data management function, UDM, network element in response to parameter update of a terminal, the terminal subscribing to authentication and key management, AKMA, service of an application, and the parameter update cause of the terminal being route identifier update; performing initial registration.

5. The method of claim 4, further comprising: receiving UDM update data related to the parameter update of the terminal sent by the AMF network element; performing parameter update according to the UDM update data.

6. The method of claim 4, wherein, Before the performing of initial registration, the method further comprises: performing deregistration. 7.A communication method applied to an access and mobility management function (AMF) network element, wherein, The method comprises: in response to parameter update of a terminal, the terminal subscribing to authentication and key management, AKMA, service of an application, and the parameter update cause of the terminal being route identifier update, receiving initial registration request information sent by a unified data management function, UDM, network element; sending the initial registration request information to the terminal.

8. The method of claim 7, further comprising: receiving UDM network element update data related to the parameter update of the terminal sent by the UDM network element; sending UDM update data related to the parameter update of the terminal to the terminal to trigger the parameter update of the terminal.

9. A communication device comprising: a memory and a processor; wherein the memory and the processor are coupled; the memory is used to store instructions executable by the processor; the processor executes the instructions to perform the method according to any one of claims 1 to 8.

10. A computer readable storage medium, wherein, The computer readable storage medium stores computer instructions, when the computer instructions run on the processor, make the processor execute the method according to any one of claims 1 to 8.

11. A computer program product, wherein, The computer program product contains a computer program, when the computer program runs on a computer, make the computer execute the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Communication method and device, storage medium and computer program product

    CN120835286A

  • User route updating method and equipment

    CN111200857A

  • Information processing method and device

    CN117413556A

  • Registration method and device, authentication method and device and computer readable storage medium

    CN117641347A

  • Session request method and apparatus, terminal, and storage medium

    US20230422032A1