Communication method for performing tracking area update, and terminal
By sending reason value 23 when no authentication request is received, the terminal negotiates a new security algorithm and key with the core network, which solves the problem of tracking area update failure and achieves business continuity and security.
Patent Information
- Application Number
- PCT/CN2025/094447
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-29
- Filing Date
- 2025-05-13
- Publication Date
- 2026-01-02
AI Technical Summary
In mobile communication networks, tracking area update failures lead to terminal service interruptions, and existing technologies cannot effectively solve this problem.
When the terminal does not receive a core network authentication request, it sends a security mode rejection message with the reason value 23, triggering the core network to reselect a security algorithm and calculate the key using the parameters carried to complete the tracking area update.
It reduces the probability of tracking area update failure, ensures business continuity and maintains the security of data transmission, and avoids three SMC failures and business interruptions caused by incorrect cause values.
Smart Images

Figure CN2025094447_02012026_PF_FP_ABST
Abstract
Description
Communication method and terminal for performing tracking area update
[0001] The present application claims priority to the Chinese patent application No. 202410870723.0, filed on June 29, 2024, and entitled "Communication method and terminal for performing tracking area update", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the technical field of terminals and communication, and in particular to a communication method and terminal for performing tracking area update. BACKGROUND
[0003] In a mobile communication network, a tracking area (TA) is a set of adjacent cells or base stations, which is used to manage the location update of a terminal. When a terminal enters a tracking area, the core network can obtain the code of the tracking area (tracking area code) where the terminal is located, so that the core network can accurately track the location of the terminal and provide some location-related services for the terminal.
[0004] Compared with the scheme of reporting location update to the core network every time the cell is switched, by setting the tracking area, the terminal only needs to synchronize the location information with the core network when updating the tracking area, and does not need to frequently update the location information to the core network when moving within the same tracking area. This can reduce the frequency of location update and reduce the burden of the communication system.
[0005] In some scenarios, tracking area update failure may occur. SUMMARY
[0006] The present application provides a communication method and terminal for performing tracking area update to reduce the probability of tracking area update failure.
[0007] In a first aspect, the present application provides a method for tracking area updating, applied to a terminal, the terminal accesses a first cell and communicates with a first core network through an access network device corresponding to the first cell, the method comprising: switching from the first cell to a second cell, the second cell and the first cell belong to different tracking areas; sending a tracking area update request to the first core network; in the case that a first security mode command sent by the first core network is received, but an authentication request responding to the tracking area update request sent by the first core network is not received, sending a first security mode rejection message responding to the first security mode command to the first core network; the authentication request comprises parameters for calculating a security algorithm; the first security mode command carries first indication information, the first indication information is used to indicate that the first algorithm is used as the security algorithm; the security algorithm is determined by the first core network based on security capability information sent by the terminal; the security capability information carries the security algorithm supported by the terminal, including the first algorithm and a second algorithm; the first security mode rejection message carries a reason value 23, the reason value 23 indicates that the terminal does not support the first algorithm; the reason value 23 is used to trigger the first core network to send a first authentication request and a second security mode command to the terminal; the first authentication request carries a first parameter; the second security mode command carries second indication information, the second indication information is used to indicate that the second algorithm is used as the security algorithm; the first parameter is used by the terminal to calculate the key of the second algorithm.
[0008] In the above embodiment, when performing the tracking area update process, in the scenario that the core network (the first core network, which can be the core network 1 involved in the embodiment) cannot send an authentication request to the terminal after receiving the tracking area update message sent by the terminal, but sends a security mode command (SMC), the terminal will return a security mode rejection message to the core network, and carries a reason value 23 for rejecting the security mode in the security mode rejection message instead of a reason value 24, and successfully implements tracking area update. The reason value 24 is a reason value that the terminal needs to feed back to the core network in this case, and the reason value 24 indicates that the reason for rejecting the security mode is unknown. However, feeding back the reason value 24 will cause the terminal to be in a scenario of three times of SMC failure (for details, please refer to the description of FIG. 4 and FIG. 5 and related contents below), and finally cause tracking area update failure, and further cause terminal service interruption. The reason value 23 is used to inform the core network that the terminal does not support the first algorithm (which can be algorithm 1 involved in the embodiment), so as to prompt the core network to reselect a security algorithm, and then reacquire parameters required for calculating the security algorithm, and send the parameters to the terminal in the authentication request, so that the terminal can calculate the key of the security algorithm, and then complete the tracking area update.
[0009] In a second aspect, the embodiments of the present application provide a method for tracking area updating, applied to a terminal, the terminal accesses a first cell and communicates with a first core network through an access network device of the first cell, and the method comprises the following steps:
[0010] In the case of processing the first service, switching from the first cell to a second cell, the second cell and the first cell belong to different tracking areas; sending a tracking area update request to the first core network; in the case that no authentication request responding to the tracking area update request is received from the first core network, but a first security mode command is received from the first core network, and the priority of the first service is lower than a preset level, sending a first security mode rejection message responding to the first security mode command to the first core network; the authentication request comprises parameters for calculating a key of a security algorithm; the first security mode command carries first indication information, the first indication information is used to indicate that the first algorithm is used as the security algorithm; the security algorithm is determined by the first core network based on security capability information sent by the terminal; the security capability information carries the security algorithms supported by the terminal, including the first algorithm and a second algorithm; the first security mode rejection message carries a reason value 23, the reason value 23 indicates that the terminal does not support the first algorithm; the reason value 23 is used to trigger the first core network to send a first authentication request and a second security mode command to the terminal; the first authentication request carries a first parameter; the second security mode command carries second indication information, the second indication information is used to indicate that the second algorithm is used as the security algorithm; and the first parameter is used by the terminal to calculate the key of the second algorithm.
[0011] In the above embodiments, after sending the reason value 23, the second algorithm (algorithm 2 in the embodiments) selected by the core network is not the preferred security algorithm of the core network, and the first algorithm (algorithm 1 in the embodiments) is the preferred one. Considering the logic of the core network to select the security algorithm, in order to avoid the second algorithm being not suitable for the first service and affecting the security of the first service, it is stipulated here that the reason value 23 can be sent only in the case that the priority of the first service is lower than a preset level. The priority lower than the preset level indicates that the first service itself has a low requirement for security, and therefore the use of the second algorithm will not affect the security of the first service.
[0012] In combination with the second aspect, in some embodiments, the method further comprises: in the case that the authentication request sent by the first core network in response to the tracking area update request is not received, but the first security mode command sent by the first core network is received, and the priority of the first service is higher than the preset level, after receiving the first security mode command sent by the first core network, sending a second security mode reject message in response to the first security mode command to the first core network; the second security mode reject message carries a cause value 24, which indicates that the reason for rejecting the security mode is unknown; in the case that the authentication request sent by the first core network is still not received, but the first security mode command sent by the first core network in response to the second security mode reject message is received, the terminal releases the connection with the second cell and initiates scanning to find an available cell.
[0013] In the above embodiments, when the priority of the first service is higher than the preset level, it indicates that the first service has higher security requirements, and in this case, the cause value 23 is not suitable for prompting the core network to select a new security algorithm. Instead, the cause value 24 is used, and the security algorithm preferred by the core network (the first algorithm) is not changed. Although the scheme of sending the cause value 24 may cause service interruption (the reason for the interruption can be referred to the description of FIG. 4 and FIG. 5 and related contents below), after the terminal finds an available cell, the terminal can still communicate with the core network and the security algorithm can meet the service requirements, and the loss of service interruption is smaller than the loss of service information leakage.
[0014] In a third aspect, the embodiments of the present application provide a method for tracking area updating, applied to a terminal, the terminal accesses a first cell and communicates with a first core network through an access network device of the first cell, the method comprising: switching from the first cell to a second cell in a case of processing a first service, the second cell and the first cell belong to different tracking areas; sending a tracking area update request to the first core network; in a case of not receiving an authentication request sent by the first core network in response to the tracking area update request, but receiving a first security mode command sent by the first core network, calculating a key of the first algorithm based on a second parameter; the authentication request comprises a parameter for calculating a key of a security algorithm; the first security mode command carries first indication information, the first indication information is used to indicate that the first algorithm is used as the security algorithm; the security algorithm is determined by the first core network based on security capability information sent by the terminal; the security capability information carries a security algorithm supported by the terminal, which comprises the first algorithm and a second algorithm; the second parameter is a parameter sent by the first core network to the terminal for calculating a key of a third algorithm; the third algorithm is a security algorithm used by the terminal in a tracking area of the first cell; sending a first security mode complete message in response to the first security mode command to the first core network; the first security mode complete message carries a first verification value; the first verification value is generated based on the key of the first algorithm, and is used to verify whether the key of the first algorithm is correct; in a case that the key of the first algorithm is incorrect, the first security mode command sent by the first core network is received again, but the authentication request sent by the first core network is still not received; sending a first security mode reject message in response to the first security mode command to the first core network; the first security mode reject message carries a reason value 23, the reason value 23 indicates that the terminal does not support the first algorithm; the reason value 23 is used to trigger the first core network to send a first authentication request and a second security mode command to the terminal; the first authentication request carries a first parameter; the second security mode command carries second indication information, the second indication information is used to indicate that the second algorithm is used as the security algorithm; the first parameter is used by the terminal to calculate a key of the second algorithm.
[0015] In the above embodiments, in a case that the terminal does not receive an authentication request sent by the core network in response to the tracking area update request, but receives a security mode command sent by the core network, the key of the first algorithm can be calculated using the second parameter (the original parameter, for example, the parameter for calculating the key of the algorithm 0 in the embodiments). The second parameter is sent by the core network to the terminal, and is used to calculate the key of the security algorithm used in the original tracking area. In this way, the terminal is provided with an opportunity to attempt to retain the first algorithm. If the key calculated using the second parameter is incorrect, the scheme of sending the reason value 23 can be implemented again, so that the tracking area update can be successful.
[0016] With reference to the third aspect, in some embodiments, the method further comprises: receiving, in the case that the key of the first algorithm is correct, a tracking area update accept message sent by the first core network in response to the tracking area update request; processing the first data of the first service by the first algorithm and the key of the first algorithm, and transmitting the processed first data to the first core network through the access network device of the second cell.
[0017] In the above embodiments, if the key of the first algorithm is calculated correctly, the terminal and the core network can use the first algorithm and the key of the first algorithm to transmit data in the new tracking area. In this way, the first algorithm is the security algorithm preferred by the core network, which is consistent with the logic of the core network selecting a security algorithm, and is conducive to ensuring the security of the service when the service is performed in the new tracking area.
[0018] With reference to any one of the first aspect, the second aspect or the third aspect, in some embodiments, after sending the first security mode reject message in response to the first security mode command to the first core network, the method further comprises: receiving the first authentication request sent by the first core network, and receiving the second security mode command sent by the first core network; calculating the key of the second algorithm based on the first parameter; processing the first data of the first service by the second algorithm and the key of the second algorithm, and transmitting the processed first data to the first core network through the access network device of the second cell.
[0019] In the above embodiments, after sending the cause value 23, the terminal can receive the parameters required for calculating the security algorithm again, calculate the key of the security algorithm based on the parameters, and thus make the tracking area update successful.
