Communication method, first network device, second network device, terminal, communication system, and storage medium
By establishing a key or random number association in the communication system, the problem of data leakage caused by fake terminals is solved, and more secure user plane communication is achieved.
Patent Information
- Application Number
- PCT/CN2024/095011
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-23
- Publication Date
- 2025-11-27
AI Technical Summary
In the field of communication technology, the existence of fake terminals during the establishment of user plane connections can lead to data leakage and pose security risks.
By establishing an association between the first piece of information, the Transport Layer Security (TLS) connection, and the terminal, and using keys or random numbers for authentication, the security of communication is ensured.
It improves the security and reliability of user plane communication and prevents data leakage from fake terminals.
Smart Images

Figure CN2024095011_27112025_PF_FP_ABST
Abstract
Description
Communication method, first network device, second network device, terminal, communication system and storage medium TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and in particular to a communication method, a first network device, a second network device, a terminal, a communication system and a storage medium. BACKGROUND
[0002] In the technical field of communication, in the process of user plane connection establishment and application, there may be a case of a fake terminal, which may lead to data leakage and pose a security risk to communication.
[0003] SUMMARY
[0004] To cope with the possible risks, the communication mechanism of the network needs to be adjusted.
[0005] Embodiments of the present disclosure provide a communication method, a first network device, a second network device, a terminal, a communication system and a storage medium.
[0006] According to a first aspect of embodiments of the present disclosure, a communication method is provided, the method being performed by a first network device, and the method comprising:
[0007] establishing an association relationship between first information, a transport layer security (TLS) connection and a terminal;
[0008] wherein the first information is a key or a random number; and the association relationship is used to perform authentication for the terminal.
[0009] According to a second aspect of embodiments of the present disclosure, a communication method is provided, the method being performed by a second network device, and the method comprising:
[0010] receiving fourth information sent by the first network device;
[0011] sending the fourth information to the terminal;
[0012] wherein the fourth information contains the first information, the first information is a key or a random number, and there is an association relationship between the first information, the TLS connection and the terminal, and the association relationship is used to perform authentication for the terminal.
[0013] According to a third aspect of embodiments of the present disclosure, a communication method is provided, the method being performed by a terminal, and the method comprising:
[0014] receiving fourth information sent by the second network device;
[0015] The fourth information contains first information, the first information is a key or a random number, an association relationship exists between the first information, the TLS connection and the terminal, and the association relationship is used for performing authentication on the terminal.
[0016] According to a fourth aspect of an embodiment of the present disclosure, a communication method is provided, the method comprising:
[0017] The first network device sends fourth information to the second network device;
[0018] The second network device sends the fourth information to the terminal;
[0019] The fourth information contains first information, the first information is a key or a random number, an association relationship exists between the first information, the TLS connection and the terminal, and the association relationship is used for performing authentication on the terminal.
[0020] According to a fifth aspect of an embodiment of the present disclosure, a first network device is provided, the first network device comprising:
[0021] The processing module is configured to:
[0022] establish an association relationship between first information, a TLS connection and a terminal;
[0023] The first information is a key or a random number; and the association relationship is used for performing authentication on the terminal.
[0024] According to a sixth aspect of an embodiment of the present disclosure, a second network device is provided, the second network device comprising:
[0025] The transceiver module is configured to:
[0026] receive fourth information sent by a first network device;
[0027] send the fourth information to a terminal;
[0028] The fourth information contains first information, the first information is a key or a random number, an association relationship exists between the first information, the TLS connection and the terminal, and the association relationship is used for performing authentication on the terminal.
[0029] According to a seventh aspect of an embodiment of the present disclosure, a terminal is provided, the terminal comprising:
[0030] The transceiver module is configured to:
[0031] receive fourth information sent by a second network device;
[0032] The fourth information includes first information, the first information is a key or a random number, the first information, the TLS connection and the terminal have an association relationship, and the association relationship is used for performing authentication on the terminal.
[0033] According to an eighth aspect of the embodiments of the present disclosure, a communication system is provided, the communication system includes a first network device, a second network device and a terminal, wherein the first network device is configured to perform the method of the first aspect, the second network device is configured to perform the method of the second aspect, and the terminal is configured to perform the method of the third aspect.
[0034] According to a ninth aspect of the embodiments of the present disclosure, a first network device is provided, the first network device includes:
[0035] one or more processors;
[0036] The first network device is configured to perform the communication method of the first aspect.
[0037] According to a tenth aspect of the embodiments of the present disclosure, a second network device is provided, the second network device includes:
[0038] one or more processors;
[0039] The first device is configured to perform the communication method of the second aspect.
[0040] According to an eleventh aspect of the embodiments of the present disclosure, a terminal is provided, the terminal includes:
[0041] one or more processors;
[0042] The terminal is configured to perform the communication method of the third aspect.
[0043] According to a twelfth aspect of the embodiments of the present disclosure, a storage medium is provided, wherein the storage medium stores instructions, when the instructions run on a communication device, the communication device performs the communication method provided by the first aspect, the second aspect and / or the third aspect.
[0044] The technical solution provided by the embodiments of the present disclosure can make the user plane-based communication more secure and reliable.
[0045] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0046] The accompanying drawings incorporated in and forming a part of the specification, illustrate the embodiments consistent with the present disclosure and serve to explain the principles of the embodiments of the present disclosure together with the specification.
[0047] FIG. 1a is a schematic diagram of an architecture of a communication system according to an example embodiment;
[0048] FIG. 1b is a schematic diagram of a flow of a communication method according to an example embodiment;
[0049] FIG. 2a is a schematic diagram of a flow of a communication method according to an example embodiment;
[0050] FIG. 3a is a schematic diagram of a flow of a communication method according to an example embodiment;
[0051] FIG. 3b is a schematic diagram of a flow of a communication method according to an example embodiment;
[0052] FIG. 4a is a schematic diagram of a flow of a communication method according to an example embodiment;
[0053] FIG. 4b is a schematic diagram of a flow of a communication method according to an example embodiment;
[0054] FIG. 5a is a schematic diagram of a flow of a communication method according to an example embodiment;
[0055] FIG. 5b is a schematic diagram of a flow of a communication method according to an example embodiment;
[0056] FIG. 6a is a schematic diagram of a flow of a communication method according to an example embodiment;
[0057] FIG. 7a is a schematic diagram of a flow of a communication method according to an example embodiment;
[0058] FIG. 7b is a schematic diagram of a flow of a communication method according to an example embodiment;
[0059] FIG. 8a is a schematic diagram of a structure of a first network device according to an example embodiment;
[0060] FIG. 8b is a schematic diagram of a structure of a second network device according to an example embodiment;
[0061] FIG. 8c is a schematic diagram of a structure of a terminal according to an example embodiment;
[0062] FIG. 9a is a schematic diagram of a structure of a UE according to an example embodiment;
[0063] FIG. 9b is a schematic diagram of a structure of a communication device according to an example embodiment. DETAILED DESCRIPTION
[0064] The embodiment of the present disclosure provides a communication method, a first network device, a second network device, a terminal, a communication system and a storage medium.
[0065] In a first aspect, the embodiment of the present disclosure provides a communication method, the method is executed by a first network device, and the method comprises the following steps.
[0066] establishing an association relationship among first information, a transmission layer security (TLS) connection and a terminal;
[0067] The first information is a key or a random number, and the association relationship is used for performing authentication on the terminal.
[0068] In the above embodiment, since the association relationship among the first information, the TLS connection and the terminal is established, authentication on the terminal can be performed based on the association relationship, so that the communication of the user plane is more secure and reliable.
[0069] In combination with the embodiment of the first aspect, in some embodiments, the establishing of the association relationship among the first information, the TLS connection and the terminal comprises the following steps.
[0070] establishing an association relationship among the first information, a first identifier of the TLS connection and a second identifier of the terminal.
[0071] In the above embodiment, the association relationship among the first information, the TLS connection and the terminal can be established based on the first identifier and the second identifier.
[0072] In combination with the embodiment of the first aspect, in some embodiments, the method further comprises the following steps.
[0073] performing authentication on the terminal based on second information;
[0074] The second information comprises information of the association relationship.
[0075] In the above embodiment, the authentication on the terminal can be performed based on the association relationship, so that the communication of the terminal based on the TLS connection is more secure.
[0076] In combination with the embodiment of the first aspect, in some embodiments, the method further comprises the following steps.
[0077] determining that the authentication on the terminal is passed, and binding the terminal and the TLS connection.
[0078] In the above embodiment, the terminal and the TLS connection can be bound after the authentication on the terminal is passed, so that the communication of the terminal based on the TLS connection is more secure.
[0079] In some embodiments of the first aspect, the method further comprises:
[0080] performing a first operation associated with the first information;
[0081] The first operation comprises one of the following:
[0082] allocating the first information;
[0083] determining that the first information used is preconfigured first information;
[0084] determining an encryption algorithm associated with the first information;
[0085] determining a lifetime of the first information;
[0086] storing the association relationship, the encryption algorithm, and / or the lifetime.
[0087] In the above embodiments, various operations associated with the first information can be performed.
[0088] In some embodiments of the first aspect, the performing a first operation associated with the first information comprises one of the following:
[0089] determining that the first network device determines to establish a TLS connection with the terminal, and performing the first operation associated with the first information;
[0090] determining that the third information sent by the terminal is received, and performing the first operation associated with the first information; wherein the third information is used to request to establish a TLS connection.
[0091] In the above embodiments, the first operation associated with the first information can be performed in different scenarios in a timely manner.
[0092] In some embodiments of the first aspect, the method further comprises:
[0093] sending fourth information to a second network device;
[0094] The fourth information contains the first information.
[0095] In the above embodiments, the fourth information can be sent to the second network device in real time.
[0096] In some embodiments of the first aspect, the fourth information is further used to indicate at least one of the following:
[0097] a TLS address of the first network device;
[0098] a first identity of the TLS connection;
[0099] an encryption algorithm associated with the first information;
[0100] a lifetime of the first information.
[0101] In some embodiments of the first aspect, the method further comprises:
[0102] receiving fifth information sent by the terminal;
[0103] The fifth information is used to indicate at least one of the following:
[0104] a first message authentication code (MAC);
[0105] the TLS connection identity;
[0106] a key;
[0107] a random number;
[0108] a timestamp.
[0109] In the above embodiments, the fifth information can be obtained from the terminal, so that the terminal can be authenticated based on the fifth information.
[0110] In some embodiments of the first aspect, the receiving the fifth information sent by the terminal comprises:
[0111] receiving a TLS connection binding request message sent by the terminal;
[0112] The TLS connection binding request message contains the fifth information.
[0113] In the above embodiments, the fifth information can be obtained through the TLS connection binding request information.
[0114] In some embodiments of the first aspect, the receiving the fifth information sent by the terminal comprises:
[0115] receiving the fifth information sent by the terminal through a TLS connection.
