Communication method and apparatus
By generating a unique key for each session, the problem of key reuse in end-to-end security protection scenarios between terminal devices and user plane functions is solved, thereby improving the security of user plane data transmission.
Patent Information
- Application Number
- PCT/CN2025/104636
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-17
- Filing Date
- 2025-06-27
- Publication Date
- 2026-01-22
AI Technical Summary
In end-to-end security protection scenarios between terminal devices and user plane functions, existing technologies cannot effectively prevent the reuse of keys used in different sessions, resulting in insufficient security of user plane data.
By generating different keys at the session level, and using a counter or random value to assign a unique first value to each session's setup request, we ensure that each session uses a different key and prevent key reuse.
Within a primary authentication cycle, keys used in different sessions are not reused, thus improving the security of user plane data transmission.
Smart Images

Figure CN2025104636_22012026_PF_FP_ABST
Abstract
Description
Communication method and apparatus
[0001] The present application claims priority to the Chinese patent application No. 202410966052.8, filed on July 17, 2024, and entitled "Communication method and apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the field of communication, in particular to a communication method and apparatus. BACKGROUND
[0003] In the current mobile communication network, user plane data is protected hop by hop during transmission, that is, user plane data is protected between a terminal device and a base station, and between the base station and a user plane function. This causes user plane data to appear in plaintext at the base station side, which is vulnerable to near-end detection, physical attacks, and the like. Therefore, it is desirable to establish end-to-end security protection between the terminal device and the user plane function, that is, the base station does not perform integrity verification and decryption on user plane data, but only forwards encrypted data.
[0004] In the hop-by-hop security protection scenario, the user plane protection key is designed with the terminal device as the granularity. In a primary authentication period, different sessions initiated by the same terminal device are protected. The terminal device and the base station can maintain the count value of the counter input when the terminal device protects user plane data. In the case of the same user plane protection key input, the output key stream will not be reused due to the different input count values. However, in the end-to-end security protection scenario between the terminal device and the user plane function, the user plane function network element serving different sessions may not be the same. The terminal device and the user plane function cannot maintain the count value input when protecting user plane data as the terminal device and the base station do in the hop-by-hop security protection scenario, to ensure that the output key stream will not be reused. Therefore, how to solve the user plane data security problem in the end-to-end security protection scenario between the terminal device and the user plane function is an urgent problem to be solved. SUMMARY
[0005] The present application provides a communication method and apparatus. In the end-to-end security protection scenario, the user plane data is protected by the session-granularity key. This can ensure that the key used by different sessions is not reused in a primary authentication period, thereby improving the security of user plane data transmission.
[0006] To achieve the above object, the present application adopts the following technical solutions:
[0007] In a first aspect, a communication method is provided. The method can be performed by a first network element, a component of the first network element, such as a processor, a chip, or a chip system of the first network element, or a logic module or software that can implement all or part of the first network element. The method includes receiving a first message from a terminal device, the first message including a session establishment request and a session identifier corresponding to the session establishment request. The method also includes sending the session establishment request, the session identifier, and a first key, the first key being used for security processing of data in a session corresponding to the session identifier, wherein the first key is determined according to the session identifier and a first value, the first value being a counting value or a random value, and different session establishment requests correspond to different first values.
[0008] In the method, the first network element can generate a first key using a first value and a session identifier of a session established by a session establishment request initiated by the terminal device for each session establishment request initiated by the terminal device, and send the first key to a corresponding user plane network element. Correspondingly, the terminal device also generates the same first key as the first network element side for each session establishment request initiated by the terminal device, the first key being used for security protection of data in a session established by the session establishment request or a session corresponding to the session identifier, and each session establishment request is assigned a different first value, which can be assigned by the first network element or the terminal device. In this way, regardless of whether the terminal device sends multiple session establishment requests with the same session identifier, the generated first keys are different. Thus, when performing end-to-end security protection between the terminal device and the user plane network element, the terminal device performs end-to-end user plane data transmission with different user plane network elements, and even if there are session establishments with the same session identifier, the first key used for security processing of user plane data can be ensured not to be reused, thereby ensuring the security of user plane data between the end-to-end.
[0009] In a possible design, the counting value can be obtained by counting using a counter, the counter being used for counting the number of session establishment requests requested by the terminal device, or the counter being used for counting the number of non-access stratum (NAS) messages sent by the terminal device, or the counter being used for counting the number of NAS messages sent to the terminal device. Thus, the counting value can be obtained by adding a new counter or reusing an NAS counter, so as to ensure that different counting values are generated for different sessions, so that the first keys of different sessions are different, thereby ensuring the security of user plane data between the end-to-end.
[0010] In a possible design, in a case where the first value is a count value and the counter corresponding to the count value is used to count the number of session establishment requests requested by the terminal device, the method in the first aspect can further include: receiving a second message, the second message being used to indicate that the count value is increased by one. The count value is increased by one according to the second message. In this way, the first network element can change the count value based on triggering of the message, so that different sessions correspond to different count values, and thus the first keys of different sessions are different, thereby guaranteeing security of user plane data between end to end.
[0011] In a possible design, the method in the first aspect can further include: in a case where the count value reaches a maximum value, sending first indication information, the first indication information being used to indicate that the terminal device is re-performed with primary authentication. After the primary authentication is completed, the count value is set to zero. In this way, in a case where the count value reaches the maximum value, the primary authentication of the terminal device can be triggered, so that the count value can be reversed, for example, the count value is re-counted from the maximum value to 0, and the key of the first network element used to generate the first key is updated after the primary authentication, and thus the first key can be guaranteed not to be reused.
[0012] In a possible design, in a case where the first value is a random value, the method in the first aspect can further include: storing a correspondence between the random value and the session identifier. The random value is sent to the terminal device. In this way, the first network element can assign different random values to different sessions to generate different first keys, and the random value is sent to the terminal device, so that the first keys generated for the same session on both sides are the same, thereby guaranteeing security of user plane data between end to end.
[0013] In a possible design, the method in the first aspect can further include: after the terminal device is authenticated, all stored random values are cleared.
[0014] In a possible design, in a case where the first value is a random value, the method in the first aspect can further include: receiving the random value from the terminal device. In this way, the random value can be generated by the terminal device, and the first network element can obtain the random value from the terminal device, so that the first keys generated for the same session on both sides are the same, thereby guaranteeing security of user plane data between end to end.
[0015] In a possible design, the random value can be carried in the first message.
[0016] In a possible design, different session establishment requests correspond to different first values, which can include: different session establishment requests of different session identifiers correspond to different first values, and different session establishment requests of the same session identifier correspond to different first values.
[0017] In a second aspect, a communication method is provided. The method can be performed by a terminal device, or by a component of the terminal device, such as a processor, a chip, or a chip system of the terminal device, or by a logic module or software that can implement all or part of the terminal device. The method includes sending a first message, the first message including a session establishment request and a session identifier corresponding to the session establishment request. A first key is determined according to the session identifier and a first value, the first key being used for security processing of data in a session corresponding to the session identifier, the first value being a count value or a random value, different session establishment requests corresponding to different first values.
[0018] In a possible design, the count value can be obtained by counting by a counter, the counter being used for counting a number of session establishment requests requested by the terminal device, or the counter being used for counting a number of NAS messages sent by the terminal device, or the counter being used for counting a number of NAS messages sent to the terminal device.
[0019] In a possible design, in a case where the first value is the count value and the counter corresponding to the count value is used for counting a number of session establishment requests requested by the terminal device, the method of the second aspect can further include, after sending the first message or after receiving a session establishment accept message, incrementing the count value by one.
[0020] In a possible design, the method of the second aspect can further include, after completing primary authentication, setting the count value to zero.
[0021] In a possible design, in a case where the first value is the random value, the method of the second aspect can further include receiving the random value.
[0022] In a possible design, the random value can be carried in a session establishment accept message.
[0023] In a possible design, the method of the second aspect can further include, after completing primary authentication, clearing all stored random values.
[0024] In a possible design, in a case where the first value is the random value, the method of the second aspect can further include storing a correspondence between the session identifier and the random value, and sending the random value.
[0025] In a possible design, the random value can be carried in the first message.
[0026] In a possible design, different session establishment requests corresponding to different first values can include: different session establishment requests of different session identifiers corresponding to different first values, and different session establishment requests of a same session identifier corresponding to different first values.
[0027] In a possible design, the method of the second aspect further includes: performing security processing on data in the session corresponding to the session identifier according to the first key.
[0028] The technical effect of the method of the second aspect can refer to the related description of the technical effect of the method of the first aspect, and details are not described herein.
[0029] In a third aspect, a communication method is provided. The method can be executed by a session management network element, or by a component of the session management network element, such as a processor, a chip, or a chip system of the session management network element, or by a logic module or software capable of implementing all or part of the session management network element. The method includes: receiving a session establishment request, a session identifier corresponding to the session establishment request, and a first key, the first key being used for security processing on data in a session corresponding to the session identifier, the first key being determined according to the session identifier and a first value, the first value being a counting value or a random value, and different session establishment requests corresponding to different first values. Sending the session identifier and the first key to a user plane network element.
[0030] In a possible design, the counting value can be obtained by counting a counter, the counter being used for counting a number of session establishment requests requested by a terminal device, or the counter being used for counting a number of NAS messages sent by the terminal device, or the counter being used for counting a number of NAS messages sent to the terminal device.
[0031] In a possible design, in the case where the first value is the counting value, the method of the third aspect further includes: sending a second message, the second message being used for indicating that the counting value is incremented by one.
[0032] In a possible design, in the case where the first value is the random value, the method of the third aspect further includes: sending a third message, the third message being used for indicating that the random value is sent to the terminal device.
[0033] The technical effect of the method of the third aspect can refer to the related description of the technical effect of the method of the first aspect, and details are not described herein.
[0034] In a fourth aspect, a communication apparatus is provided for implementing the methods described above. The communication apparatus can be a first network element in the first aspect, or a device including the first network element, or a device included in the first network element, such as a chip. The communication apparatus includes corresponding modules, units, or means for implementing the methods of the first aspect, which can be implemented by hardware, software, or by a combination of hardware and software. The hardware or software includes one or more modules or units corresponding to the functions described above.
[0035] In some possible designs, the communication apparatus includes a processing module and a transceiver module. The transceiver module is configured to receive a first message from a terminal device, where the first message includes a session establishment request and a session identifier corresponding to the session establishment request. The processing module is configured to determine a first key according to the session identifier and a first value. The transceiver module is further configured to send the session establishment request, the session identifier, and the first key. The first key is used for security processing of data in a session corresponding to the session identifier, and the first value is a counting value or a random value. Different session establishment requests correspond to different first values.