[0020] With reference to the second aspect or the third aspect, in some embodiments, the condition that the first security mode command carries the first indication information comprises: determining that the priority of the first algorithm is higher than that of the second algorithm based on the first service and / or the network condition of the tracking area in which the second cell is located.
[0021] With reference to any one of the first aspect, the second aspect or the third aspect, in some embodiments, after calculating the key of the second algorithm based on the first parameter, and before processing the first data of the first service by the second algorithm and the key of the second algorithm, the method further comprises: sending a second security mode complete message in response to the second security mode command to the first core network; the second security mode complete message carries a second verification value; the second verification value is generated based on the key of the second algorithm, and is used to verify whether the key of the second algorithm is correct; and in the case that the key of the second algorithm is correct, receiving a tracking area update accept message sent by the first core network in response to the tracking area update request.
[0022] In the above embodiment, the correctness of the key of the security algorithm calculated by the terminal can be verified by verifying the value, thereby ensuring the consistency of the key of the security algorithm at both ends of the terminal and the core network.
[0023] With reference to any one of the first aspect, the second aspect or the third aspect, in some embodiments, the authentication request sent by the first core network in response to the tracking area update request is not received, but the first security mode command sent by the first core network is received, specifically including: before the first security mode command sent by the first core network is received after the tracking area update request is sent to the first core network, the authentication request sent by the first core network in response to the tracking area update request is not received.
[0024] In the above embodiment, a reasonable time for the terminal to determine that the authentication request is not received is provided.
[0025] With reference to any one of the first aspect, the second aspect or the third aspect, in some embodiments, the first core network is a 4G core network.
[0026] In a fourth aspect, the embodiments of the present application provide a terminal, which comprises one or more processors and a memory; the memory is coupled with the one or more processors, and the memory is used to store computer program codes, the computer program codes comprising computer instructions, and the one or more processors invoke the computer instructions to enable the terminal to perform the method implemented in the first aspect.
[0027] In a fifth aspect, the embodiments of the present application provide a computer readable storage medium comprising instructions, which, when executed on a terminal, enable the terminal to perform the method implemented in the first aspect.
[0028] In a sixth aspect, the embodiments of the present application provide a chip system applied to a terminal, which comprises one or more processors configured to invoke computer instructions to enable the terminal to perform the method implemented in the first aspect. The chip system can be a system-on-chip (SoC). The processor can comprise a modem processor (also known as a Modem or a baseband chip).
[0029] In a seventh aspect, the embodiments of the present application provide a computer program product comprising instructions, which, when executed on a terminal, enable the terminal to perform the method implemented in the first aspect.
[0030] It can be understood that the terminal provided by the fourth aspect, the computer storage medium provided by the fifth aspect, the chip system provided by the sixth aspect and the computer program product provided by the seventh aspect are all used to execute the method provided by the embodiments of the present application. Therefore, other beneficial effects achieved thereby can refer to the beneficial effects in the corresponding method, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0031] FIG. 1 shows an exemplary scenario involved when successfully negotiating a security algorithm and calculating a key of the security algorithm during a tracking area update;
[0032] FIG. 2 shows an exemplary communication system involved when performing a TAU procedure;
[0033] FIG. 3 shows an exemplary flowchart involved when performing a TAU procedure between a terminal and a core network and when successful;
[0034] FIG. 4 shows an exemplary scenario involved when performing a TAU procedure between a terminal and a core network and when unsuccessful;
[0035] FIG. 5 shows an exemplary flowchart involved when performing a TAU procedure during a tracking area update of a terminal and when unsuccessful, resulting in service interruption;
[0036] FIG. 6 shows an exemplary scenario involved when a terminal does not receive an authentication request message but accepts a security mode command, and successfully performs a TAU procedure by sending a cause value 23;
[0037] FIG. 7 shows an exemplary flowchart involved when a terminal does not receive an authentication request message but accepts a security mode command, and successfully performs a TAU procedure by sending a cause value 23;
[0038] FIG. 8 shows an exemplary flowchart involved when a terminal does not receive an authentication request message but accepts a security mode command, and performs a TAU procedure;
[0039] FIG. 9 shows another exemplary flowchart involved when a terminal does not receive an authentication request message but accepts a security mode command, and performs a TAU procedure;
[0040] FIG. 10 is a structural diagram of a terminal provided by an embodiment of the present application. DETAILED DESCRIPTION
[0041] In a communication method for tracking area update, data (service data) transmission can be performed after a link is established between a terminal and a core network. In order to ensure the security of data transmission between the terminal and the core network, the terminal and the core network need to negotiate a security algorithm to be used in subsequent data transmission and unify the key of the security algorithm. Subsequently, the terminal and the core network can process data using the security algorithm and the key of the security algorithm, and then send the processed data to the opposite end. After receiving the processed data, the opposite end restores the data based on the security algorithm and the key of the security algorithm to obtain the data before processing. In this way, even if a third party (a party other than the terminal and the core network) steals the processed data, the third party does not know how to restore the data.
[0042] Similarly, in order to ensure the security of data transmission between the terminal and the core network, when the tracking area (TA) in which the terminal is located changes (is updated), the terminal and the core network need to re-negotiate a security algorithm to be used in data transmission in the new tracking area. The security algorithm usually includes an encryption algorithm and a completeness protection algorithm.
[0043] Compared with the original tracking area, the security algorithm used in the new tracking area can be the same or different. Whether the security algorithm changes depends on whether the factors referred to in the negotiation algorithm change. In some possible cases, the security algorithm used in data transmission is specified by the core network from at least one security algorithm supported by the terminal and the core network. When the security algorithm is specified, the core network refers to at least one of the following factors: network conditions of the tracking area in which the terminal is located, services currently performed by the terminal. Generally speaking, when the referred factors change, the security algorithm changes when the tracking area is updated. When the referred factors do not change, the security algorithm does not change when the tracking area is updated.
[0044] It should be noted that when the tracking area is updated, the terminal and the core network re-determine the key of the security algorithm to be used in data transmission in the new tracking area, regardless of whether the security algorithm changes.
[0045] FIG. 1 shows an exemplary scenario involved when the negotiation of the security algorithm and the calculation of the key of the security algorithm are successful when the tracking area is updated.
[0046] In FIG. 1, the curved arrow indicates that the terminal connects to a base station (for example, an evolved Node B eNB), the solid straight arrow indicates that the base station accesses the core network, and the dashed straight arrow indicates that the terminal communicates with the core network through the base station.
[0047] It should be noted that the terminal communicates with the core network, including: establishing a link and transmitting data after establishing a link. The terminal and the core network need to pass through the base station connected by the terminal as a communication bridge. This means that the signaling or data and the like transmitted by the terminal to the core network need to be transmitted to the base station first, and then further transmitted to the core network through the base station. Similarly, the signaling or data and the like transmitted by the core network to the terminal also need to be transmitted to the base station first, and then further transmitted to the terminal through the base station.
[0048] As shown in (1) of FIG. 1, in the case of TA1, the terminal connects eNB1 of cell a1 by accessing cell a1, and then accesses core network 1 through eNB1, so that the terminal realizes communication with core network 1. In TA1, algorithm 0 and the key of algorithm 0 are used when the terminal and core network 1 transmit data. Here, it is assumed that the security algorithms supported by the terminal and core network 1 include algorithm 1 and algorithm 2. Algorithm 0 is that core network 1 and the terminal support algorithm 1 or algorithm 2. The algorithm 0 is negotiated in the process of establishing a link between the terminal and core network 1, and the key of algorithm 0 is also determined in the process of establishing a link.
[0049] Referring to (1) of FIG. 1 to (2) of FIG. 1, as the terminal moves, the signal of cell a1 (belonging to TA1) weakens, the terminal determines that cell a1 is unavailable, and cell b1 (belonging to TA2) is available, so the terminal switches from cell a1 to cell b1. In TA2, the terminal connects eNB2 of cell b1 by accessing cell b1, and then accesses core network 1 through eNB2, so that the terminal realizes communication with core network 1.
[0050] The terminal moves from TA1 to TA2. The tracking area where the terminal is located is updated, and the terminal establishes a link with core network 1 through eNB2. In the process of establishing a link, the terminal needs to re-negotiate the security algorithm used when transmitting data with core network 1, and the terminal needs to re-calculate the key of the security algorithm.
[0051] Here, it is assumed that the security algorithms supported by the terminal and core network 1 include algorithm 1 and algorithm 2, and core network 1 determines that the priority of the security algorithm of the terminal in TA2 is "the priority of algorithm 1 is higher than the priority of algorithm 2". Therefore, core network 1 specifies algorithm 1 as the security algorithm used by the terminal in TA2. Core network 1 sends key calculation parameter a to the terminal, and notifies the terminal that the security algorithm used when transmitting data is algorithm 1. Subsequently, the terminal calculates the key of algorithm 1 based on key calculation parameter a, and the terminal uses algorithm 1 and the key of algorithm 1 to process data when transmitting data to core network 1. The processed data is transmitted to core network 1 through eNB2.
[0052] The details of the re-negotiation of the security algorithm and the successful determination of the key of the security algorithm after the tracking area where the terminal is located is updated can be referred to the following description of steps S20-S28 in FIG. 3, and will not be described here in detail.
[0053] In the above description, when the tracking area where the terminal is located is updated, the re-negotiation of the security algorithm and the calculation of the key of the security algorithm between the terminal and the core network occur in the process of performing a tracking area update (TAU) procedure between the terminal and the core network. The TAU procedure is also used to update the tracking area alignment between the terminal and the core network.
[0054] The TAU procedure can include that the terminal sends a tracking area update request to the core network. After receiving the tracking area update request, the core network performs authentication and security processing with the terminal, which includes the negotiation of the security algorithm and the calculation of the key of the security algorithm. After the authentication and security processing is completed, the core network accepts the tracking area update request of the terminal, and sends a tracking area update acceptance request to the terminal to update the tracking area where the terminal is located. After receiving the tracking area update acceptance request sent by the core network, the terminal ends the TAU procedure.
[0055] The following describes an exemplary process involved in performing the TAU procedure between the terminal and the core network based on FIG. 2 and FIG. 3.
[0056] First, an exemplary communication system involved in performing the TAU procedure is described in detail with reference to FIG. 2.
[0057] As shown in FIG. 2, the communication system involved in performing the TAU procedure can include a terminal 100, a 4G base station 200, and a 4G core network 300.
[0058] The 4G base station 200 can be an evolved Node B (eNB). The signal of one 4G base station 200 can cover a certain range of area. The 4G base station 200 can include at least one cell. The signal coverage of the 4G base station 200 can also be regarded as the total coverage of the signals of the at least one cell. The 4G base station 200 is responsible for managing the at least one cell. For example, the 4G base station 200 can reasonably configure the at least one cell according to the requirements of network planning, including the setting of parameters such as the frequency, power, and coverage of the cell.
[0059] The terminal 100 can connect to the 4G base station 200 by accessing a cell of the 4G base station 200. The 4G base station 200 is responsible for connection with the terminal 100, receiving signaling or data sent by the terminal 100, and transmitting the signaling or data to a 4G core network 300 accessed by the 4G base station 200. For example, after the terminal 100 connects to the 4G base station 200, the signaling (for example, the signaling involved in negotiation of security algorithms) transmitted by the terminal 100 to the 4G core network 300 in the TAU process is first transmitted to the 4G base station 200, and then further transmitted to the 4G core network 300 by the 4G base station 200.
