Key processing method and device

By generating multiple NAS keys, the problem of secure connection between UE and different core network devices under the distributed NAS architecture is solved, realizing the diversity and security of secure connections under the distributed NAS architecture.

WO2025245752A1PCT designated stage Publication Date: 2025-12-04GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/096180
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-29
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

In a distributed NAS architecture, the NAS security solution under the 5G architecture cannot be applied to establish different secure connections between the UE and different NFs in the core network, resulting in security connection problems.

Method used

The terminal and core network equipment generate multiple NAS keys with multiple core network equipment. Different NAS keys are used to protect the transmission of NAS messages between the UE and different core network equipment, thereby achieving different secure connections.

Benefits of technology

In a distributed NAS architecture, different NAS keys are generated between the terminal and different core network devices, enabling the establishment of different secure connections with different core network devices, thus ensuring both security and connectivity diversity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024096180_04122025_PF_FP_ABST
    Figure CN2024096180_04122025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a key processing method and a device. The method comprises: generating a first NAS key between a terminal and a first core network device, wherein the first NAS key is one of multiple NAS keys that can be generated by the terminal and between the terminal and multiple core network devices, and different NAS keys among the multiple NAS keys are used for protecting NAS messages transmitted between the terminal and different core network devices.
Need to check novelty before this filing date? Find Prior Art

Description

Key processing methods and devices Technical Field

[0001] This application relates to the field of communications, and more specifically, to a key processing method and apparatus. Background Technology

[0002] In the 5G architecture, the User Equipment (UE) only needs to connect to the Access and Mobility Management Function (AMF) via the N1 interface. The AMF routes different signaling from the UE to other Network Functions (NFs) in the core network. In other words, the UE only establishes a NAS secure connection with the AMF in the core network. However, a distributed non-access stratum (NAS) architecture has been proposed for 6G systems. In this architecture, the UE can establish different connections with different NFs in the core network. Therefore, the NAS security scheme under the 5G architecture is not applicable to the distributed NAS architecture. Thus, ensuring that the UE can establish different secure connections with different NFs in the core network under the distributed NAS architecture becomes a problem that needs to be solved.

[0003] Summary of the Invention

[0004] This application provides a key processing method and device.

[0005] This application provides a key processing method executed by a terminal, including:

[0006] Generate a first NAS key between the terminal and a first core network device, wherein the first NAS key is one of a plurality of NAS keys that the terminal can generate between the terminal and multiple core network devices, and different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices.

[0007] This application provides a key processing method performed by a first core network device, including:

[0008] The terminal receives a first NAS key from the second core network device and the first core network device, wherein the first NAS key is used to protect NAS messages transmitted between the terminal and the first core network device.

[0009] This application provides a key processing method performed by a second core network device, including:

[0010] Generate a first NAS key between the terminal and the first core network device, wherein the first NAS key is one of a plurality of NAS keys between the terminal and multiple core network devices that can be generated by the second core network device, and different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices;

[0011] Send the first NAS key to the first core network device.

[0012] This application provides a terminal, including:

[0013] The first processing unit is configured to generate a first NAS key between the terminal and a first core network device. The first NAS key is one of a plurality of NAS keys that the terminal can generate between the terminal and multiple core network devices. Different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices.

[0014] This application provides a first core network device, including:

[0015] The second communication unit is used to receive a first NAS key between the terminal and the first core network device from the second core network device, wherein the first NAS key is used to protect the NAS messages transmitted between the terminal and the first core network device.

[0016] This application provides a second core network device, including:

[0017] The third processing unit is used to generate a first NAS key between the terminal and the first core network device. The first NAS key is one of a plurality of NAS keys between the terminal and multiple core network devices that can be generated by the second core network device. Different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices.

[0018] The third communication unit is used to send the first NAS key to the first core network device.

[0019] By adopting the above scheme, the terminal can generate multiple NAS keys with the core network equipment, and different NAS keys are used to protect NAS messages transmitted between different terminals and different core network equipment. In this way, it can be ensured that the terminal can generate different NAS keys with different core network equipment under the distributed NAS architecture, thereby ensuring that the terminal can establish different secure connections with different core network equipment. Attached Figure Description

[0020] Figure 1 is a schematic diagram of an application scenario according to an embodiment of this application.

[0021] Figure 2 is a schematic flowchart of a communication method according to an embodiment of this application.

[0022] Figure 3 is a schematic flowchart of a communication method according to another embodiment of this application.

[0023] Figure 4 is a schematic flowchart of a communication method according to another embodiment of this application.

[0024] Figures 5 to 7 are various example flowcharts of a communication method according to an embodiment of this application.

[0025] Figure 8 is a schematic flowchart of key derivation and security algorithm negotiation according to an embodiment of this application.

[0026] Figure 9 is a schematic diagram of a key derivation architecture according to an embodiment of this application.

[0027] Figure 10 is a schematic block diagram of a terminal according to an embodiment of this application.

[0028] Figure 11 is a schematic block diagram of a first core network device according to an embodiment of the present application.

[0029] Figure 12 is a schematic block diagram of a second core network device according to an embodiment of the present application. Detailed Implementation

[0030] The technical solutions of this application embodiment can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.

[0031] This application describes various embodiments in conjunction with network devices and terminals. The terminal can be mobile or fixed, and may also be referred to as a mobile station, user unit, etc. The terminal can be a station in a WLAN, or a smart terminal, wireless modem, laptop, tablet, etc. In this application's embodiments, the terminal can be a VR / AR terminal, industrial control terminal, autonomous driving terminal, telemedicine terminal, smart grid terminal, transportation safety terminal, smart city terminal, or smart home wireless terminal, etc. By way of example and not limitation, in this application's embodiments, the terminal can also be a wearable device.

[0032] In this embodiment, the network device can be a device for communicating with a terminal. The network device can be an access point in a WLAN, an evolved base station in LTE, a relay station, a network device (gNB) in a vehicle-mounted device, wearable device, or NR network, or a network device in a future PLMN network, or a network device in a non-terrestrial network, etc. As an example and not a limitation, in this embodiment, the network device can have mobility characteristics; for example, the network device can be a mobile device.

[0033] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.

[0034] Figure 1 exemplarily illustrates a communication system 100. This communication system includes a network device 110 and two terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and the coverage area of ​​each network device 110 may include other numbers of terminals 120; this embodiment does not limit this. In another possible implementation, the communication system 100 may also include mobility management entities, access and mobility management functions, and other network entities; this embodiment does not limit this. The network devices may further include access network devices and core network devices. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities; this embodiment does not limit this.

[0035] Figure 2 is a schematic flowchart of a key processing method executed by a terminal according to an embodiment of this application. The method includes at least some of the following:

[0036] S210. Generate a first NAS key between the terminal and the first core network device, wherein the first NAS key is one of a plurality of NAS keys that the terminal can generate between the terminal and multiple core network devices, and different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices.

[0037] Figure 3 is a schematic flowchart of a key processing method performed by a first core network device according to an embodiment of this application. The method includes at least some of the following.

[0038] S310. Receive a first NAS key between the terminal and the first core network device from the second core network device, wherein the first NAS key is used to protect NAS messages transmitted between the terminal and the first core network device.

[0039] Figure 4 is a schematic flowchart of a key processing method performed by a second core network device according to an embodiment of this application. The method includes at least some of the following.

[0040] S410. Generate a first NAS key between the terminal and the first core network device, wherein the first NAS key is one of a plurality of NAS keys between the terminal and multiple core network devices that can be generated by the second core network device, and different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices.

[0041] S420: Send the first key to the first core network device.

[0042] The terminal is capable of generating multiple NAS keys with multiple core network devices. Different NAS keys correspond to different core network devices with which the terminal can establish connections (or NAS connections, or NAS secure connections). These different NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices. The protection may include at least one of the following: integrity protection, confidentiality protection, or encryption protection; and authenticateable encryption.

[0043] On the terminal side, the first NAS key is the NAS key generated by the terminal for this interaction with the first core network device. For example, this first NAS key can be represented as K. NFx , where x is a positive integer, NFx is used to represent the first core network device, and the first core network device can be any one of the multiple core network devices that the terminal can establish a connection with. It should be understood that this is only an example for illustration, and there can be other ways to represent the first NAS key, which are not limited or exhaustively listed here.

[0044] Optionally, before generating the first NAS key, the terminal may have already generated one or more NAS keys with one or more other core network devices besides the first core network device. Furthermore, after generating the first NAS key, the terminal still has the capability, support, or ability to generate NAS keys with more other core network devices. For example, when generating the first NAS key K... NFx K has already been generated. NF1 ~K NFiThere are i NAS keys, where NF1 to NFi represent i core network devices other than the first core network device, and i is an integer greater than or equal to 2 and less than or equal to x.

[0045] Optionally, before the terminal generates the first NAS key, the terminal has not generated any NAS key. However, after the terminal generates the first NAS key, the terminal has the capability, support, or ability to generate one or more NAS keys with one or more other core network devices other than the first core network device.

[0046] The first core network device can be any one of a plurality of core network devices capable of transmitting NAS messages with the terminal and / or establishing a connection (or NAS connection, or NAS secure connection) with the terminal. In some possible examples of this application, any core network device capable of transmitting NAS messages with the terminal and / or establishing a connection (or NAS connection, or NAS secure connection) with the terminal is referred to as NFx.

[0047] The multiple core network devices may include: the core network device (or network element) of the service domain where the terminal first establishes a connection, and one or more core network devices other than the core network device (or network element) of the service domain where the terminal first establishes a connection, which the terminal is capable of establishing a connection (or NAS connection, or NAS secure connection).

[0048] The core network device (or network element) of the first service domain to which the terminal establishes a connection can refer to the network element or function to which the terminal connects during the registration or authentication process. The core network device (or network element) of the first service domain to which the terminal establishes a connection can be an MM NF (Mobility Management Network Function) or an MMF (Mobility Management Function).

[0049] In addition to the core network device (or network element) of the service domain where the terminal first establishes a connection, any one of the one or more core network devices that the terminal can establish a connection (or NAS connection, or NAS secure connection) can be an SM NF (Session Management Network Function). It should be understood that this is merely an exemplary description of one or more core network devices that the terminal can establish a connection (or NAS connection, or NAS secure connection) with, other than the core network device (or network element) of the service domain where the terminal first establishes a connection. In actual processing, the one or more core network devices that the terminal can establish a connection (or NAS connection, or NAS secure connection) with, other than the core network device (or network element) of the service domain where the terminal first establishes a connection, may include many more possible functions or types. This embodiment does not limit or exhaustively list them.

[0050] The second core network device can be a network element with the function or capability to manage or generate NAS keys. Specifically, the second core network device can, supports, or is capable of generating multiple NAS keys between the terminal and multiple core network devices; wherein, different NAS keys among the multiple NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices. It should be noted that the second core network device may also have more functions, but this embodiment does not exhaustively list or limit them.

[0051] For example, the second core network device may include one of the following: Authentication Server Function (AUSF), Security Anchor Function (SEAF), or Key Management Function.

[0052] The key management function can be a newly added function dedicated to managing and / or generating keys under the distributed NAS architecture. It should be understood that this key management function may also have other functions, which is not limited in this embodiment. This key management function may be co-located with existing core network functions in the same device, or it may be set in a newly added core network device; this is also not limited in this embodiment. This key management function can be called the Distributed NAS Key Generation Function (DNKGF) or the Distributed NAS Key Management Function (DNKMF).

[0053] On the second core network device side, the first NAS key is the NAS key generated by the second core network device for this terminal and the first core network device.

[0054] Optionally, before the second core network device generates the first NAS key, the second core network device may have already generated one or more NAS keys between the terminal and one or more other core network devices other than the first core network device. After the second core network device generates the first NAS key, the second core network device still has the ability or supports or can generate NAS keys between the terminal and more other core network devices.

[0055] Optionally, before the second core network device generates the first NAS key, the second core network device has not yet generated NAS keys between the terminal and other core network devices besides the first core network device. However, after the second core network device generates the first NAS key, the second core network device has the capability, support, or ability to generate one or more NAS keys between the terminal and one or more other core network devices besides the first core network device.

[0056] In some possible implementations, on the terminal side, generating a first NAS key with the first core network device includes: generating the first NAS key with the first core network device based on an intermediate key, wherein the intermediate key is an intermediate key between the second core network device and the terminal. On the second core network device side, generating a first NAS key between the terminal and the first core network device includes: generating the first NAS key between the terminal and the first core network device based on an intermediate key, wherein the intermediate key is an intermediate key between the second core network device and the terminal.

[0057] The intermediate key is the key between the second core network device and the terminal. This intermediate key is different from any NAS key. The intermediate key can be used to generate or derive the NAS key between the terminal and any core network device. The intermediate key between the second core network device and the terminal can also be referred to as a shared key between the terminal and the second core network device, etc. This document does not limit or exhaustively list all possible ways to describe the intermediate key.