[0116] In the above embodiments, the fifth information can be obtained through the TLS connection.
[0117] In some embodiments of the first aspect, the performing authentication for the terminal based on the second information comprises:
[0118] performing authentication for the terminal based on the second information and the fifth information.
[0119] In the above embodiments, authentication for the terminal can be performed based on the second information and the fifth information, so that communication is more secure.
[0120] In combination with the embodiments of the first aspect, in some embodiments, the performing authentication for the terminal based on the second information and the fifth information comprises:
[0121] Determining that the received fifth information contains at least one of the first identifier of the TLS connection and the first MAC, the key, and the random number, and checking the at least one of the first MAC, the key, and the random number based on the second information.
[0122] In the above embodiments, the at least one of the first MAC, the key, and the random number can be checked based on information contained in the fifth information and the second information.
[0123] In combination with the embodiments of the first aspect, in some embodiments, the method further comprises:
[0124] Retrieving the association relationship based on the first identifier.
[0125] In the above embodiments, the association relationship can be retrieved based on the first identifier for subsequent authentication.
[0126] In combination with the embodiments of the first aspect, in some embodiments, the fifth information contains the key and / or the random number, and the performing authentication for the terminal based on the second information comprises:
[0127] Determining that the key corresponding in the association relationship is the same as the key contained in the fifth information and / or determining that the random number corresponding in the association relationship is the same as the random number contained in the fifth information, and determining that the terminal passes the authentication.
[0128] In the above embodiments, whether the terminal passes the authentication can be determined by comparing the key and / or the random number in the association relationship with the key and / or the random number contained in the fifth information.
[0129] In combination with the embodiments of the first aspect, in some embodiments, the fifth information contains the timestamp, and the method further comprises:
[0130] Determining whether the first MAC, the key, and / or the random number is within the validity period.
[0131] In the above embodiments, whether the first MAC, the key, and / or the random number is within the validity period can be accurately determined, so that the authentication can be reliably performed.
[0132] In combination with the embodiments of the first aspect, in some embodiments, the method further comprises:
[0133] determining that the authentication for the terminal is passed, and sending a TLS connection binding response message to the terminal;
[0134] The TLS connection binding response message is used to indicate that the binding request of the terminal is accepted.
[0135] In the above embodiment, in the case that the authentication for the terminal is passed, the terminal can be informed that the binding request of the terminal is accepted through the TLS connection binding response message.
[0136] With reference to the embodiments of the first aspect, in some embodiments, the method further includes:
[0137] receiving sixth information sent by the terminal in a TLS connection establishment process;
[0138] The sixth information contains a first identifier of the TLS connection and a first MAC, the first identifier is used as an identifier of pre-shared keys, and the first MAC is used as a PskBinderEntry of the shared key.
[0139] With reference to the embodiments of the first aspect, in some embodiments, the receiving the sixth information sent by the terminal includes:
[0140] receiving a ClientHello message sent by the terminal;
[0141] The ClientHello message contains the sixth information.
[0142] With reference to the embodiments of the first aspect, in some embodiments, the method further includes:
[0143] retrieving the association relationship based on the identifier of the pre-shared key.
[0144] In the above embodiment, the association relationship can be retrieved based on the identifier of the pre-shared key.
[0145] With reference to the embodiments of the first aspect, in some embodiments, the method further includes:
[0146] generating a second MAC based on the association relationship.
[0147] With reference to the embodiments of the first aspect, in some embodiments, the performing authentication for the terminal based on the second information includes:
[0148] determining that the first MAC is the same as the second MAC, and determining that the terminal is authenticated.
[0149] In the above embodiments, it can be determined that the terminal is authenticated based on a comparison result of the generated second MAC and the first MAC.
[0150] With reference to the embodiments of the first aspect, in some embodiments, the method further includes:
[0151] sending seventh information to the terminal;
[0152] The seventh information is used to indicate that the first identity of the TLS connection is selected as the pre-shared key.
[0153] In the above embodiments, the seventh information used to indicate that the first identity of the TLS connection is selected as the pre-shared key can be sent to the terminal.
[0154] In a second aspect, the embodiments of the present disclosure provide a communication method, the method is performed by a second network device, and the method includes:
[0155] receiving fourth information sent by a first network device;
[0156] sending the fourth information to a terminal;
[0157] The fourth information contains first information, the first information is a key or a random number, and an association relationship exists between the first information, a TLS connection, and a terminal. The association relationship is used to perform authentication for the terminal.
[0158] With reference to the embodiments of the second aspect, in some embodiments, an association relationship exists between the first information, a first identity of the TLS connection, and a second identity of the terminal.
[0159] With reference to the embodiments of the second aspect, in some embodiments, the fourth information is further used to indicate at least one of the following:
[0160] a TLS address of the first network device;
[0161] the first identity of the TLS connection;
[0162] an encryption algorithm associated with the first information;
[0163] a lifetime of the first information.
[0164] In a third aspect, the embodiments of the present disclosure provide a communication method, the method is performed by a terminal, and the method includes:
[0165] receiving fourth information sent by a second network device;
[0166] The fourth information includes the first information, which is a key or a random number. There is an association between the first information, the TLS connection, and the terminal. The association is used to perform authentication for the terminal.
[0167] In conjunction with embodiments of the third aspect, in some embodiments, there is an association between the first information, the first identifier of the TLS connection, and the second identifier of the terminal.
[0168] In conjunction with embodiments of the third aspect, in some embodiments, the fourth information is also used to indicate at least one of the following:
[0169] The TLS address of the first network device;
[0170] The first identifier of the TLS connection;
[0171] The encryption algorithm associated with the first information;
[0172] The lifecycle of the first piece of information.
[0173] In conjunction with the embodiments of the third aspect, in some embodiments, the method further includes:
[0174] A first message authentication code (MAC) is generated based at least on the first information and the first identifier of the TLS connection.
[0175] In conjunction with embodiments of the third aspect, in some embodiments, generating the first MAC based at least on the first information and the first identifier of the TLS connection includes at least one of the following:
[0176] The first MAC is generated based on the first information, the first identifier of the TLS connection, and the timestamp;
[0177] The first MAC is generated based on the first information, the first identifier of the TLS connection, and the second identifier of the terminal.
[0178] In conjunction with embodiments of the third aspect, in some embodiments, generating the MAC based at least on the first information and the first identifier of the TLS connection includes:
[0179] The MAC is generated based on the encryption algorithm, the first information, and the first identifier of the TLS connection.
[0180] In conjunction with the embodiments of the third aspect, in some embodiments, the encryption algorithm is an encryption algorithm obtained from the second network device; or, the encryption algorithm is a pre-configured encryption algorithm.
[0181] In conjunction with the embodiments of the third aspect, in some embodiments, the method further includes:
[0182] sending fifth information to the first network device;
[0183] The fifth information is used to indicate at least one of the following:
[0184] a first message authentication code (MAC);
[0185] the TLS connection identifier;
[0186] a key;
[0187] a random number;
[0188] a timestamp.
[0189] In some embodiments, the method further includes:
[0190] sending a TLS connection binding request message to the first network device;
[0191] The TLS connection binding request message contains the fifth information.
[0192] In some embodiments, the method further includes:
[0193] sending the fifth information to the first network device through the TLS connection.
[0194] In some embodiments, the method further includes:
[0195] receiving a TLS connection binding response message sent by the first network device;
[0196] The TLS connection binding response message is used to indicate acceptance of the binding request of the terminal.
[0197] In some embodiments, the method further includes:
[0198] sending sixth information to the first network device in a TLS connection establishment process;
[0199] The sixth information contains the first identifier of the TLS connection and the first MAC, the first identifier is used as an identifier of a pre-shared key, and the first MAC is used as a pre-shared key binding entry (PskBinderEntry) of the pre-shared key.
[0200] In some embodiments, the method further includes: sending a ClientHello message to the first network device.
[0201] The ClientHello message contains the sixth information.
[0202] With reference to the embodiments of the third aspect, in some embodiments, the method further includes:
[0203] receiving seventh information sent by the first network device;
[0204] The seventh information is used to indicate that the ID of the TLS connection is selected as the identification of the pre-shared key.
[0205] In a fourth aspect, the embodiments of the present disclosure provide a communication method, and the method includes:
[0206] The first network device sends fourth information to the second network device;
[0207] The second network device sends the fourth information to the terminal;
[0208] The fourth information contains first information, the first information is a key or a random number, and an association relationship exists between the first information, a TLS connection, and a terminal. The association relationship is used to perform authentication for the terminal.
[0209] In a fifth aspect, the embodiments of the present disclosure provide a first network device, and the first network device includes:
[0210] a processing module configured to:
[0211] establish an association relationship between first information, a TLS connection, and a terminal;
[0212] The first information is a key or a random number, and the association relationship is used to perform authentication for the terminal.
[0213] In a sixth aspect, the embodiments of the present disclosure provide a second network device, and the second network device includes:
[0214] a transceiver module configured to:
[0215] receive fourth information sent by the first network device;
[0216] send the fourth information to the terminal;
[0217] The fourth information contains first information, the first information is a key or a random number, and an association relationship exists between the first information, a TLS connection, and a terminal. The association relationship is used to perform authentication for the terminal.
[0218] In a seventh aspect, the embodiments of the present disclosure provide a terminal, and the terminal includes:
[0219] the transceiving module is configured to:
[0220] receive fourth information sent by the second network device;
[0221] The fourth information contains the first information, the first information is a key or a random number, and an association relationship exists between the first information, the TLS connection and the terminal, and the association relationship is used to perform authentication for the terminal.
[0222] In an eighth aspect, an embodiment of the present disclosure provides a communication system, the communication system comprising a first network device, a second network device and a terminal, the first network device being configured to implement the communication method provided in the first aspect, the second network device being configured to implement the communication method provided in the second aspect, and the terminal being configured to implement the communication method provided in the third aspect.
[0223] In a ninth aspect, an embodiment of the present disclosure provides a first network device, the first network device comprising:
[0224] one or more processors;
[0225] The first network device is configured to perform the communication method provided in the first aspect.
[0226] In a tenth aspect, an embodiment of the present disclosure provides a second network device, the second network device comprising:
[0227] one or more processors;
[0228] The second network device is configured to perform the communication method provided in the second aspect.
[0229] In an eleventh aspect, an embodiment of the present disclosure provides a terminal, the terminal comprising:
[0230] one or more processors;
[0231] The terminal is configured to perform the communication method provided in the third aspect.
[0232] In a twelfth aspect, an embodiment of the present disclosure provides a storage medium, wherein the storage medium stores instructions, and when the instructions are run on a communication device, the communication device performs the communication method described in the optional implementation manner of the first aspect, the second aspect and / or the third aspect.
[0233] In a thirteenth aspect, an embodiment of the present disclosure provides a program product, and when the program product is executed by a communication device, the communication device performs the method described in the first aspect, the second aspect and / or the third aspect.