[0060] The main components in the 4G core network 300 for implementing the TAU process can include a mobility management entity (MME) and a home subscriber server (HSS).
[0061] The main functions of the MME include authentication, security and mobility management of the terminal, etc. In the TAU process, the MME can be responsible for receiving and sending signaling for implementing TAU between the terminal 100 and the 4G core network 300, for example, the tracking area update request sent by the terminal 100 to the 4G core network 300 is actually sent to the MME. After receiving the tracking area update request, the MME triggers the related process for implementing TAU, and performs authentication and security processing with the terminal 100. For example, negotiation of security algorithms with the terminal 100, etc. After the authentication and security processing is completed, the MME sends a tracking area update accept request to the terminal 100. The interaction process between the MME and the terminal in the TAU process can be referred to the description of steps S20, steps S23-S28 below, which will not be described here in detail.
[0062] It should be noted that the MME can include at least one MME node. The MME node can be used to manage at least one tracking area, and different MME nodes manage different tracking areas. The main functions of the MME in the TAU process described above are achieved by the MME node managing the original tracking area and the MME node managing the new tracking area.
[0063] In the TAU process, the main functions of the HSS include supporting the related functions of the MME and assisting TAU between the terminal 100 and the MME. For example, supporting authentication and security processing between the MME and the terminal 100. The interaction process between the HSS and the terminal in the TAU process can be referred to the description of steps S21 and S22 below, which will not be described here in detail.
[0064] It should be noted that in some possible cases, in addition to the aforementioned MME and HSS, other 4G core network components can also be involved in the TAU process. For example, components such as a serving gateway (SGW). The main functions of the SGW include being responsible for implementing traffic optimization strategies to ensure efficient use of network resources. For example, dynamically adjusting network parameters such as bandwidth when transmitting signaling or data between the MME and the terminal.
[0065] It should be noted here that after the completion (success) of the TAU process, the terminal 100 and the 4G core network 300 are unified in the tracking area where the terminal location update is located. The 4G core network 300 can more effectively manage the data transmission of the terminal through the tracking area where the terminal is located. For example, the 4G core network 300 can optimize the data transmission path based on the tracking area where the terminal is located. To provide faster data transmission services. This helps to improve user experience, especially for business data that requires large traffic transmission, such as video streaming, online gaming, etc. At the same time, the terminal 100 and the 4G core network 300 also negotiate the security algorithm to be used for subsequent data transmission and determine the key of the security algorithm during the TAU process. When data transmission is performed, the security algorithm and the key of the security algorithm can be used to process the data, which helps to ensure the security of data transmission between the terminal 100 and the 4G core network 300, especially for services with high security requirements (such as mobile payment services), which plays a good protection role.
[0066] It should also be noted that after the 4G core network 300 receives the processed data sent by the terminal 100. The 4G core network 300 will use the same security algorithm and the key of the security algorithm to restore the processed data to the data before processing. And determine the destination terminal of the data, and then transmit the data before processing to the Internet 400 through some security mechanisms (such as secure channels or identity authentication and authorization, etc.). The Internet 400 can continue to transmit the received data to the destination terminal (such as terminal 500). For example, when the terminal 500 is consistent with the terminal 100, both are terminals connected to the base station through the access cell, and then communicate with the core network through the connected base station. The Internet 400 can also include a core network (destination core network, not shown in FIG. 2) that communicates with the terminal 500. After the destination core network receives the data sent by the terminal 100 to the terminal 500, it can process the data using the security algorithm and the key thereof negotiated with the terminal 500, and then transmit it to the terminal 500. The terminal 500 obtains the restored data based on the security algorithm and the key thereof negotiated with the destination core network.
[0067] The following describes an exemplary flowchart involved in the execution of the TAU process between the terminal and the core network in conjunction with FIG. 2 and FIG. 3.
[0068] Steps S11-S19 shown in FIG. 3 are an example procedure involved in a triggering scenario of the TAU procedure, i.e., an example procedure involved when the terminal triggers a tracking area update. Steps S20-S28 shown in FIG. 3 are an example procedure involved when the terminal and the core network perform the TAU procedure.
[0069] The VoLTE call scenario in FIG. 3 is taken as an example for illustration. The VoLTE call scenario in FIG. 3 includes that the terminal starts to access cell 1 and establish a link for the VoLTE call between the terminal and the core network through the base station (eNB1 in FIG. 3) of cell 1. Then, the terminal switches from cell 1 to cell 2 with better signal quality. The terminal determines that cell 1 and cell 2 belong to different tracking areas and determines to perform a tracking area update. After the tracking area update, the terminal performs the TAU procedure with the core network. After the TAU procedure is successful, the terminal maintains the VoLTE call connection with the core network through the base station (eNB2 in FIG. 3) of cell 2.
[0070] First, steps S11-S19 are used to describe the content involved when the terminal determines to perform a tracking area update in the VoLTE call scenario.
[0071] S11. The terminal accesses cell 1 and receives SIB1 (system information block type 1) sent by the base station (eNB1) of cell 1.
[0072] The SIB1 in step S11 carries TA code: TA1 of cell 1. Here, the tracking area to which cell 1 belongs is denoted as TA1. The TA code is a tracking area code used to identify the tracking area.
[0073] S12. The terminal sends security capability information to the MME node 1 in the core network 1 to which eNB1 is connected.
[0074] The MME node 1 is an MME node of the MME of the core network 1 that manages TA1.
[0075] The security capability information carries the security algorithms supported by the terminal, including algorithm 1 and algorithm 2.
[0076] It should be noted that the security capability information can be information carried in the UECapabilityInformation message.
[0077] S13. The terminal and the MME node 1 negotiate to use algorithm 0 as the security algorithm for data transmission, calculate the key of algorithm 0, and algorithm 0 is algorithm 1 or algorithm 2.
[0078] The MME node 1 refers to the network condition of TA1, determines an algorithm more suitable for VoLTE call service as algorithm 0 from algorithm 1 and algorithm 2, and then sends the parameter (key calculation parameter) of the key of the algorithm 0 to the terminal. The terminal and the MME node 1 both calculate the key of the algorithm 0 by using the key calculation parameter, and generate verification value 0 based on the key of the algorithm 0.
[0079] Subsequently, the terminal sends the verification value 0 to the core network 1, and the core network 1 compares the verification value 0 sent by the terminal with the verification value 0 generated by the core network 1. If they are consistent, it is determined that the key of the algorithm 0 calculated by the terminal is correct.
[0080] S14. The terminal establishes a link for VoLTE call between the eNB 1 and the core network 1.
[0081] When the terminal is in TA1, the terminal and the core network 1 can both use the algorithm 0 and the key of the algorithm 0 to send call data 1 to the opposite terminal.
[0082] In the case that the call data 1 is uplink call data, the terminal sends the call data 1 to the core network 1 by using the algorithm 0 and the key of the algorithm 0, which includes that the terminal first processes the call data 1 by using the algorithm 0 and the key of the algorithm 0, and then sends the processed call data 1 to the eNB 1. The eNB 1 further sends the processed call data 1 to the core network 1.
[0083] After the core network 1 receives the processed call data 1, it restores the data based on the algorithm 0 and the key of the algorithm 0 to obtain the call data 1 before processing. The call data 1 before processing is sent to another terminal for VoLTE call with the terminal based on some security mechanism.
[0084] In the case that the call data 1 is downlink call data, the core network 1 can send the call data 1 from another terminal to the terminal by using the algorithm 0 and the key of the algorithm 0. The process includes that the core network 1 also processes the call data 1 from another terminal by using the algorithm 0 and the key of the algorithm 0, and then sends the processed call data 1 to the eNB 1. The eNB 1 further sends the processed call data 1 to the terminal.
[0085] After the terminal receives the processed call data 1, it restores the data based on the algorithm 0 and the key of the algorithm 0 to obtain the call data 1 before processing.
[0086] It should be further noted that the core network 1 can perform the operation of transmitting and receiving call data by the SGW in the core network 1.
[0087] S15. The eNB 1 informs the terminal to perform A3 measurement.
[0088] The A3 measurement can be used to decide whether the terminal performs cell switching.
[0089] The eNB 1 receives the A3 measurement configuration issued by the core network 1, and notifies the terminal to perform A3 measurement. The notification can carry measurement information. The measurement information can include but is not limited to: objects to be measured by the terminal, which can include a list of adjacent same-system cells of the cell 1. Parameters to be measured by the terminal to represent the signal strength of the measurement object, which can include the RSRP difference of the reference signal received power (RSRP) of the adjacent same-system cell (for example, the cell 2) of the cell 1 minus the RSRP of the cell 1. The handover threshold when the terminal performs cell switching. The handover threshold indicates the threshold when the terminal actively reports the A3 measurement result. It should be noted that the RSRP involved in step S15 is an example, and other parameters that can represent signal strength can also be used. For example, signal-to-interference plus noise ratio (RSNR). The specific parameter is specified by the core network 1, and the embodiments of the present application do not limit it.
[0090] In the case of a preset RSRP difference, when the RSRP difference of the RSRP of the adjacent same-system cell (for example, the cell 2) of the cell 1 minus the RSRP of the cell 1 is greater than or equal to the preset RSRP difference, the terminal performs the following step S16, and reports the A3 measurement result to the core network 1, so that the core network 1 triggers the terminal to switch to the cell 2.
[0091] S16. The terminal reports the A3 measurement result.
[0092] The terminal first reports the A3 measurement result to the eNB 1, and then the eNB 1 transmits it to the core network 1.
[0093] The A3 measurement result can include the number of the cell that meets the switching condition measured by the terminal. Here, the cell that meets the switching condition is taken as the cell 2 for example. The core network 1 triggers the terminal to switch from the cell 1 to the cell 2. The core network 1 first sends a handover command to the eNB 1. After receiving the handover command, the eNB 1 sends the handover command to the terminal.
[0094] S17. The terminal receives the handover command.
[0095] The handover command is used to instruct the terminal to switch from the cell 1 to the cell 2.
[0096] It should be noted that in order to ensure the continuity of communication, after the eNB 1 sends the handover command to the terminal, before the terminal executes the handover command, the eNB 1 and the eNB 2 can migrate the context of the terminal on the cell 1 to the cell 2 through the X2 or S1 link.
[0097] S18. The terminal completes the handover.
[0098] The terminal is handed over from the cell 1 to the cell 2.
[0099] S19. The terminal accesses the cell 2 and receives the SIB1 sent by the base station (eNB2) of the cell 2.
[0100] The SIB1 in the step S19 carries the TA code of the cell 2: TA2. Here, the tracking area to which the cell 2 belongs is recorded as TA2.
[0101] It should be noted that the eNB2 and the eNB1 can be the same base station or different base stations, and the embodiments of the present application do not limit this.
