Communication method and device

By determining the routing path based on the terminal's authentication status after receiving NAS messages, the access network device solves the security problem of NAS message routing in the distributed NAS architecture and prevents unauthorized UEs from attacking core network elements.

WO2026011444A1PCT designated stage Publication Date: 2026-01-15GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/105322
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-12
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

In a distributed NAS architecture, how to effectively route NAS messages and prevent unauthorized UEs from attacking core network elements has become an urgent problem to be solved.

Method used

After receiving a NAS message, the access network device determines whether to route the message to the target core network element by checking the authentication status of the terminal, thus ensuring the security of the message.

Benefits of technology

This effectively prevents unauthorized terminals from attacking core network elements and ensures secure routing of NAS messages.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024105322_15012026_PF_FP_ABST
    Figure CN2024105322_15012026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a communication method and device. The method comprises: receiving a first message from a terminal, wherein the first message carries a first non-access-stratum (NAS) message; and when it is determined to route the first NAS message, routing the first NAS message to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of performing NAS message transmission with the terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods and devices Technical Field

[0001] This application relates to the field of communications, and more specifically, to a communication method and apparatus. Background Technology

[0002] In 5G architecture, the Access and Mobility Management Function (AMF) acts as a core network node connected to the access network. This AMF routes control plane signaling from the User Equipment (UE) to the Network Functions (NFs) in the core network. However, a distributed NAS (Non-Access-stratum) architecture has been proposed for 6G systems. In this architecture, the UE can establish separate NAS connections with one or more NFs in the core network. Therefore, how to route the NAS messages transmitted on these NAS connections and prevent unauthorized UE attacks on core network elements becomes a problem that needs to be solved.

[0003] Summary of the Invention

[0004] This application provides a communication method and device.

[0005] This application provides a communication method executed by an access network device, including:

[0006] Receive a first message from the terminal, wherein the first message carries a first NAS message;

[0007] If the routing of the first NAS message is determined, the first NAS message is routed to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

[0008] This application provides a communication method executed by a terminal, including:

[0009] Send a first message to the access network device, wherein the first message carries a first NAS message, and the access network device determines whether the first NAS message is routed to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

[0010] This application provides a communication method executed by a target core network element, comprising:

[0011] Receive a first NAS message from the access network device, wherein the first NAS message is carried by a first message sent by the terminal to the access network device.

[0012] This application provides a communication method executed by a first core network element, comprising:

[0013] A second message is sent to the access network device, wherein the second message is used by the access network device to determine whether to route the first NAS message from the terminal.

[0014] This application provides a communication method executed by a second core network element, comprising:

[0015] Send the AS (Access Stratum) security key between the access network device and the terminal to the access network device.

[0016] This application provides an access network device, including:

[0017] A first communication unit is configured to receive a first message from a terminal, wherein the first message carries a first NAS message; and, if the routing of the first NAS message is determined, to route the first NAS message to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

[0018] This application provides a terminal, including:

[0019] The second communication unit is used to send a first message to the access network device, wherein the first message carries a first NAS message, and the access network device determines whether the first NAS message is routed to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

[0020] This application provides a target core network element, including:

[0021] The third communication unit is used to receive a first NAS message from the access network device, wherein the first NAS message is carried by a first message sent by the terminal to the access network device.

[0022] This application provides a first core network element, including:

[0023] The fourth communication unit is used to send a second message to the access network device, wherein the second message is used by the access network device to determine whether to route the first NAS message from the terminal.

[0024] This application provides a second core network element, including:

[0025] The fifth communication unit is used to send the AS security key between the access network device and the terminal to the access network device.

[0026] By adopting the above scheme, after the access network device receives the first message carrying the first NAS message from the terminal, it will only route the first NAS message to the target core network element in the core network if it determines that the first NAS message should be routed. In this way, the access network device will determine whether to route the first NAS message, thus avoiding the problem of attacks on core network elements by unauthorized terminals that could result from the access network device directly routing the NAS message to the core network side. This ensures that the access network device routes the NAS message while also guaranteeing the security of the NAS message routed by the access network device. Attached Figure Description

[0027] Figure 1 is a schematic diagram of an application scenario according to an embodiment of this application.

[0028] Figure 2 is a schematic flowchart of a communication method according to an embodiment of this application.

[0029] Figure 3 is a schematic flowchart of a communication method according to another embodiment of this application.

[0030] Figure 4 is a schematic flowchart of a communication method according to another embodiment of this application.

[0031] Figure 5 is a schematic flowchart of a communication method according to another embodiment of this application.

[0032] Figure 6 is a schematic flowchart of a communication method according to another embodiment of this application.

[0033] Figure 7 is an exemplary flowchart of sending the UE's authentication status to the AN according to an embodiment of this application.

[0034] Figure 8 is another exemplary flowchart of a communication method according to an embodiment of this application.

[0035] Figure 9 is an example diagram of a key derivation process according to an embodiment of this application.

[0036] Figure 10 is a schematic diagram of a key derivation architecture according to an embodiment of this application.

[0037] Figure 11 is a schematic block diagram of an access network device according to an embodiment of the present application.

[0038] Figure 12 is a schematic block diagram of a terminal according to an embodiment of this application.

[0039] Figure 13 is a schematic block diagram of a target core network element according to an embodiment of the present application.

[0040] Figure 14 is a schematic block diagram of a first core network element according to an embodiment of the present application.

[0041] Figure 15 is a schematic block diagram of a second core network element according to an embodiment of the present application. Detailed Implementation

[0042] The technical solutions of this application embodiment can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.

[0043] This application describes various embodiments in conjunction with network devices and terminals. The terminal can be mobile or fixed, and may also be referred to as a mobile station, user unit, etc. The terminal can be a station in a WLAN, or a smart terminal, wireless modem, laptop, tablet, etc. In this application's embodiments, the terminal can be a VR / AR terminal, industrial control terminal, autonomous driving terminal, telemedicine terminal, smart grid terminal, transportation safety terminal, smart city terminal, or smart home wireless terminal, etc. By way of example and not limitation, in this application's embodiments, the terminal can also be a wearable device.

[0044] In this embodiment, the network device can be a device for communicating with a terminal. The network device can be an access point in a WLAN, an evolved base station in LTE, a relay station, a network device (gNB) in a vehicle-mounted device, wearable device, or NR network, or a network device in a future PLMN network, or a network device in a non-terrestrial network, etc. As an example and not a limitation, in this embodiment, the network device can have mobility characteristics; for example, the network device can be a mobile device.

[0045] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.

[0046] Figure 1 exemplarily illustrates a communication system 100. The communication system includes network devices 110 and terminals 120. In one possible implementation, the communication system 100 may include multiple network devices 110, and the coverage area of ​​each network device 110 may include other numbers of terminals 120; this embodiment does not limit this. In another possible implementation, the communication system 100 may also include other network entities such as mobility management entities and access and mobility management functions; this embodiment does not limit this. The network devices may further include access network devices and first core network elements. That is, the communication system may also include multiple core networks for communicating with the access network devices. The access network devices may be base stations of LTE, LTE-A, or NR systems. Taking the communication system shown in Figure 1 as an example, the communication devices may include network devices and terminals with communication functions. The communication devices may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities; this embodiment does not limit this.

[0047] Figure 2 is a schematic flowchart of a communication method performed by an access network device according to an embodiment of this application. The method includes at least a portion of the following.

[0048] S210. Receive a first message from the terminal, wherein the first message carries a first NAS message;

[0049] S220. If the routing of the first NAS message is determined, the first NAS message is routed to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

[0050] Figure 3 is a schematic flowchart of a communication method executed by a terminal according to an embodiment of this application. The method includes at least a portion of the following.

[0051] S310. Send a first message to the access network device, wherein the first message carries a first NAS message, and the access network device determines whether the first NAS message is routed to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

[0052] Figure 4 is a schematic flowchart of a communication method performed by a target core network element according to an embodiment of this application. The method includes at least some of the following.

[0053] S410. Receive a first NAS message from the access network device, wherein the first NAS message is carried by a first message sent by the terminal to the access network device.

[0054] Figure 5 is a schematic flowchart of a communication method performed by a first core network element according to an embodiment of this application. The method includes at least some of the following:

[0055] S510. Send a second message to the access network device, wherein the second message is used by the access network device to determine whether to route the first NAS message from the terminal.

[0056] Figure 6 is a schematic flowchart of a communication method performed by a second core network element according to an embodiment of this application. The method includes at least some of the following:

[0057] S610. Send the access layer AS security key between the access network device and the terminal to the access network device.

[0058] The access network device can be a coverage terminal on the AN (Access Network) side of the communication network and / or a device capable of transmitting AS messages with the terminal. This access network device can also be referred to as an access network node.

[0059] The terminal can transmit NAS messages with multiple core network elements on the core network side, and the number of these multiple core network elements is not limited in this embodiment.

[0060] The target core network element can be any one of multiple core network elements capable of transmitting NAS messages with the terminal and / or establishing a connection (or NAS connection, or NAS secure connection) with the terminal. In some possible examples of this application, any core network element capable of transmitting NAS messages with the terminal and / or establishing a connection (or NAS connection, or NAS secure connection) with the terminal is represented as NFx.

[0061] The multiple core network elements may include: core network elements (or network elements) of the service domain for which the terminal establishes a connection, and one or more core network elements other than the core network elements (or network elements) of the service domain for which the terminal establishes a connection, which the terminal can establish a connection (or NAS connection, or NAS secure connection).

[0062] The core network element (or network element) of the service domain to which the terminal establishes a connection can refer to the network element or function to which the terminal connects during the registration or authentication process. For example, the core network element (or network element) of the service domain to which the terminal establishes a connection can be an MM NF (Mobility Management Network Function) or an MMF (Mobility Management Function).

[0063] In addition to the core network element (or network element) of the service domain to which the terminal establishes a connection, any one of the one or more core network elements that the terminal can establish a connection (or NAS connection, or NAS secure connection) can be an SM NF (Session Management Network Function). It should be understood that this is merely an illustrative example; in actual processing, the one or more core network elements that the terminal can establish a connection (or NAS connection, or NAS secure connection) besides the core network element (or network element) of the service domain to which the terminal first establishes a connection may include many other possible functions or network elements. This embodiment does not limit or exhaustively list them.

[0064] The first core network element may include at least one of the following: UDM (Unified Data Management) function, UDR (Unified Data Repository) function, etc.

[0065] In some possible implementations, before receiving the first message, the access network device may include: receiving a second message from a first core network element, wherein the second message is used by the access network device to determine whether to route the first NAS message.

[0066] In one embodiment, the second message carries the authentication status of the terminal, wherein the authentication status of the terminal includes at least one of the following: the authentication result of the terminal, the first identifier of the terminal, and the authentication timestamp of the terminal.

[0067] The authentication result of the terminal can be used to indicate whether the terminal has been successfully authenticated; that is, the authentication result of the terminal can be an authentication result indicating whether the terminal has been successfully authenticated.

[0068] The first identifier of the terminal may include at least one of the following: the terminal's SUPI (Subscription Permanent Identifier), the terminal's GUTI (Globally Unique Temporary Identifier), the terminal's RNTI (Radio Network Temporary Identifier), etc.