[0036] In a possible design, the counting value can be obtained by counting by a counter. The counter is configured to count a number of session establishment requests requested by the terminal device, or the counter is configured to count a number of non-access stratum (NAS) messages sent by the terminal device, or the counter is configured to count a number of NAS messages sent to the terminal device.
[0037] In a possible design, in a case where the first value is a counting value and the counter corresponding to the counting value is configured to count a number of session establishment requests requested by the terminal device, the transceiver module is further configured to receive a second message, where the second message is used to indicate that the counting value is incremented by one. The counting value is incremented by one according to the second message.
[0038] In a possible design, in a case where the counting value reaches a maximum value, the transceiver module is further configured to send first indication information, where the first indication information is used to indicate that a primary authentication is performed again for the terminal device. After the primary authentication is completed, the processing module is further configured to set the counting value to zero.
[0039] In a possible design, in a case where the first value is a random value, the processing module is further configured to save a correspondence between the random value and the session identifier. The transceiver module is further configured to send the random value to the terminal device.
[0040] In a possible design, after the primary authentication is performed for the terminal device, the processing module is further configured to clear all stored random values.
[0041] In a possible design, when the first value is a random value, the transceiver is further configured to receive the random value from the terminal device.
[0042] In a possible design, the random value can be carried in the first message.
[0043] In a possible design, different session establishment requests correspond to different first values, which can include that session establishment requests with different session identifiers correspond to different first values, and session establishment requests with the same session identifier correspond to different first values.
[0044] In a possible design, the transceiver can include a receiving module and a sending module. The sending module is configured to implement the sending function of the communication apparatus in the fourth aspect, and the receiving module is configured to implement the receiving function of the communication apparatus in the fourth aspect.
[0045] In a possible design, the communication apparatus in the fourth aspect can further include a storage module that stores programs or instructions. When the processing module executes the programs or instructions, the communication apparatus in the fourth aspect can execute the method in the first aspect.
[0046] In the fifth aspect, a communication apparatus is provided for implementing the above-described methods. The communication apparatus can be the terminal device in the second aspect, or an apparatus including the terminal device, or an apparatus included in the terminal device, such as a chip. The communication apparatus includes corresponding modules, units, or means for implementing the methods in the second aspect, which can be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above-described functions.
[0047] In some possible designs, the communication apparatus includes a processing module and a transceiver. The transceiver is configured to send a first message, and the first message includes a session establishment request and a session identifier corresponding to the session establishment request. The processing module is configured to determine a first key according to the session identifier and a first value, the first key is used for security processing of data in a session corresponding to the session identifier, the first value is a count value or a random value, and different session establishment requests correspond to different first values.
[0048] In a possible design, the count value can be obtained by counting by a counter, and the counter is configured to count a number of session establishment requests requested by the terminal device, or the counter is configured to count a number of NAS messages sent by the terminal device, or the counter is configured to count a number of NAS messages sent to the terminal device.
[0049] In a possible design, in a case where the first value is a count value and the counter corresponding to the count value is used to count the number of session establishment requests requested by the terminal device, the processing module is further configured to, after sending the first message or receiving the session establishment acceptance message, increase the count value by one.
[0050] In a possible design, the processing module is further configured to, after completing the primary authentication, set the count value to zero.
[0051] In a possible design, in a case where the first value is a random value, the transceiver is further configured to receive the random value.
[0052] In a possible design, the random value can be carried in the session establishment acceptance message.
[0053] In a possible design, the processing module is further configured to, after completing the primary authentication, clear all stored random values.
[0054] In a possible design, in a case where the first value is a random value, the processing module is further configured to store the correspondence between the session identifier and the random value, and the transceiver is further configured to send the random value.
[0055] In a possible design, the random value can be carried in the first message.
[0056] In a possible design, different session establishment requests correspond to different first values, which can include that different session establishment requests corresponding to different session identifiers correspond to different first values, and different session establishment requests corresponding to the same session identifier correspond to different first values.
[0057] In a possible design, the processing module is further configured to perform security processing on data in a session corresponding to the session identifier according to the first key.
[0058] In a possible design, the transceiver can include a receiving module and a sending module. The sending module is configured to implement the sending function of the communication apparatus in the fifth aspect, and the receiving module is configured to implement the receiving function of the communication apparatus in the fifth aspect.
[0059] In a possible design, the communication apparatus in the fifth aspect can further include a storage module that stores programs or instructions. When the processing module executes the programs or instructions, the communication apparatus in the fifth aspect can execute the method in the second aspect.
[0060] In a sixth aspect, a communication apparatus is provided for implementing the methods described above. The communication apparatus can be a session management network element in the third aspect, or a device including the session management network element, or a device included in the session management network element, such as a chip. The communication apparatus includes corresponding modules, units, or means for implementing the methods described in the third aspect, which can be implemented by hardware, software, or by executing corresponding software by hardware. The hardware or software includes one or more modules or units corresponding to the functions described above.
[0061] In some possible design, the communication apparatus includes a processing module and a transceiver module. The transceiver module is configured to receive a session establishment request, a session identifier corresponding to the session establishment request, and a first key, the first key being used for security processing of data in a session corresponding to the session identifier, the first key being determined according to the session identifier and a first value, the first value being a counting value or a random value, different session establishment requests corresponding to different first values. The processing module is configured to determine a user plane network element. The transceiver module is further configured to send the session identifier and the first key to the user plane network element.
[0062] In a possible design, the counting value can be obtained by counting by a counter, the counter being configured to count a number of session establishment requests requested by the terminal device, or the counter being configured to count a number of NAS messages sent by the terminal device, or the counter being configured to count a number of NAS messages sent to the terminal device.
[0063] In a possible design, in the case where the first value is the counting value, the transceiver module is further configured to send a second message, the second message being used to indicate that the counting value is incremented by one.
[0064] In a possible design, in the case where the first value is the random value, the transceiver module is further configured to send a third message, the third message being used to indicate that the random value is sent to the terminal device.
[0065] In a possible design, the transceiver module can include a receiving module and a sending module. The sending module is configured to implement the sending function of the communication apparatus in the sixth aspect, and the receiving module is configured to implement the receiving function of the communication apparatus in the sixth aspect.
[0066] In a possible design, the communication apparatus in the sixth aspect can further include a storage module, which stores programs or instructions. When the processing module executes the programs or instructions, the communication apparatus in the sixth aspect can execute the method in the third aspect.
[0067] In a seventh aspect, a communication apparatus (which can be a chip or a chip system) is provided. The communication apparatus comprises a processor configured to implement the functions described in any of the first to third aspects.
[0068] In a possible design, the communication apparatus can further comprise a memory configured to store necessary program instructions and data. The processor is coupled to the memory, and is configured to execute the computer program or instructions stored in the memory, so that the communication apparatus performs the method described in any of the possible implementation manners of the first to third aspects.
[0069] In a possible design, the communication apparatus described in the seventh aspect can further comprise a transceiver. The transceiver can be a transceiver circuit or an interface circuit. The transceiver can be configured to enable the communication apparatus described in the seventh aspect to communicate with other communication apparatuses.
[0070] In a possible design, the processor can be integrated with the memory.
[0071] In some possible designs, when the apparatus is a chip system, the apparatus can be formed by a chip, or can comprise a chip and other discrete devices.
[0072] In an eighth aspect, a communication apparatus is provided. The communication apparatus comprises a processor and an interface circuit. The interface circuit is configured to receive a signal from another communication apparatus outside the communication apparatus and transmit the signal to the processor, or send a signal from the processor to another communication apparatus outside the communication apparatus. The processor is configured to implement the method described in any of the possible implementation manners of the first to third aspects by means of logic circuit or execution of code instructions.
[0073] It can be understood that, when the communication apparatus provided in any of the seventh aspect or the eighth aspect is a chip, the sending action / function described above can be understood as output, and the receiving action / function described above can be understood as input.
[0074] In a ninth aspect, a computer readable storage medium is provided. The computer readable storage medium stores computer programs or instructions, which, when executed on a communication apparatus, enable the communication apparatus to perform the method described in any of the first to third aspects.
[0075] In a tenth aspect, a computer program product is provided. The computer program product comprises instructions, which, when executed on a communication apparatus, enable the communication apparatus to perform the method described in any of the first to third aspects.
[0076] In an eleventh aspect, a communication system is provided, comprising: a first network element for implementing the method of the first aspect, a terminal device for implementing the method of the second aspect, and a session management network element for implementing the method of the third aspect. BRIEF DESCRIPTION OF DRAWINGS
[0077] FIG. 1 is a schematic diagram of an architecture of a non-roaming 5G system based on a service-based interface;
[0078] FIG. 2 is a schematic diagram of an architecture of a key derivation in a 5G system;
[0079] FIG. 3 is a schematic diagram of a flow of an algorithm negotiation;
[0080] FIG. 4 is a schematic diagram of a flow of a UP security activation mechanism;
[0081] FIG. 5 is a schematic diagram of a flow of data encryption and decryption defined in 3GPP;
[0082] FIG. 6 is a schematic diagram of a flow of integrity protection and verification defined in 3GPP;
[0083] FIG. 7 is a schematic diagram of an architecture of a communication system provided by an embodiment of the present application;
[0084] FIG. 8 is a schematic diagram of a flow of a communication method provided by an embodiment of the present application;
[0085] FIG. 9 is a schematic diagram of a flow of another communication method provided by an embodiment of the present application;
[0086] FIG. 10 is a schematic diagram of a flow of yet another communication method provided by an embodiment of the present application;
[0087] FIG. 11 is a schematic diagram of a flow of yet another communication method provided by an embodiment of the present application;
[0088] FIG. 12 is a schematic diagram of a structure of a communication apparatus provided by an embodiment of the present application;
[0089] FIG. 13 is a schematic diagram of a structure of another communication apparatus provided by an embodiment of the present application. DETAILED DESCRIPTION
[0090] Embodiments of the present application will present various aspects, embodiments or features around systems that can include a plurality of devices, components, modules, etc. It should be understood and appreciated that each system can include additional devices, components, modules, etc., and / or can not include all of the devices, components, modules, etc. discussed in connection with the figures. Furthermore, combinations of these approaches can also be used.
[0091] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example, a wireless fidelity (Wi-Fi) system, a vehicle to everything (V2X) communication system, a device-to-device (D2D) communication system, a vehicle networking communication system, a worldwide interoperability for microwave access (WiMAX) communication system, a 4th generation (4G) mobile communication system such as a long term evolution (LTE) system, a 5th generation (5G) mobile communication system such as a new radio (NR) system, and a future communication system, and the like.