[0058] On the second core network device side, the intermediate key can be obtained from the third core network device side and stored locally. The timing of the second core network device receiving and storing the intermediate key before the generation of the first NAS key is within the protection scope of this embodiment; therefore, the timing of the second core network device receiving and storing the intermediate key is not limited here. On the terminal side, the intermediate key can be generated during or after the terminal performs authentication. The timing of the terminal generating the intermediate key before the generation of the first NAS key is within the protection scope of this embodiment; therefore, the timing of the intermediate key generation is not limited here.

[0059] When the second core network device is AUSF, the intermediate key can be K. AUSF When the second core network device is SEAF, the intermediate key can be K. SEAF When the second core network device has a key management function, the intermediate key can be an intermediate key between the terminal and the key management function, for example, it can be represented as K. DNKGF or K DNKMF .

[0060] On the terminal side, generating the first NAS key between the terminal and the first core network device based on the intermediate key includes: generating the first NAS key between the terminal and the first core network device based on the intermediate key and first key generation parameters, wherein the first key generation parameters include at least one of the following: a permanent identifier of the terminal, a temporary identifier of the terminal, a temporary identifier of the first core network device, and type information corresponding to the first NAS key. On the second core network device side, generating the first NAS key between the terminal and the first core network device based on the intermediate key may include: generating the first NAS key between the terminal and the first core network device based on the intermediate key and the first key generation parameters.

[0061] A terminal's permanent identifier can refer to either the terminal's physical identifier or its long-term identifier. For example, the terminal's permanent identifier could be a SUPI (Subscription Permanent Identifier), or a permanent identifier defined in a 6G system, etc. We will not limit or exhaustively list all possible permanent identifiers for terminals here.

[0062] The temporary identifier of the terminal can be generated or assigned by the first core network device. The first core network device can send the terminal's temporary identifier to the terminal and the second core network device respectively; the terminal can receive the terminal's temporary identifier from the first core network device; and the second core network device can receive the terminal's temporary identifier from the first core network device. The composition and specific generation method of the terminal's temporary identifier are not limited in this embodiment.

[0063] The first key generation parameters may not simultaneously include a permanent identifier and a temporary identifier for the terminal.

[0064] The temporary identifier of the first core network device may be pre-configured or pre-stored on the first core network device side. The temporary identifier of the first core network device may be configured by the operator or may be configured in other ways. This embodiment does not limit it.

[0065] The terminal can also pre-store or pre-configure the temporary identifier of the first core network device. Alternatively, the terminal can receive the temporary identifier of the first core network device from the first core network device, meaning the first core network device can send its own temporary identifier to the terminal.

[0066] The temporary identifier of the first core network device can also be pre-stored or pre-configured on the second core network device side. Alternatively, the second core network device can receive the temporary identifier of the first core network device from the first core network device, that is, the first core network device can send its own temporary identifier to the second core network device.

[0067] The first core network device also has a corresponding instance ID. This embodiment does not limit the configuration method of the instance ID. The instance ID of the first core network device can be obtained or configured in advance on both the terminal and the second core network device.

[0068] The type information (which can be represented as NAS type) corresponding to the first NAS key can be the default of the terminal and the second core network device, or generated or represented based on the same preset rules. The preset rules can be configured according to actual conditions, and this embodiment does not limit them. As long as the terminal and the second core network device can obtain the same type information corresponding to the first NAS key, it is within the protection scope of this embodiment. For example, the preset rule is that the type information corresponding to the first NAS key is represented by the name or description information of the first core network device. Assuming the name or description information of the first core network device is MM NF, then the terminal and the second core network device can determine that the type information corresponding to the first NAS key can be MM NF based on the same preset rule; assuming the name or description information of the first core network device is NFx, then the terminal and the second core network device can determine that the type information corresponding to the first NAS key can be NFx based on the same preset rule. It should be understood that this is only an exemplary description of the type information corresponding to the first NAS key. In actual processing, the type information corresponding to the first NAS key can also have other representations, which are not exhaustively listed or limited here.

[0069] In a preferred example, the first key generation parameters may include: a temporary identifier for the terminal, a temporary identifier for the first core network device, and type information (such as NFx) corresponding to the first NAS key. This avoids using the instance identifier of the first core network device when establishing a security context between the terminal and the first core network device, thus preventing the exposure of information within the network.

[0070] In some possible examples, the first key generation parameters may include: a permanent identifier for the terminal, a temporary identifier for the first core network device, and type information corresponding to the first NAS key. This example is particularly applicable to scenarios where the second core network device is an AUSF or SEAF.

[0071] In some possible examples, the first key generation parameters may include: the temporary identifier of the terminal, the temporary identifier of the first core network device, the instance identifier of the first core network device, and the type information corresponding to the first NAS key.

[0072] It should be noted that the same first key generation parameters, the same intermediate key, and the same calculation method should be used to generate the first NAS key on the second core network equipment and terminal side. The calculation method for the first NAS key can be configured according to the actual situation, such as a key derivation function (KDF), etc., which is not limited or exhaustive here.

[0073] After the first NAS key is generated on the second core network device side, it is sent to the first core network device. The first core network device can receive and store the first NAS key, thereby protecting (ensuring full security and / or encryption and / or authenticated encryption) the NAS messages or NAS signaling transmitted between the first core network device and the terminal. Similarly, after the first NAS key is generated on the terminal side, it can protect (ensuring full security and / or encryption and / or authenticated encryption) the NAS messages or NAS signaling transmitted between the terminal and the first core network device.

[0074] In some possible implementations, the terminal establishes a connection with the first core network device on the core network side during the registration process (initial registration process).

[0075] In this embodiment, the first core network device can be the core network device (or network element) of the service domain to which the terminal first establishes a connection. Before generating the first NAS key, the terminal has not generated any other NAS keys; in other words, the first NAS key is the first NAS key generated by the terminal. For simplicity, the core network device (or network element) of the service domain to which the terminal first establishes a connection can be simply referred to as MM NF, and will not be explained again below.

[0076] The terminal's processing may include: sending a registration request, wherein the registration request is used to trigger authentication between the first core network device and the terminal. The first core network device's processing may include: receiving a registration request, wherein the registration request is used to trigger authentication between the first core network device and the terminal. Specifically, the timing of the terminal sending the registration request is before the terminal generates the first NAS key, and the timing of the first core network device receiving the registration request is before the first core network device receives the first NAS key.

[0077] The registration request can be the initial registration request of the terminal, that is, the registration request can be the registration request issued during the initial registration process of the terminal.

[0078] Specifically, the terminal sending the registration request can be done by sending a registration request to the access network device. Here, the registration request sent by the terminal can be carried by a first AS (Access Layer) message. The specific message type of this first AS message is not limited; for example, it can be an RRC message, meaning the registration request can be carried by an RRC message. More specifically, the registration request can be carried by the NAS MM container (NAS mobility management container) within the RRC message.

[0079] The processing by the access network device may include: receiving a registration request from the terminal and sending the registration request to the first core network device. Here, the registration request sent by the access network device to the first core network device may be carried by Nmm_InitialUE (Mobility Management Initialization Terminal).

[0080] Accordingly, the first core network device receiving registration requests may include: receiving registration requests from terminals of access network devices.

[0081] Optionally, the registration request may carry a permanent identifier for the terminal.

[0082] After receiving a registration request, the first core network device can trigger authentication between the terminal and the network (specifically, between the terminal and the core network). This embodiment does not limit the authentication mechanism or process used by the first core network device to trigger authentication between the terminal and the core network. For example, the authentication mechanism can reuse the AKA (Authentication and Key Agreement) mechanism or other authentication mechanisms in related technologies. This embodiment does not exhaustively list or limit the specific authentication mechanisms and processes used.

[0083] In some embodiments, the processing of the terminal after sending the registration request may further include: generating an intermediate key. The processing of the second core network device may include: receiving the intermediate key.

[0084] The second core network device receiving the intermediate key can be achieved by receiving an intermediate key from a third core network device. Correspondingly, the processing by the third core network device can include generating an intermediate key between the terminal and the second core network device, and sending this intermediate key to the second core network device.

[0085] The third core network device is a core network device that stores the upper-level key of the intermediate key on the core network side. The function of this upper-level key is to derive the intermediate key. For example, this third core network device can be a network element with authentication and authorization functions.

[0086] The third core network device can generate and send the intermediate key during the authentication process or after the terminal completes authentication. The terminal can generate the intermediate key during the authentication process between the core network and the terminal, or after the authentication process between the core network and the terminal completes authentication.

[0087] In one embodiment, the second core network device includes one of the following: Authentication Server Function (AUSF) and Security Anchor Function (SEAF).

[0088] In one example, the second core network device can be AUSF, and the third core network device can be UDM (Unified Data Management).

[0089] The UDM can derive or generate an intermediate key between the terminal and the AUSF, and the UDM can send this intermediate key to the AUSF. After receiving the intermediate key, the AUSF can store it locally. Correspondingly, the terminal's processing can include generating an intermediate key with the AUSF. This intermediate key between the terminal and the AUSF can be represented as K. AUSF .

[0090] The timing of UDM generating the intermediate key between the terminal and the AUSF can be during the authentication process between the core network and the terminal. For example, the UDM can generate the intermediate key after receiving the connection management registration message (e.g., Nudm_UE CM_Reg) corresponding to the terminal from the MM NF. The UDM can send the intermediate key between the terminal and the AUSF to the AUSF by carrying the intermediate key in a message transmitted between the UDM and the AUSF.

[0091] The timing for the terminal to generate the intermediate key between itself and AUSF can be during the authentication process between the core network and the terminal or after the authentication process between the core network and the terminal is completed; this example does not specify the timing.

[0092] The generation or derivation method of the intermediate key between the terminal and AUSF, and the generation parameters used, can adopt the K-type parameters in related technologies. AUSF The same generation method and generation parameters can be used, for example, to further derive the K between the terminal and AUSF using CK (Ciphering Key) and / or IK (Integrity Key) derived from the root key K corresponding to the terminal. AUSF Calculate K AUSF The method can be achieved using a Key Derivation Function (KDF). This document does not limit or exhaustively list the processing and parameters related to generating the intermediate key between the terminal and the AUSF. As long as the terminal and the UDM use the same method and parameters to calculate the same intermediate key between the terminal and the AUSF, it falls within the protection scope of this embodiment.

[0093] In another example, the second core network device can be SEAF, and the third core network device can be AUSF.

[0094] The AUSF can derive or generate an intermediate key between the terminal and the SEAF, and can send this intermediate key to the SEAF. After receiving the intermediate key, the SEAF can store it locally. Correspondingly, the terminal's processing can include generating an intermediate key with the SEAF. This intermediate key between the terminal and the SEAF can be represented as K. SEAF .

[0095] The timing for AUSF to derive or generate the intermediate key between the terminal and SEAF can be during the authentication process between the core network and the terminal, when the intermediate key (i.e., K) between the terminal and the upstream terminal of UDM is received. AUSF After that, the timing for the terminal to generate the intermediate key between the terminal and SEAF can be during the authentication process between the core network and the terminal or after the authentication process between the core network and the terminal is completed; this example does not specify a time limit.

[0096] The generation or derivation method of the intermediate key between the terminal and SEAF, and the generation parameters used, can adopt the K-type parameters in related technologies. SEAF The same generation method and generation parameters can be used, for example, KDF and K... AUSF Generate K SEAFThis document does not limit or exhaustively list the processing and parameters related to the intermediate key between the terminal and SEAF. As long as the terminal and AUSF use the same method and the same parameters to calculate the same intermediate key between the terminal and SEAF, it is within the protection scope of this embodiment.

[0097] In one embodiment, the second core network device includes a key management function. On the terminal side, generating an intermediate key includes: generating an intermediate key between the terminal and the key management function based on a previous-level key and a second key generation parameter. The previous-level key includes one of the following: a key between the terminal and the AUSF, a key between the terminal and the SEAF. The second key generation parameter includes at least one of the following: a permanent identifier of the terminal, a string representing the intermediate key between the terminal and the key management function.

[0098] The foregoing embodiments have shown that this key management function can be called DNKGF or DNKMF; correspondingly, the intermediate key between the terminal and the key management function can be represented as K. DNKGF or K DNKMF .

[0099] This embodiment does not limit the configuration or pre-configuration method of the permanent identifier of the terminal on the terminal and the network side (such as the core network). As long as the terminal and the network side have obtained the same permanent identifier of the terminal before the intermediate key between the derived terminal and the key management function, it is within the protection scope of this embodiment.

[0100] The string used to represent the intermediate key between the terminal and the key management function can be descriptive information of the intermediate key between the terminal and the key management function, such as "DNKGF" or "DNKMF", etc.

[0101] Regarding the string representing the intermediate key between the terminal and the key management function, this embodiment does not limit the generation method or generation rule of the terminal and the third core network device. As long as the terminal and the third core network device can obtain the same string representing the intermediate key between the terminal and the key management function when or before deriving the intermediate key between the terminal and the key management function, it is within the protection scope of this embodiment.

[0102] The aforementioned second key generation parameters may include only the terminal's permanent identifier, or only a string representing the intermediate key between the terminal and the key management function, or may include both the terminal's permanent identifier and a string representing the intermediate key between the terminal and the key management function.