[0069] The RNTI of the terminal may include at least one of the following: the terminal's RA-RNTI (Random Access-RNTI), the terminal's TC-RNTI (Temporary Cell Radio Network Temporary Identifier), the terminal's C-RNTI (Cell Radio Network Temporary Identifier), the terminal's P-RNTI (Paging Radio Network Temporary Identifier), the terminal's CS-RNTI (Cell-Specific Radio Network Temporary Identifier), etc.

[0070] Optionally, the terminal's first identifier may only include the terminal's SUPI.

[0071] After receiving the authentication status of the terminal, the access network device can associate (or bind) the terminal's SUPI in the authentication status with the terminal's second identifier and save it. The second identifier of the terminal is an identifier of the terminal that the access network device can recognize; for example, the second identifier of the terminal may include at least one of the following: the terminal's GUTI, the terminal's RNTI, etc.

[0072] Optionally, the terminal's first identifier includes the terminal's SUPI, and the terminal's first identifier also includes at least one of the terminal's GUTI and RNTI. After receiving the terminal's authentication status, the access network device can directly save the terminal's first identifier.

[0073] The authentication timestamp of the terminal can be the specific time or moment when the terminal completes authentication. Adding a timestamp during the authentication process helps prevent replay attacks, that is, it prevents attackers from repeatedly sending previously used authentication information to pass authentication.

[0074] The authentication status of the terminal may include, in addition to at least one of the following: the terminal's authentication result, the terminal's first identifier, and the terminal's authentication timestamp, at least one of the following: the terminal's authentication type, SNN (Serving Network Name), etc. The terminal's authentication type may include one of the following: 5G-AKA (5G Authentication and Key Agreement), EAP (Extensible Authentication Protocol), etc. This embodiment does not limit or exhaustively list all possible contents that the terminal's authentication status may include.

[0075] In this embodiment, the timing of the first core network element sending the second message can be performed after the terminal and the core network side have completed authentication (such as two-way authentication). For example, the first core network element sending the second message to the access network device can be as follows: after the terminal and the core network side have completed authentication and the first core network element has obtained the authentication status of the terminal, the first core network element sends a second message carrying the authentication status of the terminal to the access network device.

[0076] The second message can be carried by any type of message between the first core network element and the access network device. For example, if the first core network element is a UDM, the second message can be carried by "Nudm_UEAuthentication_ResultConfirmation Notify", which is the "UE authentication result confirmation notification" in the UDM.

[0077] This embodiment does not limit the triggering method for authentication between the terminal and the core network. For example, it can be triggered and executed during the initial registration phase of the terminal. The core network elements involved in the terminal's authentication process can include at least one of the following: MM NF, MMF, AUSF (Authentication Server Function), and UDM. Here, the core network elements involved in the terminal's authentication process are not limited or exhaustively listed.

[0078] Taking the initial registration phase of a terminal as an example, triggering and executing authentication processing between the terminal and the core network, the terminal can first send a fourth message to the access network device, which carries a registration request. The access network device's processing can include: receiving the fourth message carrying the registration request from the terminal, and sending a fifth message to the third core network element, wherein the fifth message carries the registration request. The third core network element's processing can include: receiving the fifth message from the access network device, performing interactive processing with the first core network element, and creating the terminal's MM (Mobility Management) context. After the third core network element creates the terminal's MM context, the terminal performs authentication processing with the core network element.

[0079] The method by which the access network equipment determines the third core network element is not limited in this embodiment.

[0080] This third core network element can be a core network element of a service domain that can establish a connection with a terminal among multiple core network elements that can transmit NAS messages to the terminal, such as MM NF or MMF.

[0081] The interaction between the third core network element and the first core network element may include at least one of the following: the execution of Nudm_UECM_Reg (i.e., the user context management registration process of unified data management) between the third core network element and the first core network element; the execution of Nudm_SDM_Get (i.e., the session management subscription data acquisition process between the third core network element and the first core network element); etc.

[0082] After receiving the second message carrying the authentication status of the terminal, the access network device may also include: saving the authentication status of the terminal.

[0083] Optionally, the access network device may save the authentication status of the terminal in local storage space, but does not limit the specific storage location of the authentication status of the terminal.

[0084] Optionally, the process of the access network device saving the authentication status of the terminal may include: saving the authentication status of the terminal in the AS security context. Specifically, the AS security context refers to the AS security context corresponding to the terminal.

[0085] Referring to Figure 7, an exemplary illustration is provided. This example summarizes the process as follows: After successful mutual authentication between the UE and the core network security element, the UE's authentication status (UE authentication result, UE ID, authentication timestamp) is sent to the base station (access network device) as part of the AS security context. This is used by the base station to determine, from the access network's perspective, whether it can route the first RRC message from the UE (the first NAS message carried by the first RRC message). Specifically, this includes:

[0086] S701, the UE (i.e., the terminal) sends a fourth message to the AN (including the access network equipment). This fourth message can be an RRC message carrying a registration request. Specifically, the RRC message can carry the registration request in a NAS-MM (Mobility Management) container.

[0087] S702, AN determines MM NF.

[0088] S703, AN sends a fifth message to MM NF, which may carry a registration request, and the fifth message may be a registration request for Nmm_InitialUE (initial UE).

[0089] S704, MM NF, and UDM perform user context management registration procedures (such as Nudm_UECM_Reg).

[0090] S705, UDM and MM NF execute session management subscription data acquisition procedures (such as Nudm_SDM_Get).

[0091] S706, MM NF creates the MM context for the UE. Then the UE performs authentication with the core network side equipment (such as MM NF, AUSF, UDM, etc.) through AN.

[0092] S707, the UDM sends a second message to the AN carrying the authentication status of the UE. This second message can be Nudm_UEAuthentication_ResultConfirmation Notify.

[0093] S708, AN stores the UE's authentication status.

[0094] In one embodiment, after completing authentication, the terminal can send a first message to the access network device at any time. After receiving a second message (or saving the terminal's authentication status), the access network device can receive the first message from the terminal at any time.

[0095] The first message can be any type of AS message transmitted between the terminal and the access network device. For example, the first message can be a first RRC message.

[0096] The way the first NAS message is carried in the first message can be either by including the first NAS message in the first NAS container or by including the specific content of the first NAS message.

[0097] Optionally, in addition to carrying the first NAS message, the first message may also carry a second identifier of the terminal. The second identifier of the terminal may include at least one of the terminal's GUTI, the terminal's RNTI, etc.

[0098] After receiving the first message, the access network device further includes: checking whether the terminal's authentication status is stored locally based on the second identifier of the terminal carried in the first message. Further, if the access network device determines that the terminal's authentication status is stored locally, it may also include: determining whether to route the first NAS message based on the terminal's authentication status. Additionally, it may also include: determining not to route the first NAS message if the terminal's authentication status is not stored locally.

[0099] The access network device can check whether the terminal's authentication status is stored locally based on the terminal's second identifier carried in the first message by: checking whether the terminal's authentication status exists among the candidate authentication statuses of one or more candidate terminals stored locally, based on the terminal's second identifier carried in the first message. On the access network device side, the method for obtaining the candidate authentication status of each candidate terminal is the same as the method for obtaining the terminal's authentication status; the possible content of each candidate terminal's candidate authentication status is also similar to the possible content of the terminal's authentication status, and will not be elaborated upon further.

[0100] Optionally, the first identifier of each candidate terminal in the candidate authentication status only includes the SUPI of that candidate terminal, and the access network device associates or binds and stores the first identifier and the second identifier of the candidate terminal. In this case, based on the second identifier of the terminal carried in the first message, searching for the existence of a terminal's authentication status from the candidate authentication status of each of the one or more candidate terminals stored locally can be: based on the second identifier associated with the first identifier of the candidate terminal included in the candidate authentication status of each of the one or more candidate terminals stored locally, searching for whether there is a target candidate terminal that matches the second identifier of the terminal carried in the first message; if so, the candidate authentication status of the target candidate terminal is used as the terminal's authentication status; if not, it is determined that the authentication status of the terminal is not stored locally.

[0101] Optionally, the first identifier of a candidate terminal in the candidate authentication status of each candidate terminal includes the candidate terminal's SUPI, as well as the candidate terminal's GUTI and / or the candidate terminal's RNTI. In this case, based on the second identifier of the terminal carried in the first message, searching for the existence of a terminal's authentication status from the candidate authentication status of each of the one or more locally stored candidate terminals can be done as follows: based on the first identifier of the candidate terminal included in the candidate authentication status of each of the one or more locally stored candidate terminals, searching for the existence of a target candidate terminal that matches the second identifier of the terminal carried in the first message; if it exists, then the candidate authentication status of the target candidate terminal is used as the terminal's authentication status; if it does not exist, then it is determined that the authentication status of the terminal is not stored locally.

[0102] Determining whether to route the first NAS message based on the authentication status of the terminal may include: determining whether the terminal meets a first condition based on the authentication status of the terminal. Further, it may also include: determining to route the first NAS message if the first condition is met; and determining not to route the first NAS message if the first condition is not met.

[0103] For example, the first condition may include at least one of the following: the terminal is within the authentication validity period, and the authentication result of the terminal is successful.

[0104] Optionally, the first condition may be that the terminal's authentication result is successful. The process of determining whether to route the first NAS message based on the terminal's authentication status may include: determining whether the authentication result in the terminal's authentication status is successful. Further, if the authentication result in the terminal's authentication status is successful, the first NAS message is determined to be routed; if the authentication result in the terminal's authentication status is unsuccessful, the first NAS message is determined not to be routed.

[0105] Optionally, the first condition may be that the terminal is within the authentication validity period. The process of determining whether to route the first NAS message based on the terminal's authentication status may include: extracting the terminal's authentication timestamp from the terminal's authentication status, and determining whether the terminal is within the authentication validity period based on the current time and the terminal's authentication timestamp. Further, if the terminal is within the authentication validity period, then the first NAS message is routed; if the terminal is not within the authentication validity period, then the first NAS message is not routed.

[0106] The authentication validity period can be configured according to the actual situation, and this embodiment does not limit it. Determining whether the terminal is within the authentication validity period based on the current time and the terminal's authentication timestamp can be done as follows: subtract the terminal's authentication timestamp from the current time to obtain the terminal's authentication duration, and determine whether the terminal's authentication duration has not exceeded the authentication validity period. If it has not exceeded the validity period, the terminal is within the authentication validity period; otherwise, the terminal is not within the authentication validity period.

[0107] Optionally, the first condition may include the terminal being within the authentication validity period and the terminal's authentication result being successful.

[0108] The process of determining whether to route the first NAS message based on the terminal's authentication status may include: determining whether the authentication result in the terminal's authentication status is successful; if the authentication result in the terminal's authentication status is unsuccessful, determining not to route the first NAS message; if the authentication result in the terminal's authentication status is successful, extracting the terminal's authentication timestamp contained in the terminal's authentication status, and determining whether the terminal is within the authentication validity period based on the current time and the terminal's authentication timestamp; if the terminal is within the authentication validity period, determining to route the first NAS message; if the terminal is not within the authentication validity period, determining not to route the first NAS message. It should be understood that this is only an illustrative example. In actual processing, the order in which the access network device performs the above determinations may also be: first determining whether the terminal is within the authentication validity period, then determining whether the terminal has been successfully authenticated, or the access network device may simultaneously determine whether the terminal is within the authentication validity period and whether the terminal has been successfully authenticated, etc. The order in which the access network device performs the determinations is not limited or exhaustively listed here.