[0092] The following describes related terms, concepts or technologies that can be involved in the embodiments of the present application:
[0093] 1. 5G mobile communication system
[0094] 5G is a new generation of broadband mobile communication technology with the characteristics of high speed, low delay and large connection. 5G communication facilities are network infrastructure for realizing man-machine and interconnection. As shown in FIG. 1, it is an architecture diagram of a non-roaming (Non-Roaming) 5G system based on a service interface. The 5G system includes a terminal device, a radio (R) access network (AN) and a core network (CN), and the terminal device accesses a data network (DN) through the AN and the CN.
[0095] The terminal device can be a terminal device with transceiver function, or can also be a chip or chip system arranged in the terminal device. The terminal device can also be referred to as a user equipment (UE), an access terminal, a subscriber unit, a user station, a mobile station (MS), a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent or a user apparatus. The terminal device in the embodiments of the present application can be a mobile phone, a cellular phone, a smart phone, a Pad, a wireless data card, a personal digital assistant computer (PDA), a wireless modem, a handset, a laptop computer, a machine type communication (MTC) terminal, an internet of things (IoT) terminal, a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a smart home device (for example, a refrigerator, a television, an air conditioner, an electricity meter, etc.), a smart robot, a mechanical arm, a workshop device, a wireless terminal in a self-driving vehicle, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical treatment, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, a vehicle-mounted terminal, a road side unit (RSU) with terminal function, etc., a flight device (for example, a smart robot, a hot air balloon, a drone, an airplane), etc. The terminal device of the present application can also be a vehicle-mounted module, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit built in a vehicle as one or more components or units. The terminal device can also be other devices with terminal function, for example, the terminal device can also be a device with terminal function in D2D communication.
[0096] Embodiments of the present application do not limit the device form of the terminal device, and the device for implementing the function of the terminal device can be a terminal device; or can be a device capable of supporting the terminal device to implement the function, such as a chip system. The device can be installed in the terminal device or used in matching with the terminal device. In embodiments of the present application, the chip system can be composed of a chip, or can include a chip and other discrete devices.
[0097] AN is used to implement access-related functions, can provide network access functions for authorized users in a specific area, and can determine transmission links of different qualities to transmit user data according to the level of the user, the demand of the service, and the like. AN forwards control signals and user data between the terminal device and the CN. AN can include an access network device, which can also be referred to as an access network node, a radio access network (RAN) node, a RAN device, a RAN entity, or an access node, etc., located at the network side of the above-mentioned communication system, used to help the terminal device to implement wireless access, and has a wireless transceiving function or a chip or chip system that can be arranged in the device.
[0098] The access network device includes, but is not limited to, a base station, an evolved Node B (eNodeB / eNB), an access point (AP), a transmission reception point (TRP or transmission point, TP), a next generation NodeB (gNB), a base station in a future mobile communication system, or an access node in a Wi-Fi system, etc. The access network device can be a macro base station, a micro base station or an indoor station, a relay node or a donor node, an open radio access network (ORAN), or a wireless controller in a centralized radio access network (CRAN) scenario. The access network device can also be one or a group (including multiple antenna panels) of antenna panels of a base station in 5G, or can also be a network node constituting a gNB, a TRP or a TP or a transmission measurement function (TMF), such as a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), a road side unit (RSU) with base station function, optionally, the access network device can also be a server, a wearable device, a vehicle or a vehicle-mounted device, etc. For example, the access network device in V2X technology can be an RSU. All or part of the functions of the access network device in this application can also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform). The access network device in this application can also be a logical node, a logical module or software that can implement all or part of the functions of the access network device.
[0099] The CU and the DU can be separately arranged, or can also be included in the same network element, for example, a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, for example, included in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that the access network device can be a CU node, or a DU node, or a device including the CU node and the DU node. In addition, the CU can be divided into a network device in the access network RAN, or the CU can be divided into a network device in the CN, which is not limited herein.
[0100] The CU (or CU-CP and CU-UP), DU, or RU can also have different names in different systems, but those skilled in the art can understand their meanings. For example, in an ORAN system, the CU can also be referred to as an O-CU (open CU), the DU can also be referred to as an O-DU, the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. For the convenience of description, the CU, the CU-CP, the CU-UP, the DU, and the RU are taken as examples for description in this application. Any one of the CU (or CU-CP, CU-UP), the DU, and the RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0101] The form of the access network device is not limited in the embodiments of this application. The device for implementing the function of the access network device can be the access network device; or can be a device capable of supporting the access network device to implement the function, for example, a chip system. The device can be installed in the access network device or used in matching with the access network device.
[0102] The CN is mainly responsible for maintaining subscription data of the mobile network, and provides session management, mobility management, policy management, security authentication and other functions for terminal devices. The CN mainly includes the following network elements: UPF, AUSF, AMF, session management function (SMF), network slice selection function (NSSF), network exposure function (NEF), network function repository function (NRF), policy control function (PCF), unified data management (UDM), application function (AF), edge application service discovery function (EASDF), network slice admission control function (NSACF), service communication proxy (SCP), and network slice-specific and SNPN authentication and authorization function (NSSAAF) of the network slice and standalone non-public network (SNPN).
[0103] The UPF is mainly responsible for user data processing (forwarding, receiving, charging, etc.). For example, the UPF can receive user data from the DN, and forward the user data to the terminal device through the access network device. The UPF can also receive user data from the terminal device through the access network device, and forward the user data to the DN. In a PDU session, the UPF directly connected to the DN through N6 is also called a protocol data unit session anchor (PSA).
[0104] The AUSF is mainly used to perform security authentication of the terminal device.
[0105] The AMF is mainly used for mobility management in the mobile network, such as user location update, user registration network, user handover, etc.
[0106] The SMF is mainly used for session management in a mobile network. For example, session establishment, modification, and release. Specific functions include, for example, allocating an internet protocol (IP) address for a user, selecting a UPF that provides packet forwarding functions, and the like.
[0107] The NSSF is mainly used for selecting a network slice for a terminal device.
[0108] The NEF is mainly used to support the opening of capabilities and events. For example, the NEF can expose some capabilities of the 5G network to a third-party application through an application program interface (API), and the third-party application can obtain some capabilities of the 5G network by invoking the API provided by the NEF through the AF, so that the third-party application can control some behaviors of the 5G network and the terminal device.
[0109] The NRF is mainly used to provide a network element discovery function, provide network element information corresponding to a network element type based on a request of another network element, and also provide network element management services such as network element registration, update, deregistration, and network element state subscription and push.
[0110] The PCF is mainly used to support providing a unified policy framework to control network behavior, providing policy rules to control layer network functions, and being responsible for obtaining user subscription information related to policy decision. The PCF can provide policies such as quality of service (QoS) policies and slice selection policies to the AMF and the SMF.
[0111] The UDM is mainly used to store user data such as subscription data and authentication / authorization data.
[0112] The AF is a functional network element deployed on a third party, which transmits application-side requirements for the network side, such as QoS requirements or user state event subscription. The main role is to tell the PCF the latest business requirements of a third-party enterprise for a certain application, and the PCF will generate corresponding QoS rules according to the requirements to ensure that the services provided by the network meet the requirements proposed by the third party.
[0113] The EASDF is mainly used to process domain name system (DNS) messages according to the instructions of the SMF, including exchanging DNS messages with a terminal device, forwarding the DNS messages to a central (C)-DNS or a local (L) L-DNS for DNS query, and the like.
[0114] The NSACF is mainly responsible for monitoring and controlling the number of registered terminal devices on each network slice, monitoring and controlling the number of PDU sessions established by each network slice. Based on event-based network slice status notification, the user (network function, NF) is reported.
[0115] The SCP mainly supports the function of indirect communication of hypertext transfer protocol (HTTP) signaling, and provides signaling message routing and forwarding between NFs in the CN.
[0116] The NSSAAF can be used to support slice authentication and authorization, and to support access to independent non-public networks using credential holders' credentials.
[0117] It should be understood that the above exemplary shows several core network elements contained in the CN, in addition to which other core network elements can also be included, for example, a unified data repository (UDR), which is mainly used to store structured data, and the stored content includes subscription data and policy data, structured data exposed to the outside, and application-related data.
[0118] It can be understood that the above-mentioned network elements or functions can be either physical entities in hardware devices, or software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (for example, a cloud platform). In short, an NF can be implemented by hardware or software.
[0119] The DN is a network located outside the operator network, and the operator network can access multiple DNs. Various services can be deployed on the DN, and data and / or voice services can be provided to terminal devices. For example, the DN is a private network of a smart factory, and the sensors installed in the workshop of the smart factory can be terminal devices. A control server of the sensors is deployed in the DN, and the control server can provide services for the sensors. The sensors can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions, etc. For another example, the DN is an internal office network of a company, and the mobile phones or computers of the employees of the company can be terminal devices. The mobile phones or computers of the employees can access information and data resources on the internal office network of the company.
[0120] Nnef, Nnrf, Npcf, Nudm, Nudr, Nnwdaf, Naf, Nausf, Namf, Nsmf, N1, N2, N3, N4, and N6 in FIG. 1 are interface sequence numbers. For example, the meanings of the above interface sequence numbers can refer to the meanings defined in the 3GPP standard protocol, and the present application does not limit the meanings of the above interface sequence numbers. It should be noted that the interface names between the various network functions in FIG. 1 are only an example, and in specific implementation, the interface names of the system architecture can also be other names, which are not limited by the present application. In addition, the names of the messages (or signaling) transmitted between the above various network elements are also only an example, and do not constitute any limitation on the functions of the messages themselves.
[0121] It should be noted that in the architecture shown in FIG. 1, the interface between (R)AN and CN can also be referred to as NG interface (not shown in FIG. 1), and (R)AN and CN are connected through the NG interface. The NG interface can include NG-C interface and NG-U interface, wherein the NG-C interface is a control plane interface, and the connection parties are (R)AN and AMF, which are used to transmit control plane data; the NG-U interface is a user plane interface, and the connection parties are (R)AN and UPF, which are used to transmit user plane data.
[0122] It should be understood that the AMF, SMF, UPF, NEF, AUSF, NRF, PCF, and UDM shown in FIG. 1 can be understood as network elements in the core network for realizing different functions, which can be combined into a network slice as needed. These core network network elements can be independent devices respectively, or can be integrated into the same device to realize different functions, and the present application does not limit the specific form of the above network elements.
[0123] It should also be understood that the above naming is only defined for the convenience of distinguishing different functions, and should not constitute any limitation on the present application. The present application does not exclude the possibility of using other names in 5G networks and other future networks.