[0234] In a fourteenth aspect, the embodiments of the present disclosure provide a computer program which, when running on a computer, causes the computer to perform the method described in the first aspect, the second aspect, and / or the optional implementation of the third aspect.
[0235] In a fifteenth aspect, the embodiments of the present disclosure provide a chip or chip system. The chip or chip system comprises processing circuitry configured to perform the method described in the first aspect, the second aspect, and / or the optional implementation of the third aspect.
[0236] It can be understood that the first network device, the second network device, the terminal, the communication system, the storage medium, the program product, the computer program, the chip or the chip system are used to perform the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects achieved thereby can refer to the beneficial effects in the corresponding method, which will not be described here again.
[0237] The embodiments of the present disclosure propose a communication method, a first network device, a second network device, a terminal, a communication system, and a storage medium. In some embodiments, the terms of the communication method, the information processing method, and the information transmission method can be replaced with each other, and the terms of the communication system and the information processing system can be replaced with each other.
[0238] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, some or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation of other embodiments.
[0239] In each embodiment of the present disclosure, the terms and / or descriptions of the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0240] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.
[0241] In the embodiments of the present disclosure, an element expressed in singular form, such as "a", "an", "the", "said", "the aforementioned", "the foregoing", "this", and the like, unless otherwise specified, can represent "one and only one", or can represent "one or more", "at least one", and the like. For example, in the case of using an article such as "a", "an", "the" in English, the noun after the article can be understood as a singular expression, or can be understood as a plural expression.
[0242] In the embodiments of the present disclosure, "plurality" refers to two or more.
[0243] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", and the like can be replaced with each other.
[0244] In some embodiments, the description modes such as "at least one of A, B", "A and / or B", "A in one case and B in another case", "in response to a case A, in response to a case B", and the like can include the following technical solutions according to the case: in some embodiments, A is executed regardless of B; in some embodiments, B is executed regardless of A; in some embodiments, A and B are selectively executed (A and B are selectively executed); in some embodiments, A and B are executed (A and B are both executed). When there are more branches such as A, B, C, and the like, it is similar to the above.
[0245] In some embodiments, the description modes such as "A or B" and the like can include the following technical solutions according to the case: in some embodiments, A is executed regardless of B; in some embodiments, B is executed regardless of A; in some embodiments, A and B are selectively executed (A and B are selectively executed). When there are more branches such as A, B, C, and the like, it is similar to the above.
[0246] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments, and should not be construed as redundant limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different. For another example, the description object is "information", and "first information" and "second information" can be the same information or different information, and the contents thereof can be the same or different.
[0247] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.
[0248] In some embodiments, the terms of "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.
[0249] In some embodiments, the terms of "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms of "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.
[0250] In some embodiments, the apparatuses and devices can be interpreted as entities, and can also be interpreted as virtual, whose names are not limited to the names described in the embodiments, and in some cases can also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject", etc.
[0251] In some embodiments, "network" can be interpreted as an apparatus contained in the network, for example, access network device, core network device, etc.
[0252] In some embodiments, "access network device (AN device)" can also be referred to as "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", and in some embodiments can also be understood as "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)", etc.
[0253] In some embodiments, a "terminal" or "terminal device" can be referred to as a "user equipment" (UE), a "user terminal," a "mobile station" (MS), a "mobile terminal" (MT), a subscriber station, a mobile unit, a subscriber unit, a wireless unit, a remote unit, a mobile device, a wireless device, a wireless communication device, a remote device, a mobile subscriber station, an access terminal, a mobile terminal, a wireless terminal, a remote terminal, a handset, a user agent, a mobile client, a client, and / or the like.
[0254] In some embodiments, data, information and / or the like can be obtained in compliance with laws and regulations of a country where the data, information and / or the like is obtained.
[0255] In some embodiments, data, information and / or the like can be obtained after consent of a user.
[0256] In addition, each element, each row, or each column in a table of embodiments of the present disclosure can be implemented as an independent embodiment, and a combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0257] FIG. 1a is a schematic diagram of an architecture of a communication system according to embodiments of the present disclosure.
[0258] As shown in FIG. 1a, a communication system 100 includes a terminal 101 and a network device 102.
[0259] In some embodiments, the network device 102 can be an access network device or a core network device. The network device can include a first network device and a second network device.
[0260] In some embodiments, the terminal includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a tablet (Pad), a wireless transceiver-equipped computer, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, a wireless terminal device in a smart home, and the like, but is not limited thereto.
[0261] In some embodiments, the access network device can be at least one of a node or a device that accesses a terminal to a wireless network, and can include an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a Wi-Fi system, and the like, but is not limited thereto.
[0262] In some embodiments, the technical solutions of the present disclosure can be applied to an Open RAN architecture, in which case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.
[0263] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, with some of the protocol layers being controlled by the CU and the rest of the protocol layers or all of the protocol layers being distributed in the DUs and controlled by the CU, but is not limited thereto.
[0264] In some embodiments, the core network device can be one device including one or more network elements, or can be multiple devices or device groups including all or part of the one or more network elements. The network element can be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next-generation core (NGC).
[0265] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art can know that, as the system architecture evolves and new business scenarios appear, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems.
[0266] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1a or part of the subject, but are not limited thereto. The subjects shown in FIG. 1a are exemplary, and the communication system can include all or part of the subjects in FIG. 1a, or can include other subjects other than those in FIG. 1a. The number and form of each subject is arbitrary, and the connection relationship between the subjects is exemplary. The subjects can be connected or not connected, and the connection can be in any manner, can be direct connection or indirect connection, and can be wired connection or wireless connection.
[0267] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based thereon, and the like. In addition, a plurality of systems can be combined (for example, combination of LTE or LTE-A and 5G, and the like).
[0268] In order to better understand the embodiments of the present disclosure, the technical solutions of the present disclosure are described below through some exemplary embodiments:
[0269] In some embodiments, for user plane positioning, a location management function (LMF, Location Services User Plane Protocol) or a UE can trigger establishment of a user plane connection. The UE and the LMF can maintain the established user plane connection. The LMF can modify or terminate the established user plane connection between the UE and the LMF.
[0270] In some embodiments, the LMF can send its user plane information (i.e., Internet Protocol (IP) address or Fully Qualified Domain Name (FQDN)) to the UE via a downlink (DL, Downlink) non access stratum (NAS, Non Access Stratum) transport message of the AMF.
[0271] In some embodiments, if the LMF sends its FQDN to the UE, a domain name system (DNS, Domain Name System) server or resolver is used to resolve the IP address of the LMF (e.g., edge application server discovery function (EASDF) for local LMF address resolution or local DNS).
[0272] In some embodiments, the UE uses a user route selection policy (URSP, UE Route Selection Policy) including protocol data unit (PDU, Protocol Data Unit) session parameters related to user plane positioning (e.g., dedicated data network name (DNN, Data Network Name) and network slice selection assistance information (S-NSSAI, Network Slice Selection Assistance Information)) to establish a PDU session for user plane positioning.
[0273] In some embodiments, a session management function (SMF, Session Management Function) should select a PDU session anchor (PSA, PDU session anchor) user plane function (UPF, User Plane Function) (located in a central site or a local site) connected to the LMF for this PDU session based on S-NSSAI, DNN, and UE location information, etc.
[0274] In some embodiments, referring to FIG. 1b, a communication method is shown, comprising:
[0275] Step S1101: If the UE requests to establish a Location Services (LCS, LoCation Services) secure user plane connection, a user plane connection establishment request message is sent to the LMF.
[0276] Comprises:
[0277] Step S1101a: The UE sends a UL NAS TRANSPORT message (user plane connection establishment request) to the Access and Mobility Management Function (AMF).
[0278] Step S1101b: The AMF sends a Nlmf_Location_UPConfig request (UE ID, user plane connection establishment request) or a Namf_Communication_N1MessageNotify (UE ID, user plane connection establishment request) to the LMF.
[0279] Step S1102: The LMF initiates the user plane connection establishment procedure by sending a user plane connection establishment command message to the UE or accepts the request from the UE. The LMF allocates a Location Services user plane LCS-UP connection ID for the UE and associates the LCS-UP connection ID with the UE. The user plane connection establishment command message includes the LMF LCS-UP address (i.e. IP address or FQDN of the LMF) and the LCS-UP connection ID (or LCS secure user plane connection ID, or connection ID).
[0280] Comprises:
[0281] Step S1102a: The LMF sends a Namf_Communication_N1N2MessageTransfer (user plane connection establishment command (LMF LCS-UP address, LCS-UP connection ID)) to the AMF.
[0282] Step S1102b: The AMF sends a DL NAS TRANSPORT message (user plane connection establishment command (LMF LCS-UP address, LCS-UP connection ID)) to the UE.
[0283] Step S1103: Upon receiving the user plane connection establishment command message, the UE will establish a TLS connection between the UE and the LMF.
[0284] Step S1104: After the secure user plane connection is successfully established, the UE sends, via the secure user plane connection, an LCS-UP connection binding request message including the LCS-UP connection ID received in step S1102 to the LMF to enable the LMF to perform the association of the UE with the secure user plane connection.
[0285] The LMF binds the UE with the secure user plane connection (i.e. the TLS connection) using the LCS-UP connection ID. In step S1102, the LMF associates the UE ID with the LCS-UP connection ID and receives the LCS-UP connection ID over the TLS connection, the LMF can further associate the LCS-UP connection ID with the UE IP address. Thus, the LMF can associate the UE ID with the TLS connection.
[0286] The terminal sends a UL LCS-UP TRANSPORT message (LCS-UP connection binding request (LCS-UP connection ID)) to the LMF.
[0287] Step S1105: Upon receiving the LCS-UP connection binding request message from the UE, the LMF sends an LCS-UP connection binding accept message to the UE over the LCS secure user plane connection.
[0288] The LMF sends a DL LCS-UP TRANSPORT message (accept LCS-UP connection binding) to the UE.
[0289] Step S1106: Upon receiving the LCS-UP connection binding accept message, the UE sends a user plane connection establishment complete message over the control plane in response to the user plane connection establishment command message.
[0290] Comprises:
[0291] Step S1106a: The UE sends a UL NAS TRANSPORT message (user plane connection establishment complete) to the AMF.
[0292] Step S1106b: The AMF sends a Namf_Communication_N1MessageNotify (UE ID, user plane connection establishment complete) to the LMF.
[0293] Step S1107: After the LMF receives the user plane connection establishment complete message, a UL, DL LCS-UP TRANSPORT message can be sent, e.g. a first DL LCS-UP TRANSPORT message.
[0294] In some embodiments, in the current user plane connection establishment process, the LMF binds the UE ID with the UE IP address by using the same LCS-UP connection ID in the control plane and user plane messages.
[0295] In some embodiments, if the malicious UE B uses the LCS-UP connection ID of UE A, the LMF will identify the malicious UE B as UE A using the LCS-UP connection ID, and the LMF will send the LCS-UP message related to UE A to the malicious UE B. UE A is at risk of data leakage.