[0102] The TA code of the cell 1 and the TA code of the cell 2 are different, which indicates that the tracking area is updated after the handover to the cell 2. At this time, the terminal establishes the connection with the eNB2 by accessing the cell 2, but cannot continue the VoLTE call with the core network 1 through the eNB2. The terminal needs to perform the TAU process, re-negotiate the security algorithm on the TA2 with the core network 1, and successfully determine the key of the security algorithm, so as to continue the VoLTE call with the core network 1 through the eNB2. For the process of performing the TAU process, the following description of the steps S20-S28 can be referred to.
[0103] S20. The terminal sends a tracking area update request message to the core network 1.
[0104] The tracking area update request message in the step S20 is used to request the update from the TA1 to the TA2.
[0105] Specifically, the terminal can send the tracking area update request message to the MME node 2 of the core network 1. The tracking area update request message can also be referred to as a tracking area update request.
[0106] The MME node 2 is a node in the MME of the core network 1 responsible for managing the TA2.
[0107] After receiving the tracking area update request message, the MME migrates the context of the terminal on the TA1 to the TA2. Here, the context to be migrated includes the security algorithm supported by the terminal.
[0108] It should be noted that in the case where the MME node (MME node 1) managing TA1 is different from the MME node 2, the MME will migrate the context of the terminal on TA1 to TA2, which can also be understood as the MME migrating the context on TA1 in the MME node 1 to the MME node 2.
[0109] After starting to migrate the context on TA1 to TA2, the MME node 2 will further perform step S21 of sending an authentication data request message to the HHS in the core network 1.
[0110] The authentication data request message can trigger the MME node 2 to request the HSS for at least one authentication vector (AV) used to generate a key of a security algorithm.
[0111] See step S22, in response to the authentication data request message, the HSS can send an authentication data response message to the MME node 2. The authentication data response message carries the aforementioned at least one authentication vector.
[0112] The MME node 2 can obtain parameters for calculating the security algorithm based on the authentication data. The process includes: after the MME node 2 receives the authentication data response message, selecting one authentication vector from the at least one authentication vector carried therein, which is denoted as AV(i) here. Then the MME node 2 extracts parameters for calculating the key of the security algorithm based on AV(i), including: RAND (random number), AUTN (authentication token) and other parameters.
[0113] Subsequently, the core network 1 sends the parameters for calculating the key of the security algorithm to the terminal through the MME node 2, so that the terminal can calculate the key of the security algorithm to complete the TAU process. For detailed description of the process, please refer to steps S23-S28 below.
[0114] S23. The core network 1 sends an authentication request message to the terminal through the MME node 2.
[0115] The authentication request message carries the parameters for calculating the key of the security algorithm.
[0116] After receiving the authentication request message, the terminal performs step S24, and sends (an authentication response message authentication response message) to the MME node 2.
[0117] It should be noted that, as the context of the terminal on TA1 gradually migrates to the MME node 2, the MME node 2 can obtain the security algorithms supported by the terminal (including algorithm 1 and algorithm 2). Then, the core network 1 prioritizes the security algorithms supported by the terminal and the core network 1 through the MME node 2. The security algorithm with the highest priority is selected as the security algorithm of the terminal on TA2. When prioritizing the priority of the security algorithm, the core network 1 refers to at least one of the following factors: network conditions of TA2, security requirements of VoLTE call service on algorithm.
[0118] Generally speaking, the more private the service is, the higher the security requirement for the security algorithm is, the better the network condition of TA2 is, the higher the transmission rate of data is, and the higher the security of the security algorithm used can be. It should be noted that the higher the security of the security algorithm is, the lower the efficiency of subsequent processing of data using the security algorithm and the security key of the security algorithm is. Therefore, the core network 1 needs to prioritize the priority of algorithm 1 and algorithm 2 to obtain the applicability of different security algorithms of the terminal on TA2. The higher the priority of the security algorithm is, the more suitable the terminal is for use on TA2.
[0119] Here, it is assumed that the algorithms supported by the terminal and the core network 1 include algorithm 1 and algorithm 2, and the priority of algorithm 1 is higher than that of algorithm 2. The core network 1 selects algorithm 1 as the security algorithm of the terminal on TA2 through the MME node 2, and performs the following step S25 to notify the terminal that the security algorithm used on TA2 is algorithm 1.
[0120] S25. The core network 1 sends a security mode command to the terminal through the MME node 2.
[0121] The security mode command is a command for establishing a secure connection. The terminal can calculate the security key of the security algorithm used on TA2 by executing the security mode command.
[0122] The security mode command carries the use of algorithm 1 as the security algorithm of the terminal on TA2.
[0123] After receiving the security mode command, the terminal performs the procedure of the security mode command, which includes obtaining the security algorithm (algorithm 1) specified by the core network 1. Then, the key of the algorithm 1 is calculated based on the parameters for calculating the key of the security algorithm obtained in step S23. And a verification value is obtained based on the generated key, which is used to verify whether the key of the algorithm 1 is correct. Then step S26 is performed, and the verification value is placed in the security mode complete message and fed back to the core network 1. The security mode complete message indicates that the terminal has completed the calculation of the key of the algorithm 1. The security mode complete message can be used to trigger the core network 1 to verify whether the key of the algorithm 1 calculated by the terminal is correct, and the related description of the procedure can be referred to the description of step S27 below.
[0124] S27. The core network 1 determines, through the MME node 2, that the key calculated by the terminal is the same as the key calculated by the MME node 2 based on the parameters.
[0125] The core network 1 obtains the verification value (denoted as verification value 1) in the security mode complete message through the MME node 2, and compares the verification value 1 with a verification value (denoted as verification value 2) obtained by the core network 1 based on the parameters for calculating the key of the algorithm 1. When the verification value 1 and the verification value 2 are consistent, the MME node 2 determines that the key of the algorithm 1 calculated by the terminal is correct. The verification value 2 is a verification value obtained by the MME node 2 based on the key generated by the MME node 2.
[0126] In step S27, the parameters used by the MME node 2 to calculate the key of the algorithm 1 are the parameters for calculating the security algorithm obtained by the MME node 2 based on the authentication data.
[0127] If the aforementioned migration operation (migrating the context of the terminal on TA1 to TA2) is completed, the core network 1 performs the following step S28.
[0128] S28. The core network 1 sends a tracking area update accept message to the terminal through the MME node 2.
[0129] The tracking area update accept message is used to inform the terminal that the core network 1 has updated the tracking area where the terminal is located from TA1 to TA2.
[0130] Up to now, the TAU procedure is completed (successfully), and the tracking area where the terminal is located is synchronized between the terminal and the core network 1 as TA2.
[0131] Subsequently, as described in the following step S29, the terminal can perform data transmission with the core network 1 in TA2, so that the VoLTE call connection is continued.
[0132] S29. VoLTE call connection.
[0133] When the terminal is in TA2, both the terminal and the core network 1 can use algorithm 1 and the key of algorithm 1 to send call data 2 to the opposite terminal. The process is the same as the process in which the terminal and the core network 1 use algorithm 0 and the key of algorithm 0 to send call data 1 to the opposite terminal when the terminal is in TA1. Algorithm 0 is modified to algorithm 1. The core network 1 can send and receive call data 2 through the SGW in the core network.
[0134] The foregoing FIG. 3 and its related content introduce an exemplary TAU procedure (hereinafter referred to as a regular TAU procedure) involved when the terminal changes the tracking area and the terminal and the core network successfully complete the tracking area update. The regular TAU procedure can also be understood as that when the TAU procedure is performed, neither the terminal nor the core network has an error, and the entire TAU procedure is successfully performed. In actual situations, errors can occur during the TAU procedure. Some errors can be corrected, and after correction, the TAU procedure can still be successful, but some errors can cause the TAU procedure to fail.
[0135] Scenarios in which errors occur during the TAU procedure include the following error scenarios.
[0136] Referring to the foregoing FIG. 3, consistent with FIG. 1, the terminal still sends a tracking area update request to the core network 1 after switching from the cell 1 to the cell 2. However, unlike FIG. 1, the terminal receives a security mode command (security mode command, SMC) sent by the core network 1, but fails to successfully execute the security mode command (SMC), and cannot obtain the key of the security algorithm specified in the security mode command, that is, the SMC execution fails. In the subsequent content, the security mode command involved in the foregoing error scenario can be referred to as an uncompleted security mode command.
[0137] In response to the foregoing error scenario, the standard protocol stipulates that the terminal can send a security mode rejection message (security mode reject message) to the core network for the uncompleted security mode command, indicating that the SMC execution fails, the terminal rejects the security mode, and carries a reason value in the security mode rejection message. The reason value can be used to indicate the reason for rejecting the security mode, that is, the reason why the terminal cannot calculate the key of the security algorithm.
[0138] The cause of the SMC execution failure (error cause) is not single, and the standard protocol configures a corresponding cause value for part of the common error causes. However, the cause values are limited and cannot exhaust all error causes leading to the SMC execution failure. Therefore, the standard protocol provides a special cause value (cause value 24) indicating that the cause of the security mode rejection is unknown, and the cause value 24 can be enabled when the error cause cannot be determined. That is, if the error cause leading to the SMC execution failure has no corresponding cause value, or the error cause cannot be determined, the cause value 24 can be used. The cause value 24 can be used to trigger the core network to check the error cause of the SMC execution failure, and attempt to correct the error to enable the TAU procedure to continue.
[0139] Since the cause value 24 does not indicate the cause of the SMC execution failure, the core network needs to check the error cause, attempt to correct the error, and resend the security mode command to the terminal to trigger the terminal to re-execute the SMC. Whether the core network can successfully check the error cause or not, the terminal needs to be sent the security mode command again. If the core network cannot successfully check the error cause, the terminal still has the possibility of failure when executing the security mode command again. Therefore, the standard protocol provides that the core network can enable the terminal to execute the SMC for three times in one TAU procedure. If the three SMCs all fail and the error cause is unknown, the terminal will fail in the tracking area update. The three SMC mechanism is to give the terminal and the core network more opportunities to increase the success probability of the TAU.
[0140] However, it is found in practice that one error cause leading to the failure of the terminal to perform SMC and causing the cause value 24 to be enabled is difficult for the core network to determine, and is likely to cause the TAU procedure to fail. The error cause is that the core network fails to send an authentication request message to the terminal after receiving the tracking area update message sent by the terminal, but sends a security mode command. As shown in FIG. 3, the terminal fails to obtain the parameters for calculating the key of the security algorithm without receiving the authentication request message. Therefore, the terminal fails to calculate the key of the security algorithm specified in the security mode after receiving the security mode command sent by the core network, leading to the failure of SMC. In the standard protocol, the error cause does not have a corresponding cause value at the terminal side. Therefore, the terminal sends a security mode reject message carrying the cause value 24 to the core network. In this error cause, the terminal performs SMC for 3 times, and sends a security mode reject message carrying the cause value 24 to the core network after each time of failure of performing SMC. However, the core network fails to successfully check the error cause after receiving the security mode reject message, and re-sends a security mode command to the terminal without sending an authentication request message, thereby continuing to cause the terminal to fail to perform SMC. If the terminal fails to receive the authentication request message sent by the core network after performing SMC for 3 times, the terminal performs local release and actively disconnects the connection with the base station (eNB2) of the cell 2, thereby causing the TAU procedure to fail. FIG. 4 shows an exemplary scenario involved when the TAU procedure fails due to the error cause in the tracking area update.