[0124] 2, User Plane Data Security Protection
[0125] The user plane data transmission includes uplink user plane data transmission and downlink user plane data transmission. The uplink user plane data transmission means that the user plane data of the terminal device can be transmitted to the DN through the base station and the UPF in turn, and the downlink user plane data transmission means that the user plane data of the DN can be transmitted to the terminal device through the UPF and the base station in turn.
[0126] The 5G system implements security protection of user plane data between a terminal device and a DN by hop-by-hop security protection to ensure communication security. For example, the terminal device and the base station perform security protection on transmitted user plane data, and the base station and the UPF establish an internet protocol security (IPSec) tunnel. For a data packet that needs to be protected, the 5G system can allocate the required air interface resource for the terminal device in the process of establishing a PDU session for transmitting the data packet, obtain a security protection key between the terminal device and the base station, and activate security protection of the user plane between the terminal device and the base station to ensure communication security between the terminal device and the base station.
[0127] In the scenario of hop-by-hop security protection, security protection of user plane data includes:
[0128] 2-1, Key derivation
[0129] Security protection of user plane data includes confidentiality protection (or encryption protection) and integrity protection, and the key used for user plane data protection is derived by the terminal device after registration to the network through an authentication process.
[0130] As shown in FIG. 2, it is an architecture diagram of key derivation in the 5G system. The universal subscriber identity module (USIM) of the terminal device and the UDM / authentication repository function (ARPF) of the network side save the long-term key K of the terminal device. When the terminal device registers to the network, identity authentication, i.e., primary authentication, is performed. The cipher key (CK) and the integrity key (IK) in the primary authentication process can be derived from K through 5G authentication and key agreement (AKA) or extensible authentication protocol-AKA' (EAP-AKA'). AUSF K AUSF K SEAF K SEAF K AMF K AMF K gNB NH gNB NH NASint, NAS confidentiality protection key K NASenc ), and a radio resource control (RRC) key (RRC integrity protection key K RRCint , RRC confidentiality protection key K RRCenc ), and a user plane key (user plane integrity protection key K UPint , user plane confidentiality protection key K UPenc ). For non-3rd generation partnership project (3GPP) access, K AMF may also be derived by K N3IWF for protecting subsequent data traffic of non-3GPP access.
[0131] It is assumed that the derivation of the keys is done by means of a key derivation function (KDF):
[0132] In 5G AKA, K AUSF is derived as follows: where CK||IK is the concatenation of CK and IK, 0x6A is the derivation identifier, serving network name is the serving network name, L0 is the length of the serving network name, SQN is the sequence number, AK is the anonymity key, and the exclusive OR (XOR) of SQN and AK is sent to the terminal device as part of the authentication token (AUTN), see technical specification (TS) 33.102, and L1 is the length of .
[0133] K SEAF is derived as follows: K SEAF = KDF(K AUSF , 0x6C, serving network name, L0).
[0134] K AMF is derived as follows: K AMF = KDF(K SEAF, 0x6D, IMSI / NAI / GCI / GLI, L0, ABBA paramter, L1). Wherein, IMSI, NAI, GCI, GLI are four types of subscription permanent identifier (SUPI), IMSI is international mobile station identity, NAI is network access identifier, GCI is global cable identifier, GLI is global line identifier, ABBA paramter is anti-bidding down between architectures (AABA) parameter, L1 is the length of ABBA paramter.
[0135] K gNB That is, the derivation of the key of the base station is as follows: K gNB = KDF(K AMF , 0x6E, uplink NAS COUNT, the length of uplink NAS COUNT, access type distinguisher, the length of access type distinguisher). Wherein, the value of access type distinguisher is 0x01 when 3GPP access, and the value of access type distinguisher is 0x02 when non-3GPP access.
[0136] Derive K AMF from K NASenc or K NASint , derive K gNB from K RRCenc and K RRCint , K UPenc and K UPint , the process is as follows: K NAS / K RRC / K UP = KDF(K AMF / K gNB, 0x69, algorithm type discriminator, length of the algorithm type discriminator, algorithm identifier, length of the algorithm identifier). Among them, for the NAS encryption algorithm, the algorithm type discriminator is N-NAS-enc-alg; for the NAS integrity protection algorithm, the algorithm type discriminator is N-NAS-int-alg; for the RRC encryption algorithm, the algorithm type discriminator is N-RRC-enc-alg; for the RRC integrity protection algorithm, the algorithm type discriminator is N-RRC-int-alg; for the UP encryption algorithm, the algorithm type discriminator is N-UP-enc-alg; for the UP integrity protection algorithm, the algorithm type discriminator is N-UP-int-alg. The values of each algorithm type discriminator are shown in Table 1 as follows:
[0137] Table 1
[0138] The algorithm identifier includes an encryption algorithm identifier and an integrity algorithm identifier, each network encryption algorithm (NEA) and network integrity algorithm (NIA) is assigned a 4-bit encryption algorithm identifier, different identifiers correspond to different encryption algorithms / integrity algorithms. For example, the identifier of the encryption algorithm NEA0 is 0000, the identifier of the encryption algorithm 128-NEA1 is 0001, the identifier of the encryption algorithm 128-NEA2 is 0010, and the identifier of the encryption algorithm 128-NEA3 is 0011. For another example, the identifier of the integrity algorithm NIA0 is 0000, the identifier of the integrity algorithm 128-NIA1 is 0001, the identifier of the integrity algorithm 128-NIA2 is 0010, and the identifier of the integrity algorithm 128-NIA3 is 0011.
[0139] It can be seen that, in the K NAS / K RRC / K UP During deduction, the algorithm identifier of the encryption algorithm or the integrity algorithm is taken as input, and it is distinguished whether it is encryption or integrity protection.
[0140] 2-2, Algorithm negotiation
[0141] For the hop-by-hop security protection scenario, the security algorithm used by the user plane data for security protection between the terminal device and the base station is the security algorithm with the highest priority selected by the base station side according to the security capability of the terminal device and the security capability of the base station. The base station can send the selected security algorithm to the terminal device through the access stratum (AS) security model command (SMC) process. Specifically, the base station side will send the confidentiality protection and integrity protection algorithms (selected by the terminal device's security capability and the base station's local security capability with the highest priority) to the terminal device in the AS SMC process, wherein the terminal device carries the security capability of the terminal device in the registration process.
[0142] As shown in FIG. 3, the negotiation process of the confidentiality protection and integrity protection algorithms can include the following steps:
[0143] S31a, the base station starts RRC integrity protection.
[0144] S31b, the base station sends an AS security mode command (AS Security Mode Command) to the terminal device. Correspondingly, the terminal device receives the AS security mode command from the base station. Wherein, the AS security mode command includes an integrity algorithm, an encryption algorithm, and a MAC-I.
[0145] S31c, the base station starts RRC downlink encryption.
[0146] S31d, the base station starts RRC uplink decryption.
[0147] S32a, the terminal device verifies the AS SMC integrity, and if successful, starts RRC integrity protection and RRC downlink decryption.
[0148] S32b, the terminal device sends an AS security mode complete (AS Security Mode Complete) to the base station. Correspondingly, the base station receives the AS security mode complete from the terminal device. Wherein, the AS security mode complete includes a MAC-I.
[0149] S33c, the terminal device starts RRC uplink encryption.
[0150] 2-3, security policy
[0151] The security policy of user plane data is PDU session granularity. Specifically, during the establishment of a PDU session, the SMF obtains the security policy of the PDU session (including whether to protect confidentiality, whether to protect encryption, and specific division into required, not needed, and preferred), and sends the corresponding security policy to the base station. The base station uses the security policy for all data radio bearers (DRBs) allocated for the PDU session. Specifically, AS UP integrity protection and encryption activation should be part of the DRB addition process, and the RRC connection reconfiguration process shown in FIG. 4 is used to complete the process.
[0152] As shown in FIG. 4, it is a flowchart of a UP security activation mechanism, including the following steps:
[0153] S41a, the base station determines that RRC security is activated, such as RRC encryption and RRC integrity protection are activated.
[0154] S41b, the base station sends an RRC connection reconfiguration (RRC Connection Reconfiguration) message to the terminal device. Correspondingly, the terminal device receives the RRC connection reconfiguration message from the base station. The RRC connection reconfiguration message includes the UP integrity indication and the UP ciphering indication of each DRB.
[0155] S41c, for each DRB, if the UP integrity is activated, the base station starts the uplink UP integrity verification and the downlink UP integrity protection; for each DRB, if the UP encryption is activated, the base station starts the uplink UP decryption and the downlink UP encryption.
[0156] S42a, the terminal device verifies the integrity of the RRC connection reconfiguration. If successful, for each DRB, if the UP integrity is activated, the terminal device starts the uplink UP integrity protection and the downlink UP integrity verification; for each DRB, if the UP encryption is activated, the terminal device starts the uplink UP encryption and the downlink UP decryption.
[0157] S42b, the terminal device sends an RRC connection reconfiguration complete (RRC Connection Reconfiguration Complete) message to the base station. Correspondingly, the base station receives the RRC connection reconfiguration complete message from the terminal device.
[0158] Here, the UP integrity indication and the UP ciphering indication both refer to whether protection is turned on, and do not include specific encryption and integrity protection algorithms. The encryption and integrity protection algorithms are sent by the base station to the terminal device in the above-mentioned AS SMC process (which can be earlier than user plane activation, and the AS covers RRC signaling and user plane air interface transmission).
[0159] In this way, encryption and integrity protection can be performed between the terminal device and the base station based on the DRB and the corresponding security policy. The security policy is PDU session granularity, and the security policy of the DRB corresponding to a certain PDU session is the same.
[0160] 2-4, Confidentiality protection and integrity protection
[0161] After the corresponding keys are derived, and the corresponding security protection algorithms and security policies are determined, the user plane data can be subjected to confidentiality protection and integrity protection. The confidentiality protection refers to encrypting the data to output ciphertext, and an attacker cannot derive the corresponding plaintext information from the ciphertext. As shown in FIG. 5, which is a flowchart of data encryption and decryption defined in 3GPP, the sending end inputs the key KEY, COUNT, BEARER, DIRECTION, and LENGTH into the NEA to output the key stream KEYSTREAM BLOCK, and then uses the output key stream KEYSTREAM BLOCK to perform XOR with the plaintext PLAINTEXT BLOCK to encrypt, and can output the corresponding ciphertext CIPHERTEXT BLOCK. Correspondingly, the receiving end also inputs the key KEY, COUNT, BEARER, DIRECTION, and LENGTH into the NEA to output the key stream KEYSTREAM BLOCK, and then uses the key stream KEYSTREAM BLOCK to perform XOR with the received ciphertext CIPHERTEXT BLOCK to decrypt, and can output the corresponding plaintext PLAINTEXT BLOCK.