[0296] FIG. 2a is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 2a, the embodiment of the present disclosure relates to a communication method for a communication system 100, and the method comprises:
[0297] Step S2101: The first network device establishes an association relationship.
[0298] In some embodiments, after the first network device determines to establish a TLS connection with the terminal, the first network device establishes the association relationship.
[0299] In some embodiments, the first network device establishes an association relationship between the first information, a transport layer security (TLS) connection, and the terminal.
[0300] It should be noted that the terminal indicated in the association relationship is a terminal that intends to establish a TLS connection and / or transmit data using the TLS connection, and the terminal is a legitimate terminal, not a false, illegal, or fake terminal.
[0301] In some embodiments, the association relationship can be a mapping relationship between the first information, the TLS connection, and the terminal.
[0302] Exemplarily, please refer to Table 1:
[0303] That is, after the terminal A establishes an association relationship with TLS1 and Key1, a binding relationship or a corresponding relationship exists between the three. After the association relationship is established, since the terminal A has the Key1 for communicating using the TLS1 connection, it can successfully pass the authentication based on the Key1 contained in the association relationship and perform normal communication. An illegal terminal (for example, terminal B) cannot pass the authentication based on the association relationship because it does not correspondingly establish the above association relationship, and thus will be prohibited from communicating using the TLS connection (for example, the TLS1 connection), thereby improving the security of performing communication based on the TLS connection.
[0304] In some embodiments, the TLS connection can be an LCS-UP connection or a UP connection, which can be replaced with each other, and the disclosure does not limit the same.
[0305] In some embodiments, the first information is a key or a random number.
[0306] In some embodiments, the association relationship is used to perform authentication for the terminal.
[0307] In some embodiments, the first network device establishes an association relationship between the first information, the first identifier of the TLS connection and the second identifier of the terminal.
[0308] Exemplarily, please refer to Table 2:
[0309] In some embodiments, the second identifier can be a subscriber permanent identifier (SUPI) and / or a generic public subscription identifier (GPSI).
[0310] Step S2102: The first network device performs a first operation.
[0311] In some embodiments, the first network device performs a first operation associated with the first information.
[0312] In some embodiments, the first operation includes one of the following:
[0313] allocating the first information;
[0314] determining that the used first information is a preconfigured first information;
[0315] determining an encryption algorithm associated with the first information;
[0316] determining a life cycle of the first information;
[0317] storing the association relationship, the encryption algorithm and / or the life cycle.
[0318] In some embodiments, it is determined that the first network device determines to establish a TLS connection with the terminal, and the first network device performs the first operation associated with the first information.
[0319] In some embodiments, it is determined that the third information sent by the terminal is received, and the first network device performs the first operation associated with the first information.
[0320] In some embodiments, the third information is used to request establishment of the TLS connection.
[0321] Step S2103: The first network device sends fourth information to the second network device.
[0322] In some embodiments, the second network device receives the fourth information sent by the first network device.
[0323] In some embodiments, the fourth information contains the first information.
[0324] In some embodiments, the fourth information is further used to indicate at least one of the following:
[0325] a TLS address of the first network device;
[0326] a first identifier of the TLS connection;
[0327] an encryption algorithm associated with the first information;
[0328] a lifetime of the first information.
[0329] In some embodiments, the first network device sends a user plane connection establishment command message to the second network device, wherein the user plane connection establishment command message contains the fourth information. It can also be understood that the fourth information is encapsulated in the user plane connection establishment command message.
[0330] In some embodiments, the first network device sends a Namf_Communication_N1N2MessageTransfer message to the second network device, wherein the Namf_Communication_N1N2MessageTransfer message contains the user plane connection establishment command message. It can also be understood that the user plane connection establishment command message is encapsulated in the Namf_Communication_N1N2MessageTransfer message.
[0331] Step S2104: The second network device sends the fourth information to the terminal.
[0332] In some embodiments, the terminal receives the fourth information sent by the second network device.
[0333] In some embodiments, the fourth information contains the first information, the first information is a key or a random number, and there is an association relationship between the first information, the TLS connection and the terminal, and the association relationship is used to perform authentication for the terminal.
[0334] In some embodiments, the first information, the first ID of the TLS connection and the second identification of the terminal have an association relationship.
[0335] In some embodiments, the second network device sends a user plane connection establishment command message to the terminal, wherein the user plane connection establishment command message contains the fourth information. It can also be understood that the fourth information is encapsulated in the user plane connection establishment command message.
[0336] In some embodiments, the second network device sends a DL NAS TRANSPORT message to the terminal, wherein the DL NAS TRANSPORT message contains the user plane connection establishment message. It can also be understood that the user plane connection establishment message is encapsulated in the DL NAS TRANSPORT message.
[0337] Step S2105: The terminal sends fifth information to the first network device.
[0338] In some embodiments, the first network device receives the fifth information sent by the terminal.
[0339] In some embodiments, the terminal sends a LCS-UP connection binding request message to the first network device, wherein the LCS-UP connection binding request message contains the fifth information. It can be understood that the fifth message is encapsulated in the LCS-UP connection binding request message.
[0340] In some embodiments, the terminal sends an UL LCS-UP transport message to the first network device, wherein the UL LCS-UP transport message contains the LCS-UP connection binding request message. It can also be understood that the LCS-UP connection binding request message is encapsulated in the UL LCS-UP transport message.
[0341] In some embodiments, the fifth information is used to indicate at least one of the following:
[0342] A first message authentication code MAC;
[0343] The TLS connection identification;
[0344] A key;
[0345] A random number;
[0346] A timestamp.
[0347] In some embodiments, the first network device determines whether the first MAC, the key and / or the random number is within a validity period.
[0348] In some embodiments, the first network device receives a TLS connection binding request message sent by the terminal.
[0349] In some embodiments, the TLS connection binding request message contains the fifth information.
[0350] In some embodiments, the first network device receives the fifth information sent by the terminal through the TLS connection.
[0351] In some embodiments, the first network device generates a first message authentication code (MAC) based on at least the first information and a first identifier of the TLS connection.
[0352] In some embodiments, the first network device generates the first MAC based on the first information, the first identifier of the TLS connection and a timestamp.
[0353] In some embodiments, the first network device generates the first MAC based on the first information, the first identifier of the TLS connection and a second identifier of the terminal.
[0354] In some embodiments, the first network device generates the first MAC based on an encryption algorithm, the first information and the first identifier of the TLS connection.
[0355] In some embodiments, the encryption algorithm is an encryption algorithm indicated by the second network device; or, the encryption algorithm is a preconfigured encryption algorithm.
[0356] It should be noted that step S2105 and step S2106 can be executed alternatively.
[0357] Step S2106: The terminal sends sixth information to the first network device.
[0358] In some embodiments, the first network device receives the sixth information sent by the terminal.
[0359] In some embodiments, the sixth information can include pre_shared_keys, and the terminal sends pre_shared_keys to the first network device, wherein the pre_shared_keys contains the sixth information. It can also be understood that the sixth information is encapsulated in the pre_shared_keys.
[0360] In some embodiments, the sixth information can include a ClientHello message, and the terminal sends the ClientHello message to the first network device, wherein the ClientHello message contains pre_shared_keys, which can also be understood as pre_shared_keys being encapsulated in the ClientHello message.
[0361] In some embodiments, during the TLS connection establishment process, the first network device receives the sixth information sent by the terminal.
[0362] In some embodiments, the sixth information contains a first identifier of the TLS connection and a first MAC, the first identifier is used as an identifier of pre-shared keys, and the first MAC is used as a pre-shared key binding entry PskBinderEntry of the shared key.
[0363] In some embodiments, the first network device receives a ClientHello message sent by the terminal; wherein the ClientHello message contains the sixth information.
[0364] In some embodiments, the first MAC can be generated based at least on the first information and the first identifier of the TLS connection.
[0365] In some embodiments, the first MAC can be generated based on the first information, the first identifier of the TLS connection, and a timestamp.
[0366] In some embodiments, the first MAC can be generated based on the first information, the first identifier of the TLS connection, and the second identifier of the terminal.
[0367] In some embodiments, the first MAC can be generated based on an encryption algorithm, the first information, and the first identifier of the TLS connection.
[0368] Step S2107: The first network device performs authentication for the terminal.
[0369] In some embodiments, the first network device performs authentication for the terminal based on the second information.
[0370] In some embodiments, the second information contains information of the association relationship.
[0371] In some embodiments, the first network device performs authentication for the terminal based on the second information and the fifth information (in the case of performing step S2105).
[0372] In some embodiments, the fifth information comprises the first identifier of the TLS connection and at least one of the first MAC, the key and the random number, and the first network device checks the at least one of the first MAC, the key and the random number based on the second information.
[0373] In some embodiments, the first network device retrieves the association relationship based on the first identifier.
[0374] In some embodiments, the fifth information comprises a key, and it is determined that the corresponding key in the association relationship is the same as the key comprised in the fifth information, and the first network device determines that the terminal passes the authentication.
[0375] In some embodiments, the fifth information comprises a random number, and it is determined that the corresponding random number in the association relationship is the same as the random number comprised in the fifth information, and the first network device determines that the terminal passes the authentication.
[0376] In some embodiments, the fifth information comprises a first MAC, and the first network device generates a second MAC based on the association relationship; it is determined that the first MAC is the same as the second MAC, and it is determined that the terminal passes the authentication.
[0377] In some embodiments, the first network device performs the authentication for the terminal based on the second information and sixth information (in the case of performing step S2106).
[0378] In some embodiments, the first network device retrieves the association relationship based on the identifier of the pre-shared key.
[0379] In some embodiments, the first network device generates a second MAC based on the association relationship; it is determined that the first MAC is the same as the second MAC, and it is determined that the terminal passes the authentication.
[0380] Step S2108: The first network device binds the terminal and the TLS connection.
[0381] In some embodiments, the first network device determines that the authentication for the terminal passes, and binds the terminal and the TLS connection.
[0382] Step S2109: The first network device sends seventh information to the terminal.
[0383] In some embodiments, the terminal receives the seventh information sent by the first network device.
[0384] In some embodiments, the seventh information is used to indicate that the first identifier of the TLS connection is taken as the selected identifier of the pre-shared key.
[0385] Step S2110: The first network device sends a TLS connection binding response message to the terminal.
[0386] In some embodiments, the terminal receives the TLS connection binding response message sent by the first network device.
[0387] In some embodiments, the first core network device determines that the authentication for the terminal is passed, and sends a TLS connection binding response message to the terminal.
[0388] In some embodiments, the TLS connection binding response message is used to indicate that the binding request of the terminal is accepted.
[0389] For step S2105:
[0390] In some embodiments, the first network device sends an LCS-UP connection binding accept message, i.e., a TLS connection binding response message, to the terminal.