[0141] In FIG. 4, the curved arrow represents the connection of the terminal with the base station, the solid straight arrow represents the access of the base station to the core network, and the dashed straight arrow represents the communication of the terminal with the core network through the base station.
[0142] As shown in FIG. 4, the terminal is still in TA1 and communicates with the core network 1 through the eNB1 of the cell a1, and then moves to TA2 and expects to continue to communicate with the core network 1 through the eNB2 of the cell b1 in TA2. In FIG. 4, the performance of the terminal in TA1 and the process of the terminal moving from TA1 to TA2 are the same as those in the foregoing FIG. 1, and the related description in the foregoing FIG. 1 can be referred to, for example, the content involved in FIG. 4(1) is the same as that in FIG. 1(1), and thus is not described herein again.
[0143] After the terminal moves to TA2, the terminal and the core network need to perform the TAU procedure to re-negotiate the security algorithm for transmitting data and the terminal needs to re-calculate the key of the security algorithm. Here, it is still exemplarily taken that the core network 1 determines that the priority of the security algorithm of the terminal in TA2 is "the priority of algorithm a is higher than that of algorithm 2".
[0144] However, in FIG. 4, the TAU procedure fails. Referring to (2) in FIG. 4, the core network 1 sends a security mode command (SMC) to the terminal, but does not send an authentication request message. The core network 1 specifies algorithm 1 as a security algorithm in the security mode command when transmitting data. However, because the core network 1 does not send the authentication request message, the terminal cannot obtain the key calculation parameter a (which is supposed to be carried in the authentication request message and is used to calculate the key of the security algorithm), and thus cannot calculate the key of algorithm 1, that is, the terminal fails to execute the SMC and sends a cause value 24 to the core network 1 to inform the core network 1 of the unknown failure cause. The procedure is repeated three times. When the core network 1 obtains the cause value 24 for the third time, the core network 1 still does not send the authentication request message to the terminal, and thus, as shown in (3) in FIG. 4, the TAU procedure fails, and the terminal releases the link with the eNB 2. Here, the detailed content involved in the failure of the TAU procedure can be referred to the description of steps S113-S120 in FIG. 5 below.
[0145] An example flowchart involved in the failure of the TAU procedure and the resulting service interruption when the terminal performs the TAU procedure is shown in FIG. 5. The description of the procedure can be referred to the description of steps S101-S120 below.
[0146] In FIG. 5, the same as in FIG. 3, the VoLTE call scenario is still taken as an example for description. The procedure involved in the triggering scenario of the TAU procedure is the same as steps S11-S19 in FIG. 3. The description of the related steps in FIG. 3 can be referred to, and will not be repeated here.
[0147] The terminal determines that the TA code of the cell 1 and the TA code of the cell 2 are different, indicating that the tracking area is updated after the handover to the cell 2. At this time, the terminal needs to perform the TAU procedure, re-negotiate the security algorithm on the TA 2 with the core network 1, and successfully determine the key of the security algorithm, before the terminal can continue the VoLTE call with the core network 1 through the eNB 2. However, the TAU procedure fails here, resulting in the termination of the VoLTE call of the terminal. The description of the procedure can be referred to the description of steps S110-S120 below.
[0148] S110. The terminal sends a tracking area update request message to the core network 1.
[0149] The tracking area update request message in step S110 is used to request the update from the TA 1 to the TA 2.
[0150] Specifically, the terminal can send the tracking area update request message to the MME node 2 of the core network 1. The tracking area update request message can also be referred to as a tracking area update request.
[0151] The MME node 2 is a node of the MME of the core network 1 responsible for managing a tracking area 2 (TA2).
[0152] After the MME node 2 receives the tracking area update request message, the MME migrates the context of the terminal on TA1 to TA2. Here, the context to be migrated includes the security algorithm supported by the terminal.
[0153] It should be noted that in the case where the MME node (MME node 1) managing TA1 is different from the MME node 2, the MME migrates the context of the terminal on TA1 to TA2, which can also be understood as the MME migrating the context of TA1 in the MME node 1 to the MME node 2.
[0154] After starting to migrate the context on TA1 to TA2, the MME node 2 also performs step S111, sending an authentication data request message to the HHS in the core network 1.
[0155] The authentication data request message is used to include: triggering the MME node 2 to request at least one authentication vector (AV) used to generate a security algorithm from the HSS, and carrying at least one authentication vector in the authentication data response message to the MME node 2.
[0156] However, the MME node 2 does not receive the authentication data response message. The reason for not sending may include: the HSS does not send the authentication data response message, or after sending, the MME node 2 does not receive it due to network congestion.
[0157] Subsequently, in response to the event that the MME node 2 does not receive the authentication data response, the core network 1 makes an unreasonable response, resulting in the failure of the TAU process. The unreasonable response includes: in the case where the MME node 2 cannot obtain the parameters for calculating the key based on the authentication vector, the MME node 2 cannot generate the authentication request message carrying the parameters (parameters for calculating the key). Therefore, the core network 1 does not perform the operation of sending the authentication request message to the terminal through the MME node 2. However, in the case where the authentication request message is not sent to the terminal, the following step S112 is performed, and the security mode command is sent to the terminal through the MME node 2.
[0158] S112. The core network 1 sends a security mode command to the terminal through the MME node 2.
[0159] The security mode command carries the algorithm 1 as the security algorithm used by the terminal on the TA 2.
[0160] The security mode command is a command for establishing a secure connection. The terminal can calculate the key of the security algorithm (algorithm 1) used on the TA 2 by executing the security mode command.
[0161] Since the terminal does not receive the authentication request message sent by the core network 1, the terminal cannot obtain the parameters for calculating the algorithm 1 and cannot calculate the key of the algorithm 1 after receiving the security mode command, so the terminal fails to execute the SMC. Then, the terminal executes step S113 and sends a security mode reject message to the core network 1. The security mode reject message in step S113 carries a reason value of reason value 24. For details about the reason value 24, refer to the foregoing description of the reason value 24, which will not be described here.
[0162] After the core network 1 receives the security mode reject message, the error cause cannot be checked, but step S112 is repeatedly executed, and the security mode command is sent to the terminal through the MME node 2 again. The terminal fails to execute the SMC for the second time, and then the terminal executes step S113 again and sends the security mode reject message carrying the reason value 24 to the core network 1. The reason value 24 indicates that the reason for the security mode rejection is unspecified.
[0163] After the core network 1 receives the security mode reject message again, the error cause still cannot be checked, but step S112 is repeatedly executed, and the security mode command is sent to the terminal through the MME node 2 again. The terminal fails to execute the SMC for the third time, and then the terminal executes step S113 again and sends the security mode reject message carrying the reason value 24 to the core network 1.
[0164] After the SMC fails for the third time, the terminal sends the security mode reject message carrying the reason value 24 to the core network for the third time, and waits for a preset time. If the authentication request message sent by the core network is not received by the terminal within the preset time, the terminal executes the following step S114 and actively releases the link with the eNB 2.
[0165] S114. The terminal is locally released.
[0166] The terminal releases the link with the eNB2.
[0167] S115. The terminal sends an RRC connection request to the eNB1.
[0168] The purpose of sending the RRC connection request to the eNB1 is that the terminal can re-access the cell 1 and establish a link with the base station eNB1, and then communicate with the core network 1 through the eNB1.
[0169] In response to the RRC connection request sent by the terminal, the eNB1 performs step S116, and sends an RRC connection setup to the terminal.
[0170] After receiving the RRC connection setup, the terminal determines to switch back to the cell 1 belonging to the TA1 from the cell 2 belonging to the TA2, and the terminal determines that the tracking area where the terminal is located is changed from the TA2 to the TA1. The terminal performs the following step S117, and sends a tracking area update request to the core network 1.
[0171] S117. The terminal sends a tracking area update request message to the core network 1.
[0172] The tracking area update request message in step S117 is used to request updating from the TA2 to the TA1.
[0173] Specifically, the terminal can send the tracking area update request message to the MME node 1 of the core network 1.
[0174] The MME node 1 is a node in the MME of the core network 1 responsible for managing the tracking area 1 (TA1).
[0175] However, after the core network 1 receives the tracking area update request message from TA1 to TA2 in the aforementioned step S110, it will migrate the context of the terminal in TA1 to TA2 (the context to be migrated includes the security algorithm supported by the terminal) through the MME. Since there is a task of migrating the context from TA1 to TA2 in the MME node 1, when the core network 1 receives the tracking area update request message, if the migration task has not been completed, the MME node 1 will continue to process the migration task preferentially and will not agree to the tracking area update request. If the migration task has been completed, the MME node 1 considers that the terminal is already in TA2 and should not return to TA1, and will not agree to the tracking area update request. Therefore, the core network 1 will perform step S118 and send a tracking area update rejected message to the terminal.
[0176] The tracking area update request will be received by the eNB1 first before reaching the terminal and then sent to the terminal. After the eNB1 receives the tracking area update rejected message, it can perform step S119 and send an RRC connection release message to the terminal.
[0177] After the terminal receives the RRC connection release message, it determines that the eNB1 is unavailable and disconnects the link with the eNB1. This causes the VoLTE call to be interrupted (see step S120).
[0178] Based on the foregoing, it can be seen that after the terminal fails to perform the SMC three times, the TAU process will fail, which in turn causes the service or communication to be interrupted, affecting the user experience. In order to avoid the scenario of TAU process failure involved in the aforementioned FIG. 4, another communication method for performing tracking area update is proposed. In this method, in the tracking area update scenario, after the terminal sends a tracking area update request to the core network when performing the TAU process, in the case that no authentication request message sent by the core network in response to the tracking area update request is received, but a security mode command sent by the core network is received, the terminal cannot calculate the key of the security algorithm specified in the security mode command. Then the terminal fails to perform the SMC and needs to return a security mode reject message to the core network with a cause value. However, the terminal does not return the security mode reject message with the cause value 24 at this time. Instead, it returns the security mode reject message with the cause value 23. The cause value 23 indicates that the security capabilities of the terminal do not match (UE security capabilities mismatch), i.e., the terminal cannot support the security algorithm specified by the core network in the security mode message.
[0179] The cause value 23 can be used to trigger the core network to reselect the security algorithm, and send the terminal an authentication request message and a security mode command carrying key calculation parameters (for calculating the key of the reselected security algorithm), so that the terminal can obtain the key calculation parameters from the authentication request message, calculate the key of the reselected security algorithm, and thus make the TAU procedure successful. The reselected security algorithm is the algorithm with the highest priority among the algorithms supported by the terminal and the core network, except for the security algorithms specified above, on the new tracking area. The content of the priority ranking of the security algorithms can refer to the foregoing related content, which will not be described here again.
[0180] FIG. 6 shows an exemplary scenario diagram in which the terminal does not receive the authentication request message, but receives the security mode command, and makes the TAU procedure successful by sending the cause value 23.
[0181] In FIG. 6, the curved arrow represents the terminal connecting the base station, the solid straight arrow represents the base station accessing the core network, and the dashed straight arrow represents the terminal communicating with the core network through the base station.