[0162] Among them, KEY is a 128-bit key, COUNT is a 32-bit COUNT value (uplink and uplink packet data convergence protocol (PDCP) COUNT value), BEARER is a 5-bit bearer identifier, DIRECTION is a 1-bit transmission direction (0 for uplink and 1 for downlink), and LENGTH is the length of the required key stream.
[0163] As shown in FIG. 6, it is a flowchart of integrity protection and verification defined in 3GPP. The sending end inputs the key KEY, COUNT, MESSAGE, DIRECTION, BEARER into NIA, and outputs the corresponding message authentication code (MAC) value (such as MAC-I / NAS-MAC). Correspondingly, the receiving end also inputs the key KEY, COUNT, MESSAGE, DIRECTION, BEARER into NIA, calculates the MAC value (such as XMAC-I / XNAS-MAC), and compares whether the received MAC value is equal to the locally calculated MAC value. Among them, MESSAGE is the message itself for integrity protection and verification, and the bit length is LENGTH.
[0164] The entire key derivation architecture and data protection described above are based on hop-by-hop security protection design. In the hop-by-hop security protection scenario, the terminal device and the base station share the user plane encryption and integrity protection key, and use the key to protect the data, so that decryption and integrity verification will be performed at the base station side.
[0165] 3. PDU session identity
[0166] The PDU (protocol data unit) session is the carrier of the PDU service. The PDU connection service is a service for exchanging PDU data packets between the terminal device and the DN. The PDU connection service is implemented by the terminal device initiating the establishment of a PDU session. After the establishment of a PDU session, a data transmission channel between the terminal device and the DN is established.
[0167] In a mobile communication network, the terminal device requests the network side to establish a PDU session. According to different DN and slice information, multiple PDU sessions may need to be established. In the process of requesting the establishment of a PDU session, the terminal device randomly allocates a PDU session identity for the session. The PDU session identity is indicated by 8 bits (1 byte) 1, so there are at most 255 values, 00000001-00001111 (1-15) are 8 PDU session identity values that have been allocated, and the remaining values are reserved values. If the PDU session identity is allocated by the network side to a terminal device that does not support N1 mode, the PDU session identity with a value of 64-95 is reserved for this scenario. For the reserved PDU session identity, only the core network side can see it.
[0168] How the terminal device allocates the PDU session identity depends on the internal implementation of each manufacturer.
[0169] From the above, in the current hop-by-hop security protection scenario, that is, the user plane data is protected between the terminal device and the base station and between the base station and the user plane function, the user plane data appears in plaintext at the base station side in the process of secure transmission, and is vulnerable to near-end detection, physical attacks, and the like. Therefore, it is hoped that end-to-end security protection can be established between the terminal device and the user plane function, that is, the base station does not perform integrity verification and decryption on the user plane data, and can only forward the encrypted and integrity-protected data.
[0170] In the hop-by-hop security protection scenario, the user plane protection key is designed with the terminal device as the granularity. In a primary authentication period, the terminal device and the base station can maintain the count value of the counter input when the terminal device protects the user plane data, and the key stream output is not reused due to the different input count values in the case of the same user plane protection key input.
[0171] In the end-to-end security protection scenario, the security does not need to be terminated at the base station side, and therefore, the corresponding key does not need to be derived for the base station, but the security control of the terminal device and the user plane function needs to be focused on. However, because the user plane functions serving different sessions can be different, the terminal device and the user plane function cannot maintain the count value of the counter input when the user plane data is protected in the same way as the terminal device and the base station in the hop-by-hop security protection scenario, to ensure that the key stream output is not reused. Therefore, how to solve the user plane data security problem in the end-to-end security protection scenario between the terminal device and the user plane function is urgent.
[0172] To this end, an embodiment of the present application provides a communication method and device, which protects the user plane data by using the session-granularity key, so as to ensure that the key used by different sessions is not reused in a primary authentication period, and improve the security of user plane data transmission.
[0173] In order to better understand the embodiments of the present application, the following points are explained before the embodiments of the present application are introduced.
[0174] First, in the embodiments of the present application, “used for indicating” can include direct indication and indirect indication. When it is described that “indication information” is used for indicating A, it can include that the indication information directly indicates A or indirectly indicates A, and does not mean that A must be carried in the indication information.
[0175] The information indicated by the indication information is referred to as to-be-indicated information. In a specific implementation process, there are many ways to indicate the to-be-indicated information, for example, but not limited to, the to-be-indicated information can be directly indicated, such as the to-be-indicated information itself or an index of the to-be-indicated information. The to-be-indicated information can also be indirectly indicated by indicating other information, where the other information and the to-be-indicated information have an association relationship. The to-be-indicated information can also be only indicated in part, and the other part of the to-be-indicated information is known or agreed in advance. For example, the indication of specific information can also be achieved by means of the arrangement order of each information agreed in advance (for example, specified by a protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common part of each information can be identified and uniformly indicated, so as to reduce the indication overhead caused by separately indicating the same information.
[0176] In addition, the specific indication manner can also be various existing indication manners, for example, but not limited to, the above indication manners and various combinations thereof. The specific details of various indication manners can be referred to the prior art, which will not be described herein. As can be known from the above, for example, when multiple information of the same type needs to be indicated, the indication manners of different information can be different. In a specific implementation process, the required indication manner can be selected according to specific needs, and the selected indication manner is not limited by the embodiments of the present application. In this way, the indication manner involved in the embodiments of the present application should be understood as covering various methods that can enable the to-be-indicated party to know the to-be-indicated information.
[0177] The to-be-indicated information can be sent as a whole, or can be divided into multiple sub-information and sent separately, and the sending period and / or sending time of the sub-information can be the same or different. The specific sending method is not limited by the present application. The sending period and / or sending time of the sub-information can be predefined, for example, predefined according to a protocol, or configured by the transmitting end device by sending configuration information to the receiving end device.
[0178] Secondly, in the embodiments of the present application, the first, second and various numerical numbers are only for differentiation for convenience of description, and do not limit the scope of the embodiments of the present application. For example, different indication information is differentiated. For another example, the first indication information and the second indication information are only for differentiating different indication information, and the sequence thereof is not limited. Those skilled in the art can understand that the words "first", "second" and the like do not limit the number and execution sequence, and the words "first", "second" and the like do not necessarily mean different.
[0179] Third, in the embodiments of the present application, "when", "in the case of", "if" and the like all refer to the device making corresponding processing under certain objective circumstances, and are not limited in time, and do not require the device to have a judgment action when implemented, nor does it mean that there are other limitations.
[0180] Meanwhile, in the embodiments of the present application, "exemplary" or "for example" and the like are used to indicate an example, illustration or description. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the use of "exemplary" or "for example" and the like is intended to present the relevant concept in a specific manner for ease of understanding.
[0181] Finally, the network architecture and service scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that, as network architectures evolve and new service scenarios appear, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0182] Referring to FIG. 7, an architecture schematic diagram of a communication system provided by an embodiment of the present application is shown. As shown in FIG. 7, the communication system includes a first network element, a terminal device, and a session management network element. Optionally, the communication system can further include a user plane network element.
[0183] The first network element is configured to derive and generate a session-granularity key, which is used for security processing or security protection of data in a corresponding session. In the embodiments of the present application, the first network element usually refers to an access and mobility management network element or a security anchor network element. In some scenarios, the access and mobility management network element and the security anchor network element are co-located, or the security anchor network element is part of the access and mobility management network element, which is not limited. In some implementations, the first network element can also be an authentication service network element or a session management network element, which is not limited.
[0184] The access and mobility management network element is configured to implement access management and mobility management of the terminal device. For example, the access and mobility management network element is responsible for state maintenance of the terminal device, reachability management of the terminal device, forwarding of non-mobility management (MM) NAS messages, forwarding of session management (SM) N2 messages, and the like. The access and mobility management network element can be an AMF in the 5G mobile communication system shown in FIG. 1.
[0185] The security anchor network element is configured to initiate an authentication request to the authentication service network element, and to complete network-side authentication of the terminal device in an authentication process. The security anchor network element can be a security anchor function (SEAF) in a 5G mobile communication system.
[0186] The authentication service network element is configured to implement bidirectional authentication of the terminal device by authentication services and key generation, to support a unified authentication framework, and to perform security authentication of the terminal device. The authentication service network element can be an AUSF in the 5G mobile communication system shown in FIG. 1.
[0187] The session management network element is configured to implement session management of the terminal device, to allocate resources and release resources for a session of the terminal device. The resources include resource preset parameters QoS, a session path, a forwarding rule, and the like. The session management network element can be an SMF in the 5G mobile communication system shown in FIG. 1.
[0188] The user plane network element is configured to implement packet routing and forwarding, QoS processing of user plane data, and the like. The user plane network element can perform user data packet forwarding according to a routing rule of the session management network element, such as sending uplink data to a data network or another user plane network element, and forwarding downlink data to another user plane network element or a (R)AN. The user plane network element can be a UPF in the 5G mobile communication system shown in FIG. 1.
[0189] The terminal device is specifically described in the above description of the terminal device in the 5G mobile communication system, and thus is not described again here.
[0190] In the embodiments of the present application, the terminal device sends a first message to the first network element, the first message including a session establishment request and a session identifier corresponding to the session establishment request, so that the first network element and the terminal device can determine a first key used for security processing of data in a session corresponding to the session identifier according to the session identifier and a first value, the first value being a random value or a count value, which can be sent by the first network element to the session management network element, and then sent by the session management network element to the user plane network element. Thus, in an end-to-end security protection scenario after session establishment is completed, the terminal device and the user plane network element perform security processing of data in the session corresponding to the session identifier by using the first key, and the first key used for different sessions is different in one main authentication period, so that reuse of the first key can be avoided. The specific implementation can be understood by referring to the related description in the method embodiments below, and thus is not described again here.
[0191] It should be understood that the names of nodes, modules, devices or network elements in different scenarios or architectures or systems and the names of communication interfaces between nodes, modules, devices or network elements in the embodiments of the present application are exemplarily given, and the possibility of name changes in future communication systems or scenarios or architectures is not excluded.
[0192] The communication method provided by the embodiments of the present application will be described in detail below in conjunction with FIGS. 8-11.