[0391] In some embodiments, the first network device sends a DL LCS-UP transport to the terminal, wherein the DL LCS-UP transport contains the LCS-UP connection binding accept message. It can also be understood that the LCS-UP connection binding accept is encapsulated in the DL LCS-UP transport.
[0392] For step S2106: In some embodiments, the first network device sends a pre_shared_keys, i.e., a TLS connection binding response message, to the terminal.
[0393] In some embodiments, the first network device sends a server hello message, i.e., a ServerHello message, to the terminal, wherein the ServerHello message contains the pre_shared_keys. It can also be understood that the pre_shared_keys is encapsulated in the ServerHello message.
[0394] In some embodiments, the term "information" can be mutually interchangeable with the terms "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "field", "data", and the like.
[0395] In some embodiments, the term "send" can be mutually interchangeable with the terms "transmit", "report", and the like.
[0396] The communication method related to the embodiments of the present disclosure can include at least one of steps S2101 to S21010. For example, step S2101 can be implemented as an independent embodiment, step S2102 can be implemented as an independent embodiment, step S2103 can be implemented as an independent embodiment, step S2104 can be implemented as an independent embodiment, step S2105 can be implemented as an independent embodiment, step S2106 can be implemented as an independent embodiment, step S2107 can be implemented as an independent embodiment, step S2108 can be implemented as an independent embodiment, step S2109 can be implemented as an independent embodiment, and step S2110 can be implemented as an independent embodiment. For example, step S2101 can be implemented as an independent embodiment in combination with step S2103, step S2104, step S2105, step S2107, and step S2108, step S2101 can be implemented as an independent embodiment in combination with step S2102, step S2103, step S2104, step S2105, step S2107, and step S2108, step S2101 can be implemented as an independent embodiment in combination with step S2102, step S2103, step S2104, step S2105, step S2107, step S2108, and step S2109, step S2101 can be implemented as an independent embodiment in combination with step S2103, step S2104, step S2106, step S2107, and step S2108, step S2101 can be implemented as an independent embodiment in combination with step S2102, step S2103, step S2104, step S2106, step S2107, and step S2108, and step S2101 can be implemented as an independent embodiment in combination with step S2102, step S2103, step S2104, step S2106, step S2107, step S2108, step S2109, and step S2110, but the present disclosure is not limited thereto. It should be noted that each step can be implemented independently, or can be implemented in any order and freely combined without contradiction.
[0397] FIG. 3a is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3a, the embodiments of the present disclosure relate to a communication method, which is performed by a first network device, and the above method comprises the following steps.
[0398] Step S3101: establishing an association relationship.
[0399] In some embodiments, the optional implementation of step S3101 can refer to the optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be described here.
[0400] Step S3102: performing a first operation.
[0401] In some embodiments, the optional implementation of step S3102 can refer to the optional implementation of step S2102 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be repeated here.
[0402] Step S3103: sending fourth information to the second network device.
[0403] In some embodiments, the optional implementation of step S3103 can refer to the optional implementation of step S2103 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be repeated here.
[0404] Step S3104: receiving fifth information sent by the terminal.
[0405] The optional implementation of step S3104 can refer to the optional implementation of step S2105 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be repeated here.
[0406] Step S3105: receiving sixth information sent by the terminal.
[0407] In some embodiments, the optional implementation of step S3105 can refer to the optional implementation of step S2106 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be repeated here.
[0408] Step S3106: performing authentication for the terminal.
[0409] The optional implementation of step S3106 can refer to the optional implementation of step S2107 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be repeated here.
[0410] Step S3107: binding the terminal and the TLS connection.
[0411] The optional implementation of step S3107 can refer to the optional implementation of step S2108 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be repeated here.
[0412] Step S3108: sending seventh information to the terminal.
[0413] The optional implementation of step S3108 can refer to the optional implementation of step S2109 in FIG. 2a and other associated parts in the embodiments involved in FIG. 2a, which will not be repeated here.
[0414] Step S3109: sending a TLS connection binding response message to the terminal.
[0415] The optional implementation of step S3109 can refer to the optional implementation of step S2110 in FIG. 2a, and other associated parts in the embodiments related to FIG. 2a, which are not described herein again.
[0416] The communication method related to the embodiments of the present disclosure can include at least one of steps S3101 to S3109. For example, step S3101 can be implemented as an independent embodiment, step S3102 can be implemented as an independent embodiment, step S3103 can be implemented as an independent embodiment, step S3104 can be implemented as an independent embodiment, step S3105 can be implemented as an independent embodiment, step S3106 can be implemented as an independent embodiment, step S3107 can be implemented as an independent embodiment, step S3108 can be implemented as an independent embodiment, and step S3109 can be implemented as an independent embodiment. For example, step S3101 in combination with step S3103, step S3104, step S3106, and step S3107 can be implemented as an independent embodiment, step S3101 in combination with step S3102, step S3103, step S3104, step S3106, and step S3107 can be implemented as an independent embodiment, step S3101 in combination with step S3103, step S3104, step S3106, step S3107, and step S3108 can be implemented as an independent embodiment, step S3101 in combination with step S3103, step S3105, step S3106, and step S3107 can be implemented as an independent embodiment, step S3101 in combination with step S3102, step S3103, step S3105, step S3106, and step S3107 can be implemented as an independent embodiment, step S3101 in combination with step S3103, step S3105, step S3106, step S3107, step S3108, and step S3109 can be implemented as an independent embodiment, but the present disclosure is not limited thereto. It should be noted that each step can be implemented independently, or can be implemented by being arbitrarily exchanged in order and freely combined without contradiction.
[0417] FIG. 3b is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3b, the embodiments of the present disclosure relate to a communication method, which is performed by a first network device, and the above method comprises the following steps:
[0418] Step S3201: establishing an association relationship between first information, a transport layer security (TLS) connection, and a terminal.
[0419] In some embodiments, the first information is a key or a random number; and the association relationship is used to perform authentication for the terminal.
[0420] In some embodiments, the optional implementation of step S3201 can refer to the optional implementation of step S2101 in FIG. 2a and other associated parts in the embodiments involved by FIG. 2a, which are not described herein again.
[0421] In some embodiments, the establishing the association between the first information, the TLS connection and the terminal comprises:
[0422] establishing an association between the first information, a first identifier of the TLS connection and a second identifier of the terminal.
[0423] In some embodiments, the method further comprises:
[0424] performing authentication for the terminal based on second information;
[0425] wherein the second information contains information of the association.
[0426] In some embodiments, the method further comprises:
[0427] determining that the authentication for the terminal is passed, and binding the terminal and the TLS connection.
[0428] In some embodiments, the method further comprises:
[0429] performing a first operation associated with the first information;
[0430] wherein the first operation comprises one of:
[0431] allocating the first information;
[0432] determining that the first information used is preconfigured first information;
[0433] determining an encryption algorithm associated with the first information;
[0434] determining a lifetime of the first information;
[0435] storing the association, the encryption algorithm and / or the lifetime.
[0436] In some embodiments, the performing the first operation associated with the first information comprises one of:
[0437] determining that the first network device determines to establish a TLS connection with the terminal, and performing the first operation associated with the first information;
[0438] determining that third information sent by the terminal is received, and performing the first operation associated with the first information; wherein the third information is used to request to establish a TLS connection.
[0439] In some embodiments, the method further includes:
[0440] sending fourth information to the second network device;
[0441] wherein the fourth information comprises the first information.
[0442] In some embodiments, the fourth information is further used to indicate at least one of:
[0443] a TLS address of the first network device;
[0444] a first identity of the TLS connection;
[0445] an encryption algorithm associated with the first information;
[0446] a lifetime of the first information.
[0447] In some embodiments, the method further includes:
[0448] receiving fifth information sent by the terminal;
[0449] wherein the fifth information is used to indicate at least one of:
[0450] a first message authentication code (MAC);
[0451] the TLS connection identity;
[0452] a key;
[0453] a random number;
[0454] a timestamp.
[0455] In some embodiments, the receiving the fifth information sent by the terminal includes:
[0456] receiving a TLS connection binding request message sent by the terminal;
[0457] wherein the TLS connection binding request message comprises the fifth information.
[0458] In some embodiments, the receiving the fifth information sent by the terminal includes:
[0459] receiving the fifth information sent by the terminal through a TLS connection.
[0460] In some embodiments, the performing authentication for the terminal based on the second information includes:
[0461] performing authentication for the terminal based on the second information and the fifth information.
[0462] In some embodiments, the performing authentication for the terminal based on the second information and the fifth information comprises:
[0463] The received fifth information contains the first identifier of the TLS connection and at least one of the first MAC, the key and the random number, and the at least one of the first MAC, the key and the random number is checked based on the second information.
[0464] In some embodiments, the method further comprises:
[0465] The association relationship is retrieved based on the first identifier.
[0466] In some embodiments, the fifth information contains the key and / or the random number, and the performing authentication for the terminal based on the second information comprises:
[0467] The corresponding key in the association relationship is determined to be the same as the key contained in the fifth information, and / or the corresponding random number in the association relationship is determined to be the same as the random number contained in the fifth information, and the terminal is determined to pass the authentication.
[0468] In some embodiments, the fifth information contains the timestamp, and the method further comprises:
[0469] It is determined whether the first MAC, the key and / or the random number is within a validity period.
[0470] In some embodiments, the method further comprises:
[0471] It is determined that the authentication for the terminal passes, and a TLS connection binding response message is sent to the terminal;
[0472] The TLS connection binding response message is used to indicate that the binding request of the terminal is accepted.
[0473] In some embodiments, the method further comprises:
[0474] In the TLS connection establishment process, sixth information sent by the terminal is received;
[0475] The sixth information contains the first identifier of the TLS connection and a first MAC, the first identifier is used as an identifier of pre-shared keys, and the first MAC is used as a pre-shared key binding entry PskBinderEntry of the shared key.
[0476] In some embodiments, the receiving the sixth information sent by the terminal comprises:
[0477] receiving a ClientHello message sent by the terminal;
[0478] The ClientHello message comprises the sixth information.
[0479] In some embodiments, the method further comprises:
[0480] retrieving the association relationship based on the identification of the pre-shared key.
[0481] In some embodiments, the method further comprises:
[0482] generating a second MAC based on the association relationship.
[0483] In some embodiments, the performing authentication for the terminal based on the second information comprises:
[0484] determining that the first MAC is the same as the second MAC, and determining that the terminal passes the authentication.
[0485] In some embodiments, the method further comprises:
[0486] sending seventh information to the terminal;
[0487] The seventh information is used to indicate that the first identification of the TLS connection is selected as the identification of the pre-shared key.
[0488] FIG. 4a is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 4a, the embodiment of the present disclosure relates to a communication method, which is performed by a second network device, and the above method comprises:
[0489] Step S4101: receiving fourth information sent by a first network device.
[0490] In some embodiments, the optional implementation of step S4101 can refer to the optional implementation of step S2103 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be described here.