[0103] It should be understood that the above process of generating the intermediate key (i.e., the intermediate key between the terminal and the key management function) is executed on the terminal side, and the processing method for generating the intermediate key between the terminal and the key management function executed on the third core network device side should also be the same as the terminal's processing method. The above is only an exemplary description of the possible contents of the second key generation parameters. In actual processing, the second key generation parameters may also contain other contents, which are not limited or exhaustively listed here. The calculation method used to generate the intermediate key between the terminal and the key management function can be configured according to the actual situation, such as KDF or other possible methods. This embodiment does not limit or exhaustively list them. As long as the terminal and the third core network device use the same second key generation parameters and the same calculation method to obtain the same intermediate key when deriving the intermediate key between the terminal and the key management function, it is within the protection scope of this embodiment.

[0104] In this embodiment, the function of the upper-level key is to derive or generate an intermediate key between the terminal and the key management function.

[0105] The third core network device is a core network device that stores the key of the previous level on the core network side. For example, if the previous level key is the key between the terminal and the AUSF, the third core network device can be the AUSF that stores the key between the terminal and the AUSF; or if the previous level key is the key between the terminal and the SEAF, the third core network device can be the SEAF that stores the key between the terminal and the SEAF.

[0106] In this embodiment, the key between the terminal and AUSF is K. AUSF The key between the terminal and AUSF is K. SEAF In this embodiment, K AUSF or K SEAF The function differs from the aforementioned embodiments, where K... AUSF or K SEAF It can be used directly as an intermediate key, but in this embodiment, it needs to be based on K. AUSF or K SEAF Further derive the intermediate key, therefore K AUSF or K SEAF This is called the next-level key above the intermediate key. It's important to understand that regardless of K... AUSF For which of the above functions is K? AUSF The generation method is the same as in the aforementioned embodiments, regardless of K SEAF For which of the above functions is generated in the same way as the aforementioned embodiments, regarding the receipt or acquisition of K by AUSF or SEAF. AUSF or K SEAF The method is also the same as in the aforementioned embodiments (e.g., K is generated by UDM). AUSFAnd send it to AUSF for storage, etc.), K will not be discussed here. AUSF or K SEAF The generation, transmission, or storage of data will be described again.

[0107] In one example, the third core network device is AUSF; correspondingly, the upstream key of the intermediate key can be the key between the terminal and AUSF (i.e., K). AUSF ).

[0108] This AUSF can be based on the locally stored key between the terminal and the AUSF (i.e., K). AUSF The terminal derives or generates an intermediate key between the terminal and the key management function from the second key generation parameters, and the AUSF can send this intermediate key to the key management function. Correspondingly, the terminal uses the key between the terminal and the AUSF (i.e., K...) AUSF The second key generation parameter generates the intermediate key between the terminal and the key management function.

[0109] For example, after authentication between the terminal and the network, the terminal and the UDM can generate key K based on the root key K. AUSF UDM will K AUSF Send to AUSF. AUSF is based on K. AUSF Derivate or generate the intermediate key K between the terminal and DNKGF DNKGF Then AUSF will K DNKGF Send to the key management function. The timing of the terminal generating the intermediate key between the terminal and DNKGF can be during or after the core network and terminal authentication process. Similarly, the terminal generates key K based on the root key K. AUSF Then, based on K AUSF Derivate or generate the intermediate key K between the terminal and DNKGF DNKGF The input parameters for generating the key KDNKGF include at least one of the following: the string "DNKGM", or a permanent identifier for the terminal (e.g., SUPI in 5G, or a permanent identifier for the terminal in 6G).

[0110] In one example, the third core network device is SEAF; correspondingly, the upper-level key can be the key between the terminal and SEAF (i.e., K). SEAF ).

[0111] This SEAF can be based on the locally stored intermediate key between the terminal and the SEAF (i.e., K). SEAFThe SEAF derives or generates an intermediate key between the terminal and the key management function using the second key generation parameters, and the SEAF can send this intermediate key to the key management function. Correspondingly, the terminal uses the intermediate key between the terminal and the SEAF (i.e., K...) SEAF The second key generation parameter generates the intermediate key between the terminal and the key management function.

[0112] In one example, the terminal can also generate a key identifier for the intermediate key, and / or, a third core network device (AUSF or SEAF) can also generate a key identifier for the intermediate key. In this example, the key identifier for the intermediate key specifically refers to the key identifier of the intermediate key between the terminal and the key management function. This key identifier of the intermediate key between the terminal and the key management function can be represented as D-KID, where D represents the key management function (such as DNKGF or DNKMF), and KID represents the key identifier (Key ID).

[0113] The key identifier of the intermediate key may include at least one of the following: a routing identifier included in the permanent identifier of the terminal, or a temporary identifier corresponding to the intermediate key, wherein the temporary identifier corresponding to the intermediate key is generated based on the parent key and at least one of the following: a string used to represent the temporary identifier, or the permanent identifier of the terminal.

[0114] The permanent identifier of a terminal may include multiple components, and the routing identifier may be one of these components. Other components of the terminal's permanent identifier besides the routing identifier are not limited or exhaustively listed in this embodiment. The routing identifier may be represented as a RID (Routing Identifier).

[0115] In this example, the key identifier of the intermediate key is specifically the key identifier of the intermediate key between the terminal and the key management function. Correspondingly, the temporary identifier of the intermediate key can also be called the temporary terminal identifier of the key management function, which can be represented as D-TID. Here, D can be used to represent the key management function (such as DNKGF or DNKMF), and TID can refer to the temporary identifier (Temp ID, or Temporary ID) or the temporary ID corresponding to the terminal.

[0116] The string used to represent the temporary identifier can be descriptive information about the temporary identifier, such as "D-TID", etc. This embodiment does not limit the generation method or rules of the string used to represent the temporary identifier in the terminal and the third core network device. As long as the same string representing the temporary identifier can be obtained in both the terminal and the third core network device, it is within the protection scope of this embodiment.

[0117] When generating the temporary identifier corresponding to the intermediate key, you can use only the string representing the temporary identifier as the input parameter, or only the terminal's permanent identifier as the input parameter, or both the string representing the temporary identifier and the terminal's permanent identifier as input parameters. The input key used to generate the temporary identifier corresponding to the intermediate key can be the parent key; the relevant description of the parent key is the same as in the previous embodiments and will not be repeated. The calculation method used to generate the temporary identifier corresponding to the intermediate key can be configured according to actual conditions, and this embodiment does not impose any limitations.

[0118] The key identifier D-KID of the intermediate key between the terminal and the key management function may include only the routing identifier, only the temporary identifier, or both the routing identifier and the temporary identifier (e.g., composed of RID and D-TID).

[0119] Optionally, the key identifier of the intermediate key can be generated on the terminal side and also on the third core network device side. In this case, the third core network device can also send the key identifier of the intermediate key to the key management function, and the key management function can receive and save the key identifier of the intermediate key. Regarding the timing of the third core network device sending the key identifier of the intermediate key to the key management function, it can be at the same time or after the third core network device sends the intermediate key between the terminal and the key management function to the key management function; this embodiment does not limit or exhaustively list such instances.

[0120] Optionally, the key identifier of the intermediate key can be generated by a third core network device. In this case, the third core network device can also send the key identifier of the intermediate key to the key management function and the terminal respectively. Correspondingly, the key management function can receive and save the key identifier of the intermediate key, and the terminal can receive and save the key identifier of the intermediate key. Here, the third core network device can send the key identifier of the intermediate key to the terminal through the first core network device, that is, the terminal receives the key identifier of the intermediate key sent by the first core network device. Regarding the timing of the key identifier of the intermediate key received by the key management function, it can be at the same time or after the key management function receives the intermediate key between the terminal and the key management function. This embodiment does not limit or exhaustively list such cases. The timing of the terminal receiving the key identifier of the intermediate key is not limited in this embodiment. As long as it is before the terminal generates the first NAS key, it is within the protection scope of this embodiment.

[0121] In some embodiments, after sending a registration request and generating an intermediate key, the terminal can generate a first NAS key with the first core network device. After receiving the intermediate key, the second core network device can generate the first NAS key between the terminal and the first core network device, and send the first NAS key to the first core network device. The first core network device receives and stores the first NAS key.

[0122] In this embodiment, the first core network device is an MM NF, and the first NAS key is the NAS key between the terminal and the MM NF. This first NAS key can be represented as K. MM NF .

[0123] The first NAS key K is generated by the terminal and the second core network equipment respectively, triggered by registration and authentication. MM NF The method involves generating the first NAS key K based on the intermediate key and the first key generation parameters. MM NF The specific instructions for generating the first NAS key are the same as those in the aforementioned embodiments, and will not be repeated here.

[0124] It should be noted that the terminal may need to obtain at least part of the first key generation parameters before generating the first NAS key; and / or, the second core network device may also need to obtain at least part of the first key generation parameters before generating the first NAS key.

[0125] The processing on the first core network device side may further include: sending at least one of the following to the terminal: a temporary identifier of the terminal, or a temporary identifier of the first core network device. Correspondingly, the processing on the terminal side may further include: receiving at least one of the following: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

[0126] The processing of the first core network device further includes sending at least one of the following to the second core network device: a temporary identifier of the terminal, or a temporary identifier of the first core network device. Correspondingly, the processing of the second core network device may further include receiving at least one of the following from the first core network device: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

[0127] Optionally, the first core network device may send only the terminal's temporary identifier to the terminal; the first core network device may send only the terminal's temporary identifier to the second core network device.

[0128] Specifically, the terminal can receive its own temporary identifier, and the terminal has pre-stored or pre-configured the temporary identifier of the first core network device and the instance identifier of the first core network device. The terminal can also obtain the type information of the first NAS key, which is either default or generated based on preset rules. Therefore, the terminal can obtain the first key generation parameters. In addition to the terminal's temporary identifier, the first key generation parameters can also include at least one of the following: the temporary identifier of the first core network device, the instance identifier of the first core network device, and the type information of the first NAS key.

[0129] The second core network device can receive the terminal's temporary identifier. The second core network device has pre-stored or pre-configured the temporary identifier and instance identifier of the first core network device. The second core network device can also obtain the type information of the first NAS key, either by default or generated based on preset rules. Therefore, the second core network device can ultimately generate the same first key generation parameters as the terminal.

[0130] Optionally, the first core network device may send only its temporary identifier to the terminal; the first core network device may also send only its temporary identifier to the second core network device. In this case, the first key generation parameters may exclude the terminal's temporary identifier but include the terminal's permanent identifier.

[0131] Specifically, the terminal can receive the temporary identifier of the first core network device, and the terminal has pre-stored or pre-configured the instance identifier of the first core network device and its own permanent identifier. The terminal can also obtain the type information of the first NAS key, which is either default or generated based on preset rules. Therefore, the terminal can obtain the first key generation parameters. In addition to the temporary identifier of the first core network device and the permanent identifier of the terminal, the first key generation parameters can also include at least one of the instance identifier of the first core network device and the type information of the first NAS key.

[0132] The second core network device can receive the temporary identifier of the first core network device. The second core network device has pre-stored or pre-configured the instance identifier of the first core network device and the permanent identifier of the terminal. The second core network device can also obtain the type information of the first NAS key by default or based on preset rules. Therefore, the second core network device can eventually generate the same first key generation parameters as the terminal.

[0133] Optionally, the first core network device can send the terminal's temporary identifier and the first core network device's temporary identifier to the terminal; the first core network device can also send the terminal's temporary identifier and the first core network device's temporary identifier to the second core network device.

[0134] The terminal can receive its own temporary identifier and the temporary identifier of the first core network device. The terminal can also pre-configure or pre-store the instance identifier of the first core network device. Furthermore, the terminal can obtain the type information of the first NAS key, either by default or generated based on preset rules. Therefore, the terminal can obtain the first key generation parameters. These parameters include, in addition to the terminal's temporary identifier and the temporary identifier of the first core network device, at least one of the instance identifier of the first core network device and the type information of the first NAS key. The processing of the first key generation parameters by the second core network device is similar to that of the terminal and will not be elaborated upon.

[0135] In this embodiment, the first core network device sends at least one of the following to the terminal: the terminal's temporary identifier and the first core network device's temporary identifier. Alternatively, the first core network device can send at least one of the following to the terminal via the access network device: the terminal's temporary identifier and the first core network device's temporary identifier. The terminal receives at least one of the following: the terminal's temporary identifier and the first core network device's temporary identifier. Alternatively, it can receive at least one of the following from the access network device: the terminal's temporary identifier and the first core network device's temporary identifier.

[0136] The type of message used for transmitting the temporary identifier of the terminal and / or the temporary identifier of the first core network device between the access network device and the first core network device is not limited in this embodiment. The access network device may send a second AS message to the terminal, which carries the temporary identifier of the terminal and / or the temporary identifier of the first core network device. The message type of the second AS message can be an RRC (Radio Resource Control) message or a downlink RRC message, etc., which is not limited or exhaustively listed here.

[0137] This embodiment does not limit the type and timing of the message used for transmitting the temporary identifier of the terminal between the first core network device and the second core network device and / or the temporary identifier of the first core network device. As long as it is ensured that the first core network device can receive the first NAS key before sending the registration acceptance message, it is within the protection scope of this embodiment.