[0193] Exemplarily, FIG. 8 is a flow diagram of a communication method provided by the embodiments of the present application, which is exemplarily described by taking the communication between the first network element, the terminal device and the session management network element shown in FIG. 7 as an example. Of course, the subject performing the action of the first network element in the method can also be a device / module in the first network element, such as a chip, a processor, a processing unit, etc. in the first network element, and the subject performing the action of the terminal device in the method can also be a device / module in the terminal device, such as a chip, a processor, a processing unit, etc. in the terminal device, and the subject performing the action of the session management network element in the method can also be a device / module in the session management network element, such as a chip, a processor, a processing unit, etc. in the session management network element, and the subjects are not limited in this regard.
[0194] As shown in FIG. 8, the communication method includes:
[0195] S801, the terminal device sends a first message to the first network element. Correspondingly, the first network element receives the first message from the terminal device.
[0196] In the embodiments of the present application, the first network element generally refers to an access and mobility management network element (such as AMF in 5G) or a security anchor point network element (such as SEAF in 5G), and the first message can be a NAS message. The first message includes a session establishment request and a session identifier corresponding to the session establishment request, the session establishment request is used to request to establish a session, and the session identifier corresponding to the session establishment request is an identifier allocated by the terminal device for the requested session, which is used to identify the requested session.
[0197] After completing the primary authentication process, the terminal device can send the session establishment request and the identifier of the requested session to the first network element through the first message each time the terminal device requests to establish a session within a primary authentication period. For example, the first message is a NAS message, the session establishment request is used to request to establish session #1, and the session identifier of session #1 is ID1. Therefore, the NAS message includes the session establishment request and ID1, and the session establishment request can be carried in the N1 SM container.
[0198] It should be understood that the primary authentication period can refer to the time between completing a primary authentication process for the terminal device and starting the next primary authentication process.
[0199] S802, the first network element sends a session establishment request, a session identifier and a first key to a session management network element. Correspondingly, the session management network element receives the session establishment request, the session identifier and the first key from the first network element.
[0200] The first key is used for security processing of data in a session corresponding to the session identifier, or in other words, the first key is used for security processing of data in a session requested to be established. The security processing includes, but is not limited to, encryption, decryption, integrity protection and integrity verification.
[0201] It should be understood that in the embodiments of the present application, the first key is used for security processing of data in a session for end-to-end transmission between a terminal device and a user plane network element, and therefore the first network element is the first key derived for a user plane network element for end-to-end transmission with the terminal device.
[0202] After receiving the first message, the first network element can first verify the legitimacy of the terminal device and whether the terminal device can initiate the session establishment request. If it is confirmed that the terminal device can initiate the session establishment request, the first network element can derive the first key for the session requested to be established by the current terminal device, so as to send the first key to the corresponding user plane network element through the session management network element, so that when performing end-to-end session transmission, the user plane network element can perform security processing on data in the corresponding session according to the first key.
[0203] For example, the session establishment request is used to request to establish session #1, the session identifier of session #1 is ID1, and the user plane network element can perform decryption and / or integrity verification on uplink data in session #1 from the terminal device according to the first key, or can perform encryption and / or integrity protection on downlink data in session #1 sent to the terminal device according to the first key.
[0204] Optionally, the user plane network element can further derive an encryption key and an integrity protection key according to the first key, which are respectively used for encryption / decryption and integrity protection / verification of data.
[0205] In the embodiments of the present application, the security processing can also be referred to as security protection, protection processing, etc., which is not limited in this regard.
[0206] The first key is determined according to the session identifier and the first value, and different session establishment requests correspond to different first values. In the embodiment of the application, different session establishment requests refer to session establishment requests initiated by the terminal device at different times, and there can be session establishment requests with the same session identifier in the session establishment requests sent at different times, that is, the session establishment requests initiated by the terminal device at different times can be used to request establishment of the same session, or there can be session establishment requests with different session identifiers, that is, the session establishment requests initiated by the terminal device at different times can be used to request establishment of different sessions, and this is not limited.
[0207] In other words, different session establishment requests corresponding to different first values can include: session establishment requests associated with different session identifiers corresponding to different first values, and session establishment requests associated with the same session identifier corresponding to different first values.
[0208] Therefore, for each session establishment request initiated by the terminal device, the first network element obtains the first value to generate the first key. The first network element takes the session identifier in the first message currently received and the first value obtained as input, and outputs the first key through a key derivation algorithm. Optionally, the input of the key derivation algorithm can also include the key of the first network element, which can be obtained in the process of primary authentication of the terminal device, and the key of the first network element is updated once for each primary authentication. Exemplarily, the first key is represented as K session , K session = KDF(K l , ID, θ i ), wherein K l is the key of the first network element, ID is the identifier (session identifier) of the session to be established corresponding to the first key, and θ i is the first value.
[0209] In one primary authentication period, that is, from the completion of primary authentication of the terminal device to the re-performing of primary authentication of the terminal device, for session establishment requests received at different times, the first network element assigns different first values to different sessions requested to be established at different times to generate different first keys, so that when the terminal device performs end-to-end user plane data transmission with different user plane network elements, even if there are session establishments with the same session identifier, the first key for security processing of user plane data can be ensured not to be reused, so that the security of end-to-end user plane data can be ensured. Or, the first network element at least ensures that different first values are assigned to session establishment requests with the same session identifier sent at different times.
[0210] That is, for each acquired session establishment request, the first network element acquires a first value different from a first value corresponding to a previously received session establishment request, regardless of whether the session currently requested to be established is the same as the session previously requested to be established, i.e., the session identifiers are the same. Or, for different session establishment requests of the same session identifier, the first network element acquires a first value different from a first value corresponding to a previously received session establishment request of the same identifier.
[0211] For example, the first network element receives a first message at time t1, the first message including a session establishment request #1 for requesting establishment of session #1 and a session identifier ID1 of session #1, and the first network element acquires a first value θ1 for the session establishment request #1. Then, after time t1, if the first network element receives a first message again, the first message including a session establishment request #2 for requesting establishment of session #2 and a session identifier ID2 of session #2, the first network element acquires a first value θ2 for the session establishment request #2, θ1≠θ2. Thus, the first key for performing security processing on session #1 requested by the session establishment request #1 can be KDF(K l ,ID1,θ1), and the first key for performing security processing on session #2 requested by the session establishment request #2 can be KDF(K l ,ID2,θ2).
[0212] In the embodiments of the present application, the first value can be a counting value or a random value. The following describes two cases of the first value being a counting value and the first value being a random value, respectively.
[0213] Case 1: The first value is a counting value.
[0214] The counting value can be obtained by counting by a counter (COUNT).
[0215] In a possible design 1, the counter can be a counter, e.g., a session counter (session COUNT), newly added or newly defined by the first network element for the terminal device when the initial primary authentication procedure for the terminal device is completed, and the counter is used to count the number of session establishment requests requested by the terminal device, i.e., the counting value is the number of session establishment requests requested by the terminal device (session COUNT value), and the counting value of the counter is stored in the context maintained for the terminal device. The initial counting value of the counter can be set to 0.
[0216] For change of the counting value:
[0217] In a possible implementation 1, when the first network element receives a session establishment request, the counting value of the first network element is incremented by 1.
[0218] In the primary authentication cycle, for example, the initial count value is 0, the first network element receives a first session establishment request, the count value changes from 0 to 1, and the first key is generated for the session requested by the first session establishment request using the count value 1. For another example, the first network element receives a second session establishment request, the count value changes from 1 to 2, and the first key is generated for the session requested by the second session establishment request using the count value 2. Similarly, the count value changes similarly for the subsequent received session establishment requests.
[0219] In a possible implementation 2, the first network element can add 1 to the count value after completing the generation or sending of the first key of the currently requested session, and the count value after the addition is the total number of the currently received session establishment requests, and the count value used by the first network element to generate the first key is the count value before the addition, that is, the total number of the last received session establishment requests.
[0220] In the primary authentication cycle, for example, the initial count value is 0, the first network element receives a first session establishment request, and the count value does not change from 0 to 1 due to the reception of the session establishment request, but the currently recorded count value is kept as 0. The first key is generated for the session requested by the first session establishment request using the count value 0, and the count value is added by 1, that is, changes from 0 to 1, after the generation or sending of the first key. For another example, the second network element receives a second session establishment request, and the count value does not change from 1 to 2 due to the reception of the session establishment request, but the currently recorded count value is kept as 1. The first key is generated for the session requested by the second session establishment request using the count value 1, and the count value is added by 1, that is, changes from 1 to 2, after the generation or sending of the first key. Similarly, the count value changes similarly for the subsequent received session establishment requests.
[0221] In a possible implementation 3, the first network element can also trigger the change of the count value according to a second message fed back by the session management network element, or after receiving the second message from the session management network element. The second message is used to indicate that the count value is added by 1, and the second message can be a message sent by the session management network element after performing the legality verification on the received session establishment request, session identifier, and first key, and selecting the user plane network element for establishing the requested session according to the obtained session related policy. Thus, the first network element receives the second message from the session management network element, and adds 1 to the count value according to the second message.
[0222] For example, the second message can be a session establishment accept message, or a message used to carry the session establishment accept message, such as a Namf_communication_N1N2messageTransfer request message, the Namf_communication_N1N2messageTransfer request message including the session establishment accept message, the session establishment accept message used to indicate that the current requested session establishment is accepted. That is, the first network element increments the count value by one according to the session establishment accept message after receiving the session establishment accept message, or the first network element increments the count value by one after completing the session establishment process.
[0223] At this time, the count value of the first key generated by the first network element is incremented by one according to the second message fed back by the session management network element for the previous session establishment request.
[0224] In the main authentication period, for example, the initial count value is 0, the first network element receives a first session establishment request, at this time, the first network element does not change the count value from 0 to 1 due to the reception of the session establishment request, but keeps the currently recorded count value as 0, generates a first key for the session requested by the first session establishment request using the count value 0, and then sends the first key, the session establishment request, and the session identifier to the session management network element, and changes the count value 0 to 1 according to the second message sent by the session management network element. For another example, the first network element receives a second session establishment request, at this time, the first network element also does not change the count value from 1 to 2 due to the reception of the session establishment request, but keeps the currently recorded count value as 1, generates a first key for the session requested by the second session establishment request using the count value 1, and then sends the first key, the session establishment request, and the session identifier to the session management network element, and changes the count value 1 to 2 according to the second message sent by the session management network element. Similarly, the count values corresponding to subsequent session establishment requests also change similarly.
[0225] In a possible design 2, the counter can be a NAS counter (NAS COUNT) that is reused by the first network element and is maintained by the first network element and the terminal device side. The NAS counter can be an uplink NAS counter or a downlink NAS counter. The uplink NAS counter is used to count the number of NAS messages sent by the terminal device to the network side or the number of NAS messages received by the network side and sent by the terminal device. The downlink NAS counter is used to count the number of NAS messages sent to the terminal device, that is, the count value is the number of NAS messages received by the terminal device or sent by the network side to the terminal device.