[0109] Once the access network device determines the route for the first NAS message, it can send the first NAS message to the target core network element. Correspondingly, the target core network element receives the first NAS message from the access network device.

[0110] Optionally, the target core network element can be determined by the first core network element. In this case, the processing of the access network device may further include: receiving information about the target core network element from the first core network element. Furthermore, the access network device may determine the target core network element based on the information about the target core network element.

[0111] The information of the target core network element may include at least one of the following: the network address of the target core network element, the instance ID of the target core network element, and the FQDN (Fully Qualified Domain Name) of the target core network element. The network address may include at least one of the following: IP address (Internet Protocol Address) and MAC address (Media Access Control Address).

[0112] Before receiving information from the target core network element from the first core network element, the processing of the access network device may further include: sending a third message to the first core network element, wherein the third message is used to request information from the target core network element. Correspondingly, the processing of the first core network element further includes: receiving a third message from the access network device, wherein the third message is used to request information from the target core network element.

[0113] In one scenario, the third message may carry the identifier of the terminal and the type of the first NAS message.

[0114] The identifier of the terminal carried in the third message can be the second identifier of the terminal. That is, the access network device can add the second identifier of the terminal carried in the first message to the third message. Alternatively, the identifier of the terminal carried in the third message can be the first identifier of the terminal. That is, the access network device can determine the first identifier of the terminal associated with the second identifier of the terminal based on the second identifier of the terminal carried in the first message, and add the first identifier of the terminal to the third message.

[0115] The type of the first NAS message can be carried in the first message. This embodiment does not limit how the type of the first NAS message is carried in the first message, and the access network device can obtain the type of the first NAS message from the first message. Alternatively, the type of the first NAS message can be determined by the access network device based on the first message. This embodiment also does not limit how the access network device specifically determines the type of the first NAS message based on the first message.

[0116] The method for determining the target core network element in the first core network element can be as follows: Based on the terminal's identifier, determine multiple core network elements corresponding to the terminal; and select one core network element from these multiple core network elements that matches the type of the first NAS message as the target core network element. Specifically, determining multiple core network elements corresponding to the terminal based on the terminal's identifier can include one of the following: If the third message carries the terminal's second identifier, determine the terminal's first identifier associated with the terminal's second identifier, and determine multiple core network elements corresponding to the terminal based on the terminal's first identifier; or, if the third message carries the terminal's first identifier, determine multiple core network elements corresponding to the terminal based on the terminal's first identifier.

[0117] In one scenario, the third message may carry the identifier of the terminal.

[0118] The terminal identifier carried in this third message is the same as that in the aforementioned embodiments, and will not be described again.

[0119] The method for determining the target core network element in the first core network element can be as follows: based on the terminal's identifier, determine multiple core network elements corresponding to the terminal, and arbitrarily select one core network element from these multiple core network elements as the target core network element. These multiple core network elements are those capable of transmitting NAS messages with the terminal. The processing method for determining the multiple core network elements corresponding to the terminal based on the terminal's identifier is the same as in the aforementioned embodiments and will not be repeated here.

[0120] The above is merely an illustrative example of how the first core network element determines the target core network element. In actual processing, the first core network element may also use other methods to determine the target core network element, which are not limited or exhaustively listed here.

[0121] It should be understood that the above-mentioned first core network element can also be replaced by other core network elements, such as MM NF, AUSF, NRF (Network Repository Function), etc.

[0122] Optionally, the target core network element can be determined by the NRF (Network Repository Function). In this case, the processing of the access network device may include receiving information about the target core network element from the NRF. Furthermore, the access network device can determine the target core network element based on the information about the target core network element. The method by which the NRF determines the target core network element is similar to the method described above for determining the target core network element using the first core network element, and will not be repeated here.

[0123] It should be noted that the above are all illustrative examples. In actual processing, as long as the access network device can obtain the information of the target core network element from any core network element, it is within the protection scope of this embodiment.

[0124] Optionally, the target core network element can be determined by the access network device. For example, the access network device can directly determine the target core network element based on the type of the first NAS message. The method for obtaining the type of the first NAS message and its related description are the same as in the previous embodiments, and therefore will not be repeated. The access network device can pre-store the types of NAS messages processed or corresponding to different core network elements among multiple core network elements.

[0125] The access network device may also use other methods to determine the target core network element. This embodiment does not limit or exhaustively list the methods by which the access network device determines the target core network element.

[0126] Additionally, if the access network device determines that it will not route the first NAS message, the process may also include: the access network device terminating the process. This termination process may refer to the access network device performing no processing, or the access network device sending a notification message to the terminal refusing to transmit the first NAS message.

[0127] In the above scheme, after the access network device receives the first message carrying the first NAS message from the terminal, it can determine whether to route the first NAS message based on the pre-obtained authentication status of the terminal. In this way, the authentication status of the terminal can be used to detect whether the terminal is legitimate, thereby avoiding the problem of attacks on the core network elements caused by illegal terminals due to direct routing of NAS messages to the core network side. Thus, while enabling the access network device to route NAS messages, it also ensures the security of the access network device in routing NAS messages.

[0128] In some possible implementations, after receiving a first message carrying a first NAS message from a terminal, the access network device sends a third message to a first core network element to request information from the target core network element, and then receives a second message from the first core network element for the access network device to determine whether to route the first NAS message from the terminal.

[0129] The third message may carry the identifier of the terminal, which may be either the second identifier or the first identifier of the terminal.

[0130] The second message may carry at least one of the following: the terminal's authentication status and information about the target core network element.

[0131] The terminal sends the first message at any time after authentication is completed. In this embodiment, the authentication process performed between the terminal and the core network is the same as in the previous embodiments, and therefore will not be repeated. After authentication is completed, the first core network element can store the terminal's authentication status. The content of this authentication status is the same as in the previous embodiments, and will not be elaborated further.

[0132] In one embodiment, after receiving the first message, the access network device sends a third message to the first core network element. In this embodiment, the function of the third message may include: requesting information from the target core network element; and may also include requesting to obtain the authentication status of the terminal.

[0133] The processing of the first core network element after receiving the third message may include: searching for the first identifier of the candidate terminal included in the candidate authentication status of each of the one or more candidate terminals stored locally, to see if there is a target candidate terminal that matches the identifier of the terminal carried in the third message; if there is, the candidate authentication status of the target candidate terminal is used as the authentication status of the terminal; if there is, it is determined that the authentication status of the terminal is not stored locally.

[0134] The step of searching for a target candidate terminal that matches the identifier of the terminal carried in the third message from the first identifier of the candidate terminal included in the candidate authentication status of each of the one or more locally stored candidate terminals may include one of the following: when the third message carries the second identifier of the terminal, the first core network element determines the first identifier of the terminal associated with the second identifier of the terminal, and searches for a target candidate terminal that matches the first identifier of the terminal from the first identifier of the candidate terminal included in the candidate authentication status of each of the one or more locally stored candidate terminals; or when the third message carries the first identifier of the terminal, searches for a target candidate terminal that matches the first identifier of the terminal from the first identifier of the candidate terminal included in the candidate authentication status of each of the one or more locally stored candidate terminals.

[0135] On the first core network element side, the method for obtaining or saving the candidate authentication status of each candidate terminal is the same as the method for obtaining or saving the authentication status of the aforementioned terminal; the content that may be included in the candidate authentication status of each candidate terminal is also similar to the content that may be included in the authentication status of the terminal, and will not be described in detail.

[0136] The first core network element sends a second message to the access network device. This can be done by sending the second message to the access network device if the terminal's authentication status is stored or found locally. The second message can carry the terminal's authentication status.

[0137] In addition, the processing of the first core network element may also include: sending a reply message indicating that the authentication status of the terminal is not saved locally to the access network device. Correspondingly, the processing of the access network device may also include: upon receiving the reply message from the first core network element indicating that the authentication status of the terminal is not saved, determining not to route the first NAS message.

[0138] The processing of the access network device after receiving the second message may further include: determining whether to route the first NAS message based on the authentication status of the terminal. The specific processing method for the access network device to determine whether to route the first NAS message based on the terminal's authentication status is the same as in the aforementioned embodiments and will not be repeated here.

[0139] In addition, the processing by the access network device after receiving the second message may also include: saving the authentication status of the terminal. For example, the access network device can save the authentication status of the terminal in the AS security context corresponding to the terminal.

[0140] Once the access network device determines the route for the first NAS message, it can send the first NAS message to the target core network element. Correspondingly, the target core network element receives the first NAS message from the access network device.

[0141] Optionally, the target core network element can be determined by the first core network element, and the information of the target core network element can be sent from the first core network element to the access network device. The description of the content of the target core network element's information is the same as in the previous embodiments and will not be repeated. The method by which the first core network element determines the target core network element is the same as in the previous embodiments and will not be repeated.

[0142] The second message may carry information about a target core network element, wherein the target core network element is one of multiple core network elements capable of transmitting NAS messages with the terminal. That is, the second message may simultaneously carry the terminal's authentication status and information about the target core network element. Accordingly, the access network device can determine the target core network element based on the information carried in the second message.

[0143] Optionally, the target core network element can be determined by the access network device. The method by which the access network device determines the target core network element is the same as in the aforementioned embodiments, and will not be described again.

[0144] In one embodiment, after receiving the first message, the access network device first checks whether the terminal's authentication status is stored locally.

[0145] Specifically, the processing performed by the access network device after receiving the first message may include: checking whether the terminal's authentication status is stored locally based on the second identifier of the terminal carried in the first message. The explanation regarding checking whether the terminal's authentication status is stored locally based on the second identifier of the terminal carried in the first message is the same as in the previous embodiments and will not be repeated.

[0146] In one example, if the access network device determines that it has locally stored the authentication status of the terminal, it may further include: determining whether to route the first NAS message based on the authentication status of the terminal. The explanation regarding determining whether to route the first NAS message based on the authentication status of the terminal is the same as in the previous embodiments and will not be repeated.

[0147] In this example, the access network device may have already obtained and stored the terminal's authentication status locally in other processes (e.g., it may be stored in the AS security context corresponding to the terminal). The type of these other processes is not limited in this embodiment. The processing of obtaining the terminal's authentication status when the terminal executes these other processes before sending the first message may include: the terminal sending other AS messages carrying a second NAS message to the access network device; and the access network device obtaining the terminal's authentication status after receiving the other AS messages but before determining whether to route the second NAS message. The specific types or contents of the other AS messages and the second NAS message are not limited in this embodiment, as long as the access network device has already obtained and stored the terminal's authentication status through other processes before receiving the first message, it is within the scope of protection of this embodiment.

[0148] When the access network device determines the route for the first NAS message based on the authentication status of the terminal, it may further include sending a third message to the first core network element. In this example, the third message may be used only to request information from the target core network element.