[0138] The first core network device can generate a temporary identifier for the terminal after receiving a registration request.

[0139] Optionally, the first core network device may carry the terminal's temporary identifier and / or the first core network device's temporary identifier in the registration acceptance message when sending the registration acceptance message.

[0140] Optionally, the first core network device may carry the terminal's temporary identifier and / or the first core network device's temporary identifier in the authentication-related message transmitted to the terminal during the terminal authentication process (before sending the registration acceptance message).

[0141] In some embodiments, the shared key K between the terminal and the first core network device NFx (Specifically, K is used in this embodiment) MM NF This key will be used to generate at least one of the following: a confidentiality key, an integrity protection key (hereinafter referred to as the integrity protection key), and an authenticable encryption key to protect NAS-NFx (or NAS signaling transmitted between the first core network device and the terminal). Furthermore, the terminal and the first core network device need to negotiate at least one of the following: an encryption algorithm (or confidentiality algorithm), an integrity protection algorithm (hereinafter referred to as the integrity protection algorithm), and an authenticable encryption algorithm to protect the NAS-NFx connection.

[0142] During the registration process (or initial registration process), the terminal can report the security algorithms it supports. Specifically, the registration request carries indication information of the security algorithms supported by the terminal, wherein the security algorithms include at least one of the following: integrity protection algorithm, confidentiality algorithm, and authenticateable encryption algorithm.

[0143] The indication information of the security algorithms supported by the terminal may include at least one of the following: an identifier of one or more integrity protection algorithms supported by the terminal, an identifier of one or more confidentiality algorithms supported by the terminal, and an identifier of one or more authentication encryption algorithms supported by the terminal. In some possible examples, the identifier of one or more integrity protection algorithms supported by the terminal may also be replaced with the type of each integrity protection algorithm among the one or more integrity protection algorithms supported by the terminal; the identifier of one or more confidentiality algorithms supported by the terminal may be replaced with the type of each confidentiality algorithm among the one or more confidentiality algorithms supported by the terminal; and the identifier of one or more authentication encryption algorithms supported by the terminal may be replaced with the type of each authentication encryption algorithm among the one or more authentication encryption algorithms supported by the terminal, which will not be explained again below.

[0144] Here, the authenticable encryption algorithm may include AEAD (Authenticated Encryption with Associated Data) mode or AEAD algorithm, etc., which can simultaneously provide confidentiality, integrity and authenticity protection for data.

[0145] For example, the terminal may support one or more authentication-enabled encryption algorithms, including one or more AEAD algorithms. These AEAD algorithms could include: Encrypt-then-MAC (EtM), Encrypt-and-MAC (E&M), MAC-then-Encrypt (MtE), etc. For instance, EtM could refer to encrypting plaintext data (plaintext) to obtain ciphertext data (ciphertext), and then generating an authentication check code (MAC) based on the ciphertext, sending both the ciphertext and the MAC simultaneously. Alternatively, E&M could involve generating an authentication check code based on plaintext, encrypting the plaintext, and sending both the authentication check code and the ciphertext together. Similarly, MtE could involve generating an authentication check code based on plaintext, encrypting both the plaintext and the authentication check code together to generate ciphertext, and then sending the ciphertext. It should be understood that this is merely an illustrative example and does not constitute a limitation or exhaustive list of authentication-enabled encryption algorithms supported by the terminal.

[0146] After receiving the indication information of the security algorithms supported by the terminal, the first core network device can select or determine the security algorithm to be used between the first core network device and the terminal based on the locally configured algorithm list and the indication information of the security algorithms supported by the terminal.

[0147] For example, if the indication information of the security algorithm supported by the terminal includes the identifier of the first integrity algorithm supported by the terminal, the identifier of the first confidentiality algorithm supported by the terminal, and the identifier of the first authenticable encryption algorithm supported by the terminal, and the algorithm list configured locally by the MM NF contains the first integrity algorithm, the first confidentiality algorithm, and the first authenticable encryption algorithm, then the MM NF can determine to use the first integrity algorithm, the first confidentiality algorithm, and the first authenticable encryption algorithm as the security algorithms used between the MM NF and the terminal.

[0148] For example, if the indication information of the security algorithms supported by the terminal includes the identifiers of multiple integrity protection algorithms supported by the terminal, the identifiers of multiple confidentiality algorithms supported by the terminal, and the identifiers of multiple authenticable encryption algorithms supported by the terminal, and the algorithm list configured locally by the MM NF contains a target integrity protection algorithm that is the same as any one of the identifiers of the multiple integrity protection algorithms supported by the terminal, a target confidentiality algorithm that is the same as any one of the multiple confidentiality algorithms supported by the terminal, and a target authenticable encryption algorithm that is the same as any one of the multiple authenticable encryption algorithms supported by the terminal, then the MM NF can determine to use the target integrity protection algorithm, the target confidentiality algorithm, and the target authenticable encryption algorithm as the security algorithms used between the MM NF and the terminal.

[0149] Furthermore, after the first core network device determines the security algorithm used between itself and the terminal, it may further include at least one of the following: sending indication information of the security algorithm used between the first core network device and the terminal to the terminal; sending indication information of the security algorithm used between the first core network device and the terminal to the key management function; and sending indication information of the security algorithm used between the first core network device and the terminal to the UDM. The indication information of the security algorithm used between the first core network device and the terminal is similar to the indication information of the security algorithms supported by the terminal mentioned above, and will not be elaborated further. Here, if the terminal only reports the identifier of one integrity protection algorithm, one confidentiality algorithm, and one authenticateable encryption algorithm it supports through the registration request, then the terminal can default to using the integrity protection algorithm, confidentiality algorithm, and authenticateable encryption algorithm as the security algorithm used between the first core network device and the terminal; that is, the first core network device does not need to send the identifier of the security algorithm used between itself and the terminal to the terminal.

[0150] In other words, after the terminal performs or completes the initial registration, the identifier (i.e., indication information) of the security algorithm used between the first core network device and the terminal has been saved or determined on both the terminal and the first core network device side, and / or the identifier of the security algorithm used between the first core network device and the terminal has also been saved in the key management function (or may also include UDM) on the core network side.

[0151] The foregoing embodiments have described how different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices. Further, any NAS key used to protect NAS messages transmitted between the terminal and the core network device can be: the NAS key itself or a key derived from the NAS key is used to protect NAS messages transmitted between the terminal and the core network device.

[0152] In this embodiment, the first NAS key is used to protect NAS messages transmitted between the terminal and the first core network device. Specifically, it refers to a first security parameter used to protect NAS messages transmitted between the terminal and the first core network device, which is obtained based on the first NAS key. On the first core network device side, a registration acceptance message may be sent after receiving the first NAS key from the second core network device. Before sending the registration acceptance message, the first core network device can enable protection. For example, the first core network device can protect and transmit downlink messages (such as registration acceptance messages) based on the first security parameter. This protection may include integrity protection and / or confidentiality protection and / or authenticable encryption protection.

[0153] The first security parameter may include at least one of the following: a first NAS key, a first integrity key, a first confidentiality key, and a first authenticable encryption key, wherein the first integrity key is derived from the first NAS key, the first confidentiality key is derived from the first NAS key, and the first authenticable encryption key is derived from the first NAS key. This first security parameter is the same on both the terminal and the first core network device side.

[0154] The first security parameter includes a first NAS key, which can refer to the terminal and the first core network device directly using the first NAS key to perform integrity protection and / or encryption and / or authenticateable encryption protection on the NAS messages transmitted between the terminal and the first core network device.

[0155] The first security key can be calculated using a first calculation method from the first NAS key and security key derivation parameters. The first confidentiality key can be calculated using a second calculation method from the first NAS key and confidentiality key derivation parameters. The first authenticable encryption key can be calculated using a third calculation method from the first NAS key and authenticable encryption key derivation parameters. The first calculation method, security key derivation parameters, second calculation method, confidentiality key derivation parameters, third calculation method, and authenticable encryption key derivation parameters can all be configured or determined according to actual conditions. This embodiment does not limit them. As long as the same first calculation method, security key derivation parameters, second calculation method, confidentiality key derivation parameters, third calculation method, and authenticable encryption key derivation parameters are used on the terminal and the first core network device side, and the terminal and the first core network device obtain the same first security parameter, it is within the protection scope of this embodiment.

[0156] The registration acceptance message sent by the first core network device may carry a first integrity verification code calculated based on the first security parameter and the integrity verification algorithm used between the first core network device and the terminal, which is to perform integrity verification on the registration acceptance message; and / or, the registration acceptance message sent by the first core network device may carry encrypted data, which may be obtained by encrypting the content or parameters carried in the registration acceptance message based on the first security parameter and the confidentiality algorithm used between the first core network device and the terminal.

[0157] Furthermore, the first core network device may carry a registration acceptance message in the Nran_Initial UEMMcontext (Initial UE Mobility Management Context) message sent to the access network device, and the access network device may send the registration acceptance message to the terminal via an RRC message. The RRC message sent by the access network device may carry a NAS-MM (Mobility Management) container, within which the registration acceptance message is carried. The NAS-MM container may be the first downlink NAS container corresponding to the first core network device (or simply the NAS container corresponding to the first core network device).

[0158] In some examples, the registration acceptance message may carry at least part of the first key generation parameters (e.g., at least the temporary identifier of the terminal and / or the temporary identifier of the first core network device). In such examples, only the registration acceptance message may be processed for integrity protection.

[0159] For example, the first security parameter may include a first NAS key. The first core network device can use the first NAS key and the integrity verification algorithm used between the first core network device and the terminal to calculate a first integrity verification code on the registration acceptance message. The registration acceptance message carries the first integrity verification code (i.e., integrity verification is performed) and at least a portion of the first key generation parameters. Correspondingly, after the terminal receives the RRC message carrying the NAS-MM container from the access network device, it extracts the registration acceptance message from the NAS-MM container, generates a first key generation parameter based on at least a portion of the first key generation parameters carried in the registration acceptance message, generates a first NAS key based on the intermediate key and the first key generation parameters, calculates a first integrity verification code based on the first NAS key and the integrity verification algorithm used between the first core network device and the terminal, performs integrity verification on the registration acceptance message based on the first integrity verification code and the first integrity verification code, and saves the content or parameters carried in the registration acceptance message if the verification passes, and discards the registration acceptance message if the verification fails.

[0160] For example, the first security parameter may include a first integrity key and a first confidentiality key. The first core network device can use the first integrity key and the integrity algorithm used between the first core network device and the terminal to calculate a first integrity check code on the registration acceptance message for integrity protection, and carry the first integrity check code and at least part of the first key generation parameter in the registration acceptance message. Correspondingly, after the terminal receives the RRC message carrying the NAS-MM container from the access network device, it extracts the registration acceptance message from the NAS-MM container, generates a first key generation parameter based on at least part of the first key generation parameter carried in the registration acceptance message, generates a first NAS key based on the intermediate key and the first key generation parameter, derives the first integrity key and the first confidentiality key based on the first NAS key, calculates the first integrity check code on the registration acceptance message based on the first integrity key and the integrity algorithm used between the first core network device and the terminal, performs integrity verification on the registration acceptance message based on the first integrity check code and the first integrity check code, and saves the content or parameters carried in the registration acceptance message if the verification passes, and discards the registration acceptance message if the verification fails.

[0161] Furthermore, if the registration acceptance message is discarded, the terminal can initiate a new registration request and perform the aforementioned processing again, without repeating the explanation.

[0162] In some examples, the first core network device may carry the terminal's temporary identifier and / or the first core network device's temporary identifier in the authentication-related message transmitted to the terminal during the terminal authentication process (before sending the registration acceptance message). In this example, the terminal and the first core network device may have already generated the first NAS key (or generated the first security parameter) when the terminal completes authentication. Therefore, the registration acceptance message sent by the first core network device can be protected for integrity and / or confidentiality. Correspondingly, the terminal side can perform integrity protection verification and / or decryption on the registration acceptance message carried by the received NAS-MM container based on the first security parameter.

[0163] For example, the first security parameter may include a first NAS key. The first core network device carries a first integrity verification code in the registration acceptance message it sends, and also carries plaintext or ciphertext data in the registration acceptance message. The first integrity verification code is calculated based on the first NAS key and the integrity algorithm used between the first core network device and the terminal, and / or the ciphertext data is obtained by encrypting the content or parameters (i.e., plaintext data) in the registration acceptance message based on the first NAS key and the confidentiality algorithm used between the first core network device and the terminal. Correspondingly, after receiving an RRC message carrying a NAS-MM container from the access network device, the terminal extracts the registration acceptance message from the NAS-MM container, calculates the first integrity verification code based on the first NAS key and the integrity algorithm used between the first core network device and the terminal, performs integrity verification on the registration acceptance message based on the first integrity verification code and the first integrity verification code, and saves the registration acceptance message if the verification passes. Furthermore, saving the registration acceptance message can mean: if the registration acceptance message carries plaintext data, then the content carried by the registration acceptance message (i.e., plaintext data) is directly saved; if the registration acceptance message carries ciphertext data, then the ciphertext data is decrypted based on the first NAS key and the confidentiality algorithm used between the first core network device and the terminal to obtain the plaintext data. Additionally, if the verification fails, the registration acceptance message is discarded.