[0491] Step S4102: sending the fourth information to a terminal.
[0492] In some embodiments, the optional implementation of step S4102 can refer to the optional implementation of step S2104 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be described here.
[0493] The communication method related to the embodiments of the present disclosure can include at least one of steps S4101 to S4102. For example, step S4101 can be implemented as an independent embodiment, and step S4102 can be implemented as an independent embodiment. For example, step S4101 in combination with step S4102 can be implemented as an independent embodiment, but is not limited thereto. It should be noted that each step can be independently implemented, or can be implemented in any order or freely combined without contradiction.
[0494] FIG. 4b is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4b, the embodiments of the present disclosure relate to a communication method, which is performed by a second network device, and the above method comprises:
[0495] Step S4201: receiving fourth information sent by a first network device.
[0496] In some embodiments, the optional implementation of step S4201 can refer to the optional implementation of step S2103 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0497] Step S4202: sending the fourth information to a terminal;
[0498] In some embodiments, the fourth information includes first information, the first information is a key or a random number, and there is an association relationship between the first information, the TLS connection and the terminal, the association relationship being used to perform authentication for the terminal.
[0499] In some embodiments, the optional implementation of step S4202 can refer to the optional implementation of step S2104 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0500] In some embodiments, there is an association relationship between the first information, a first identifier of the TLS connection and a second identifier of the terminal.
[0501] In some embodiments, the fourth information is further used to indicate at least one of the following:
[0502] The TLS address of the first network device;
[0503] The first identifier of the TLS connection;
[0504] The encryption algorithm associated with the first information;
[0505] The life cycle of the first information.
[0506] FIG. 5a is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 5a, the embodiment of the present disclosure relates to a communication method, which is performed by a terminal, and the method comprises the following steps.
[0507] Step S5101: receiving fourth information sent by the second network device.
[0508] In some embodiments, the optional implementation of step S5101 can refer to the optional implementation of step S2104 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0509] Step S5102: sending fifth information to the first network device.
[0510] In some embodiments, the optional implementation of step S5102 can refer to the optional implementation of step S2105 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0511] Step S5103: sending sixth information to the first network device.
[0512] In some embodiments, the optional implementation of step S5103 can refer to the optional implementation of step S2106 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0513] Step S5104: receiving seventh information sent by the first network device.
[0514] In some embodiments, the optional implementation of step S5104 can refer to the optional implementation of step S2109 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0515] Step S5105: receiving a TLS connection binding response message sent by the first network device.
[0516] In some embodiments, the optional implementation of step S5105 can refer to the optional implementation of step S2110 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be repeated here.
[0517] The communication method related to the embodiments of the present disclosure can include at least one of steps S5101 to S5105. For example, step S5101 can be implemented as an independent embodiment, step S5102 can be implemented as an independent embodiment, step S5103 can be implemented as an independent embodiment, step S5104 can be implemented as an independent embodiment, and step S5105 can be implemented as an independent embodiment. For example, step S5101 in combination with step S5102, step S5104, and step S5105 can be implemented as an independent embodiment, step S5101 in combination with step S5103, step S5104, and step S5105 can be implemented as an independent embodiment, but the present disclosure is not limited thereto. It should be noted that each step can be implemented independently, or in the case of no contradiction, the order can be exchanged and combined freely.
[0518] FIG. 5b is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 5b, the embodiments of the present disclosure relate to a communication method performed by a terminal, and the above method includes:
[0519] Step S5201: receiving fourth information sent by a second network device.
[0520] In some embodiments, the optional implementation of step S5201 can refer to the optional implementation of step S2104 in FIG. 2a and other associated parts in the embodiments related to FIG. 2a, which will not be described here.
[0521] The first information, the first identifier of the TLS connection, and the second identifier of the terminal have an association relationship.
[0522] In some embodiments, the fourth information is further used to indicate at least one of:
[0523] The TLS address of the first network device;
[0524] The first identifier of the TLS connection;
[0525] The encryption algorithm associated with the first information;
[0526] The lifetime of the first information.
[0527] In some embodiments, the method further includes:
[0528] Generating a first message authentication code (MAC) based at least on the first information and the first identifier of the TLS connection.
[0529] In some embodiments, the generating of the first MAC based at least on the first information and the first identifier of the TLS connection includes at least one of:
[0530] generate the first MAC based on the first information, the first identification of the TLS connection, and a timestamp;
[0531] generate the first MAC based on the first information, the first identification of the TLS connection, and a second identification of the terminal.
[0532] In some embodiments, the generating the MAC based on at least the first information and the first identification of the TLS connection comprises:
[0533] generate the MAC based on an encryption algorithm, the first information, and the first identification of the TLS connection.
[0534] In some embodiments, the encryption algorithm is an encryption algorithm obtained from the second network device, or the encryption algorithm is a preconfigured encryption algorithm.
[0535] In some embodiments, the method further comprises:
[0536] sending fifth information to the first network device;
[0537] The fifth information is used to indicate at least one of:
[0538] a first message authentication code (MAC);
[0539] the identification of the TLS connection;
[0540] a key;
[0541] a random number;
[0542] a timestamp.
[0543] In some embodiments, the sending the fifth information to the first network device comprises:
[0544] sending a TLS connection binding request message to the first network device;
[0545] The TLS connection binding request message contains the fifth information.
[0546] In some embodiments, the sending the fifth information to the first network device comprises:
[0547] sending the fifth information to the first network device through the TLS connection.
[0548] In some embodiments, the method further comprises:
[0549] receiving a TLS connection binding response message sent by the first network device;
[0550] The TLS connection binding response message is used to indicate acceptance of the binding request of the terminal.
[0551] In some embodiments, the method further includes:
[0552] sending sixth information to the first network device in the TLS connection establishment process;
[0553] The sixth information includes the first identifier of the TLS connection and the first MAC, the first identifier is used as an identifier of the pre-shared key, and the first MAC is used as a pre-shared key binding entry PskBinderEntry of the pre-shared key.
[0554] In some embodiments, the sending of the sixth information to the first network device includes sending a ClientHello message to the first network device.
[0555] The ClientHello message includes the sixth information.
[0556] In some embodiments, the method further includes:
[0557] receiving seventh information sent by the first network device;
[0558] The seventh information is used to indicate that the ID of the TLS connection is selected as an identifier of the pre-shared key.
[0559] FIG. 6a is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 6a, the embodiment of the present disclosure relates to a communication method, which is used in the communication system 100, and the method includes one of the following steps:
[0560] Step S6101: The first network device sends fourth information to the second network device.
[0561] Step S6102: The second network device sends the fourth information to the terminal.
[0562] In some embodiments, the optional implementation of step S6101 and step S6102 can refer to the optional implementation of steps and other associated parts in the embodiments involved in FIG. 2a, which will not be described here.
[0563] In some embodiments, the above method can include the methods of the above communication system side, first network device side, second network device side, terminal side, and the like, which will not be described here.
[0564] In order to better understand the embodiments of the present disclosure, the present disclosure will be further described through some exemplary embodiments as follows:
[0565] Example 1
[0566] Referring to FIG. 7a, a communication method is provided, the method comprising:
[0567] Step S7101: If the UE requests to establish a LCS secure user plane connection, a user plane connection establishment request message is sent to the LMF.
[0568] comprising:
[0569] Step S7101a: The UE sends a UL NAS TRANSPORT message (user plane connection establishment request) to an Access and Mobility Management Function (AMF);
[0570] Step S7101b: The AMF sends a Nlmf_Location_UPConfig request (UE ID, user plane connection establishment request) or a Namf_Communication_N1MessageNotify (UE ID, user plane connection establishment request) to the LMF.
[0571] Step S7102: The LMF initiates a user plane connection establishment procedure or accepts the request from the UE by sending a user plane connection establishment command message to the UE. The LMF allocates a LCS-UP connection ID for the UE and associates the LCS-UP connection ID with the UE.
[0572] comprising:
[0573] Step S7102a: The LMF sends a Namf_Communication_N1N2MessageTransfer (user plane connection establishment command (LMF LCS-UP address, LCS-UP connection ID, key, encryption algorithm indication, key lifetime)) to the AMF.
[0574] Step S7102b: The AMF sends a DL NAS TRANSPORT message (user plane connection establishment command (LMF LCS-UP address, LCS-UP connection ID, key, encryption algorithm indication, key lifetime)) to the UE.
[0575] In some embodiments, the LMF also allocates / determines a key for the UE, or the LMF can allocate or determine a random number for the UE. If the UE and the LMF pre-configure a key or a random number, the LMF uses the pre-configured key or random number.
[0576] In some embodiments, the LMF can also determine an encryption algorithm and a lifetime of the key or the random number.
[0577] In some embodiments, the LMF associates the LCS-UP connection ID with the UE ID (i.e. SUPI and / or GPSI), the key (or nonce), and stores the association, the lifetime of the key, and the encryption algorithm.
[0578] In some embodiments, the user plane connection establishment command message includes the LMF LCS-UP address (i.e. IP address or FQDN of the LMF), the LCS-UP connection ID (or LCS secure user plane connection ID, or connection ID), the key (if assigned / determined) and the indication of the encryption algorithm, and the lifetime of the key or nonce.
[0579] Step S7103: Upon receiving the user plane connection establishment command message, the UE shall establish a TLS connection between the UE and the LMF.
[0580] Step S7104: After the secure user plane connection is successfully established, the UE sends a LCS-UP connection binding request message to the LMF including the LCS-UP connection ID and the MAC (or key or nonce). This enables the LMF to perform the association of the UE with the secure user plane connection.
[0581] In some embodiments, the UE can generate the MAC using the key / nonce (received or pre-configured), the LCS-UP connection ID, the timestamp.
[0582] In some embodiments, the UE can generate the MAC using the key / nonce (received or pre-configured), the LCS-UP connection ID, the UE ID.
[0583] In some embodiments, the UE can generate the MAC using the key / nonce (received or pre-configured), the LCS-UP connection ID.
[0584] In some embodiments, the UE can generate the MAC using the indicated algorithm.
[0585] In some embodiments, the UE can also include in the message only the received nonce or key.
[0586] In some embodiments, if the encryption algorithm is indicated, the UE can generate the MAC using the indicated algorithm. If no encryption algorithm indication is received, the UE can use a pre-configured or default algorithm.
[0587] In some embodiments, how to generate the MAC is known to the UE, and the LMF, UE and LMF can use one of the above cases.
[0588] In some embodiments, the timestamp can be included in the message.
[0589] In some embodiments, the terminal sends a UL LCS-UP TRANSPORT message (LCS-UP connection binding request (LCS-UP connection ID, timestamp, MAC / key / random number)) to the LMF.
[0590] Step S7105: Upon receiving the UL LCS-UP TRANSPORT message from the UE via the TLS connection, the LMF authenticates the UE using the LCS-UP connection ID and the MAC / key / random number.