[0149] The processing by the first core network element after receiving the third message may include: sending a second message carrying information about the target core network element to the access network device. The method by which the first core network element determines the target core network element is the same as in the previous embodiments and will not be described again.

[0150] The processing by the access network device after receiving the second message may further include: determining the target core network element based on the information of the target core network element, and routing the first NAS message to the target core network element. Correspondingly, the target core network element receives the first NAS message from the access network device.

[0151] In one example, the processing after the access network device receives the first message may further include: if the access network device determines that it does not have the authentication status of the terminal stored locally, it sends a third message to the first core network element.

[0152] In this example, the function of the third message may include requesting information from the target core network element, and may also include requesting to obtain the authentication status of the terminal. The related processing after the first core network element receives the third message, and the related processing after the access network device receives the second message, are the same as the related processing in the embodiment where the function of the third message may include requesting information from the target core network element and requesting to obtain the authentication status of the terminal, and therefore will not be described in detail.

[0153] In one embodiment, after receiving the first message, the access network device sends a third message to the first core network element.

[0154] In this embodiment, the third message can be used to request information from the target core network element; optionally, the third message can also be used (or used to trigger) the first core network element to perform the process of determining whether to route the first NAS message.

[0155] The processing performed by the first core network element after receiving the third message may include: based on the terminal identifier carried in the third message, searching from the first identifier of the candidate terminal included in the candidate authentication status of each of the one or more candidate terminals stored locally, to see if there is a target candidate terminal that matches the terminal identifier; if so, the candidate authentication status of the target candidate terminal is used as the terminal's authentication status; if not, it is determined that the authentication status of the terminal is not stored locally. The description of the terminal identifier carried in the third message is the same as in the previous embodiments and will not be repeated; the process of searching from the first identifier of the candidate terminal included in the candidate authentication status of each of the one or more candidate terminals stored locally to see if there is a target candidate terminal that matches the terminal identifier is the same as in the previous embodiments and will not be elaborated further.

[0156] The processing of the first core network element may further include: if the authentication status of the terminal is stored locally or found, determining whether the terminal meets the first condition based on the authentication status of the terminal; if the first condition is met, determining that the access network device can route the first NAS message; if the first condition is not met, determining that the access network device cannot route the first NAS message.

[0157] The first condition is the same as in the previous embodiments and will not be described again. The processing by which the first core network element determines whether the terminal meets the first condition based on the authentication status of the terminal is similar to the processing by which the access network device determines whether the terminal meets the first condition based on the authentication status of the terminal in the previous embodiments. The only difference is that in this embodiment, the judgment processing is performed by the first core network element, so it will not be described again.

[0158] In addition, the processing of the first core network element may also include: if the authentication status of the terminal is not stored locally, or if it is determined based on the authentication status of the terminal that the access network device cannot route the first NAS message, sending a reply message indicating that the routing of the NAS message (or the first NAS message) will not be performed to the access network device. Correspondingly, the processing of the access network device may also include: upon receiving the NAS message (or the first NAS message) from the first core network element, determining that the first NAS message will not be routed.

[0159] Furthermore, if the first core network element determines that the access network device can route the first NAS message, it may further include: sending a second message to the access network device, the second message carrying information about the target core network element. The method by which the first core network element determines the target core network element is the same as in the aforementioned embodiments, and the relevant description of the information of the target core network element is also the same as in the aforementioned embodiments, and will not be repeated here.

[0160] The processing after the access network device receives the second message may further include: determining the route for the first NAS message if the second message carries information about the target core network element. After determining the route for the first NAS message, the processing may further include: determining the target core network element based on the information about the target core network element, and routing the first NAS message to the target core network element. Accordingly, the target core network element receives the first NAS message from the access network device.

[0161] In addition, the relevant explanations regarding the situation where the access network device determines not to route the first NAS message are the same as those in the aforementioned embodiments and will not be repeated here.

[0162] Referring to Figure 8, another exemplary description of the communication method provided in this embodiment is given. The process in Figure 8 can be summarized as follows: When the base station (access network device, schematically represented as AN in Figure 8) performs the discovery and selection of the target core network element (target NFx) for the first RRC message of the UE (terminal), it queries the UDM (first core network element) for information about the target NFx serving the UE. The UDM / base station determines whether to route the first NAS message to the target NFx based on the UE's authentication status. Optionally, the UDM can choose whether to send the UE's authentication status to the base station, which stores it as part of the AS security context. Specifically, this includes:

[0163] S801, the UE sends a first RRC message to the AN, which carries a first NAS container (including the first NAS message) and a UE ID. The UE ID may be a second identifier of the terminal in the aforementioned embodiments (e.g., at least one of the UE's GUTI, UE's RNTI, etc.).

[0164] S802, the AN sends an NF discovery and selection request (i.e., the third message in the aforementioned embodiment) to the UDM. The NF discovery and selection request may carry the UE ID.

[0165] S803, UDM sends an NF discovery and selection response (i.e., the second message in the aforementioned embodiment) to AN; the NF discovery and selection response may carry the UE ID, the target NFx information (info), and optionally, the UE's authentication status.

[0166] S804, the AN determines whether to route the first NAS message. Specifically, the AN can determine whether to route the first NAS message. If it determines to route the first NAS message, it executes S805; otherwise, it terminates the process. If the AN terminates the process, it can also send a notification to the UE rejecting the route to the first NAS message.

[0167] S805, AN sends the first NAS message to the target NFx. This first NAS message can be carried by an Nnf_request message.

[0168] In the above scheme, the core network side or access network device determines whether to route the first NAS message based on the authentication status of the terminal. This can detect whether the terminal is legitimate by checking the authentication status of the terminal, thereby avoiding the problem of attacks on the core network elements caused by illegal terminals due to direct routing of NAS messages to the core network side. This not only enables the access network device to route NAS messages, but also ensures the security of the NAS messages routed by the access network device.

[0169] In some possible implementations, after receiving the first message carrying the first NAS message from the terminal, the access network device further includes: if the first message is successfully verified based on the AS security context, determining the route for the first NAS message. Specifically, the AS security context refers to the AS security context corresponding to the terminal.

[0170] Specifically, the processing after the access network device receives the first message includes: verifying the first message based on the AS security context corresponding to the terminal; and determining to route the first NAS message if the verification is successful (or passes verification). Alternatively, it may include: determining not to route the first NAS message if the verification of the first message based on the AS security context corresponding to the terminal fails (or the verification is unsuccessful or passes verification). The subsequent processing after determining not to route the first NAS message is the same as in the aforementioned embodiments and will not be described again.

[0171] The access network device can obtain or acquire the AS security context corresponding to the terminal before receiving the first message. For example, the access network device can obtain and save the AS security context corresponding to the terminal after the terminal has completed authentication with the core network. The relevant descriptions of the authentication process between the terminal and the core network are the same as those in the previous embodiments and will not be repeated. This embodiment does not limit the method of generating the AS security context.

[0172] Furthermore, before receiving the first message, the terminal and the access network device can enable security protection (i.e., enable AS security protection based on the AS security context). That is, the terminal can send the first message to the access network device at any time after security protection can be enabled. The first message is a message for security protection based on the AS security context, wherein the AS security context includes at least one of the following: the AS security key between the access network device and the terminal, an AS integrity key derived from the AS security key, and an AS encryption key derived from the AS security key.

[0173] In this embodiment, the security protection refers to AS security protection, that is, security protection between the terminal and the access network device; the AS security protection may include AS encryption protection and / or AS integrity protection. The first message may be a message that performs AS encryption protection and / or AS integrity protection based on the AS security context.

[0174] Optionally, the first message is an AS message that performs AS integrity protection based on the AS security context.

[0175] The first message may carry a first message authentication code and the content carried by the first message. The content carried by the first message includes at least a first NAS message or a first NAS container containing the first NAS message; the content carried by the first message may also include at least one of the following: a second identifier of the terminal and a type of the first NAS message.

[0176] The first message authentication code can be calculated based on the AS integrity key (or AS security key) and the content carried in the first message.

[0177] The terminal can use an integrity protection algorithm (or AS integrity protection algorithm, or simply AS integrity protection algorithm) to calculate the first message authentication code. The AS integrity protection algorithm can be pre-configured or pre-negotiated and determined by both the terminal and the access network device. This embodiment does not limit or exhaustively list all possible AS integrity protection algorithms. As long as the terminal and the access network device use the same AS integrity protection algorithm, it is within the protection scope of this embodiment.

[0178] The input parameters used to calculate the first message authentication code include: the AS integrity key and the content carried by the first message. Furthermore, the input parameters used to calculate the first message authentication code may also include at least one of the following: the length of the content carried by the first message, a first integrity count value, a first bearer identifier, first transmission direction indication information, etc.

[0179] The length of the first complete protection count value can be 32 bits, and this embodiment does not limit it.

[0180] In one possible example, the terminal and the access network device jointly maintain a pair of counter values: an uplink counter (or uplink AS counter (COUNT) value) and a downlink counter (or downlink AS counter (COUNT) value). The uplink counter is incremented by one with each transmission of an uplink message, and the downlink counter is incremented by one with each transmission of a downlink message. In this example, the terminal and the access network device may use the current uplink counter value as the first integrity counter value.

[0181] In one possible example, the terminal and access network device jointly maintain a counter value, which is incremented by one each time a security protection (verification of security protection, such as integrity protection / verification) is performed between the terminal and access network device. In this example, the terminal and access network device can use the current counter value as the initial integrity protection counter value.

[0182] The first bearer identifier can be represented as bearer ID, and its length can be 5 bits; the first transmission direction indication information can be represented as DIRECTION, and its length can be 1 bit. When the first transmission direction indication information takes a first value (such as 0), it indicates uplink; when it takes a second value (such as 1), it indicates downlink. In this example, the value of the first transmission direction indication information can be the first value. As long as the first value and the second value are different, they are within the protection scope of this embodiment, and are not limited or exhaustively enumerated.

[0183] The access network device verifies the first message based on the AS security context corresponding to the terminal. This verification may include: calculating a first message checksum based on the AS integrity key in the AS security context corresponding to the terminal and the content carried in the first message; and verifying the first message based on the first message checksum and the first message authentication code. The process by which the access network device calculates the first message checksum should be the same as the process by which the terminal calculates the first message authentication code, and will not be repeated here.

[0184] Verifying the first message based on the first message verification code and the first message authentication code may include one of the following: if the first message verification code and the first message authentication code are the same, determine that the verification of the first message is passed or successful; if the first message verification code and the first message authentication code are different, determine that the verification of the first message fails.

[0185] Optionally, the first message is an AS message protected by AS encryption based on the AS security context.

[0186] The first message may carry first encrypted data, wherein the first encrypted data is calculated based on the AS encryption key (or AS security key) and first plaintext data. The first plaintext data includes at least a first NAS message or a first NAS container containing the first NAS message; the first plaintext data may also include at least one of the following: a second identifier of the terminal and a type of the first NAS message.

[0187] The algorithm for calculating the first ciphertext data can be an encryption algorithm. This encryption algorithm (or AS confidentiality algorithm, or AS encryption algorithm) can be pre-configured or pre-negotiated by both the terminal and the access network equipment, and is not limited here.