[0182] As in FIG. 1, as shown in FIG. 6 (1) to FIG. 6 (2), the terminal is still in TA1, communicates with the core network 1 through the eNB1 of the cell a1, and then moves to TA2, and expects to continue to communicate with the core network 1 through the eNB2 of the cell b1 on TA2. In FIG. 6, the performance of the terminal on TA1 and the process of the terminal moving from TA1 to TA2 are the same as those in FIG. 1, and can refer to the related description in FIG. 1, for example, the content involved in FIG. 6 (1) is the same as that in FIG. 1 (1), which will not be described here again.
[0183] After the terminal moves to TA2, the terminal needs to send a tracking area update request to the core network 1, and then perform a TAU procedure with the core network to re-negotiate the security algorithm used for transmitting data with the core network 1, and the terminal needs to re-calculate the key of the security algorithm. Here, still taking the case that the core network 1 determines that the priority of the security algorithm of the terminal on TA2 is "the priority of algorithm a is higher than that of algorithm 2" as an example.
[0184] However, the core network 1 does not send an authentication request message in response to the tracking area update request message after receiving the tracking area update request message sent by the terminal. Referring to (2) in FIG. 6, the core network 1 sends a security mode command (SMC) to the terminal without sending an authentication request message. The core network 1 specifies algorithm 1 as the security algorithm in the security mode command. However, because the core network 1 does not send an authentication request message, the terminal cannot obtain the key calculation parameter a (which is originally carried in the authentication request message and is used to calculate the key of the security algorithm), and thus cannot calculate the key of algorithm 1. That is, the terminal fails to execute the SMC, and sends a cause value 23 to the core network 1 to indicate that the terminal does not support algorithm 1.
[0185] Referring to (3) in FIG. 6, after receiving the cause value 23, the core network 1 reselects a security algorithm, and here the core network 1 selects algorithm 2 as the security algorithm. After reselecting the security algorithm, the core network 1 further sends the key calculation parameter b to the terminal through an authentication request message, and sends a security mode command (SMC) to the terminal again, to notify the terminal that algorithm 2 is used as the security algorithm when transmitting data. Then, the terminal calculates the key of algorithm 2 based on the key calculation parameter b, and thus the TAU procedure is successful. Subsequently, algorithm 2 and the key of algorithm 2 are used by the terminal and the core network 1 when transmitting data.
[0186] FIG. 7 shows an exemplary flowchart of a case where the terminal does not receive an authentication request message but accepts a security mode command, and makes the TAU procedure successful by sending a cause value 23. The description of the process can be referred to the description of steps S201-S222 below.
[0187] In FIG. 7, the same as in FIG. 3, the VoLTE call scenario is still taken as an example for description. The procedures involved in the triggering scenario of the TAU procedure are the same as steps S11-S19 in FIG. 3. The description of the related steps in FIG. 3 can be referred to, and will not be repeated here.
[0188] The terminal determines that the TA code of cell 1 and the TA code of cell 2 are different, which indicates that the tracking area is updated after switching to cell 2. At this time, the terminal needs to perform the TAU procedure, and re-negotiate the security algorithm on TA2 with the core network 1. After successfully determining the key of the security algorithm, the terminal can continue the VoLTE call with the core network 1 through eNB2. The description of the process can be referred to the description of steps S210-S222 below.
[0189] S210. The terminal sends a tracking area update request message to the core network 1.
[0190] The tracking area update request message in step S110 is used to request updating from TA1 to TA2.
[0191] In particular, the terminal can send the tracking area update request message to the MME node 2 of the core network 1. The tracking area update request message can also be referred to as a tracking area update request. The related content about the MME node 2 can refer to the description of the MME node 2 in the aforementioned step S20, and will not be described here.
[0192] After receiving the tracking area update request message, the MME node 2 migrates the context of the terminal on TA1 to TA2. Here, the context to be migrated includes the security algorithm supported by the terminal.
[0193] After starting to migrate the context on TA1 to TA2, the MME node 2 performs step S211, and sends an authentication data request message to the HHS in the core network 1.
[0194] The authentication data request message is used to include: triggering the MME node 2 to request the HSS to generate at least one key for the security algorithm authentication vector (AV), and send at least one authentication vector to the MME node 2 in the authentication data response message.
[0195] However, the MME node 2 does not receive the authentication data response message. The reason for not sending may include: the HSS does not send the authentication data response message, or after sending, the MME node 2 does not receive due to network congestion.
[0196] Subsequently, in response to the event that the MME node 2 does not receive the authentication data response, the core network 1 makes an unreasonable response consistent with the aforementioned TAU process failure scenario. The unreasonable response includes: in the case that the MME node 2 cannot obtain the calculation key based on the authentication vector, the MME node 2 cannot generate the authentication request message carrying the parameter (the parameter for calculating the key). Therefore, the core network 1 does not perform the operation of sending the authentication request message to the terminal through the MME node 2. However, in the case that the authentication request message is not sent to the terminal, the step S212 is performed, and the security mode command is sent to the terminal through the MME node 2.
[0197] S212. The core network 1 sends a security mode command to the terminal through the MME node 2.
[0198] The security mode command carries the security algorithm 1 as the security algorithm used by the terminal in the TA 2.
[0199] The security mode command is a command for establishing a secure connection. The terminal can calculate the key of the security algorithm (algorithm 1) used in the TA 2 by executing the security mode command.
[0200] Since the terminal does not receive the authentication request message sent by the core network 1, the terminal cannot obtain the parameters for calculating the algorithm 1 and cannot calculate the key of the algorithm 1 after receiving the security mode command, and the terminal fails to execute the SMC. Then, the terminal executes step S213 and sends a security mode reject message to the core network 1.
[0201] The cause value carried in the security mode reject message in step S213 is the cause value 23 (UE security capabilities mismatch), to inform the core network 1 that the terminal does not support the algorithm 1. The related content about carrying the cause value 23 can refer to the foregoing description of the cause value 23, which will not be repeated here.
[0202] After receiving the security mode reject message, the core network 1 obtains the cause value 23 therein and determines that the terminal does not support the algorithm 1, and then reselects a security algorithm. The reselected security algorithm is the algorithm 2, and the related content about reselecting the security algorithm can refer to the foregoing related content, which will not be repeated here.
[0203] It should be noted that in some possible cases, the timing of the core network 1 to sort the priorities of the algorithm 1 and the algorithm 2 to obtain the sorting result can be after receiving the tracking area update request message and before sending the security mode command (carrying the security algorithm 1). After receiving the security mode reject message, in order to save computing resources, the core network 1 usually does not re-sort the algorithm 1 and the algorithm 2, but directly uses the foregoing sorting result. However, the core network 1 can also re-sort the algorithm 1 and the algorithm 2, and select the security algorithm with the highest priority except the algorithm 1, depending on the security algorithm selection mechanism of the core network 1. Here, the algorithm 1 and the algorithm 2 are only examples, and there can be more security algorithms. The content of the core network 1 to sort the priorities of the algorithm 1 and the algorithm 2 can refer to the related content involved in the foregoing step S23 of sorting the priorities of the algorithm 1 and the algorithm 2, which will not be repeated here.
[0204] As the core network 1 reselects the security algorithm, the core network 1 re-sends an authentication data request message to the HSS via the MME node 2, see step S214.
[0205] In response to the authentication data request message, see step S215, the HSS can send an authentication data response message to the MME node 2. The authentication data response message carries at least one authentication vector.
[0206] The MME node 2 can obtain the parameters of the security algorithm based on the authentication data. The procedure includes that after the MME node 2 receives the authentication data response message, it selects one authentication vector from the at least one authentication vector carried in the authentication data response message, here, the authentication vector is denoted as AV(i). Then, the MME node 2 extracts the parameters of the security algorithm based on the AV(i), including the parameters such as RAND (random number) and AUTN (authentication token).
[0207] Subsequently, the core network 1 can send the parameters of the security algorithm to the terminal via the MME node 2, so that the terminal can calculate the security algorithm key to complete the TAU procedure. For the detailed description of the procedure, see steps S216 to S221.
[0208] S216. The core network 1 sends an authentication request message to the terminal via the MME node 2.
[0209] The authentication request message carries the parameters of the security algorithm.
[0210] After receiving the authentication request message, the terminal performs step S217 and sends an authentication response message to the MME node 2.
[0211] After receiving the authentication response message, the core network 1 performs step S218 and notifies the terminal to use algorithm 2 as the security algorithm.
[0212] S218. The core network 1 sends a security mode command to the terminal via the MME node 2.
[0213] The security mode command is a command for establishing a secure connection. The terminal can calculate the key of the security algorithm 2 used on the TA 2 by executing the security mode command.
[0214] The security mode command carries the security algorithm 2 as the security algorithm of the terminal on the TA 2.
[0215] After the terminal calculates the key of the algorithm 2, the terminal executes step S219 to send a security mode complete message to the terminal, which is used to indicate that the key of the algorithm 2 has been configured. The security mode complete message can be used to trigger the core network 1 to execute step S220 to determine, by the MME node 2, that the key calculated by the terminal is the same as the key calculated by the MME node 2 based on the parameters. The content involved in the step S220 is the same as that of the aforementioned step S27, and reference can be made to the foregoing description of the step S27, which will not be described here again.
[0216] In the case that the core network 1 determines that the key calculated by the terminal is correct, and the aforementioned migration operation (migrating the context of the terminal on the TA 1 to the TA 2) is completed, the core network 1 executes the following step S221.
[0217] S221. The core network 1 sends a tracking area update accept message to the terminal through the MME node 2.
[0218] The tracking area update accept message is used to inform the terminal that the core network 1 has updated the tracking area where the terminal is located from the TA 1 to the TA 2.
[0219] At this point, the TAU procedure is completed (successfully), and the tracking area where the terminal is located is synchronized between the terminal and the core network 1 as the TA 2.
[0220] It should be noted that the content of the steps S217-S221 is similar to that of the aforementioned steps S24-S28, respectively, and reference can be made to the description of the foregoing related content by changing the algorithm 1 to the algorithm 2, which will not be described here again.
[0221] Subsequently, see the following step S222, the terminal can perform data transmission with the core network 1 on the TA 2, so that the VoLTE call connection is continued.
[0222] S222. The VoLTE call connection is continued.
[0223] When the terminal is in TA2, both the terminal and the core network 1 can use algorithm 2 and the key of algorithm 2 to send the call data 2 to the opposite terminal. The process is the same as the process that the terminal and the core network 1 use algorithm 0 and the key of algorithm 0 to send the call data 1 to the opposite terminal when the terminal is in TA1, and algorithm 0 is modified to algorithm 2. The core network 1 can send and receive the call data 2 through the SGW in the core network.
[0224] Based on the foregoing FIG. 6, FIG. 7 and the description, in the case that the terminal does not receive the authentication request sent by the core network in response to the tracking area update request, but receives the security mode command sent by the core network (carrying the use of algorithm 1), after the execution of SMC fails, the terminal actually supports algorithm 1 in the scheme of sending the cause value 23 to inform the core network that the terminal does not support algorithm 1, so the terminal carries the security algorithms supported by the terminal in the security capability information, which are algorithm 1 and algorithm 2. Here, the terminal "lies" to the core network that it does not support algorithm 1, so as to trigger the core network to reselect the security algorithm. After the reselection of the security algorithm, the core network can reacquire the parameters for calculating the security algorithm, so that the core network can send the authentication request message to the terminal, thereby ensuring the success of the TAU process.