[0591] In some embodiments, if the LMF receives the MAC, key, and / or random number and the LCS-UP connection ID, the LMF further obtains the stored association to check the MAC, key, and / or random number. For example, if the LMF receives a MAC generated by the LCS-UP connection ID, timestamp, and key, the LMF can use the LCS-UP connection ID, the timestamp in the message, and the stored key in the association to check the MAC in the message.
[0592] In some embodiments, if the timestamp is included in the message, the LMF can further check whether the MAC, key, and / or random number corresponds within the lifetime of the MAC, key, and / or random number.
[0593] In some embodiments, after the authentication, the LMF binds the stored UE ID with the secure user plane connection (i.e., the TLS connection).
[0594] Step S7106: Upon receiving the LCS-UP connection binding request message from the UE, the LMF sends a LCS-UP connection binding accept message to the UE over the LCS secure user plane connection.
[0595] In some embodiments, the LMF sends a DL LCS-UP TRANSPORT message (accept LCS-UP connection binding) to the terminal.
[0596] Step S7107: Upon receiving the LCS-UP connection binding accept message, the UE sends a user plane connection setup complete message over the control plane in response to the user plane connection setup command message.
[0597] Comprising:
[0598] Step S7107a: The terminal sends a UL NAS transport message (user plane connection setup complete) to the AMF.
[0599] Step S7107b: The AMF sends a Namf_Communication_N1MessageNotify (UE ID, user plane connection setup complete) to the LMF.
[0600] Step S7108: sending a first DL LCS-UP TRANSPORT message, wherein the first DL LCS-UP TRANSPORT message shall be sent after the LMF receives the user plane connection setup complete message.
[0601] Example 2
[0602] In some embodiments, during the TLS connection setup procedure, the UE can provide a pre_shared_key to the LMF to indicate which of the client (i.e. UE) provided pre-shared keys (PSKs) is selected.
[0603] In some embodiments, the “pre_shared_key” extension is used to negotiate the identity of the pre-shared key to use with a given handshake associated with PSK key establishment.
[0604] In some embodiments, the pre_shared_key includes an identity and an obfuscated_ticket_age. Another possible way to bind the TLS connection to the UE is to use the connection ID as the identity of the pre_shared_key.
[0605] Referring to FIG. 7b, a communication method is provided, the method comprising:
[0606] Step S7201: if the UE requests to establish a LCS secure user plane connection, sending a user plane connection setup request message to the LMF.
[0607] Comprising:
[0608] Step S7201a: the UE sends a UL NAS TRANSPORT message (user plane connection setup request) to an access and mobility management function (AMF).
[0609] Step S7201b: the AMF sends a Nlmf_Location_UPConfig request (UE ID, user plane connection setup request) or a Namf_Communication_N1MessageNotify (UE ID, user plane connection setup request) to the LMF.
[0610] Step S7202: the LMF initiates the user plane connection setup procedure or accepts the request from the UE by sending a user plane connection setup command message to the UE. The LMF allocates a LCS-UP connection ID for the UE and associates the LCS-UP connection ID with the UE.
[0611] comprises:
[0612] Step S7202a: The LMF sends Namf_Communication_N1N2MessageTransfer (User Plane Connection Setup Command (LMF LCS-UP Address, LCS-UP Connection ID, Key, Encryption Algorithm Indication, Key Lifetime)) to the AMF.
[0613] Step S7202b: The AMF sends DL NAS TRANSPORT message (User Plane Connection Setup Command (LMF LCS-UP Address, LCS-UP Connection ID, Key, Encryption Algorithm Indication, Key Lifetime)) to the UE.
[0614] In some embodiments, the LMF also allocates / determines the key for the UE, or the LMF can allocate or determine a random number for the UE. If the UE and the LMF are pre-configured with a key or a random number, the LMF uses the pre-configured key or random number.
[0615] In some embodiments, the LMF can also determine the encryption algorithm and the lifetime of the key or the random number.
[0616] In some embodiments, the LMF associates the LCS-UP Connection ID with the UE ID (i.e., SUPI and / or GPSI), the key (or random number), and stores the association, the lifetime of the key, and the encryption algorithm.
[0617] In some embodiments, the User Plane Connection Setup Command message includes the LMF LCS-UP Address (i.e., IP address or FQDN of the LMF), the LCS-UP Connection ID (or LCS Secure User Plane Connection ID, or Connection ID), the key (if allocated / determined), and the indication of the encryption algorithm, and the lifetime of the key or the random number.
[0618] Step S7203a: To establish the TLS connection between the UE and the LMF, the UE sends a ClientHello message including the pre-shared key to the LMF. The received LCS-UP Connection ID is used as the identity of the pre-shared key, and the MAC is used as the PskBinderEntry of the pre-shared key.
[0619] Step S7203b: Perform authentication. When the client Hello message is received from the client UE, the LMF uses the identity of the pre-shared key to retrieve the correlation (Connection ID, SUPI and / or GPSI) maintained in step 1b. The LMF further generates a MAC and uses the retrieved result. If the MAC generated by the LMF is similar to the MAC received from the UE, the UE is authenticated. The LMF can further bind the Connection ID with the TLS connection, further associating the TLS connection with the Connection ID and the UE ID.
[0620] Step S7203c: The LMF responds to the UE with a server hello message and includes the LCS-UP Connection ID as the selected identity of the pre-shared key.
[0621] Step S7207: After the UE receives the LCS-UP Connection Binding Accept message, the UE sends a user plane connection setup complete message over the control plane in response to the user plane connection setup command message.
[0622] Comprises:
[0623] Step S7207a: The terminal sends an UL NAS TRANSPORT message (user plane connection setup complete) to the AMF.
[0624] Step S7207b: The AMF sends a Namf_Communication_N1MessageNotify (UE ID, user plane connection setup complete) to the LMF.
[0625] Step S7208: Send the first DL LCS-UP TRANSPORT message, wherein the first DL LCS-UP TRANSPORT message should be sent after the LMF receives the user plane connection setup complete message.
[0626] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners of other embodiments.
[0627] The embodiments of the present disclosure also propose an apparatus for implementing any of the above methods, for example, an apparatus comprising units or modules for implementing the steps performed by the terminal in any of the above methods. For another example, another apparatus is proposed, comprising units or modules for implementing the steps performed by the network device (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.
[0628] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any of the above methods or realize the functions of the units or modules of the above apparatus, wherein the processor is, for example, a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship of elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the units or modules. All units or modules of the above apparatus can be implemented in the form of processor calling software, or all units or modules can be implemented in the form of hardware circuit, or part of the units or modules are implemented in the form of processor calling software, and the remaining part is implemented in the form of hardware circuit.
[0629] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), and the like. In another implementation, the processor can implement certain functions through a logical relationship of hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.
[0630] FIG. 8a is a structural schematic diagram of the first network device 8100 according to an embodiment of the present disclosure. As shown in FIG. 8a, the first network device 8100 can include at least one of a transceiver module 8101, a processing module 8102, and the like. Optionally, the transceiver module 8101 is configured to perform at least one of the communication steps, such as transmitting and / or receiving, performed by the first network device 8100 in any of the above methods, details of which are not described herein. Optionally, the processing module 8102 is configured to perform at least one of the other steps performed by the first network device 8100 in any of the above methods, details of which are not described herein.
[0631] FIG. 8b is a structural schematic diagram of the second network device 8200 according to an embodiment of the present disclosure. As shown in FIG. 8b, the second network device 8200 can include at least one of a transceiver module 8201, a processing module 8202, and the like. Optionally, the transceiver module 8201 is configured to perform at least one of the communication steps such as transmitting and / or receiving performed by the terminal 8200 in any of the above methods, details of which are not described herein. In some embodiments, the transceiver module 8201 can include a transmitting module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module 8201 can be mutually replaced with a transceiver. Optionally, the processing module 8202 is configured to perform at least one of the other steps performed by the second network device 8200 in any of the above methods, details of which are not described herein.
[0632] FIG. 8c is a structural schematic diagram of the terminal 8300 according to an embodiment of the present disclosure. As shown in FIG. 8c, the terminal 8300 can include at least one of a transceiver module 8301, a processing module 8302, and the like. Optionally, the transceiver module 8301 is configured to perform at least one of the communication steps such as transmitting and / or receiving performed by the terminal 8300 in any of the above methods, details of which are not described herein. In some embodiments, the transceiver module 8301 can include a transmitting module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module 8301 can be mutually replaced with a transceiver. Optionally, the processing module 8302 is configured to perform at least one of the other steps performed by the terminal 8300 in any of the above methods, details of which are not described herein.
[0633] In some embodiments, the processing module can be a module or can include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module, respectively. Optionally, the processing module can be mutually replaced with a processor.
[0634] FIG. 9a is a structural schematic diagram of the communication device 8100 according to an embodiment of the present disclosure. The communication device 8100 can be a network device (such as an access network device, a core network device, and the like), a terminal (such as a user equipment, and the like), a chip, a chip system, or a processor supporting the network device to implement any of the above methods, or a chip, a chip system, or a processor supporting the terminal to implement any of the above methods. The communication device 8100 can be used to implement the methods described in the above method embodiments, details of which can be referred to the descriptions in the above method embodiments.
[0635] As shown in FIG. 9a, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general processor or a special-purpose processor, etc., for example, a baseband processor or a central processor. The baseband processor can be used to process communication protocols and communication data, the central processor can be used to control a communication apparatus (e.g., a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. The communication device 8100 is configured to perform any of the above methods.
[0636] In some embodiments, the communication device 8100 further includes one or more memories 8102 configured to store instructions. Optionally, all or part of the memory 8102 can also be outside the communication device 8100.
[0637] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the transceiver 8103 performs at least one of the communication steps such as transmitting and / or receiving in the above methods, and the processor 8101 performs at least one of the other steps.
[0638] In some embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced with each other, the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced with each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced with each other.
[0639] In some embodiments, the communication device 8100 can include one or more interface circuits 8104. Optionally, the interface circuit 8104 is connected to the memory 8102, and the interface circuit 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0640] The communication device 8100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 can not be limited by FIG. 9a. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: 1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, and the like; (6) and the like.
[0641] FIG. 9b is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 is a chip or a chip system, the structural schematic diagram of the chip 8200 shown in FIG. 9b can be referred to, but is not limited thereto.
[0642] The chip 8200 includes one or more processors 8201, and the chip 8200 is configured to execute any of the above methods.
[0643] In some embodiments, the chip 8200 further includes one or more interface circuits 8202. Optionally, the interface circuit 8202 is connected to the memory 8203, and the interface circuit 8202 can be configured to receive signals from the memory 8203 or other devices, and the interface circuit 8202 can be configured to send signals to the memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201.
[0644] In some embodiments, the interface circuit 8202 performs at least one of the communication steps such as sending and / or receiving in the above methods, and the processor 8201 performs at least one of the other steps.