[0188] The input parameters used to compute the first ciphertext data include the AS encryption key (or AS security key) and the first plaintext data. Additionally, the input parameters used to compute the first ciphertext data may also include at least one of the following: the length of the first plaintext data, a first confidentiality count, a first bearer identifier, first transmission direction indication information, the length required by the first keystream (KEYSTREAM), etc.

[0189] In one possible example, the terminal and the access network device jointly maintain a pair of count values, namely an uplink count value and a downlink count value. In this example, the terminal and the access network device may use the current uplink count value as the first confidentiality count value.

[0190] In one possible example, the terminal and access network device jointly maintain a counter value, which is incremented by one each time a security protection (verification of the security protection) is performed between the terminal and the access network device. In this example, the terminal and access network device can use the current counter value as the primary confidentiality counter value.

[0191] The access network device verifies the first message based on the AS security context corresponding to the terminal. This verification may include: decrypting the first ciphertext data carried in the first message based on the AS encryption key (or AS security key) in the AS security context corresponding to the terminal; if decryption is successful, the verification of the first message is determined to be successful; if decryption fails, the verification of the first message is determined to have failed. The method for determining whether the access network device has successfully decrypted the first message may be: if the access network device decrypts and obtains garbled text, then the decryption is determined to have failed; if the access network device decrypts and obtains the correct content, i.e., the first plaintext data, then the decryption is determined to have succeeded. The decryption algorithm used by the access network device to decrypt the first ciphertext data should correspond to the encryption algorithm used by the terminal, and will not be described again.

[0192] Optionally, the first message is an AS message that is protected by AS encryption and AS integrity based on the AS security context.

[0193] In one scenario, the first message may carry first encrypted data and a first message authentication code. The terminal may first calculate the first message authentication code and then calculate the first encrypted data.

[0194] The calculation and processing of the first encrypted data, the description of the first plaintext data, and other related matters are the same as those in the aforementioned embodiments, and will not be repeated here.

[0195] The first message authentication code is calculated based on the AS integrity protection key (or AS security key) and the first plaintext data. The AS integrity protection algorithm and input parameters used to calculate the first message authentication code are similar to those in the previous embodiments, the only difference being that the content carried by the first message is replaced with the first plaintext data in this case, so it will not be described again.

[0196] The access network device verifies the first message based on the AS security context corresponding to the terminal, which may include: decrypting the first ciphertext data carried in the first message based on the AS encryption key (or AS security key) in the AS security context corresponding to the terminal, and obtaining the first plaintext data if the decryption is successful; calculating the first message checksum based on the AS integrity key (or AS security key) in the AS security context corresponding to the terminal and the first plaintext data; verifying the first message based on the first message checksum and the first message authentication code; and determining that the verification of the first message is successful if the first message checksum and the first message authentication code are the same.

[0197] Additionally, it may include one of the following: determining that the verification of the first message failed if decryption fails; or determining that the verification of the first message failed if the first message verification code and the first message authentication code are different.

[0198] The decryption of the first encrypted data and the calculation of the first message verification code by the access network device are similar to those in the aforementioned embodiments, and will not be described in detail here.

[0199] In one scenario, the first message may carry first encrypted data and a first message authentication code. The terminal may first calculate the first encrypted data and then calculate the first message authentication code.

[0200] The calculation and processing of the first encrypted data are the same as in the aforementioned embodiments, and will not be repeated here.

[0201] The first message authentication code is calculated based on the AS integrity protection key (or AS security key) and the first ciphertext data. The AS integrity protection algorithm and input parameters used to calculate the first message authentication code are similar to those in the previous embodiments, except that the content carried by the first message is replaced with the first ciphertext data in this case, so they will not be described again.

[0202] The access network device verifies the first message based on the AS security context corresponding to the terminal, which may include: calculating a first message checksum based on the AS integrity key (or AS security key) in the AS security context corresponding to the terminal and the first ciphertext data carried in the first message; verifying the first message based on the first message checksum and the first message authentication code; if the first message checksum and the first message authentication code are the same, decrypting the first ciphertext data carried in the first message based on the AS encryption key (or AS security key) in the AS security context corresponding to the terminal; if decryption is successful, determining that the verification of the first message is successful and obtaining the first plaintext data. Alternatively, it may include one of the following: if decryption fails, determining that the verification of the first message has failed; if the first message checksum and the first message authentication code are different, determining that the verification of the first message has failed.

[0203] The decryption of the first encrypted data and the calculation of the first message verification code by the access network device are similar to those in the aforementioned embodiments, and will not be described in detail here.

[0204] In one scenario, the first message may carry first encrypted data, which is calculated based on the AS encryption key (or AS security key), the first plaintext data, and the first message authentication code. The first message authentication code is calculated based on the AS integrity key (or AS security key) and the first plaintext data.

[0205] The AS integrity protection algorithm and input parameters used to calculate the first message authentication code are similar to those in the aforementioned embodiments. The only difference is that the content carried by the first message is replaced with the first ciphertext data in this case, so it will not be described again.

[0206] The encryption algorithm and input parameters used to calculate the first ciphertext data are similar to those in the previous embodiments. The only difference is that a first message authentication code is added in this case to calculate the first ciphertext data, so it will not be described again.

[0207] The access network device verifies the first message based on the AS security context corresponding to the terminal, which may include: decrypting the first ciphertext data carried in the first message based on the AS encryption key (or AS security key) in the AS security context corresponding to the terminal; if decryption is successful, obtaining the first plaintext data and the first message authentication code; calculating the first message checksum based on the AS integrity key (or AS security key) in the AS security context corresponding to the terminal and the first plaintext data; verifying the first message based on the first message checksum and the first message authentication code; and determining that the verification of the first message is successful if the first message checksum and the first message authentication code are the same. Alternatively, it may include one of the following: determining that the verification of the first message has failed if decryption fails; or determining that the verification of the first message has failed if the first message checksum and the first message authentication code are different.

[0208] Once the access network device determines the route for the first NAS message, it can send the first NAS message to the target core network element. Correspondingly, the target core network element receives the first NAS message from the access network device.

[0209] Optionally, the target core network element can be determined by a first core network element. The processing of the access network device may further include: receiving information about the target core network element from the first core network element. Furthermore, before receiving the information about the target core network element from the first core network element, the processing of the access network device may further include: sending a third message to the first core network element, wherein the third message is used to request information about the target core network element. Correspondingly, the processing of the first core network element further includes: receiving a third message from the access network device, wherein the third message is used to request information about the target core network element.

[0210] The content carried in the third message, the determination of the target core network element by the first core network element, and the related explanations after the access network device receives the information from the target core network element are all the same as in the aforementioned embodiments and will not be repeated. Furthermore, the aforementioned first core network element can be replaced with other core network elements, as long as the access network device can obtain the information of the target core network element from any core network element, it falls within the protection scope of this embodiment.

[0211] Optionally, the target core network element can be determined by the access network device. For example, the access network device can directly determine the target core network element based on the type of the first NAS message. The specific processing method in this case is the same as in the aforementioned embodiments and will not be described again.

[0212] In the above implementation, since the terminal authenticates with the network after access registration, an AS security context corresponding to the terminal can be generated, and encryption protection (AS encryption protection) and / or integrity protection (AS integrity protection) with the access network device can be enabled. Therefore, after the terminal access registration, if the access network device receives the terminal's first message (such as the first RRC message), the access network device can use the locally stored AS security context to verify the first message. If the verification is successful, the legitimacy of the terminal can be implicitly verified, and the first NAS message carried by the first message can be routed to the corresponding target core network element. Through this implementation, the routing judgment and forwarding of the first NAS message can be completed more quickly and efficiently. It can also avoid the problem of attacks on core network elements caused by illegal terminals due to direct routing of NAS messages to the core network side. Thus, while enabling the access network device to route NAS messages, the security of the access network device's routing of NAS messages is also guaranteed.

[0213] It should be noted that the above-mentioned various implementation methods can be executed independently.

[0214] Alternatively, the above implementation methods can be determined by the access network device based on different scenarios. For example, in one scenario, if the access network device determines that the locally stored AS security context corresponding to the terminal is available or that the AS security context corresponding to the terminal does not need to be updated, it can verify the first message based on the AS security context corresponding to the terminal to determine whether to route the first NAS message and perform its subsequent related processing. In another scenario, if the access network device determines that the locally stored AS security context corresponding to the terminal is unavailable, or that the AS security context corresponding to the terminal needs to be updated, or that security protection between the access network device and the terminal is not enabled, and if the access network device receives a second message carrying the authentication status of the terminal from the first core network element after the terminal has completed authentication with the core network side but before receiving the first message, the access network device can determine whether to route the first NAS message based on the authentication status of the terminal after receiving the first message and perform its subsequent related processing. In one scenario, if the access network device determines that the locally stored AS security context corresponding to the terminal is unavailable, or the AS security context corresponding to the terminal needs to be updated, or security protection between the access network device and the terminal is not enabled, and if the access network device does not locally store the terminal's authentication status after the terminal completes authentication with the core network side and before receiving the first message, the access network device can send a third message to the first core network element to request information from the target core network element after receiving the first message, and perform its subsequent related processing.

[0215] In some possible implementations, after authentication, the terminal can generate and save the AS security context locally; on the access network device side, the AS security context corresponding to the terminal can also be saved locally after the terminal completes authentication. The AS security context includes at least one of the following: the AS security key between the access network device and the terminal, the AS integrity key derived from the AS security key, and the AS encryption key derived from the AS security key.

[0216] In this implementation, considering that the NAS connections between the terminal and different network elements of the core network are all carried on the terminal and the access network device, and that the access network device (such as the access network node or base station) can route the NAS messages between the terminal and the core network element, the same AS security context can be used to protect the connection between the terminal and the access network device.

[0217] In one embodiment, on the access network device side, the AS security key can be sent by the second core network element, that is, the second core network element generates the AS security key and sends it to the access network device.

[0218] Specifically, the processing of the access network device may further include: receiving the AS security key between the access network device and the terminal from the second core network element. The processing on the second core network element side may include: sending the AS security key between the access network device and the terminal to the access network device.

[0219] On the terminal side, the AS security key can be generated locally on the terminal.

[0220] On the second core network element and terminal side, the AS security key is generated based on the shared key between the terminal and the second core network element. On the second core network element and terminal side, the AS security key can be generated during the authentication process between the terminal and the core network side, or after authentication is completed; this embodiment does not limit this.

[0221] The AS security key includes either the initial AS security key or the NH (Next Hop key). In some possible examples, the NH may also be referred to as the intermediate key.

[0222] The initial AS security key can be the initial K. gNB The initial K gNB The corresponding NCC (Next Hop Chaining Counter) is equal to 0. Alternatively, the initial AS security key can be Kmn, which is the initial AS security key of the master node in a dual-connection scenario.

[0223] NH is used in switching safety for vertically derived K. gNB (K NG-RAN* The input key for NH. For example, when a terminal switches from a source access network device to a target access network device, the target access network device can request a fresh {NH, NCC} from the second core network element for vertical handover within the site. The input parameters for generating NH include the previously generated AS security key (such as the initial K). gNB Or the NH generated in the last time).