[0226] In this design, after the first network element derives or sends the first key for the current requested session, or the first network element obtains the second message from the session management network element, the first network element can also perform the increment operation on the count value of the NAS counter, which is not described herein.
[0227] In the above case 1 or case 2, if the count value of the first network element reaches the maximum value in one primary authentication cycle, the first network element can re-trigger the primary authentication for the terminal device, and after the primary authentication is completed, the count value is reset to zero. In a possible implementation, in the case where the count value reaches the maximum value, the first network element can send first indication information, and the first indication information is used to indicate that the primary authentication for the terminal device is re-performed, and after the primary authentication is completed, the first network element resets the count value to zero. For example, the first network element can send the first indication information to an authentication service network element (such as AUSF in 5G), so that the authentication service network element re-performs the primary authentication with the terminal device, and after the primary authentication is completed, the terminal device can perform the above steps in a new primary authentication cycle.
[0228] Case 2: the first value is a random value.
[0229] In a possible design 1, the random value can be randomly generated by the first network element. In this design, the first network element can randomly generate a random value for each received session establishment request, and if the randomly generated random value is the same as the random value randomly generated for any one of the previously received session establishment requests, the random value is re-generated until the generated random value is different from the random value randomly generated for any one of the previously received session establishment requests, and the first network element saves the correspondence between the session identifier and the random value of each received session establishment request. In some implementations, the first network element can also store the three-way correspondence between the identifier of the session establishment request, the session identifier, and the random value.
[0230] For example, the first network element receives a first message at time t1, the first message including a session establishment request #1 for requesting establishment of session #1 and a session identifier ID1 of session #1, and generates a random value R1 for the session #1 requested by the session establishment request #1 and stores the correspondence {ID1, R1}; the first network element receives a first message at time t2, the first message including a session establishment request #2 for requesting establishment of session #2 and a session identifier ID2 of session #2, and generates a random value R2 for the session #2 requested by the session establishment request #2 and stores the correspondence {ID2, R2}; the first network element receives a first message at time t3, the first message including a session establishment request #3 for requesting establishment of session #1 and a session identifier ID1 of session #1, and generates a random value R3 for the session #1 requested by the session establishment request #3 and stores the correspondence {ID1, R3}. The R1, R2 and R3 are all different.
[0231] Since the first network element can receive different session establishment requests with the same session identifier at different times, when receiving a session establishment request, the first network element can determine whether the session identifier of the session currently requested to be established has a corresponding random value stored according to the correspondence between the session identifier and the random number currently stored, if not, the first network element can directly select a random value for the session identifier, if yes, the first network element needs to ensure that the currently selected random value is different from the random value previously selected for the session identifier.
[0232] For example, the first network element receives a first message at time t1, the first message including a session establishment request #1 for requesting establishment of session #1 and a session identifier ID1 of session #1, and generates a random value R1 for the session #1 requested by the session establishment request #1 and stores the correspondence {ID1, R1}; the first network element receives a first message at time t2, the first message including a session establishment request #2 for requesting establishment of session #2 and a session identifier ID2 of session #2, and generates a random value R2 for the session #2 requested by the session establishment request #2 and stores the correspondence {ID2, R2}; the first network element receives a first message at time t3, the first message including a session establishment request #3 for requesting establishment of session #1 and a session identifier ID1 of session #1, and the first network element can determine that the session identifier ID1 has been assigned a random value R1 according to the {IDx, Rx} stored, and thus the first network element currently needs to generate a random value different from R1 for the session identifier ID1, such as generating a random value R3, and stores the correspondence {ID1, R3}. The R1, R2 and R3 are all different.
[0233] In the design 1, the first network element generates a random value, or generates a first key according to the random value, or after receiving the session establishment acceptance request, the first network element can further send the random value to the terminal device, so that the terminal device uses the same random value to derive the same first key as the first network element side. Optionally, in the case that the first network element sends the random value to the terminal device after receiving the session establishment acceptance request, the random value can be carried in the session establishment acceptance message sent by the first network element to the terminal device.
[0234] In a possible design 2, the random value can be locally generated by the terminal device and sent to the first network element. In this design, the terminal device can generate a random value for the session to be established when preparing to initiate the session establishment request, and ensure that the generated random value is different from the random value of the previously requested session establishment. If the same, the random value is re-generated until the generated random value is different from the random value generated by the previously requested session establishment. The terminal device saves the correspondence between the session identifier and the random value of each requested session establishment, and sends the random value corresponding to the current requested session establishment to the first network element, so that the first network element can generate a first key for the current requested session establishment according to the received random value from the terminal device. It should be understood that the way the terminal device locally generates the random value is similar to the way the first network element locally generates the random value, which will not be described here.
[0235] Optionally, the random value can be carried in the first message, that is, the terminal device can carry the random value in the first message and send it to the first network element together with the session establishment request.
[0236] In this case 2, after the terminal device is subjected to primary authentication, the first network element and the terminal device can clear all stored random values and the corresponding relationship of the corresponding session identifiers.
[0237] Therefore, after generating the first key, the first network element can send the received session establishment request, session identifier and the first key generated for the session to be established to the session management network element.
[0238] Optionally, the session establishment request, session identifier and first key can be sent in the same message, or can be partially sent in the same message and partially sent in another message, which is not limited.
[0239] In some possible implementations, after obtaining the first message, the first network element can first send the session establishment request and the session identifier to the session management network element. After the session management network element verifies the legality of the session, the first network element generates the first key based on the trigger of the session management network element and the first value and the session identifier, and then sends the first key to the session management network element, which is not limited here.
[0240] S803, the session management network element sends the session identifier and the first key to the user plane network element. Correspondingly, the user plane network element receives the session identifier and the first key from the session management network element.
[0241] After the session management network element receives the session establishment request, the session identifier and the first key, the session management network element can select a suitable user plane network element that can be used to establish the session according to the session-related policy, for example, a user plane network element with lower load, a user plane network element close to the access network device, and the like, and send the session identifier and the first key of the session to be established to the user plane network element, so that the user plane network element can obtain the first key and the session identifier of the session corresponding to the first key.
[0242] For example, the session identifier and the first key can be carried in the N4 session establishment request and sent.
[0243] In a possible design, after the user plane network element obtains the first key, the user plane network element can further derive the corresponding encryption key and integrity protection key based on the first key. The input parameters of the key derivation include the first key, the algorithm identifier of the encryption or integrity protection algorithm, the distinguisher corresponding to the encryption or integrity protection, the length of the corresponding parameter, and the like. For details, refer to the derivation of the encryption key and the integrity protection key in the above-mentioned related technology 2, which will not be described herein. UP
[0244] Further, in the case where the first value is a count value, the session management network element can send a second message to the first network element, the second message being used to indicate that the count value is incremented by one. Alternatively, in the case where the first value is a random value and the random value is generated by the first network element, the session management network element can send a third message to the first network element, the third message being used to indicate that the random value is sent to the terminal device.
[0245] Optionally, the second message and the third message can be a session establishment acceptance message, or a message used to carry the session establishment acceptance message, such as an N1N2 message transfer request (Namf_commination_N1N2messageTransfer request) message. The N1N2 message transfer request message includes the session establishment acceptance message, and the session establishment acceptance message is used to indicate that the current requested session establishment is accepted.
[0246] S804, the terminal device determines the first key according to the session identifier and the first value.
[0247] Since the first key is a key used for security processing of end-to-end user plane data between the terminal device and the user plane network element, after sending the first message, the terminal device also derives the same first key as the network side using the same derivation algorithm and parameters as the first network element side for the current initiated session establishment request. Thus, the terminal device can use the first key to decrypt and / or integrity check the downlink data in the session from the user plane network element, or can use the first key to encrypt and / or integrity protect the uplink data in the session sent to the user plane network element.
[0248] The terminal device derives the first key using the first key and the session identifier, which is similar to the first network element, and specific details can be referred to the above description of the first network element deriving the first key in S802, which will not be repeated here.
[0249] For the design 1 of the above case 1, when the first value is a count value, the terminal device can also synchronously add or newly define a same counter for counting the number of session establishment requests requested by the terminal device, generate different count values for each session establishment request requested by the terminal device, and generate the context corresponding to the counter, and the initial count value in the context is also set to 0.
[0250] For the transformation of the count value, there can be two implementations as follows:
[0251] In one possible implementation 1, when the terminal device sends the first session establishment request, the count value on the terminal device side is incremented by 1.
[0252] In the main authentication period, for example, the initial count value is 0, the terminal device sends the first session establishment request, and the count value is changed from 0 to 1, at which time the count value 1 is used to generate the first key for the session requested by the first session establishment request. For another example, the terminal device sends the second session establishment request, and the count value is changed from 1 to 2, at which time the count value 2 is used to generate the first key for the session requested by the second session establishment request. Similarly, the count value corresponding to the subsequent session establishment request is also changed.
[0253] The count value change on the terminal device side based on the implementation 1 can be matched with the count value change on the first network element side based on the implementation 1, so that the count value changes on the terminal device and the first network element side are consistent, and thus the same count value is used on both sides to generate the same first key for the currently requested session.
[0254] In one possible implementation 2, the terminal device can also increment the count value by 1 after completing the generation of the first key or receiving the session establishment acceptance message, and the count value after the increment is the number of session establishment requests that have been sent, and the count value used by the terminal device to generate the first key is the count value before the increment.
[0255] In the main authentication cycle, for example, the initial count value is 0, the terminal device sends the first session establishment request, at this time, the terminal device does not change the count value from 0 to 1 due to sending the session establishment request, but keeps the currently recorded count value as 0, and uses the count value 0 to generate the first key for the session requested by the first session establishment request, and the first network element increments the count value by one, i.e., from 0 to 1, after generating the first key. For another example, the terminal device sends the second session establishment request, at this time, the terminal device also does not change the count value from 1 to 2 due to sending the session establishment request, but keeps the currently recorded count value as 1, and uses the count value 1 to generate the first key for the session requested by the second session establishment request, and the terminal device increments the count value by one, i.e., from 1 to 2, after generating the first key. Similarly, the count value corresponding to the subsequent session establishment request also changes similarly.
[0256] The count value change on the terminal device side based on implementation 2 can be matched with the count value change on the first network element side based on implementation 2 or implementation 3, so that the count value changes on the terminal device and the first network element side are consistent, and the same count value is used on both sides to generate the same first key for the currently requested session.