[0164] For example, the first security parameter may include a first integrity key and a first confidentiality key. The first core network device carries a first integrity verification code in the registration acceptance message it sends, and also carries plaintext or ciphertext data in the registration acceptance message. The first integrity verification code is calculated based on the first integrity key and the integrity algorithm used between the first core network device and the terminal, and / or the ciphertext data is obtained by encrypting the content or parameters (i.e., plaintext data) in the registration acceptance message based on the first confidentiality key and the confidentiality algorithm used between the first core network device and the terminal. Correspondingly, after receiving the RRC message carrying the NAS-MM container from the access network device, the terminal extracts the registration acceptance message from the NAS-MM container, calculates the first integrity verification code based on the first integrity key and the integrity algorithm used between the first core network device and the terminal, performs integrity verification on the registration acceptance message based on the first integrity verification code and the first integrity verification code, and saves the registration acceptance message if the verification passes. Furthermore, saving the registration acceptance message can mean: if the registration acceptance message carries plaintext data, then the content carried by the registration acceptance message (i.e., plaintext data) is directly saved; if the registration acceptance message carries ciphertext data, then the ciphertext data is decrypted based on the first confidentiality key and the confidentiality algorithm used between the first core network device and the terminal to obtain the plaintext data. Additionally, if the verification fails, the registration acceptance message is discarded.

[0165] For example, the first security parameter may include a first authenticable encryption key and an authenticable encryption algorithm (MtE) used between the terminal and the first core network device. The first core network device carries ciphertext data (obtained by encrypting plaintext data and a first integrity check code) in its registration acceptance message. The ciphertext data is obtained by encrypting the plaintext data and the first integrity check code in the registration acceptance message using the first authenticable encryption key and the authenticable encryption algorithm used between the first core network device and the terminal. The first integrity check code is calculated based on the first authenticable encryption key and the authenticable encryption algorithm used between the first core network device and the terminal. Accordingly, after receiving the RRC message carrying the NAS-MM container from the access network device, the terminal extracts the registration acceptance message from the NAS-MM container, decrypts the ciphertext data in the registration acceptance message based on the first authenticable encryption key and the authenticable encryption algorithm used between the first core network device and the terminal, obtaining plaintext data and a first integrity verification code; then, based on the first authenticable encryption key and the authenticable encryption algorithm used between the first core network device and the terminal, it calculates the first integrity verification code on the plaintext data, performs integrity verification based on the first integrity verification code and the first integrity verification code, and saves the registration acceptance message if the verification passes. It should be noted that this is only an illustrative example, and in actual processing, the authenticable encryption algorithm may include, but is not limited to, the calculation method in the above example; however, it is not limited or exhaustive here.

[0166] The following, with reference to Figure 5, provides an exemplary description of the scenario where the terminal establishes a connection with the first core network device on the core network side during the initial registration process, as provided in this embodiment. In the following example, the terminal is a UE, the first core network device is an MM NF, the second core network device is an AUSF, and the third core network device is a UDM, specifically including:

[0167] S501, during the initial registration process, the UE sends a registration request to the AN (Access Network Equipment). This registration request can be carried by an RRC message, specifically by the NAS MM container in the RRC message.

[0168] S502, after receiving the registration request, AN determines the connection MM NF.

[0169] S503, AN sends a registration request to MM NF, which can be carried by Nmm_InitialUE.

[0170] S504, upon receiving the initial registration request, the MM NF triggers authentication between the UE and the network, and sends a connection management registration message to the UDM (e.g., it can be represented as Nudm_UE CM_Reg).

[0171] S505, the UDM sends Nudm_SDM_Get (Slice Selection Subscription data) to the MM NF. Then the MM NF establishes the UE mobility management context (UE MM context).

[0172] S506 performs the authentication process between the UE and the network.

[0173] The authentication process between the UE and the network can reuse existing AKA authentication mechanisms (5G-AKA, EAP'-AKA). For example, in 5G-AKA, the UE authenticates with SEAF (a security network element co-located with AMF), AUSF, and UDM.

[0174] In this example, during the authentication process of Distributed NAS (Distributed NAS architecture), UDM generates key K for AUSF. AUSF (i.e., the intermediate key), provided by AUSF based on K AUSF The key K between the generated NF (specifically MM NF in this example) and the UE is... MM NF (i.e., NAS key), and send it to MM NF; or, AUSF based on K AUSF Generate key K for the key management function of Distributed NAS DNKMF (i.e., the intermediate key), and then the key management function based on K DNKMF Generate the key K between the UE and each NF (specifically, the MM NF in this example). MM NF .

[0175] For simplicity, Figure 5 shows S506 followed by the illustration that MM NF can obtain the key K. MM NF AUSF can obtain the key K AUSF However, Figure 5 is not used to limit when MM NF and AUSF actually obtain their respective keys.

[0176] S507, the MM NF enables protection and sends a registration acceptance message to the AN. This registration acceptance message can be carried by the Nran_Initial UEMMcontext, and the downlink NAS message sent by the MM NF to the UE (in this example, the registration acceptance message) can use K. MM NF The derived integrity protection key enables integrity protection.

[0177] S508, the AN sends a registration acceptance message to the UE, which can be carried by the NAS-MM container in the RRC message.

[0178] K in this example MM NF The input parameters for generating the key (i.e., the first key generation parameters) may include at least one of the following: the identifier assigned to the UE by the MM NF; the instance ID of the MM NF; the NAS type: MM NF; and the temporary identifier of the MM NF. Generating the key... MM NF The input key (i.e., the intermediate key) is any one of the following: K DNKMF K AUSF 、or K SEAF .

[0179] It is important to understand that the UE can also derive an intermediate key (K). DNKMF K AUSF 、or K SEAF (any one of them) and K MM NF Regarding UE derived intermediate key and K MM NF The timing and related processing are the same as in the previous embodiments, and will not be described in detail in this example for the sake of brevity.

[0180] In some possible implementations, the first core network device can be any one of one or more core network devices that the terminal can establish a NAS connection with, other than the core network device of the service domain to which the terminal first establishes a connection (such as MM NF). The first core network device can be the core network device that the terminal establishes a new connection with after the terminal has established a NAS-MM NF (i.e., a NAS connection between the terminal and MM NF) security. For example, the first core network device can be an SM NF or can be represented as NFx.

[0181] In this embodiment, before generating the first NAS key, the terminal has at least generated a NAS key between itself and the core network device (or network element) of the first service domain with which it has established a connection (i.e., the terminal and the MM NF have at least obtained a K key). MM NF In other words, the first NAS key in this implementation is not the first NAS key generated by the terminal.

[0182] It should also be understood that, due to the derivative K MM NF Previously, the intermediate key had to be obtained first. Therefore, the intermediate key was derived or obtained before the terminal generated the first NAS key, and the intermediate key was also obtained or saved before the second core network device generated the first NAS key. Therefore, this embodiment will not repeat the description of the intermediate key processing.

[0183] During the initial registration process of the terminal, the terminal can establish NAS-MM NF security with the MM NF. In other processes or procedures following the establishment of NAS-MM NF security, the terminal can establish secure connections with other NFs (the first core network device in this embodiment), such as the SM NF. Next, based on two scenarios—one initiated by the terminal and the other where the first core network device pages a specific terminal through the access network device—the relevant processing for establishing a security context (including at least the first NAS key) between the terminal and the first core network device in each scenario will be described.

[0184] In some embodiments, the terminal may actively trigger the establishment of a connection with the first core network device.

[0185] The terminal's processing may include: sending a second message, wherein the second message is used for the first core network device to establish a connection with the terminal. The first core network device's processing may include: receiving a second message, wherein the second message is used for the first core network device to establish a connection with the terminal.

[0186] The second message carries a connection establishment request. This connection establishment request can be represented as UE_NFx communication establishment request (communication establishment request between the terminal and the first core network device).

[0187] The second message may carry at least one of the following: a protected identifier of the terminal, a key identifier of the intermediate key, and an indication of the security algorithm supported by the terminal, wherein the security algorithm includes at least one of the following: a integrity protection algorithm, a confidentiality algorithm, and an authenticable encryption algorithm.

[0188] In this embodiment, the protected identifier of the terminal may include: an encrypted permanent identifier of the terminal, which may be a SUCI (Subscription Concealed Identifier). The key identifier of the intermediate key may include the key identifier of the intermediate key between the terminal and the key management function.

[0189] Specifically, the terminal sending the second message can involve sending a second message to the access network device. The access network device's processing can include receiving the second message from the terminal and sending the second message to the first core network device. Correspondingly, the first core network device receiving the second message can include receiving the second message from the access network device.

[0190] The sending of the second message from the terminal to the access network device may include: the terminal sending a third AS message to the access network device, wherein the third AS message carries a first uplink NAS container corresponding to the first core network device, and the second message is carried in the first uplink NAS container. The first uplink NAS container can be represented as a NAS-NFx container, where NFx can refer to the first core network device. The type of the third AS message is not limited in this embodiment; it can be an RRC message or an uplink RRC message, etc.

[0191] The access network device may send a second message to the first core network device by: directly sending the first uplink NAS container carried in the third AS message to the first core network device; or by extracting the first uplink NAS container from the third AS message, extracting the second message carried in the first uplink NAS container, and sending it to the first core network device.

[0192] In one embodiment, after the first core network device receives the second message, it may include sending at least one of the following to the second core network device: a temporary identifier of the terminal, or a temporary identifier of the first core network device. Correspondingly, the second core network device may process by receiving at least one of the following from the first core network device: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

[0193] The temporary identifier of the terminal can be generated by the first core network device after receiving the second message.

[0194] Specifically, the processing of the first core network device may include: retrieving the security context of the terminal locally; if the terminal's security context is retrieved, extracting the first NAS key contained in the terminal's security context; and if the terminal's security context is retrieved, sending a key retrieval request to the second core network device. The key retrieval request may carry key generation material, which may include at least one of the following: a temporary identifier of the terminal, or a temporary identifier of the first core network device. The key generation material may also be referred to as at least a portion of the parameters or content in the first key generation parameters, or at least a portion of the content or parameters used to generate the first NAS key, etc. That is, the first core network device may already have the terminal's security context (which includes the first NAS key corresponding to the terminal). In this case, the first core network device can directly use the first NAS key; otherwise, it needs to obtain the first NAS key derived by the second core network device by sending a key retrieval request to the second core network device.

[0195] Optionally, if the second message carries the protected identifier of the terminal, the key retrieval request may also carry the protected identifier of the terminal. Here, the possible contents carried by the key retrieval message are not limited or exhaustively listed.

[0196] Optionally, if the second message carries a key identifier of the intermediate key, the processing of the first core network device may further include: determining the second core network device based on the key identifier of the intermediate key. For example, if the first core network device receives the key identifier of the intermediate key between the terminal and the key management function carried in the second message, the first core network device may look up the corresponding key management function based on the key identifier of the intermediate key between the terminal and the key management function.

[0197] In one embodiment, after receiving a key retrieval request, the second core network device can generate a first NAS key between the terminal and the first core network device. This first NAS key can be generated based on an intermediate key.

[0198] Specifically, generating the first NAS key between the terminal and the first core network device based on the intermediate key may include: generating the first NAS key between the terminal and the first core network device based on the intermediate key and the first key generation parameters.

[0199] The processing of the second core network device may further include: detecting the authentication result of the terminal stored locally; if no authentication result of the terminal is stored, searching for the terminal's authentication result from the next higher-level core network device (such as the third core network device) and obtaining the terminal's authentication result sent by the third core network device; if the terminal's authentication result (which can be the authentication result stored locally or sent by the third core network device) is an authentication failure, then authentication of the terminal can be triggered; if the terminal's authentication result is a successful authentication, then the first NAS key between the terminal and the first core network device can be generated based on the intermediate key. Here, the terminal's authentication processing and the generation of the intermediate key and K during the authentication process are described. MM NF The related processing is the same as in the aforementioned embodiments and will not be described again. The second core network device storing the terminal's authentication result and / or the third core network device storing the terminal's authentication result can be done after the terminal has completed authentication.

[0200] The description of the intermediate key is the same as that in the previous embodiments, and will not be repeated here.

[0201] The first key generation parameter can be obtained based on the key generation material carried in the key retrieval request.

[0202] Alternatively, the key generation material may consist only of a temporary identifier for the terminal.

[0203] The second core network device can receive the terminal's temporary identifier, and the second core network device has pre-stored or pre-configured the temporary identifier and instance identifier of the first core network device. The second core network device can also obtain the type information of the first NAS key, which is either default or generated based on preset rules. Therefore, the second core network device can obtain the first key generation parameters. In addition to the terminal's temporary identifier, the first key generation parameters can also include at least one of the following: the temporary identifier of the first core network device, the instance identifier of the first core network device, and the type information of the first NAS key.

[0204] Optionally, the key generation material may include only the temporary identifier of the first core network device. In this case, the first key generation parameters may exclude the terminal's temporary identifier but include the terminal's permanent identifier.