[0224] Furthermore, the AS security key is generated based on the shared key between the terminal and the second core network element and at least one of the following: a parameter that distinguishes the access type, a fresh value, and the previously generated AS security key.

[0225] Specifically, on the second core network element and the terminal side, an initial AS security key or NH is generated, and the input key used is the shared key between the terminal and the second core network element.

[0226] Optionally, on the second core network element and terminal side, the input parameters for generating the initial AS security key may include at least one of the following: a parameter that distinguishes the access type, or a fresh value.

[0227] The parameters that distinguish access types can include: parameters for 3GPP access types and parameters for non-3GPP access types. The specific values ​​of the 3GPP access type parameters and non-3GPP access type parameters can be configured according to actual conditions. For example, the 3GPP access type parameter can be 0x01. The fresh value can be the value of a counter jointly held by the second core network element and the terminal, or the value transmitted between the second core network element and the terminal. In some possible examples, the fresh value can be the uplink NAS COUNT.

[0228] Furthermore, on the second core network element and terminal side, the input parameters for generating the initial AS security key may also include at least one of the following: a first fixed value, the length of the fresh value, and the length of the parameter that distinguishes the access type. The first fixed value can be pre-configured by both the second core network element and the terminal, for example, it can be represented as FC = 0x6E.

[0229] Optionally, on the second core network element and terminal side, the input parameters for generating the NH may include: the previously generated AS security key. The previously generated AS security key can be: the initial AS security key, or the previously generated NH.

[0230] Furthermore, on the second core network element and terminal side, the input parameters for generating NH may also include at least one of the following: a second fixed value, and the length of the previously generated AS security key. This second fixed value can be pre-configured by both the second core network element and the terminal, for example, it can be represented as FC = 0x6F.

[0231] The second core network element includes one of the following: MM NF, or key management function. The key management function can be a newly added function dedicated to managing and / or generating keys under the distributed NAS architecture. It should be understood that the key management function may also have other functions, which are not limited in this embodiment. The key management function may be co-located with existing core network functions in the same device or entity, for example, the key management function may be co-located with AUSF in the same device or entity; or the key management function may be a newly added separate core network element or entity, which is also not limited in this embodiment. For example, the key management function may be called DNKGF (Distributed NAS Key Generation Function) or DNKMF (Distributed NAS Key Management Function).

[0232] The shared key between the terminal and the second core network element may be related to the specific network element type of the second core network element.

[0233] In one example, when the second core network element is MM NF, the shared key between the terminal and MM NF can be K. MM NF 。

[0234] That is, the NH and / or initial key K between the terminal and the access network equipment. gNB It will be generated by MM NF.

[0235] If the terminal re-performs master authentication, or the NAS COUNT between the terminal and the MM NF reaches its maximum value, or the operator's policy determines that the shared key between the terminal and the MM NF needs to be updated, the shared key between the MM NF and the terminal may change, and the MM NF and the terminal will update to obtain a new shared key K. MM NF MM NF and the terminal will be based on the updated K MM NF The new AS security key between the terminal and the access network device is then obtained through an update. The method for calculating this new AS security key is similar to the previous example and will not be repeated here. Furthermore, the new AS security key (e.g., a new initial K) is obtained through the MM NF update. gNB In the case of ), MM NF will also send a new AS security key to the access network device.

[0236] In one example, when the second core network element is a key management function, the shared key between the terminal and the key management function can be K. DNKGF or K DNKMF For the sake of brevity, the following text will use K. DNKGF Let's take an example to illustrate.

[0237] During initial terminal access, the registration request is routed through the new management network element to the security network element (such as AUSF or UDM) to perform mutual authentication with the network. Since a distributed NAS architecture requires a mechanism for secure isolation between network elements, a key management center can generate NAS keys for the core network element establishing the NAS connection with the terminal. This key management center also generates initial AS security keys, such as the initial K key, for the access network device. gNB At least one of NH and Kmn.

[0238] Referring to Figure 9 as an example, it can include:

[0239] In S901, the UE first performs authentication processing with the authentication and authorization function in the core network through the AN.

[0240] In S902, the UE, authentication, and authorization functions each derive keys based on the root key (the UE's root key). For example, the authentication and authorization functions can at least derive the shared key K between the terminal and the key management function. DNKGF For example, the terminal can at least derive the shared key K between the terminal and the key management function. DNKGF .

[0241] S903, the shared key K between the authentication and authorization function sending terminal and the key management function. DNKGF To key management function.

[0242] S904, Key Management Function sends AS security key (e.g., initial K) gNB (One of NH, Kmn) to AN.

[0243] S905, AS Security Mode Command is transmitted between UE and AN. This AS Security Mode Command may be used for negotiation and / or determination of AS encryption algorithm and / or AS integrity protection algorithm between UE and AN, etc. The contents or related processing of the AS Security Mode Command are not exhaustively listed or limited here.

[0244] It should be noted that, for the sake of simplicity, the process of the UE deriving the AS security key is not illustrated in Figure 9. The UE can derive the AS security key at any time after completing S902 and before executing S905, which will not be elaborated here.

[0245] It should be noted that "NFx" is also shown in Figure 9. NFx can be used to represent any core network element on the core network side that can transmit NAS messages with the UE. The NAS key between the NFx and the UE can also be derived by the key management function and sent to the NFx. Since this example mainly describes the derivation process of the AS security key between the UE and the AN, the key derivation and transmission process between the key management function and NFx is not explained in Figure 9 for the sake of simplicity. However, this does not mean that there is no corresponding transmission process or content between the key management function and NFx.

[0246] Furthermore, after authentication between the UE and the network, the security network element and the UE will generate a key K between the key management center and the terminal. DNKGF The key management center will use this key to generate an initial K for the base station. gNB (NCC=0) and NH (security parameters used for the handover process). This security element may include authentication and authorization functions; alternatively, it may include UDM, AUSF, etc.

[0247] Referring to Figure 10, taking the security network elements including UDM and AUSF as examples, the key derivation architecture involved in this example is illustrated as follows: UDM can derive CK (Ciphering Key) and / or IK (Integrity Key) based on the root key K; K is further derived from CK and IK by UDM. AUSF Concurrently sent to AUSF; AUSF is based on K AUSF Derivative K DNKGF Concurrently sent to DNKGF; DNKGF based on K DNKGF Initial K between derived terminal and access network equipment gNB Or NH. Where, the initial K is generated. gNB The input parameters include: parameters that distinguish the access type (e.g., 3GPP access, non-3GPP access) and fresh values ​​(e.g., a counter jointly held by the UE and the key generation center, or a value transmitted between the key generation center and the UE). Among these, generating the initial K... gNB The input key is K DNKGF NH is used in switching safety for vertically derived KgNB (K NG-RAN* The input key for NH is derived by the key management center for the base station in this example, and the input key for NH is also K. DNKGF The input parameters for generating NH can include the previously generated NH (or the previously generated initial K). gNB ).

[0248] This example allows AS security to be debonded from the Mobility Management Network Element (MMNF), avoiding the problem that AS security needs to be updated as well due to AS security context updates between the MMNF and the terminal.

[0249] In one embodiment, after the access network device receives the AS security key and the terminal derives the AS security key, the access network device and the terminal can generate or derive the AS integrity key and / or the AS encryption key based on the AS security key.

[0250] Specifically, on the access network device and terminal side, the AS integrity protection key can be calculated using a first calculation method from the AS security key and the first derived parameter, and the AS encryption key can be calculated using a second calculation method from the AS security key and the second derived parameter. The first calculation method, the first derived parameter, the second calculation method, and the second derived parameter can all be configured or determined according to actual conditions. This embodiment does not limit them. As long as the same first calculation method, the first derived parameter, the second calculation method, and the second derived parameter are used on the access network device and terminal side, and the access network device and terminal side obtain the same AS integrity protection key and / or AS encryption key, it falls within the protection scope of this embodiment.

[0251] It should be noted that in some possible scenarios, if the shared key between the terminal and the second core network element is updated, the access network device will receive the new AS security key and the terminal will also generate a new AS security key. In this scenario, the access network device and the terminal can generate or derive a new AS integrity key and / or a new AS encryption key based on the new AS security key.

[0252] For example, when the second core network element is an MM NF, if the terminal re-performs master authentication, or the NAS COUNT between the terminal and the MM NF reaches its maximum value, or the operator's policy determines that the shared key between the terminal and the MM NF needs to be updated, the shared key between the MM NF and the terminal may change. That is, the MM NF and the terminal will update to obtain a new shared key K. MM NF Accordingly, MM NF and the terminal will be based on the updated K MM NF The new AS security key between the terminal and the access network device is obtained through the update; the new AS security key (such as the new initial key) is obtained through the MM NF update. gNB In the event of a new AS security key being sent to the access network device, the MM NF will also send a new AS security key to the access network device. The access network device and the terminal can then generate or derive a new AS integrity key and / or a new AS encryption key based on the new AS security key.

[0253] The methods provided above for deriving keys in the AS security context are more suitable for distributed architectures.

[0254] In some possible implementations, the first NAS message is a message that provides security protection based on the target NAS security context and the target NAS count value between the terminal and the target core network element. The target NAS count value includes at least one of the following: a target uplink NAS count value and a target downlink NAS count value. The terminal maintains different NAS count values ​​with different core network elements among the plurality of core network elements.

[0255] The target NAS security context includes at least one of the following: the target NAS key between the terminal and the target core network element, the target NAS integrity key derived from the target NAS key, the target NAS confidentiality key derived from the target NAS key, and the target NAS authenticable encryption key derived from the target NAS key.

[0256] On the terminal side, the target NAS key between the terminal and the target core network element can be derived from the terminal. On the target core network element side, the target NAS key between the terminal and the target core network element can be received by the target core network element from the key management function. That is, the target NAS key is derived or generated by the key management function. This embodiment does not limit the method of deriving the target NAS key on the terminal and key management function sides respectively.

[0257] On the terminal and target core network element sides, at least one of the following can be generated or derived based on the target NAS key: target NAS integrity key, target NAS confidentiality key, and target NAS authenticable encryption key. This embodiment does not limit the specific methods used by the terminal and target core network element sides to derive the target NAS integrity key, target NAS confidentiality key, and target NAS authenticable encryption key.

[0258] The target NAS count can be jointly maintained by the terminal and the target core network element. The target NAS count includes a pair of counts: the target uplink NAS count and the target downlink NAS count. The target uplink NAS count is incremented by one for each uplink NAS message transmitted between the terminal and the target core network element, and the target downlink NAS count is incremented by one for each downlink NAS message transmitted between the terminal and the target core network element.

[0259] On the terminal side, when generating the first NAS message, this first NAS message is an uplink NAS message. The first NAS message can be generated by performing security protection on the content carried by the first NAS message based on the target NAS security context. The content carried by the first NAS message includes at least: the target uplink NAS count value and other content transmitted by the terminal to the target core network element. This embodiment does not limit the other content transmitted by the terminal to the target core network element.