[0645] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, and the like can be replaced with each other.
[0646] In some embodiments, the chip 8200 further includes one or more memories 8203 for storing instructions. Optionally, all or part of the memory 8203 can be outside the chip 8200.
[0647] The disclosure further provides a storage medium having stored instructions which, when executed on the communication device 8100, cause the communication device 8100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited to this, and can also be a storage medium readable by other devices. Optionally, the storage medium can be a non-transitory storage medium, but is not limited to this, and can also be a transitory storage medium.
[0648] The disclosure further provides a program product which, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above methods. Optionally, the program product is a computer program product.
[0649] The disclosure further provides a computer program which, when executed on a computer, causes the computer to perform any of the above methods.
Claims
1. A communication method characterized by comprising: The method is performed by a first network device, and the method comprises: establishing an association relationship between first information, a transport layer security (TLS) connection and a terminal; wherein the first information is a key or a random number; and the association relationship is used for performing authentication for the terminal.
2. The method of claim 1, wherein, The establishing of the association relationship between the first information, the TLS connection and the terminal comprises: establishing an association relationship between the first information, a first identifier of the TLS connection and a second identifier of the terminal.
3. The method of claim 1, wherein, The method further comprises: performing authentication for the terminal based on second information; wherein the second information comprises information of the association relationship.
4. The method of claim 3, wherein, The method further comprises: determining that the authentication for the terminal is passed, and binding the terminal and the TLS connection.
5. The method of claim 1, wherein, The method further comprises: performing a first operation associated with the first information; wherein the first operation comprises one of the following: allocating the first information; determining that the used first information is preconfigured first information; determining an encryption algorithm associated with the first information; determining a lifetime of the first information; storing the association relationship, the encryption algorithm and / or the lifetime.
6. The method of claim 5, wherein, The performing of the first operation associated with the first information comprises one of the following: determining that the first network device determines to establish a TLS connection with the terminal, and performing the first operation associated with the first information; determining that third information sent by the terminal is received, and performing the first operation associated with the first information; wherein the third information is used for requesting establishment of a TLS connection.
7. The method of claim 1, wherein, The method further comprises: sending fourth information to a second network device; wherein the fourth information comprises the first information.
8. The method of claim 7, wherein, The fourth information is further used for indicating at least one of the following: a TLS address of the first network device; a first identifier of the TLS connection; an encryption algorithm associated with the first information; a lifetime of the first information.
9. The method of claim 3, wherein, The method further comprises: receiving fifth information sent by the terminal; wherein the fifth information is used for indicating at least one of the following: a first message authentication code (MAC); an identifier of the TLS connection; a key; a random number; a timestamp.
10. The method of claim 9, wherein, The receiving of the fifth information sent by the terminal comprises: receiving a TLS connection binding request message sent by the terminal; wherein the TLS connection binding request message comprises the fifth information.
11. The method of claim 9, wherein, The receiving of the fifth information sent by the terminal comprises: receiving the fifth information sent by the terminal through a TLS connection.
12. The method of claim 9, wherein, The performing of authentication for the terminal based on the second information comprises: performing authentication for the terminal based on the second information and the fifth information.
13. The method of claim 12, wherein, The performing of authentication for the terminal based on the second information and the fifth information comprises: determining that the received fifth information comprises a first identifier of the TLS connection and at least one of the first MAC, the key and the random number, and checking the at least one of the first MAC, the key and the random number based on the second information.
14. The method of claim 13, wherein, The method further comprises: retrieving the association relationship based on the first identifier.
15. The method of claim 14, wherein, The fifth information contains the key and / or random number, and the authentication for the terminal is performed based on the second information, including: determining that the key corresponding to the association relationship is the same as the key contained in the fifth information and / or determining that the random number corresponding to the association relationship is the same as the random number contained in the fifth information, and determining that the terminal passes the authentication.
16. The method of claim 13, wherein, The fifth information contains the timestamp, and the method further includes: determining whether the first MAC, the key and / or the random number are within the validity period.
17. The method of claim 12, wherein, The method further includes: determining that the authentication for the terminal passes, and sending a TLS connection binding response message to the terminal; wherein the TLS connection binding response message is used to indicate that the binding request of the terminal is accepted.
18. The method of claim 3, wherein, The method further includes: receiving sixth information sent by the terminal in a TLS connection establishment process; wherein the sixth information contains a first identifier of the TLS connection and a first MAC, the first identifier is used as an identifier of pre-shared keys, and the first MAC is used as a pre-shared key binding entry PskBinderEntry of the shared key.
19. The method of claim 18, wherein, The receiving of the sixth information sent by the terminal includes: receiving a ClientHello message sent by the terminal; wherein the ClientHello message contains the sixth information.
20. The method of claim 18, wherein, The method further includes: retrieving the association relationship based on the identifier of the pre-shared key.
21. The method of claim 14 or 20, wherein, The method further includes: generating a second MAC based on the association relationship.
22. The method of claim 21, wherein, The authentication for the terminal is performed based on the second information, including: determining that the first MAC is the same as the second MAC, and determining that the terminal passes the authentication.
23. The method of claim 22, wherein, The method further includes: sending seventh information to the terminal; wherein the seventh information is used to indicate that the first identifier of the TLS connection is selected as an identifier of pre-shared keys.
24. A method of communication, comprising: The method is performed by a second network device, and the method includes: receiving fourth information sent by a first network device; sending the fourth information to a terminal; wherein the fourth information contains first information, the first information is a key or a random number, and an association relationship exists between the first information, a TLS connection and the terminal, the association relationship is used to perform authentication for the terminal.
25. The method of claim 24, wherein, An association relationship exists between the first information, a first identifier of the TLS connection and a second identifier of the terminal.
26. The method of claim 24, wherein, The fourth information is further used to indicate at least one of the following: a TLS address of the first network device; the first identifier of the TLS connection; an encryption algorithm associated with the first information; a lifetime of the first information.
27. A method of communication, comprising: The method is performed by a terminal, and the method includes: receiving fourth information sent by a second network device; wherein the fourth information contains first information, the first information is a key or a random number, and an association relationship exists between the first information, a TLS connection and the terminal, the association relationship is used to perform authentication for the terminal.
28. The method of claim 27, wherein, The first information, the first identifier of the TLS connection, and the second identifier of the terminal have an association relationship.
29. The method of claim 27, wherein, The fourth information is further used to indicate at least one of the following: a TLS address of the first network device; a first identifier of the TLS connection; an encryption algorithm associated with the first information; a lifetime of the first information.
30. The method of claim 27, wherein, The method further includes: generating a first message authentication code (MAC) based at least on the first information and the first identifier of the TLS connection.
31. The method of claim 30, wherein, The generating of the first MAC based at least on the first information and the first identifier of the TLS connection includes at least one of the following: generating the first MAC based on the first information, the first identifier of the TLS connection, and a timestamp; generating the first MAC based on the first information, the first identifier of the TLS connection, and the second identifier of the terminal.
32. The method of claim 30, wherein, The generating of the first MAC based at least on the first information and the first identifier of the TLS connection includes: generating the first MAC based on an encryption algorithm, the first information, and the first identifier of the TLS connection.
33. The method of claim 32, wherein, The encryption algorithm is an encryption algorithm obtained from the second network device, or the encryption algorithm is a preconfigured encryption algorithm.
34. The method of claim 30, wherein, The method further includes: sending fifth information to the first network device; The fifth information is used to indicate at least one of the following: a first message authentication code (MAC); an identifier of the TLS connection; a key; a random number; a timestamp.
35. The method of claim 34, wherein, The sending of the fifth information to the first network device includes: sending a TLS connection binding request message to the first network device; The TLS connection binding request message contains the fifth information.
36. The method of claim 34, wherein, The sending of the fifth information to the first network device includes: sending the fifth information to the first network device through the TLS connection.
37. The method of claim 35, wherein, The method further includes: receiving a TLS connection binding response message sent by the first network device; The TLS connection binding response message is used to indicate acceptance of the binding request of the terminal.
38. The method of claim 30, wherein, The method further includes: sending sixth information to the first network device in a TLS connection establishment process; The sixth information contains the first identifier of the TLS connection and the first MAC, the first identifier is used as an identifier of a pre-shared key, and the first MAC is used as a pre-shared key binding entry (PskBinderEntry) of the pre-shared key.
39. The method of claim 38, wherein, The sending of the sixth information to the first network device includes sending a client hello (ClientHello) message to the first network device; The ClientHello message contains the sixth information.
40. The method of claim 38, wherein, The method further includes: receiving seventh information sent by the first network device; The seventh information is used to indicate that the ID of the TLS connection is used as a selected identifier of a pre-shared key.
41. A method of communication, comprising: The method includes: a first network device sends fourth information to a second network device; the second network device sends the fourth information to a terminal; The fourth information contains the first information, the first information is a key or a random number, and an association relationship exists between the first information, the TLS connection and the terminal, and the association relationship is used for performing authentication on the terminal.
42. A first network device, comprising: The first network device comprises: a processing module configured to: establish an association relationship between the first information, the TLS connection and the terminal; The first information is a key or a random number, and the association relationship is used for performing authentication on the terminal.
43. A second network device, comprising: The second network device comprises: a transceiver module configured to: receive fourth information sent by the first network device; send the fourth information to the terminal; The fourth information contains the first information, the first information is a key or a random number, and an association relationship exists between the first information, the TLS connection and the terminal, and the association relationship is used for performing authentication on the terminal.
44. A terminal, characterized by The terminal comprises: a transceiver module configured to: receive fourth information sent by the second network device; The fourth information contains the first information, the first information is a key or a random number, and an association relationship exists between the first information, the TLS connection and the terminal, and the association relationship is used for performing authentication on the terminal.
45. A communication system, characterized by The communication system comprises a first network device, a second network device and a terminal, wherein the first network device is configured to implement the method of any one of claims 1 to 23, the second network device is configured to implement the method of any one of claims 24 to 26, and the terminal is configured to implement the method of any one of claims 27 to 40.
46. A first network device, comprising: The first network device comprises: one or more processors; The first network device is configured to implement the communication method of any one of claims 1 to 23.
47. A second network device, comprising: The second network device comprises: one or more processors; The second network device is configured to implement the communication method of any one of claims 24 to 26.
48. A terminal, characterized by The terminal comprises: one or more processors; The terminal is configured to implement the communication method of any one of claims 27 to 40.
49. A storage medium, wherein, The storage medium stores instructions, when the instructions run on the communication device, cause the communication device to execute the communication method of any one of claims 1 to 23, 24 to 26 and / or 27 to 40.
Citation Information
Patent Citations
Communication method and communication device
CN114980094A
Message verification method and device
CN116472731A
Information processing method, terminal, first network element, communication system and storage medium
CN117941383A
Methods and apparatuses for enabling an establishment of a second secure session over a communication network
US20170134357A1
Methods and nodes for authentication of a TLS connection
US20210235268A1