[0225] In the process of performing the tracking area update, the core network 1 selects the security algorithm with the highest priority from the security algorithms supported by both the terminal and the core network 1 as the security algorithm on the new tracking area. The factors considered by the core network 1 when selecting the security algorithm include, but are not limited to, at least one of the following factors: the network condition of TA2, the security requirement of the service on the algorithm. However, based on FIG. 6, FIG. 7 and the description, the priority of the security algorithm (for example, algorithm 2) reselected by the core network in the new tracking area (for example, TA2) is actually lower than that of the initially selected security algorithm (for example, algorithm 1). Therefore, the initially selected security algorithm by the core network is actually more suitable for the data transmission of the terminal in the new tracking area. Therefore, the terminal can try to retain the initially selected security algorithm by the core network as much as possible. In a possible implementation, in the case that the terminal does not receive the authentication request sent by the core network in response to the tracking area update request, but receives the security mode command sent by the core network (carrying the use of algorithm 1), the terminal can first calculate the key of algorithm 1 using the original parameters (for example, the parameters for calculating the key of algorithm 0). The original parameters are sent by the core network to the terminal, and are used to calculate the parameters of the security algorithm used in the original tracking area. If the key of algorithm 1 is calculated correctly, the terminal and the core network can use algorithm 1 and the key of algorithm 1 to transmit data in the new tracking area.
[0226] Here, whether the key calculation of algorithm 1 is correct is determined by the core network. If the core network determines that the key calculation of algorithm 1 is incorrect, the core network considers that the terminal has an error in the process of calculating the key of algorithm 1, and can retransmit the security mode command (carrying algorithm 1) to the terminal to trigger the terminal to calculate the key of algorithm 1 again. However, at this time, the terminal will not calculate again, but will take the scheme of sending the cause value 23 to trigger the core network to reselect the security algorithm, calculate the key of the reselected security algorithm, and then make the core network 1 accept the tracking area update. The detailed contents involved in this process can be referred to the description of steps S301-S308 in FIG. 8.
[0227] As described in the foregoing FIG. 3, FIG. 5, and FIG. 7, the present embodiment still takes the terminal in the VoLTE call service, the triggering scenario of TAU process (the same as the foregoing steps S11-S19, which will not be described again) as an example for description. The process of TAU process is described with reference to the following steps S301-S308.
[0228] S301. The terminal sends a tracking area update request message to the core network 1.
[0229] In the case where the TA code of the cell 1 and the TA code of the cell 2 are determined to be different, the terminal sends a tracking area update request message to the core network 1.
[0230] The tracking area update request message in step S301 is used to request updating from TA1 to TA2.
[0231] Specifically, the terminal can send the tracking area update request message to the MME node 2 of the core network 1. The tracking area update request message can also be referred to as a tracking area update request. The related content of the MME node 2 can be referred to the description of the MME node 2 in the foregoing step S20, which will not be described again.
[0232] After receiving the tracking area update request message, the MME node 2 migrates the context of the terminal on TA1 to TA2. Here, the context to be migrated includes the security algorithm supported by the terminal, and the parameter 1 (the parameter for calculating the key of algorithm 0) for calculating the key on TA1.
[0233] After starting to migrate the context on TA1 to TA2, the MME node 2 performs step S302, and sends an authentication data request message to the HHS in the core network 1.
[0234] However, the MME node 2 does not receive the authentication data response message. The related content about the authentication data request message and the authentication data response message can refer to the foregoing description of step S211, and will not be described here again.
[0235] Subsequently, in response to the event that the MME node 2 does not receive the authentication data response, the core network 1 makes an unreasonable response, which is consistent with the foregoing scenario of the TAU process failure. The step S303 is executed, in which the security mode command is sent to the terminal through the MME node 2, without sending the authentication request message to the terminal.
[0236] S303. The core network 1 sends the security mode command to the terminal through the MME node 2.
[0237] The security mode command carries the algorithm 1 as the security algorithm used by the terminal on the TA 2.
[0238] The security mode command is a command for establishing a secure connection. The terminal can calculate the key of the algorithm 1 by executing the security mode command.
[0239] Without receiving the authentication request message sent by the core network 1, the terminal executes step S304 to calculate the key of the algorithm 1 using the parameter 1.
[0240] Then, the terminal obtains a verification value (verification value a) based on the key of the algorithm 1. The step S305 is executed to place the verification value a in the security mode complete message and feed back to the core network 1. The security mode complete message indicates that the terminal has completed the calculation of the key of the algorithm 1.
[0241] In the case that the core network 1 also calculates the key of the algorithm 1 using the parameter 1, the core network 1 can verify whether the key of the algorithm 1 calculated by the terminal is correct based on the security mode complete message. The related description of the process can refer to the description of step S306 below.
[0242] S306. The core network 1 determines that the key calculated by the terminal is the same as the key calculated by the MME node 2 based on the parameter 1 through the MME node 2.
[0243] The core network 1 acquires the authentication value a in the security mode complete message through the MME node 2, and compares the authentication value a with the authentication value b obtained by the core network 1 using the algorithm 1 key. If the authentication value a and the authentication value b are consistent, the MME node 2 determines that the algorithm 1 key calculated by the terminal is correct. If the authentication value a and the authentication value b are inconsistent, the MME node 2 determines that the algorithm 1 key calculated by the terminal is incorrect.
[0244] If the core network 1 does not use the parameter 1 to calculate the algorithm 1 key, the core network 1 determines that the algorithm 1 key calculated by the terminal is incorrect.
[0245] If the key calculated by the terminal is correct, and the context migration is completed, the core network 1 performs the following step S307, and notifies the terminal that the tracking area update is successful.
[0246] S307. The core network 1 sends a tracking area update accept message to the terminal through the MME node 2.
[0247] At this time, the TAU procedure is completed (successfully), and the tracking area in which the terminal is located is synchronized between the terminal and the core network 1 as TA2.
[0248] Subsequently, the terminal can perform data transmission with the core network 1 in the TA2, so that the VoLTE call connection is continued. The terminal and the core network 1 use the algorithm 1 and the algorithm 1 key to send call data to the opposite end.
[0249] If the key calculated by the terminal is incorrect, the core network 1 performs the following step S308, and triggers the terminal to recalculate the algorithm 1 key.
[0250] S308. The core network 1 sends a security mode command to the terminal through the MME node 2.
[0251] The security mode command still indicates that the algorithm 1 is used as the security algorithm.
[0252] If the terminal has not received the authentication request message sent by the core network 1 to carry the parameter for calculating the key before receiving the security mode command in step S308, the terminal performs SMC failure, and cannot calculate the algorithm 1 key.
[0253] Then, the terminal takes the scheme of sending the cause value 23, triggers the core network to reselect the security algorithm, calculates the key of the reselected security algorithm, and further makes the core network 1 accept the tracking area update. The VoLTE call service is kept connected. The content involved in this process can refer to the description of steps S213-S222 in FIG. 7, and will not be repeated here.
[0254] Based on the foregoing FIG. 6, FIG. 7 and description, in the case that the terminal fails to perform SMC, the terminal feeds back the cause value 23 to the core network, but the priority of the reselected security algorithm (for example, algorithm 2) of the core network 1 in the new tracking area (for example, TA2) is actually lower than that of the initially selected security algorithm (for example, algorithm 1). Since the core network considers the possibility of service privacy when selecting the security algorithm, the security performance of the reselected security algorithm is not as good as that of the initially selected security algorithm when data is transmitted, which may not meet the security requirements of some services with high security requirements. For some services with high security requirements, in the case that the terminal fails to perform SMC, the terminal can feed back the cause value 24 instead of the cause value 23. Because the feedback of the cause value 24 makes the core network troubleshoot the error cause instead of replacing the security algorithm, if the core network can troubleshoot the error cause, the TAU has the possibility of success, and the terminal and the core network use the security algorithm with high security when transmitting data. The description of this process can refer to FIG. 9 as follows.
[0255] As described in the foregoing FIG. 3, FIG. 5 and FIG. 7, the terminal is still taken as an example in the triggering scenario of the TAU process in the VoLTE call service (the same as the foregoing steps S11-S19, which will not be repeated here), and the execution of the TAU process is triggered.
[0256] S401. The terminal sends a tracking area update request message to the core network 1.
[0257] In the case that the TA code of the cell 1 and the TA code of the cell 2 are determined to be different, the terminal sends a tracking area update request message to the core network 1.
[0258] Specifically, the terminal can send the tracking area update request message to the MME node 2 of the core network 1. The related content of the MME node 2 can refer to the description of the MME node 2 in the foregoing step S20, and will not be repeated here.
[0259] After receiving the tracking area update request message, the MME node 2 migrates the context of the terminal in TA1 to TA2. Here, the context to be migrated includes the security algorithm supported by the terminal.
[0260] After starting the migration of the context in TA1 to TA2, the MME node 2 performs step S402, and sends an authentication data request message to the HHS in the core network 1.
[0261] However, the MME node 2 does not receive the authentication data response message. The related content involved in the authentication data request message and the authentication data response message can refer to the foregoing description of step S211, and will not be described here.
[0262] Subsequently, in response to the event that the MME node 2 does not receive the authentication data response, the core network 1 makes an unreasonable response, which is consistent with the foregoing scenario of the TAU process failure. The step S403 is performed, and the security mode command is sent to the terminal through the MME node 2, without sending the authentication request message to the terminal.
[0263] S403. The core network 1 sends a security mode command to the terminal through the MME node 2.
[0264] The security mode command carries the algorithm 1 as the security algorithm of the terminal in TA2.
[0265] The security mode command is a command for establishing a secure connection. The terminal can calculate the key of the security algorithm (algorithm 1) used in TA2 by executing the security mode command.
[0266] Without receiving the authentication request message sent by the core network 1, the terminal cannot calculate the key of the algorithm 1. The terminal fails to execute the SMC.
[0267] S404. In the case of the failure of the execution of the SMC, the terminal judges the priority of the current service.
[0268] The current service can be the service being executed by the terminal in the case of the failure of the execution of the SMC, which can be the VoLTE call service involved in the foregoing description.
[0269] Here, the priority of the current service is proportional to the privacy of the current service. If the privacy of the current service is higher, a security algorithm with higher security is required.
[0270] The terminal judges the priority of the current service in the following manner: a high-priority service list is set, and if the current service is in the list, the priority of the current service is higher than a preset level. If the current service is not in the list, the priority of the current service is lower than the preset level.
[0271] If the priority of the current service is lower than the preset level, the following step S405a is performed.
[0272] S405a. The terminal triggers the core network to reselect a security algorithm and calculates a key of the reselected security algorithm in the manner of the aforementioned sending reason value 23, and then accepts the tracking area update from the core network 1. If the current service is still a VoLTE call service, the VoLTE call service can be maintained. After the TAU procedure is successful, the terminal and the core network can use the algorithm 2 and the key of the algorithm 2 to send call data to the opposite terminal. The detailed content involved in the process can be referred to the description of steps S301-S308 in FIG. 8.
[0273] If the priority of the current service is higher than the preset level, the following step S405b is performed.