[0260] On the target core network element side, after receiving the first NAS message, it may include: verifying the first NAS message based on the target NAS security context and the target NAS count value between the terminal and the target core network element, wherein the target NAS count value includes at least one of the following: target uplink NAS count value and target downlink NAS count value.

[0261] In this embodiment, security protection refers to NAS security protection, which may include NAS encryption protection and / or NAS integrity protection.

[0262] Optionally, the first NAS message is a message that performs NAS integrity protection based on the target NAS security context.

[0263] The first NAS message may carry a second message authentication code, the target uplink NAS count value, and other content transmitted by the terminal to the target core network element. The second message authentication code may be calculated based on the target NAS integrity key (or target NAS key), the target uplink NAS count value, and other content transmitted by the terminal to the target core network element.

[0264] Specifically, the terminal can use the target NAS integrity protection algorithm to calculate the second message authentication code. This target NAS integrity protection algorithm can be pre-configured or pre-negotiated and determined by both the terminal and the target core network element. This embodiment does not impose any limitations.

[0265] The input parameters used to calculate the second message authentication code include: the target NAS integrity key, the target uplink NAS count value, and other content transmitted by the terminal to the target core network element. Furthermore, the input parameters used to calculate the second message authentication code may also include at least one of the following: the length of the content carried in the first NAS message (i.e., the target uplink NAS count value, and other content transmitted by the terminal to the target core network element), the first bearer identifier, the first transmission direction indication information, etc.

[0266] The target core network element verifies the first NAS message based on the target NAS security context and the target NAS count value between the terminal and the target core network element. This verification may include: calculating a second message checksum based on the target NAS integrity key, the target uplink NAS count value carried by the first NAS, and other content transmitted by the terminal to the target core network element; and verifying the first NAS message based on the second message checksum and the second message authentication code. The calculation of the second message checksum by the target core network element should be performed in the same way as the calculation of the second message authentication code by the terminal, and will not be repeated here.

[0267] Verifying the first NAS message based on the second message verification code and the second message authentication code may include one of the following: if the second message verification code and the second message authentication code are the same, determine that the verification of the first NAS message is successful; if the second message verification code and the second message authentication code are different, determine that the verification of the first NAS message fails.

[0268] Before the target core network element calculates the second message checksum based on the target NAS integrity key, the target uplink NAS count value carried by the first NAS, and other content transmitted by the terminal to the target core network element, the process may further include: determining whether the locally stored target uplink NAS count value is the same as the target uplink NAS count value carried by the first NAS; if they are the same, then performing the process of calculating the second message checksum based on the target NAS integrity key, the target uplink NAS count value carried by the first NAS, and other content transmitted by the terminal to the target core network element. Additionally, the process may further include: if they are different, then determining that the verification of the first NAS message has failed.

[0269] Optionally, the first NAS message is a NAS-encrypted message based on the target NAS security context.

[0270] The first NAS message may carry second encrypted data, which is calculated based on the target NAS encryption key (or target NAS key) and the second plaintext data. The second plaintext data includes at least the target uplink NAS count value and other content transmitted by the terminal to the target core network element.

[0271] The input parameters used to compute the second ciphertext data include the target NAS encryption key (or target NAS key) and the second plaintext data; in addition, the input parameters used to compute the second ciphertext data may also include at least one of the following: the length of the second plaintext data, the first bearer identifier, the first transmission direction indication information, the length required by the second key stream, etc.

[0272] The algorithm for calculating the second ciphertext data can be a target NAS encryption algorithm. This target NAS encryption algorithm can be pre-configured or pre-negotiated and determined by both the terminal and the target core network element, and there are no restrictions here.

[0273] The target core network element verifies the first NAS message based on the target NAS security context and the target NAS count value between the terminal and the target core network element. This verification may include: decrypting the second ciphertext data based on the target NAS encryption key; if the decryption is successful and yields the second plaintext data, and / or the target uplink NAS count value in the second plaintext data is the same as the locally stored target uplink NAS count value, then the verification of the first NAS message is determined to be successful; if the decryption fails (e.g., yielding garbled text), or the target uplink NAS count value in the decrypted second plaintext data is different from the locally stored target uplink NAS count value, then the verification of the first NAS message is determined to be unsuccessful. The target NAS decryption algorithm used by the target core network element to decrypt the second ciphertext data should correspond to the target NAS encryption algorithm used by the terminal, and will not be described again.

[0274] Optionally, the first NAS message is a message that performs NAS encryption protection and NAS integrity protection based on the target NAS security context.

[0275] In one scenario, the first NAS message may carry second encrypted data and a second message authentication code. The terminal can calculate the second message authentication code first and then calculate the second encrypted data.

[0276] The encryption algorithm and input parameters used to calculate the second ciphertext data are the same as those in the previous embodiments, and will not be described again.

[0277] The second message authentication code is calculated based on the target NAS integrity protection key (or target NAS key) and the second plaintext data. The target NAS integrity protection algorithm and input parameters used to calculate the second message authentication code are similar to those in the previous embodiments, except that the content carried by the first NAS message is replaced with the second plaintext data in this case, so it will not be described again.

[0278] The target core network element verifies the first NAS message based on the target NAS security context and the target NAS count value between the terminal and the target core network element. This verification may include: decrypting the second ciphertext data based on the target NAS encryption key; if the decryption is successful and the second plaintext data is obtained, and / or the target uplink NAS count value in the second plaintext data is the same as the target uplink NAS count value stored locally; calculating a second message checksum based on the target NAS security key (or target NAS key) and the second plaintext data; verifying the first NAS message based on the second message checksum and the second message authentication code; and determining that the verification of the first NAS message is successful if the second message checksum and the second message authentication code are the same.

[0279] Additionally, it may include one of the following: if decryption fails (e.g., garbled text is obtained), or if the target uplink NAS count value in the decrypted second plaintext data is different from the target uplink NAS count value stored locally, it is determined that the verification of the first NAS message has failed; if the second message checksum and the second message authentication code are different, it is determined that the verification of the first NAS message has failed.

[0280] The processing of the target core network element for decrypting the second ciphertext data and calculating the second message check code is similar to that in the aforementioned embodiments, and will not be described in detail here.

[0281] In one scenario, the first NAS message can carry second encrypted data and a second message authentication code. The terminal can calculate the second encrypted data first and then calculate the second message authentication code.

[0282] The target NAS encryption algorithm and input parameters used to calculate the second ciphertext data are the same as those in the previous embodiment, and will not be described again.

[0283] The second message authentication code is calculated based on the target NAS integrity key (or target NAS key) and the second ciphertext data. The integrity protection algorithm and input parameters used to calculate the second message authentication code are similar to those in the previous embodiments, the only difference being that the content carried by the first NAS message is replaced by the second ciphertext data in this case, so it will not be described again.

[0284] The target core network element verifies the first NAS message based on the target NAS security context and the target NAS count value between the terminal and the target core network element. This verification may include: calculating a second message checksum based on the target NAS integrity key (or target NAS key) and the second ciphertext data; verifying the first NAS message based on the second message checksum and the second message authentication code; if the second message checksum and the second message authentication code are the same, decrypting the second ciphertext data carried in the first NAS message based on the target NAS encryption key (or target NAS key); if decryption is successful and the second plaintext data is obtained, and / or if the target uplink NAS count value in the second plaintext data is the same as the locally stored target uplink NAS count value, determining that the verification of the first NAS message is successful. Alternatively, it may include one of the following: if decryption fails, or if the target uplink NAS count value in the decrypted second plaintext data is different from the locally stored target uplink NAS count value, determining that the verification of the first NAS message has failed; if the second message checksum and the second message authentication code are different, determining that the verification of the first NAS message has failed.

[0285] In one scenario, the first NAS message may carry second encrypted data, which is calculated based on the target NAS encryption key (or target NAS key), the second plaintext data, and the second message authentication code. The second message authentication code is calculated based on the target NAS integrity key (or target NAS key) and the second plaintext data.

[0286] The integrity protection algorithm and input parameters used to calculate the second message authentication code are similar to those in the aforementioned embodiments, and therefore will not be described again.

[0287] The encryption algorithm and input parameters used to calculate the second ciphertext data are similar to those in the previous embodiments. The only difference is that a second message authentication code is added in this case to calculate the second ciphertext data, so it will not be described again.

[0288] The target core network element verifies the first NAS message based on the target NAS security context and the target NAS count value between the terminal and the target core network element. This verification may include: decrypting the second ciphertext data carried in the first NAS message based on the target NAS encryption key (or target NAS key); if decryption is successful and the second plaintext data and second message authentication code are obtained, and / or the target uplink NAS count value in the second plaintext data is the same as the locally stored target uplink NAS count value, calculating a second message checksum based on the target NAS security key (or target NAS key) and the second plaintext data; verifying the first NAS message based on the second message checksum and the second message authentication code; and determining that the verification of the first NAS message is successful if the second message checksum and the second message authentication code are the same. Alternatively, it may include one of the following: if decryption fails, or if the target uplink NAS count value in the decrypted second plaintext data is different from the locally stored target uplink NAS count value, determining that the verification of the first NAS message has failed; or if the second message checksum and the second message authentication code are different, determining that the verification of the first NAS message has failed.

[0289] It should be noted that the above mainly describes the transmission of the first NAS message between the terminal and the target core network element, and the NAS security protection / verification. In actual processing, the terminal can transmit NAS messages with each of the multiple core network elements. Similarly, the terminal can have a corresponding NAS security context with each core network element. Furthermore, the terminal maintains corresponding uplink NAS count values ​​and downlink NAS count values ​​with each core network element. For example, each time an uplink NAS message is transmitted between the terminal and a core network element, the uplink NAS count value corresponding to that core network element is incremented by one; and each time a downlink NAS message is transmitted between the terminal and a corresponding core network element, the downlink NAS count value corresponding to that core network element is incremented by one. This embodiment does not elaborate on the related processing of NAS message transmission between all core network elements and the terminal.

[0290] For example, a key K exists between the UE and a specific network element NFx. NFx There is a key K between the UE and the base station. gNBThese keys can be further used to derive integrity keys and / or encryption keys, which are used to protect the UE's NAS and AS connections, respectively. To protect these connections and prevent replay attacks, the input parameters for encryption and integrity protection can include a pair of uplink and downlink COUNT values. For example, the UE maintains a pair of uplink / downlink NAS COUNT values ​​with each NFx. Each time an uplink NAS message is sent between the UE and the corresponding NFx, the uplink NAS COUNT value for that UE and NFx is incremented by 1; each time a downlink NAS message is sent between the UE and the corresponding NFx, the downlink NAS COUNT value for that UE and NFx is incremented by 1. Similarly, the UE maintains a pair of uplink / downlink COUNT values ​​with the base station (which can be called uplink / downlink AS COUNT(values)). Each time an uplink AS message is sent between the UE and the base station, the uplink AS COUNT value maintained by the UE and the base station is incremented by 1; each time a downlink AS message is sent between the UE and the base station, the downlink AS COUNT value maintained by the UE and the base station is incremented by 1.

[0291] The above scheme can maintain corresponding uplink and downlink count values ​​between the terminal and the access network equipment, and between the terminal and each core network element that can transmit NAS messages, thereby ensuring the security of messages transmitted between the terminal and various different devices or network elements.