[0205] The second core network device can receive the temporary identifier of the first core network device. The second core network device has pre-stored or pre-configured the instance identifier of the first core network device and the permanent identifier of the terminal. The second core network device can also obtain the type information of the first NAS key, which is either default or generated based on preset rules. Therefore, the second core network device can obtain the first key generation parameters. In addition to the temporary identifier of the first core network device and the permanent identifier of the terminal, the first key generation parameters can also include at least one of the instance identifier of the first core network device and the type information of the first NAS key.

[0206] Optionally, the key generation material may include a temporary identifier for the terminal and a temporary identifier for the first core network device.

[0207] The second core network device can receive its own temporary identifier and the temporary identifier of the first core network device. The second core network device can pre-configure or pre-store the instance identifier of the first core network device. The second core network device can also obtain the type information of the first NAS key, which is either default or generated based on preset rules. Therefore, the second core network device can obtain the first key generation parameters. In addition to the temporary identifier of the terminal and the temporary identifier of the first core network device, the first key generation parameters can also include at least one of the instance identifier of the first core network device and the type information of the first NAS key.

[0208] The specific instructions for generating the first NAS key on the second core network device side are the same as those in the aforementioned embodiments, and will not be repeated here.

[0209] After generating the first NAS key, the second core network device can send the first NAS key to the first core network device. Specifically, sending the first NAS key from the second core network device to the first core network device can be done by sending a key retrieval response, which carries the first NAS key. Correspondingly, the first core network device receiving the first NAS key can be done by receiving a key retrieval response carrying the first NAS key from the second core network device.

[0210] In one embodiment, after receiving a first NAS key from a second core network device, the first core network device may perform the following processing: sending a first message, wherein the first message is used by the terminal to determine that a connection has been established with the first core network device. The terminal's processing may include: receiving the first message, wherein the first message is used by the terminal to determine that a connection has been established with the first core network device.

[0211] Sending the first message from the first core network device may include: the first core network device sending the first message to the access network device. The access network device's processing may include: receiving the first message from the first core network device and sending the first message to the terminal. The terminal receiving the first message may involve: receiving the first message from the access network device.

[0212] The type of message used for transmitting the first message between the access network device and the first core network device is not limited in this embodiment. The first message sent by the first core network device to the access network device can be carried by the second downlink NAS container corresponding to the first core network device. The access network device can send the first message to the terminal as follows: the access network device sends a fourth AS (access layer) message to the terminal, wherein the fourth AS message carries the second downlink NAS container corresponding to the first core network device, and the first message is carried in the second downlink NAS container. The second downlink NAS container can also be represented as a NAS-NFx container, and the message type of the fourth AS message can be a downlink RRC message, etc., which is not limited or exhaustively listed here.

[0213] In this embodiment, the terminal and NFx (first core network device) need to negotiate the encryption algorithm and the integrity algorithm (i.e., the security algorithm). The first core network device and the terminal can negotiate the security algorithm used between them in two ways:

[0214] In Method 1, different core network devices in the core network support different security algorithms. When a terminal establishes a connection with the first core network device, it needs to report the identifier of the security algorithms it supports to the first core network device; that is, the second message can carry indication information of the security algorithms supported by the terminal. In this case, the first core network device can select or determine the security algorithm used between the first core network device and the terminal based on its locally configured algorithm list and the indication information of the security algorithms supported by the terminal. The method by which the first core network device and the terminal determine the security algorithm used between them is the same as in the aforementioned embodiments and will not be repeated.

[0215] Method 2: Different core network devices in the core network support the same security algorithm. In this case, the second message may not carry indication information about the security algorithm supported by the terminal. The processing of the first core network device also includes one of the following: obtaining the security algorithm used by the terminal from the core network device of the service domain where the terminal first establishes a connection; or obtaining the security algorithm used by the terminal from the second core network device.

[0216] The core network device of the service domain where the terminal first establishes a connection is the core network device connected during the terminal registration and authentication process in the aforementioned embodiments, such as the MM NF. The security algorithm used by the terminal can refer to the security algorithm used between the terminal and the core network device (i.e., the MM NF) of the service domain where the terminal first establishes a connection. Specifically, the security algorithm used by the terminal obtained by the first core network device can be the identifier of the security algorithm used between the terminal and the core network device (MM NF) of the service domain where the terminal first establishes a connection.

[0217] For example, during or after the terminal completes authentication, the MM NF on the core network side can determine the security algorithm used between the MM NF and the terminal. When the terminal interacts with other core network devices (the first core network device in this embodiment), since the first core network device supports the same security algorithm as the MM NF, it can directly obtain the identifier of the security algorithm used between the MM NF and the terminal, and determine the security algorithm used between the MM NF and the terminal based on the identifier of the security algorithm used between the MM NF and the terminal. Furthermore, the first core network device can use the security algorithm used between the MM NF and the terminal as the security algorithm used between itself and the terminal.

[0218] For example, during or after the terminal completes authentication, the MM NF on the core network side can determine the security algorithm used between the MM NF and the terminal, and can also send the identifier (or type) of the security algorithm used between the MM NF and the terminal to the second core network device (such as DNKMF). When the terminal interacts with other core network devices (the first core network device in this embodiment), since the first core network device and the MM NF support the same security algorithm, the first core network device can directly obtain the identifier of the security algorithm used between the MM NF and the terminal from the second core network device (such as DNKMF), and determine the security algorithm used between the MM NF and the terminal based on the identifier of the security algorithm used between the MM NF and the terminal; thus, the first core network device can use the security algorithm used between the MM NF and the terminal as the security algorithm used between itself and the terminal.

[0219] The security algorithms involved in this embodiment are described in the same way as those in the previous embodiments, and will not be repeated here.

[0220] The first message may carry at least one of the following protected based on the first security parameter: a temporary identifier of the terminal, or a temporary identifier of the first core network device. That is, the first message may also carry key generation material, which is the same as the key generation material described above for the key generation material sent to the second core network device. The key generation material carried in the first message may be protected based on the first security parameter.

[0221] The first security parameter includes at least one of the following: the first NAS key, a first integrity key derived from the first NAS key, a first confidentiality key derived from the first NAS key, and a first authenticable encryption key derived from the first NAS key.

[0222] Optionally, the first message may also carry a connection establishment response, which may be protected based on a first security parameter. The connection establishment response may be used to instruct the terminal to complete the connection establishment with the first core network device. The connection establishment response may be represented as UE_NFx communication establishment response (communication establishment response between the terminal and the first core network device).

[0223] After receiving the first message on the terminal side, a first NAS key can be generated. The specific method for generating the first NAS key is the same as in the aforementioned embodiments and will not be repeated. Furthermore, the terminal can also derive a first integrity key and a first confidentiality key based on the first NAS key. That is, the first NAS key (or shared key) K between the terminal and NFx (first core network device) NFxIt can also be used to generate encryption keys and integrity protection keys to protect NAS-NFx (such as NAS signaling or NAS messages). That is, both the terminal and the first core network device can generate or obtain the first security parameter. The relevant description of the first security parameter is the same as that in the previous embodiments, and will not be repeated.

[0224] In some preferred examples, since the first message carries at least a portion of the content used to generate the first key generation parameters, only the first message can be processed for integrity protection.

[0225] For example, the first security parameter may include a first NAS key. The first core network device can directly use the first NAS key to calculate a first integrity verification code for the first message to perform integrity protection. Correspondingly, after the terminal receives the fourth AS message from the access network device, it extracts the first message from the second downlink NAS container of the fourth AS message, generates a first key generation parameter based on the terminal's temporary identifier and / or the temporary identifier of the first core network device carried in the first message; generates a first NAS key based on the intermediate key and the first key generation parameter; calculates a first integrity verification code based on the first NAS key and the integrity protection algorithm used between the first core network device and the terminal; performs integrity verification on the first message based on the first integrity verification code and the first integrity verification code; if the verification passes, the content or parameters carried in the first message are saved; if the verification fails, the first message is discarded.

[0226] For example, the first security parameter may include a first integrity key and a first confidentiality key; the first core network device can use the first integrity key to calculate a first integrity check code for the first message to perform integrity protection. Correspondingly, after receiving the fourth AS message from the access network device, the terminal extracts the first message from the second downlink NAS container of the fourth AS message, generates a first key generation parameter based on the terminal's temporary identifier and / or the first core network device's temporary identifier carried in the first message; generates a first NAS key based on the intermediate key and the first key generation parameter; derives the first integrity key and the first confidentiality key based on the first NAS key; calculates a first integrity check code based on the first integrity key and the integrity algorithm used between the first core network device and the terminal; performs integrity verification on the first message based on the first integrity check code and the first integrity check code; if the verification passes, the content or parameters carried in the first message are saved; if the verification fails, the first message is discarded.

[0227] For example, the first message sent by the first core network device may carry a first integrity check code calculated based on the first NAS key or the first integrity key in the first security parameters, that is, to ensure the integrity of the first message; and / or, the first message may carry encrypted data, which may be obtained by encrypting the content or parameters carried by the first message (such as at least including the temporary identifier of the terminal and / or the temporary identifier of the first core network device) based on the first NAS key or the first confidentiality key in the first security parameters.

[0228] For example, the first security parameter includes a first authenticable encryption key and EtM, a authenticable encryption algorithm used between the terminal and the first core network device. The first core network device carries ciphertext data and a first integrity verification code in the first message it sends. The ciphertext data is obtained by encrypting the plaintext data in the first message and the first integrity verification code based on the first authenticable encryption key and the authenticable encryption algorithm used between the first core network device and the terminal. The first integrity verification code is calculated from the ciphertext data based on the first authenticable encryption key and the authenticable encryption algorithm used between the first core network device and the terminal. Correspondingly, the terminal can calculate the first integrity verification code from the ciphertext data based on the first authenticable encryption key and the authenticable encryption algorithm used between the first core network device and the terminal, perform integrity verification based on the first integrity verification code and the first integrity verification code, and decrypt the ciphertext data to obtain the plaintext data if the verification passes. Alternatively, if the verification fails, the first message is discarded. It should be noted that this is merely an illustrative example, and the verifiable encryption algorithms used in actual processing may include, but are not limited to, the calculation methods in the above example; however, no limit or exhaustive list is made here.

[0229] Furthermore, if the terminal discards the first message, the terminal can try to establish a connection with the first core network device again and perform the same processing as in the scenario triggered by the aforementioned terminal, without repeating the explanation.

[0230] The following, referring to Figure 6, uses NFx (representing the first core network device), UD (representing the terminal), and DNKGF (representing the second core network device) as an example to illustrate how, after the terminal completes registration (authentication) with the MM NF, the UE triggers the establishment of a connection with NFx (e.g., the UE establishes a PDU session through the SM NF). Specifically, this includes:

[0231] S601, the RRC message sent by the UE to the AN contains a NAS-NFx container, which contains a connection establishment request (UE_NFx communication establishment request) and the UE ID (such as the UE's SUCI).

[0232] S602, the AN routes the message to the corresponding NFx. For example, as shown in Figure 6, the AN sends a connection establishment request to the NFx.

[0233] S603, NFx sends a key retrieval request to DNKGF, which may include key generation materials and UE ID.

[0234] Specifically, NFx can send a key retrieval request to DNKGF (Distribute NAS Key Generation Function) if the security context of the UE cannot be retrieved.

[0235] S604, DNKGF derived K NFx .

[0236] Specifically, DNKGF can retrieve the UE authentication results it stores (for example, the UE's authentication result will be stored in DNKGF after the initial UE authentication); or DNKGF can query AUSF / UDM to determine whether authentication needs to be triggered for the UE. If AUSF / UDM has the UE's authentication result, it determines that authentication does not need to be triggered for the UE; otherwise, authentication needs to be triggered for the UE. After obtaining the UE's authentication result (and after successful authentication), DNKGF generates a key K. NFx .

[0237] S605, DNKGF sends a key request response to NFx, which carries K NFx .

[0238] S606, NFx generates encryption and integrity keys to protect the NAS-NFx connection, and can enable integrity protection in the sent downlink signaling.

[0239] S607, NFx sends a connection establishment response to AN, which carries key generation material.

[0240] S608, the AN sends an RRC message to the UE. The RRC message contains the NAS-NFx container, which can carry a connection establishment response.

[0241] In other words, NFx can transmit some of the NFx-related parameters (key generation material) used to generate KNFx to the UE in this downlink signaling. Furthermore, the AN will send an RRC message containing the connection establishment response to the UE.

[0242] S609, the UE can generate K based on the key generation material. NFx The UE uses an encryption key and an integrity key to verify the integrity of the signaling. If verification fails, the UE needs to discard the downlink message and attempt to re-establish a connection with NFx.

[0243] In some embodiments, the terminal may be connected to the first core network device by being paged.

[0244] The processing by the first core network device may include: sending a paging message, wherein the paging message carries a protected identifier of the terminal. The processing by the terminal may include: receiving a paging message, wherein the paging message carries a protected identifier of the terminal.