[0274] S405b. The terminal releases the connection with the cell 2 and initiates scanning to find an available cell in the manner of the sending reason value 24 in the case that the authentication request message sent by the core network 1 has not been received yet but the security mode command sent by the core network 1 is received again.
[0275] In step S405b, the terminal can release the connection with the cell 2 and initiate scanning to find an available cell in the manner of the sending reason value 24, which can be referred to the aforementioned description of step S113. Here, the terminal can release the connection with the cell 2 and initiate scanning to find an available cell after at most three (for example, 1, 2 or 3) times of failure of performing SMC.
[0276] It should be noted that although the manner of the sending reason value 24 can cause service interruption, after the terminal finds an available cell, the terminal can still communicate with the core network and the security algorithm can also meet the needs of the service. Compared with service information leakage, the loss of service interruption is smaller.
[0277] The following introduces an exemplary terminal provided by an embodiment of the present application.
[0278] FIG. 10 is a structural schematic diagram of a terminal provided by an embodiment of the present application.
[0279] It should be understood that the terminal can have more or fewer components than those shown in FIG. 10, can combine two or more components, or can have a different component configuration. The various components shown in FIG. 10 can be implemented in hardware, software, or a combination of hardware and software including one or more signal processing and / or application specific integrated circuits.
[0280] The terminal can include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headset interface 170D, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 can include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0281] In the embodiments of the present application, the processor 110 can call the computer instructions stored in the internal memory 121 to enable the terminal to perform the method in the embodiments of the present application. For example, the processor 110 can include one or more processing units, and can include an application processor (AP) and a modem. After the AP determines that the terminal is in a tracking area update, the AP sends an instruction to perform a tracking area update to the modem. After the modem receives the instruction to perform a tracking area update, the modem can interact with the base station through the antenna to implement the method in the embodiments of the present application to perform a tracking area update.
[0282] Some embodiments of the present application provide a chip system applied to a terminal, the chip system including one or more processors, the processor being configured to call computer instructions to enable the terminal to perform the communication method for performing a tracking area update. The chip system can be a modem or a system on chip (Soc) including a modem, and the method in the embodiments of the present application can be implemented by the modem.
[0283] In addition to the processor, the chip system can further include at least one interface configured to receive computer instructions and transmit the computer instructions to the processor.
[0284] The application further provides a computer program product, comprising a computer program (also referred to as code or instructions), which, when executed by a computer, causes the computer to perform the method performed by the terminal in any one of the above embodiments.
[0285] The application further provides a computer readable storage medium, which stores a computer program (also referred to as code or instructions). When the computer program is executed, it causes a computer to perform the method performed by the terminal in any one of the above embodiments.
[0286] The above-described embodiments are only used to illustrate the technical solutions of the present application, but not limit the present application; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement to part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.
[0287] In the above-described embodiments, according to the context, the term "when" can be interpreted as meaning "if" or "after" or "in response to determining" or "in response to detecting". Similarly, according to the context, the phrase "upon determining" or "if detecting (the stated condition or event)" can be interpreted as meaning "if determining" or "in response to determining" or "upon detecting (the stated condition or event)" or "in response to detecting (the stated condition or event)".
[0288] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to be limiting to the present application. As used in the specification and the appended claims of the present application, the singular forms "a," "an," and "the" are intended to include plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "and / or" used in the present application, mean and include any or all possible combinations of one or more listed items.
[0289] The terms "first", "second" are only used for description purposes, and cannot be understood as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features, and in the description of the embodiments of the present application, unless otherwise specified, the meaning of "multiple" is two or more.
[0290] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk) and the like.
[0291] Those of ordinary skill in the art understand that all or part of the processes in the above embodiments can be implemented by a computer program to instruct the relevant hardware, which can be stored in a computer readable storage medium. When the program is executed, it can include the processes of the above method embodiments. The aforementioned storage medium includes ROM or random access memory (RAM), magnetic disk or optical disk, and various media that can store program codes.
Claims
1. A communication method for updating tracking regions, characterized in that, Applied to a terminal, the terminal accesses a first cell and communicates with a first core network through the access network equipment corresponding to the first cell. The method includes: The user switches from the first cell to the second cell, where the second cell and the first cell belong to different tracking areas. Send a tracking area update request to the first core network; If no authentication request in response to the tracking area update request is received from the first core network, but a first security mode command is received from the first core network, a first security mode rejection message in response to the first security mode command is sent to the first core network. The authentication request includes parameters for calculating the key of a security algorithm. The first security mode command carries first indication information, which indicates that the first algorithm should be used as the security algorithm. The security algorithm is determined by the first core network based on security capability information sent by the terminal. The security capability information carries the security algorithms supported by the terminal, including the first algorithm and the second algorithm. The first security mode rejection message carries a reason value 23, which indicates that the terminal does not support the first algorithm. The reason value 23 is used to trigger the first core network to send a first authentication request and a second security mode command to the terminal. The first authentication request carries a first parameter. The second security mode command carries second indication information, which indicates that the second algorithm should be used as the security algorithm. The first parameter is used by the terminal to calculate the key of the second algorithm.
2. A communication method for updating tracking regions, characterized in that, Applied to a terminal that is connected to a first cell and communicates with a first core network through the access network equipment of the first cell, the method includes: When handling the first service, the system switches from the first cell to the second cell, where the second cell and the first cell belong to different tracking areas. Send a tracking area update request to the first core network; If the authentication request for responding to the tracking area update request is not received from the first core network, but a first security mode command is received from the first core network, and the priority of the first service is lower than a preset level, a first security mode rejection message for responding to the first security mode command is sent to the first core network. The authentication request includes parameters for calculating the key of the security algorithm. The first security mode command carries first indication information, which indicates that the first algorithm is used as the security algorithm. The security algorithm is determined by the first core network based on security capability information sent by the terminal. The security capability information carries the security algorithms supported by the terminal, including the first algorithm and the second algorithm. The first security mode rejection message carries a reason value 23, which indicates that the terminal does not support the first algorithm. The reason value 23 is used to trigger the first core network to send a first authentication request and a second security mode command to the terminal. The first authentication request carries a first parameter. The second security mode command carries second indication information, which indicates that the second algorithm is used as the security algorithm. The first parameter is used by the terminal to calculate the key of the second algorithm.
3. The method according to claim 2, characterized in that, The method further includes: If no authentication request for responding to the tracking area update request is received from the first core network, but a first security mode command is received from the first core network, and the priority of the first service is higher than the preset level, after receiving the first security mode command from the first core network, a second security mode rejection message for responding to the first security mode command is sent to the first core network; the second security mode rejection message carries a reason value 24, which indicates that the reason for rejecting the security mode is unknown; If the terminal still does not receive the authentication request sent by the first core network, but receives a first security mode command sent by the first core network in response to the second security mode rejection message, the terminal releases the connection with the second cell and initiates a scan to find an available cell.
4. A communication method for updating tracking regions, characterized in that, Applied to a terminal that is connected to a first cell and communicates with a first core network through the access network equipment of the first cell, the method includes: When handling the first service, the system switches from the first cell to the second cell, where the second cell and the first cell belong to different tracking areas. Send a tracking area update request to the first core network; If no authentication request for responding to the tracking area update request is received from the first core network, but a first security mode command is received from the first core network, the key for the first algorithm is calculated based on the second parameter. The authentication request includes parameters for calculating the key for the security algorithm. The first security mode command carries first indication information, which indicates that the first algorithm is used as the security algorithm. The security algorithm is determined by the first core network based on security capability information sent by the terminal. The security capability information carries the security algorithms supported by the terminal, including the first algorithm and the second algorithm. The second parameter is a parameter sent by the first core network to the terminal for calculating the key for the third algorithm. The third algorithm is the security algorithm used by the terminal in the tracking area of the first cell. A first security mode completion message is sent to the first core network in response to the first security mode command; the first security mode completion message carries a first verification value; the first verification value is generated based on the key of the first algorithm and is used to verify whether the key of the first algorithm is correct; In the event of a key error in the first algorithm, the first security mode command sent by the first core network is received again, but the authentication request sent by the first core network is still not received. A first security mode rejection message is sent to the first core network in response to the first security mode command. The first security mode rejection message carries a reason value 23, which indicates that the terminal does not support the first algorithm. The reason value 23 is used to trigger the first core network to send a first authentication request and a second security mode command to the terminal. The first authentication request carries a first parameter. The second security mode command carries second indication information, which indicates that the second algorithm should be used as the security algorithm. The first parameter is used by the terminal to calculate the key of the second algorithm.
5. The method according to claim 4, characterized in that, The method further includes: If the key of the first algorithm is correct, a tracking area update receiving message sent by the first core network in response to the tracking area update request is received; The first data of the first service is processed using the first algorithm and the key of the first algorithm, and the processed first data is transmitted to the first core network through the access network equipment of the second cell.
6. The method according to any one of claims 1-5, characterized in that, After sending a first security mode rejection message in response to a first security mode command to the first core network, the method further includes: Receive the first authentication request sent by the first core network, and receive the second security mode command sent by the first core network; The key for the second algorithm is calculated based on the first parameter; The first data of the first service is processed by the second algorithm and the key of the second algorithm, and the processed first data is transmitted to the first core network through the access network equipment of the second cell.
7. The method according to any one of claims 2-5, characterized in that, The conditions under which the first security mode command carries the first indication information include: determining that the first algorithm has a higher priority than the second algorithm based on the network conditions of the tracking area where the first service and / or the second cell are located.
8. The method according to claim 6, characterized in that, After calculating the key for the second algorithm based on the first parameter, and before processing the first data of the first service using the second algorithm and the key of the second algorithm, the method further includes: A second security mode completion message is sent to the first core network in response to the second security mode command; the second security mode completion message carries a second verification value; the second verification value is generated based on the key of the second algorithm and is used to verify whether the key of the second algorithm is correct; If the key for the second algorithm is correct, a tracking area update receive message sent by the first core network in response to the tracking area update request is received.
9. The method according to any one of claims 1-8, characterized in that, The system did not receive an authentication request from the first core network in response to the tracking area update request, but received a first security mode command from the first core network, specifically including: After sending a tracking area update request to the first core network, but before receiving the first security mode command sent by the first core network, no authentication request for responding to the tracking area update request is received from the first core network.
10. The method according to any one of claims 1-9, characterized in that, The first core network is a 4G core network.
11. A terminal, characterized in that, include: One or more processors and a memory; the memory is coupled to the one or more processors, the memory being used to store computer program code, the computer program code including computer instructions, the one or more processors invoking the computer instructions to cause the terminal to perform the method as described in any one of claims 1-10.
12. A computer-readable storage medium comprising computer instructions, characterized in that, When the computer instructions are executed on the terminal, the terminal causes the terminal to perform the method as described in any one of claims 1-10.
13. A chip system applied to a terminal, characterized in that, The chip system includes one or more processors, which are used to invoke computer instructions to cause the terminal to perform the method as described in any one of claims 1-10.
Citation Information
Patent Citations
Network registration method and terminal
CN108024326A
Method for tracking area update in wireless communication system and apparatus therefor
CN109076330A
Security mode integrity verification
US20200288320A1
Communication method and apparatus, and device
WO2022067815A1