[0292] By adopting the above scheme, after the access network device receives the first message carrying the first NAS message from the terminal, it will only route the first NAS message to the target core network element in the core network if it determines that the first NAS message should be routed. In this way, the access network device will determine whether to route the first NAS message, thus avoiding attacks on core network elements by unauthorized terminals that could result from the access network device directly routing the NAS message to the core network. This ensures the security of the NAS messages routed by the access network device while also enabling the access network device to route the NAS messages. Furthermore, since the above scheme avoids attacks on core network elements by unauthorized terminals (such as DDoS (Distributed Denial of Service) attacks and / or replay attacks) that could result from the access network device directly routing the NAS message to the core network, it also avoids network congestion and service quality issues.

[0293] Figure 11 is a schematic diagram of the composition structure of an access network device according to an embodiment of this application, including:

[0294] The first communication unit 1101 is configured to receive a first message from a terminal, wherein the first message carries a first non-access stratum (NAS) message; and, if the routing of the first NAS message is determined, to route the first NAS message to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

[0295] The first communication unit is configured to receive a second message from a first core network element, wherein the second message is used by the access network device to determine whether to route the first NAS message.

[0296] The second message carries the authentication status of the terminal, wherein the authentication status of the terminal includes at least one of the following: the authentication result of the terminal, the first identifier of the terminal, and the authentication timestamp of the terminal.

[0297] The access network equipment also includes:

[0298] The first processing unit 1102 is used to determine whether to route the first NAS message based on the authentication status of the terminal.

[0299] The first processing unit is used to save the authentication status of the terminal in the access layer AS security context.

[0300] The first processing unit is configured to determine the route of the first NAS message when the second message carries information about the target core network element.

[0301] The first processing unit is configured to determine the route for the first NAS message if the first message is successfully verified based on the access layer AS security context.

[0302] The AS security context includes at least one of the following: the AS security key between the access network device and the terminal, the AS integrity key derived from the AS security key, and the AS encryption key derived from the AS security key.

[0303] The first communication unit is used to receive information from the target core network element from the first core network element.

[0304] The first communication unit is configured to send a third message to a first core network element, wherein the third message is used to request information from the target core network element.

[0305] The first communication unit is used to receive the AS security key between the access network device and the terminal from the second core network element.

[0306] The second core network element includes one of the following: mobility management network function, key management function.

[0307] Figure 12 is a schematic diagram of the composition structure of a terminal according to an embodiment of this application, including:

[0308] The second communication unit 1201 is used to send a first message to the access network device, wherein the first message carries a first non-access stratum (NAS) message, and the access network device determines whether the first NAS message is routed to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

[0309] The first message is a security protection message based on the access layer AS security context, wherein the AS security context includes at least one of the following: the AS security key between the access network device and the terminal, the AS integrity key derived from the AS security key, and the AS encryption key derived from the AS security key.

[0310] The AS security key is generated based on a shared key between the terminal and the second core network element, wherein the second core network element includes one of the following: mobility management network function and key management function.

[0311] The AS security key is generated based on the shared key between the terminal and the second core network element and at least one of the following: a parameter that distinguishes the access type, a fresh value, and the previously generated AS security key.

[0312] The first NAS message is a message that provides security protection based on the target NAS security context and the target NAS count value between the terminal and the target core network element. The target NAS count value includes at least one of the following: target uplink NAS count value and target downlink NAS count value. The terminal and different core network elements among the plurality of core network elements maintain different NAS count values.

[0313] Figure 13 is a schematic diagram of the composition structure of the target core network elements according to an embodiment of this application, including:

[0314] The third communication unit 1301 is used to receive a first non-access stratum (NAS) message from the access network device, wherein the first NAS message is carried by a first message sent by the terminal to the access network device.

[0315] The target core network elements also include:

[0316] The third processing unit 1302 is used to verify the first NAS message based on the target NAS security context and the target NAS count value between the terminal and the target core network element, wherein the target NAS count value includes at least one of the following: target uplink NAS count value and target downlink NAS count value.

[0317] Figure 14 is a schematic diagram of the composition structure of a first core network element according to an embodiment of this application, including:

[0318] The fourth communication unit 1401 is used to send a second message to the access network device, wherein the second message is used by the access network device to determine whether to route a first non-access stratum (NAS) message from the terminal.

[0319] The second message carries the authentication status of the terminal, wherein the authentication status of the terminal includes at least one of the following: the authentication result of the terminal, the first identifier of the terminal, and the authentication timestamp of the terminal.

[0320] The second message carries information about the target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

[0321] The fourth communication unit is used to receive a third message from the access network device, wherein the third message is used to request information from the target core network element.

[0322] Figure 15 is a schematic diagram of the composition structure of a second core network element according to an embodiment of this application, including:

[0323] The fifth communication unit 1501 is used to send the access layer AS security key between the access network device and the terminal to the access network device.

[0324] The AS security key is generated based on the shared key between the terminal and the second core network element.

[0325] The AS security key is generated based on the shared key between the terminal and the second core network element and at least one of the following: a parameter that distinguishes the access type, a fresh value, and the previously generated AS security key.

[0326] The second core network element includes one of the following: mobility management network function, key management function.

[0327] The device in the application embodiments can realize the corresponding functions of the various devices in the foregoing communication method embodiments. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in this device can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the device of the application embodiments can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).

[0328] It should be understood that the sequence number of each process in the various embodiments of this application does not imply the order of execution; the execution order of each process should be determined by its function and internal logic. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. The above descriptions are merely specific embodiments of this application, and the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method executed by an access network device, comprising: Receive a first message from the terminal, wherein the first message carries a first non-access stratum (NAS) message; If the routing of the first NAS message is determined, the first NAS message is routed to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

2. The method according to claim 1, further comprising: The access network device receives a second message from a first core network element, wherein the second message is used to determine whether to route the first NAS message.

3. The method according to claim 2, wherein, The second message carries the authentication status of the terminal, wherein the authentication status of the terminal includes at least one of the following: the authentication result of the terminal, the first identifier of the terminal, and the authentication timestamp of the terminal.

4. The method according to claim 3, further comprising: Based on the authentication status of the terminal, determine whether to route the first NAS message.

5. The method according to claim 3 or 4, further comprising: The authentication status of the terminal is stored in the access layer AS security context.

6. The method according to claim 2, further comprising: If the second message carries information about the target core network element, the route for the first NAS message is determined.

7. The method according to claim 1, further comprising: If the first message is successfully verified based on the access layer AS security context, the route for the first NAS message is determined.

8. The method according to claim 4 or 7, wherein, The AS security context includes at least one of the following: the AS security key between the access network device and the terminal, the AS integrity key derived from the AS security key, and the AS encryption key derived from the AS security key.

9. The method according to any one of claims 4, 5, and 7, further comprising: Receive information from the target core network element from the first core network element.

10. The method according to any one of claims 1-9, further comprising: A third message is sent to the first core network element, wherein the third message is used to request information from the target core network element.

11. The method according to any one of claims 1-10, further comprising: The access network device receives the AS security key from the second core network element between the terminal and the access network device.

12. The method according to claim 11, wherein, The second core network element includes one of the following: mobility management network function, key management function.

13. A communication method executed by a terminal, comprising: Send a first message to the access network device, wherein the first message carries a first non-access stratum NAS message, and the access network device determines whether the first NAS message is routed to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

14. The method according to claim 13, wherein, The first message is a security protection message based on the access layer AS security context, wherein the AS security context includes at least one of the following: the AS security key between the access network device and the terminal, the AS integrity key derived from the AS security key, and the AS encryption key derived from the AS security key.

15. The method according to claim 14, wherein, The AS security key is generated based on a shared key between the terminal and the second core network element, wherein the second core network element includes one of the following: mobility management network function and key management function.

16. The method according to claim 15, wherein, The AS security key is generated based on the shared key between the terminal and the second core network element and at least one of the following: a parameter that distinguishes the access type, a fresh value, and the previously generated AS security key.

17. The method according to any one of claims 13-16, wherein, The first NAS message is a message that provides security protection based on the target NAS security context and the target NAS count value between the terminal and the target core network element. The target NAS count value includes at least one of the following: target uplink NAS count value and target downlink NAS count value. The terminal and different core network elements among the plurality of core network elements maintain different NAS count values.

18. A communication method executed by a target core network element, comprising: Receive a first non-access stratum (NAS) message from an access network device, wherein the first NAS message is carried by a first message sent by the terminal to the access network device.

19. The method of claim 18, further comprising: Based on the target NAS security context and the target NAS count value between the terminal and the target core network element, the first NAS message is verified, wherein the target NAS count value includes at least one of the following: target uplink NAS count value and target downlink NAS count value.

20. A communication method executed by a first core network element, comprising: A second message is sent to the access network device, wherein the second message is used by the access network device to determine whether to route a first non-access stratum (NAS) message from the terminal.

21. The method according to claim 20, wherein, The second message carries the authentication status of the terminal, wherein the authentication status of the terminal includes at least one of the following: the authentication result of the terminal, the first identifier of the terminal, and the authentication timestamp of the terminal.

22. The method according to claim 20 or 21, wherein, The second message carries information about the target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

23. The method according to any one of claims 20-22, further comprising: A third message is received from the access network device, wherein the third message is used to request information from the target core network element.

24. A communication method executed by a second core network element, comprising: Send the access layer AS security key between the access network device and the terminal to the access network device.

25. The method according to claim 24, wherein, The AS security key is generated based on the shared key between the terminal and the second core network element.

26. The method according to claim 25, wherein, The AS security key is generated based on the shared key between the terminal and the second core network element and at least one of the following: a parameter that distinguishes the access type, a fresh value, and the previously generated AS security key.

27. The method according to any one of claims 24-26, wherein, The second core network element includes one of the following: mobility management network function, key management function.

28. An access network device, comprising: A first communication unit is configured to receive a first message from a terminal, wherein the first message carries a first non-access stratum (NAS) message; and, if the routing of the first NAS message is determined, to route the first NAS message to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

29. A terminal, comprising: The second communication unit is used to send a first message to the access network device, wherein the first message carries a first non-access stratum (NAS) message, and the access network device determines whether the first NAS message is routed to a target core network element, wherein the target core network element is one of a plurality of core network elements capable of transmitting NAS messages with the terminal.

30. A target core network element, comprising: The third communication unit is used to receive a first non-access stratum (NAS) message from the access network device, wherein the first NAS message is carried by a first message sent by the terminal to the access network device.

31. A first core network element, comprising: The fourth communication unit is used to send a second message to the access network device, wherein the second message is used by the access network device to determine whether to route a first non-access stratum (NAS) message from the terminal.

32. A second core network element, comprising: The fifth communication unit is used to send the access layer AS security key between the access network device and the terminal to the access network device.

Citation Information

Patent Citations

  • Method and device for providing and acquiring security context

    CN105532026A

  • Information transmission method and apparatus, network device, and user equipment

    CN113412655A

  • Method, device and system for core network device reassignment in wireless network

    CN117242823A

  • Network access method and communication device

    CN117377030A

  • Handling of 3GPP and non-3GPP access in the 5g system

    US20220078692A1