[0245] In this embodiment, the protected identifier of the terminal includes at least one of the following: an encrypted permanent identifier of the terminal, and a temporary identifier of the terminal. The description of the encrypted permanent identifier of the terminal is the same as in the previous embodiments and will not be repeated. The temporary identifier of the terminal may be generated by the first core network device. In some preferred examples, the protected identifier of the terminal may at least include the temporary identifier of the terminal.

[0246] The sending of a paging message by the first core network device can include: the first core network device sending a paging message (specifically, a paging request) to the access network device. The processing by the access network device can include: receiving the paging message from the first core network device and sending a paging message to the terminal. The terminal receiving the paging message can be: receiving the paging message from the access network device. The paging message sent by the access network device to the terminal can be an RRC message (e.g., represented as an RRC message request).

[0247] The processing by the terminal after receiving the paging message may include: sending a second message, wherein the second message is used for the first core network device to establish a connection with the terminal. The processing by the first core network device may include: receiving a second message, wherein the second message is used for the first core network device to establish a connection with the terminal.

[0248] The second message is a response message to the paging message. In this embodiment, the second message can be used by the first core network device to determine that the terminal has been paged, and then to determine to initiate a connection with the terminal.

[0249] The second message may carry at least one of the following: a protected identifier of the terminal, a key identifier of the intermediate key, and an indication of the security algorithm supported by the terminal, wherein the security algorithm includes at least one of the following: a integrity protection algorithm, a confidentiality algorithm, and an authenticable encryption algorithm.

[0250] Specifically, the terminal sending the second message can be as follows: the terminal sends a second message to the access network device. The access network device's processing can include: receiving the second message from the terminal and sending the second message to the first core network device. Correspondingly, the first core network device receiving the second message can include: receiving the second message from the access network device. Here, the second message sent by the terminal to the access network device is carried in a paging message response message; more specifically, it can be an RRC message response carrying the second message for responding to a paging message. The second message sent by the access network device to the first core network device can be carried in a paging response.

[0251] After the first core network device receives the second message, it can send at least one of the following to the second core network device: the temporary identifier of the terminal, or the temporary identifier of the first core network device. Correspondingly, the second core network device can process the following by receiving at least one of the following from the first core network device: the temporary identifier of the terminal, or the temporary identifier of the first core network device. The related processing of the first and second core network devices after the first core network device receives the second message until it receives the first NAS key is similar to the processing in the aforementioned embodiment where the terminal triggers the establishment of a connection with the first core network device. The only difference is that in this embodiment, the first core network device can carry the temporary identifier of the terminal when sending the paging message. All other related processing is the same and will not be elaborated further.

[0252] After receiving the first NAS key from the second core network device, the first core network device can perform the following processing: sending a first message, wherein the first message is used by the terminal to determine that a connection has been established with the first core network device. The terminal's processing may include: receiving the first message, wherein the first message is used by the terminal to determine that a connection has been established with the first core network device. Regarding the processing after the first core network device receives the first NAS key until the first core network device sends the first message, and the terminal's processing after receiving the first message, is the same as the processing in the aforementioned embodiment where the terminal triggers the establishment of a connection with the first core network device, therefore, it will not be described in detail.

[0253] Referring to Figure 7, and taking the first core network device as NFx, the terminal as UD, and the second core network device as DNKGF as an example, the following illustrative explanation is provided regarding the network-triggered communication establishment process after the terminal completes registration (authentication) with the MM NFx. Specifically, this includes:

[0254] S701, NFx sends a paging request to AN, which carries the UE ID, which may include: an encrypted permanent UE identifier (e.g., the UE's SUCI), and / or a temporary identifier assigned to the UE by NFx.

[0255] S702, the AN sends an RRC message request to the UE, which carries the UE ID.

[0256] S703, the UE sends an RRC message response to the AN, which includes the UE ID.

[0257] S704, AN sends a paging response (carrying the UE ID) to NFx.

[0258] The specific processing of S705 to S711 is the same as that of S603 to S609 in the example of Figure 6 above, and will not be repeated.

[0259] Referring to Figure 8, taking the terminal as UE and the core network side including DNKGF (i.e., the second core network device), NFx (the first core network device), and AUSF (the third core network device) as an example, let's examine the intermediate key K. DNKGF The derivation and security algorithm negotiation processes are illustrated by example.

[0260] S801, after the UE and the network (authentication and authorization function) authenticate each other, the UE and the authentication and authorization function (such as UDM) can generate key K based on the root key K. AUSF .

[0261] S802, authentication and authorization functions (such as UDM) will K AUSF Send to AUSF.

[0262] S803, AUSF uses key K AUSF Generate key K DNKGF AUSF sends K DNKGF The key KDNKGF is generated by providing the input parameters, which include at least one of the following: the string "DNKGM", the UE's permanent identifier (e.g., SUPI in 5G, or the UE's permanent identifier in 6G).

[0263] AUSF and / or UE can also generate K DNKGFThe key identifier D-KID can be used by the UE to trigger connection establishment with the NFx. Specifically, the connection establishment request includes the DDNKGF key identifier, enabling the NFx to request a key from a specific DNKGF. The key identifier D-KID can consist of two parts: RID and D-TID. The RID is included in the SUPI, and the generation parameters of the D-TID include at least one of the following: the string "D-TID", and the UE ID (e.g., the UE's permanent identifier SUPI). The generated input key is K... AUSF .

[0264] S804, Security Algorithm Selection. The process for selecting the security algorithm is the same as that in the previous embodiments, and will not be described again.

[0265] Referring to Figure 9, an exemplary illustration of the key derivation architecture involved in the embodiments of this application is provided. UDM can derive CK,IK based on the root key K; and UDM can further derive K based on CK,IK. AUSF Concurrently sent to AUSF; AUSF is based on K AUSF (i.e., the parent key) derives K DNKGF (i.e., the intermediate key) is sent to DNKGF; DNKGF then uses K... DNKGF The NAS keys corresponding to the derived UE and each of the i NFs are (e.g., represented as Knf1, Knf2, Knf3 to Knfi in Figure 9, where i is an integer greater than 3). The key K between the UE and NFx (any NF) is... NFx Will be generated by DNKGF, K NFx The input key for generation is: K DNKGF K NFx The generated input parameters include at least one of the following: the identifier assigned to the UE by NFx; the instance ID of NFx; NAS type: NFx; and the temporary identifier of NFx.

[0266] It should be noted that the above exemplary description of Figure 9 is based on the derivation of various keys between core network side devices. The terminal can also use the same key derivation architecture as Figure 9 to derive keys. However, the key transmission is no longer required in the process of deriving the various keys shown in Figure 9 on the terminal side. For the sake of simplicity, this will not be repeated here.

[0267] It should also be noted that the example provided in Figure 9 uses only K. AUSF Generate K DNKGF Then by K DNKGF Derivative K NFx The illustration is based on an example, but Figure 9 does not represent the actual derived K. DNKGF and / or derived K NFx The constraints are generated by all possible methods. For example, in practical processing, KDNKGF It can be generated using other keys derived from the root key K, such as keys based on K. SEAF Generate K DNKGF Alternatively, K can be omitted. DNKGF Instead, use K directly. AUSF or K SEAF Derivative K NFx (For example, Knf1, Knf2, Knf3~Knfi), which will not be elaborated here.

[0268] In terms of related technologies, a proposed 6G architecture for 6G systems is the Distributed Non-Access-Stratum (NAS) architecture. This architecture supports independent distributed NAS termination between User Equipment (UE) and its corresponding 6G network functions. Under this architecture, various functions within a 6G UE can directly transmit signaling or messages with appropriate Network Functions (NFs) without needing to transmit signals, signaling, or messages with NFs on the core network side through a single termination point (such as the Access and Management Functions (AMF) in a 5G system). Therefore, regardless of the location of the UE or individual NFs, the UE should be able to communicate directly with each other through the 6G Radio Access Network (RAN) and the 6G Core Network Network Functions (CN NFs).

[0269] The design motivations for the distributed NAS architecture include: to fully leverage the potential of SBI-N2, i.e., the ability of 6G-RAN and 6G-CN NFs to communicate directly with each other without being limited by their location, a fully distributed NAS node is needed in 6G, so that even functions in 6G-UE can signal with appropriate network functions without signaling through a single node in the core network; to facilitate the addition and removal of new services and functions, and to make the entire system easy to modify and evolve by leveraging the SBA (Service-Oriented Architecture) principle; and to enable secure associations for each service, which enhances security, with service-specific security keys only used by network functions that require them.

[0270] Distributed NAS architecture offers the following advantages: simplified signaling between NFs and between UE and NFs, maximized parallel operation and minimized processing latency, increased flexibility, optimized signaling, maximized functionality within NFs, minimized inter-NF dependencies, and effective utilization of network resources (e.g., computing, transmission).

[0271] However, in existing 5G security, the UE connects to the Access and Mobility Management Function (AMF) via the N1 interface. The AMF can route different signaling from the UE to other network elements, and the UE only establishes a NAS secure connection with the AMF. If a distributed NAS architecture is to be introduced in 6G, different connections will be established between the UE and different NFs. To ensure secure isolation between the UE and different NFs, the security contexts used by the UE and different NFs must be different. Specifically, the keys used to protect transport security (or NAS keys) should be different between the UE and different NFs. Therefore, the NAS security in existing 5G security is clearly not applicable to a distributed NAS architecture. Furthermore, considering that NF network element information is sensitive information within the network, exposing internal network information (such as network element identifiers) may lead to network attacks. Therefore, when establishing security contexts between the UE and different network elements, methods that expose internal network information should be avoided as much as possible.

[0272] This disclosure provides an authentication and key establishment scheme during the initial registration process. Specifically, after UE authentication with the network, secure materials can be derived for the Distributed NAS key management function DNKMF, and a key between the UE and the MM NF can be generated. Furthermore, it provides key derivation methods during the process of establishing a secure connection between the UE and the NFx in the core network, which can be either initiated by the UE or initiated by the NF through paging a specific UE via the AN. Additionally, it provides a key architecture under the distributed NAS architecture, and a method for negotiating encryption, integrity, and authentication algorithms between the UE and the NFx.

[0273] By adopting the solution provided in this disclosure, the terminal can generate multiple NAS keys with the core network equipment, and different NAS keys are used to protect NAS messages transmitted between different terminals and different core network equipment. In this way, it can be ensured that the terminal can generate different NAS keys with different core network equipment under a distributed NAS architecture, thereby ensuring that the terminal can establish different secure connections with different core network equipment.

[0274] Figure 10 is a schematic diagram of the composition structure of a terminal according to an embodiment of this application, including:

[0275] The first processing unit 1001 is used to generate a first non-access stratum NAS key between the terminal and a first core network device. The first NAS key is one of a plurality of NAS keys that the terminal can generate between the terminal and multiple core network devices. Different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices.

[0276] The first processing unit is configured to generate a first NAS key between itself and the first core network device based on an intermediate key, wherein the intermediate key is an intermediate key between the second core network device and the terminal.

[0277] The first processing unit is configured to generate a first NAS key between itself and the first core network device based on the intermediate key and the first key generation parameters, wherein the first key generation parameters include at least one of the following: a permanent identifier of the terminal, a temporary identifier of the terminal, a temporary identifier of the first core network device, and type information corresponding to the first NAS key.

[0278] As shown in Figure 10, the terminal also includes:

[0279] The first communication unit 1002 is used to send a registration request, wherein the registration request is used to trigger authentication between the first core network device and the terminal.

[0280] The first processing unit is used to generate the intermediate key.

[0281] The second core network device includes one of the following: Authentication Server Function (AUSF) or Security Anchor Function (SEAF).

[0282] The second core network device includes a key management function. The first processing unit is used to generate an intermediate key between the terminal and the key management function based on the upper-level key and the second key generation parameters. The upper-level key includes one of the following: the key between the terminal and AUSF, and the key between the terminal and SEAF. The second key generation parameters include at least one of the following: the permanent identifier of the terminal, and a string used to represent the intermediate key between the terminal and the key management function.

[0283] The key identifier of the intermediate key includes at least one of the following: a routing identifier contained in the permanent identifier of the terminal, and a temporary identifier corresponding to the intermediate key, wherein the temporary identifier corresponding to the intermediate key is generated based on the parent key and at least one of the following parameters: a string used to represent the temporary identifier, and the permanent identifier of the terminal.

[0284] The registration request carries indication information of the security algorithms supported by the terminal, wherein the security algorithms include at least one of the following: integrity protection algorithm, confidentiality algorithm, and authenticable encryption algorithm.

[0285] The first communication unit is configured to receive at least one of the following: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

[0286] The first communication unit is configured to receive a first message, wherein the first message is used by the terminal to determine that a connection has been established with the first core network device.

[0287] The first message carries at least one of the following protected by a first security parameter: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

[0288] The first security parameter includes at least one of the following: the first NAS key, a first integrity key derived from the first NAS key, a first confidentiality key derived from the first NAS key, and a first authenticable encryption key derived from the first NAS key.

[0289] The first communication unit is used to send a second message, wherein the second message is used for the first core network device to establish a connection with the terminal.

[0290] The second message carries a connection establishment request.

[0291] The first communication unit is configured to receive a paging message, wherein the paging message carries a protected identifier of the terminal.

[0292] The second message is a response message to the paging message.

[0293] The second message carries at least one of the following: a protected identifier of the terminal, a key identifier of the intermediate key, and an indication of the security algorithm supported by the terminal, wherein the security algorithm includes at least one of the following: a integrity protection algorithm, a confidentiality algorithm, and an authenticable encryption algorithm.

[0294] The protected identifier of the terminal includes at least one of the following: an encrypted permanent identifier of the terminal, or a temporary identifier of the terminal.

[0295] Figure 11 is a schematic diagram of the composition structure of a first core network device according to an embodiment of this application, including:

[0296] The second communication unit 1101 is used to receive a first NAS key between the terminal and the first core network device from the second core network device, wherein the first NAS key is used to protect the NAS messages transmitted between the terminal and the first core network device.

[0297] The second communication unit is configured to send at least one of the following to the second core network device: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

[0298] The second communication unit is used to receive a registration request, wherein the registration request is used to trigger authentication between the first core network device and the terminal.

[0299] The registration request carries indication information of the security algorithms supported by the terminal, wherein the security algorithms include at least one of the following: integrity protection algorithm, confidentiality algorithm, and authenticable encryption algorithm.

[0300] The second communication unit is configured to send at least one of the following to the terminal: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

[0301] The second communication unit is used to send a first message, wherein the first message is used by the terminal to determine that a connection has been established with the first core network device.

[0302] The first message carries at least one of the following protected based on a first security parameter: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

[0303] The first security parameter includes at least one of the following: the first NAS key, a first integrity key derived from the first NAS key, a first confidentiality key derived from the first NAS key, and a first authenticable encryption key derived from the first NAS key.

[0304] The second communication unit is used to receive a second message, wherein the second message is used for the first core network device to establish a connection with the terminal.

[0305] The second message carries a connection establishment request.

[0306] The second communication unit is used to send a paging message, wherein the paging message carries a protected identifier of the terminal.

[0307] The second message is a response message to the paging message.

[0308] The second message carries at least one of the following: a protected identifier of the terminal, a key identifier of the intermediate key, and an indication of the security algorithm supported by the terminal, wherein the security algorithm includes at least one of the following: a integrity protection algorithm, a confidentiality algorithm, and an authenticable encryption algorithm.

[0309] The protected identifier of the terminal includes at least one of the following: an encrypted permanent identifier of the terminal, or a temporary identifier of the terminal.

[0310] The second communication unit is configured to perform one of the following: obtain the security algorithm used by the terminal from the core network device of the service domain where the terminal first establishes a connection; or obtain the security algorithm used by the terminal from the second core network device.

[0311] The second core network device includes one of the following: Authentication Server Function (AUSF), Security Anchor Function (SEAF), and Key Management Function.

[0312] Figure 12 is a schematic diagram of the composition structure of a second core network device according to an embodiment of this application, including:

[0313] The third processing unit 1201 is used to generate a first NAS key between the terminal and the first core network device. The first NAS key is one of a plurality of NAS keys between the terminal and multiple core network devices that can be generated by the second core network device. Different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices.

[0314] The third communication unit 1202 is used to send the first NAS key to the first core network device.

[0315] The third processing unit is configured to generate the first NAS key between the terminal and the first core network device based on the intermediate key, wherein the intermediate key is the intermediate key between the second core network device and the terminal.

[0316] The third processing unit is configured to generate the first NAS key between the terminal and the first core network device based on the intermediate key and the first key generation parameters, wherein the first key generation parameters include at least one of the following: the permanent identifier of the terminal, the temporary identifier of the terminal, the temporary identifier of the first core network device, and the type information corresponding to the first NAS key.

[0317] The third communication unit is used to receive the intermediate key.

[0318] The third communication unit is configured to receive at least one of the following from the first core network device: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

[0319] The second core network device includes one of the following: Authentication Server Function (AUSF), Security Anchor Function (SEAF), and Key Management Function.

[0320] The device in this application embodiment can realize the corresponding functions of the various devices in the foregoing communication method embodiments. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in this device can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the device of this application embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).

[0321] It should be understood that the sequence number of each process in the various embodiments of this application does not imply the order of execution; the execution order of each process should be determined by its function and internal logic. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. The above descriptions are merely specific embodiments of this application, and the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A key processing method executed by a terminal, comprising: Generate a first non-access stratum NAS key between the terminal and a first core network device, wherein the first NAS key is one of a plurality of NAS keys that the terminal can generate between the terminal and multiple core network devices, and different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices.

2. The method according to claim 1, wherein, The generation of the first NAS key between the first core network device and the first NAS key includes: The first NAS key between the second core network device and the first core network device is generated based on the intermediate key, wherein the intermediate key is the intermediate key between the second core network device and the terminal.

3. The method according to claim 2, wherein, The generation of the first NAS key between the intermediate key and the first core network device includes: Based on the intermediate key and the first key generation parameters, a first NAS key is generated between the terminal and the first core network device. The first key generation parameters include at least one of the following: the permanent identifier of the terminal, the temporary identifier of the terminal, the temporary identifier of the first core network device, and the type information corresponding to the first NAS key.

4. The method according to claim 2 or 3, wherein, The method further includes: Send a registration request, wherein the registration request is used to trigger authentication between the first core network device and the terminal.

5. The method according to claim 4, wherein, The method further includes: Generate the intermediate key.

6. The method according to any one of claims 2-5, wherein, The second core network device includes one of the following: Authentication Server Function (AUSF) or Security Anchor Function (SEAF).

7. The method according to claim 5, wherein, The second core network device includes a key management function, wherein generating an intermediate key includes: An intermediate key between the terminal and the key management function is generated based on the upper-level key and the second key generation parameters. The upper-level key includes one of the following: the key between the terminal and AUSF, and the key between the terminal and SEAF. The second key generation parameters include at least one of the following: the permanent identifier of the terminal, and a string used to represent the intermediate key between the terminal and the key management function.

8. The method according to claim 7, wherein, The key identifier of the intermediate key includes at least one of the following: a routing identifier contained in the permanent identifier of the terminal, and a temporary identifier corresponding to the intermediate key, wherein the temporary identifier corresponding to the intermediate key is generated based on the parent key and at least one of the following parameters: a string used to represent the temporary identifier, and the permanent identifier of the terminal.

9. The method according to any one of claims 4-8, wherein, The registration request carries indication information of the security algorithms supported by the terminal, wherein the security algorithms include at least one of the following: integrity protection algorithm, confidentiality algorithm, and authenticable encryption algorithm.

10. The method according to any one of claims 4-9, wherein, The method further includes: Receive at least one of the following: the temporary identifier of the terminal, or the temporary identifier of the first core network device.

11. The method according to claim 2 or 3, wherein, The method further includes: The terminal receives a first message, wherein the first message is used for the terminal to determine that a connection has been established with the first core network device.

12. The method according to claim 11, wherein, The first message carries at least one of the following protected by a first security parameter: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

13. The method according to claim 12, wherein, The first security parameter includes at least one of the following: the first NAS key, a first integrity key derived from the first NAS key, a first confidentiality key derived from the first NAS key, and a first authenticable encryption key derived from the first NAS key.

14. The method according to any one of claims 11-13, wherein, The method further includes: Send a second message, wherein the second message is used for the first core network device to establish a connection with the terminal.

15. The method according to claim 14, wherein, The second message carries a connection establishment request.

16. The method of claim 14, wherein, The method further includes: Receive a paging message, wherein the paging message carries a protected identifier of the terminal.

17. The method according to claim 16, wherein, The second message is a response message to the paging message.

18. The method according to any one of claims 14-17, wherein, The second message carries at least one of the following: a protected identifier of the terminal, a key identifier of the intermediate key, and an indication of the security algorithm supported by the terminal, wherein the security algorithm includes at least one of the following: a integrity protection algorithm, a confidentiality algorithm, and an authenticable encryption algorithm.

19. The method according to claim 16 or 18, wherein, The protected identifier of the terminal includes at least one of the following: an encrypted permanent identifier of the terminal, or a temporary identifier of the terminal.

20. A key processing method performed by a first core network device, comprising: The terminal receives a first NAS key from the second core network device and the first core network device, wherein the first NAS key is used to protect NAS messages transmitted between the terminal and the first core network device.

21. The method according to claim 20, wherein, The method further includes: Send at least one of the following to the second core network device: the temporary identifier of the terminal, or the temporary identifier of the first core network device.

22. The method according to claim 20 or 21, wherein, The method further includes: A registration request is received, wherein the registration request is used to trigger authentication between the first core network device and the terminal.

23. The method according to claim 22, wherein, The registration request carries indication information of the security algorithms supported by the terminal, wherein the security algorithms include at least one of the following: integrity protection algorithm, confidentiality algorithm, and authenticable encryption algorithm.

24. The method according to claim 22 or 23, wherein, The method further includes: Send at least one of the following to the terminal: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

25. The method according to claim 20 or 21, wherein, The method further includes: Send a first message, wherein the first message is used by the terminal to confirm that a connection has been established with the first core network device.

26. The method of claim 25, wherein, The first message carries at least one of the following protected based on a first security parameter: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

27. The method according to claim 26, wherein, The first security parameter includes at least one of the following: the first NAS key, a first integrity key derived from the first NAS key, a first confidentiality key derived from the first NAS key, and a first authenticable encryption key derived from the first NAS key.

28. The method according to any one of claims 25-27, wherein, The method further includes: Receive a second message, wherein the second message is used for the first core network device to establish a connection with the terminal.

29. The method according to claim 28, wherein, The second message carries a connection establishment request.

30. The method according to claim 28, wherein, The method further includes: Send a paging message, wherein the paging message carries a protected identifier of the terminal.

31. The method according to claim 30, wherein, The second message is a response message to the paging message.

32. The method according to any one of claims 28-31, wherein, The second message carries at least one of the following: a protected identifier of the terminal, a key identifier of the intermediate key, and an indication of the security algorithm supported by the terminal, wherein the security algorithm includes at least one of the following: a integrity protection algorithm, a confidentiality algorithm, and an authenticable encryption algorithm.

33. The method according to claim 29 or 32, wherein, The protected identifier of the terminal includes at least one of the following: an encrypted permanent identifier of the terminal, or a temporary identifier of the terminal.

34. The method according to any one of claims 25-32, wherein, The method also includes one of the following: The security algorithm used by the terminal is obtained from the core network device of the service domain where the terminal first establishes a connection. Obtain the security algorithm used by the terminal from the second core network device.

35. The method according to any one of claims 20-34, wherein, The second core network device includes one of the following: Authentication Server Function (AUSF), Security Anchor Function (SEAF), and Key Management Function.

36. A key processing method performed by a second core network device, comprising: Generate a first NAS key between the terminal and the first core network device, wherein the first NAS key is one of a plurality of NAS keys between the terminal and multiple core network devices that can be generated by the second core network device, and different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices; Send the first NAS key to the first core network device.

37. The method of claim 36, wherein, The first NAS key between the generating terminal and the first core network device includes: The first NAS key between the terminal and the first core network device is generated based on the intermediate key, wherein the intermediate key is the intermediate key between the second core network device and the terminal.

38. The method according to claim 37, wherein, The process of generating the first NAS key between the terminal and the first core network device based on the intermediate key includes: Based on the intermediate key and the first key generation parameters, a first NAS key is generated between the terminal and the first core network device, wherein the first key generation parameters include at least one of the following: the permanent identifier of the terminal, the temporary identifier of the terminal, the temporary identifier of the first core network device, and the type information corresponding to the first NAS key.

39. The method according to claim 37 or 38, wherein, The method further includes: Receive the intermediate key.

40. The method according to any one of claims 36-39, wherein, The method further includes: Receive at least one of the following from the first core network device: a temporary identifier of the terminal, or a temporary identifier of the first core network device.

41. The method according to any one of claims 36-40, wherein, The second core network device includes one of the following: Authentication Server Function (AUSF), Security Anchor Function (SEAF), and Key Management Function.

42. A terminal, comprising: The first processing unit is configured to generate a first non-access stratum NAS key between the terminal and a first core network device. The first NAS key is one of a plurality of NAS keys that the terminal can generate between the terminal and multiple core network devices. Different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices.

43. A first core network device, comprising: The second communication unit is used to receive a first NAS key between the terminal and the first core network device from the second core network device, wherein the first NAS key is used to protect the NAS messages transmitted between the terminal and the first core network device.

44. A second core network device, comprising: The third processing unit is used to generate a first NAS key between the terminal and the first core network device. The first NAS key is one of a plurality of NAS keys between the terminal and multiple core network devices that can be generated by the second core network device. Different NAS keys among the plurality of NAS keys are used to protect NAS messages transmitted between the terminal and different core network devices. The third communication unit is used to send the first NAS key to the first core network device.

Citation Information

Patent Citations

  • Methods and network entity for sending public warning system (PWS) key information to terminal

    CN102821385A

  • Key determination method and device, storage medium and electronic device

    CN110830997A

  • Safety protection method and device for air interface information

    CN112601222A

  • System and method for event processing order guarantee

    US20190296960A1