[0257] For the design 2 of the above case 1, correspondingly, the terminal device also reuses the NAS counter corresponding to the first network element to generate different count values for different session establishment requests.
[0258] It should be understood that, to ensure that the count values for generating the first key for the same requested session on the first network element and the terminal device side are consistent, if the first network element uses the uplink NAS counter, the terminal device uses the uplink NAS counter; if the first network element uses the downlink NAS counter, the terminal device uses the downlink NAS counter.
[0259] In this design, after the terminal device also derives the first key for the currently requested session, or after the terminal device sends the session establishment request, the count value of the NAS counter can also be incremented by one, which is not described herein.
[0260] Similarly to the first network element, in one main authentication cycle, if the count value of the terminal device reaches the maximum value, the terminal device can perform re-main authentication, and after the main authentication is completed, the count value is reset to zero or zero.
[0261] For the design 1 of the above case 2, the terminal device can receive a random value from the first network element, which is a random value generated by the first network element for the session currently requested by the terminal device to establish. Therefore, the terminal device can generate the first key according to the received random value and the session identifier of the requested session to establish.
[0262] In this design, the terminal device can start derivation of the first key after obtaining the random value.
[0263] For the design 2 of the case 2, the terminal device locally generates a random value for the session currently requested to be established, and then the terminal device can directly start derivation of the first key according to the session identifier of the session requested to be established and the random value, or start derivation of the first key after receiving the session establishment accept message. In this design, the terminal device can send the random value to the first network element, so that the first network element generates the same first key as the terminal device side for the session currently requested to be established based on the same random value. For details, refer to the description of the first network element receiving the random value above, which is not repeated here.
[0264] In a possible implementation, after obtaining the first key, the terminal device can further derive a corresponding encryption key and integrity protection key based on the first key. The input parameters for key derivation include the first key, an algorithm identifier of the encryption or integrity protection algorithm, a distinguisher corresponding to encryption or integrity protection, lengths of corresponding parameters, and the like. For details, refer to the derivation of the encryption key and the integrity protection key in the related technology 2 above, which is not repeated here. UP
[0265] Therefore, the terminal device can generate a first key for each session corresponding to a session establishment request initiated by the terminal device. Correspondingly, the first network element also generates a same first key as the terminal device side for each session corresponding to a received session establishment request, and sends the first key to the corresponding user plane network element.
[0266] Further, when the terminal device and the user plane network element perform transmission of a session requested by a session establishment request, in the scenario of uplink transmission, the terminal device can use the first key corresponding to the session establishment request to encrypt and / or integrity protect data in the session requested by the session establishment request. Correspondingly, the user plane network element can use the corresponding first key to decrypt and / or integrity verify the data in the session requested by the session establishment request. In the scenario of downlink transmission, the user plane network element can use the first key corresponding to the session establishment request to encrypt and / or integrity protect data in the session requested by the session establishment request. Correspondingly, the terminal device can use the corresponding first key to decrypt and / or integrity verify the data in the session requested by the session establishment request.
[0267] In the communication method shown in FIG. 8, the first network element can generate the first key by using the first value and the session identifier of the session to be established for each session establishment request initiated by the terminal device, and send the first key to the corresponding user plane network element. Correspondingly, the terminal device also generates the same first key as the first network element side for each session establishment request initiated by the terminal device. The first key is used for security protection of data in the session to be established or the session corresponding to the session identifier. Each session establishment request is assigned a different first value, which can be assigned by the first network element or the terminal device. In this way, the generated first key is different regardless of whether the terminal device sends multiple session establishment requests with the same session identifier. When the terminal device and the user plane network element perform end-to-end security protection, the terminal device and different user plane network elements perform end-to-end user plane data transmission. Even if there are session establishments with the same session identifier, the first key for security processing of the user plane data can be ensured not to be reused, thereby ensuring the security of the user plane data between the end-to-end.
[0268] In the embodiments of the present application, the first key for security protection of the user plane data between the end-to-end is mainly generated in the granularity of the session. In addition, the key of the QoS flow corresponding to the specific session can also be derived. In this case, since the identifier of the QoS flow can be reused, if the session key does not add the COUNT value, the corresponding COUNT value, such as the NAS COUNT value or the independently maintained COUNT value, needs to be added when the key of the QoS flow is derived. Details are not described herein.
[0269] In addition, in the case where the first network element is an authentication service network element, after the terminal device sends the first message, the access and mobility management network element can forward the first message to the authentication service network element. The authentication service network element generates the first key according to the session identifier and the first value, and sends the generated first key to the access and mobility management network element. Then, the access and mobility management network element sends the first key, the session establishment request and the session identifier to the session management network element.
[0270] The communication method shown in FIG. 8 will be described in detail below in combination with the 5G communication system shown in FIG. 1. In the communication method, the terminal device is a UE, the first network element is an AMF, the session management network element is an SMF, the user plane network element is a UPF, and the first key is a K session The session is a PDU session.
[0271] It should be understood that the names of the above-mentioned network elements or devices can change in future communication systems, and are not limited.
[0272] For example, FIG. 9 is a flowchart of a communication method provided by an embodiment of the present application, taking a first value as a COUNT value. As shown in FIG. 9, the communication method includes:
[0273] S901, the UE sends a registration request to the AMF. Correspondingly, the AMF receives the registration request from the UE.
[0274] The registration request carries a user concealed identifier (SUCI) of the UE.
[0275] S902, the AMF sends an authentication request to the UDM. Correspondingly, the UDM receives the authentication request from the AMF.
[0276] S903, the UDM obtains the SUPI according to the SUCI.
[0277] The authentication request can carry the above-mentioned SUCI. If the authentication request carries the SUCI, the corresponding SUPI is obtained by decrypting the SUCI through the UDM and sent to the AUSF.
[0278] S904, the UDM sends the SUPI to the AUSF. Correspondingly, the AUSF receives the SUPI from the UDM.
[0279] The specific implementation of the registration process of S901-S904 can be referred to the related description in the implementation process of UE registration defined in 3GPP TS 23.501, which will not be described here.
[0280] S905, the AUSF and the UE perform a primary authentication process.
[0281] In the primary authentication process, K AMF At the same time, the AMF adds a session COUNT value in the context maintained for the UE, which is used to count the number of PDU session establishment requests requested by the UE, and the initial value is 0. Correspondingly, the UE side also generates a session COUNT context, and sets the session COUNT value of the context to 0. Alternatively, the AMF and the UE can also use a commonly maintained NAS COUNT value. The following takes the uplink NAS COUNT value as an example. For the UE, the uplink NAS COUNT value is the number of NAS messages sent by the UE. For the AMF, the uplink NAS COUNT value is the number of NAS messages received from the UE.
[0282] The specific implementation of the primary authentication process between the AUSF and the UE can be referred to the related description in the implementation process of UE primary authentication defined in 3GPP TS 33.501, which will not be described here.
[0283] S906, the UE sends a NAS message to the AMF. Correspondingly, the AMF receives the NAS message from the UE.
[0284] The NAS message can correspond to the first message, and the NAS message carries a PDU session identifier ID1 and an N1 SM container. The N1 SM container includes a PDU session establishment request, and the PDU session establishment request is used to request establishment of a PDU session with the PDU session identifier ID1.
[0285] It should be understood that the PDU session establishment request message can also include information such as a requested PDU session type, a requested session and service continuity (SSC) mode, and the like.
[0286] S907, the AMF determines K AMF based on ID1, a COUNT1 value, and K session .
[0287] In the case of a new session COUNT value, COUNT1 is a value counted by the AMF for the PDU session establishment request received from the UE, and is used to generate K session for the PDU session requested by the currently received PDU session establishment request.
[0288] If the PDU session establishment request in the first message is the first PDU session establishment request sent by the UE after the completion of the primary authentication, the COUNT1 value used to determine K session may be 0 or 1. The AMF can input K AMF , the current PDU session identifier ID1, and the COUNT value 0 into a key derivation algorithm to obtain K session , for example, K session = KDF(K AMF , ID1, 0 / 1).
[0289] If the PDU session establishment request in the first message is the Nth (N≠1) PDU session establishment request sent by the UE after the completion of the primary authentication, the COUNT1 value used to determine K session may be N-1 or N. The AMF can input K AMF , the current PDU session identifier ID1, and the COUNT value N-1 / N into a key derivation algorithm to obtain K session , for example, Ksession = KDF(K AMF , ID1, N-1 / N).
[0290] It should be understood that, in the case of the count value being 1 or N, the AMF performs the key derivation after receiving the PDU session establishment request and then adds 1 to the count value; and in the case of the count value being 0 or N-1, the AMF performs the key derivation first and then adds 1 to the count value after receiving the PDU session establishment request.
[0291] In the case of the count value being a NAS count value (NAS COUNT value), COUNT1 is obtained by the AMF counting a NAS message received from the UE, and is used to generate K session for the PDU session requested by the currently received PDU session establishment request. session The NAS COUNT value can be the number of uplink NAS messages counted until the PDU session establishment request is received, and can or can not include the NAS message carried by the PDU session establishment request, which is not limited.
[0292] S908, the AMF sends a PDU session creation session management context request (Nsmf_PDUSession_CreateSMContext request) message to the SMF. Correspondingly, the SMF receives the PDU session creation session management context request message from the AMF.
[0293] The PDU session creation session management context request message includes the PDU session establishment request, the PDU session identifier ID1, and K session .
[0294] It should be understood that the PDU session creation session management context request message can also include a radio access technology (RAT) type, a data network name, slice information, and the like. The RAT type is used to indicate the wireless technology by which the UE accesses the CN.
[0295] S909, the SMF selects a UPF.
[0296] After receiving the PDU session creation session management context request, the SMF can perform the authentication / authorization process of the PDU session, and after completion, can select a UPF suitable for the current session, such as a UPF with low load, a UPF close to the RAN device, and the like.
[0297] S910, the SMF sends an N4 session establishment request message to the UPF. Correspondingly, the UPF receives the N4 session establishment request message from the SMF.
[0298] The N4 session establishment request message includes the PDU session identity ID1 and K session .
[0299] It should be understood that the N4 session establishment request message can further include an N4 session identity and a packet detection rule. The packet detection rule is used to instruct the UPF to perform corresponding processing, such as quality of service guarantee, etc., on data packets that meet the packet detection rule.
[0300] It should be understood that after receiving the N4 session establishment request message, the UPF can further send an N4 session establishment response message to the SMF, and correspondingly, the SMF receives the N4 session establishment response message from the UPF (not reflected in FIG. 9). The N4 session establishment response message can include CN tunnel information of the N4 session, which is used for the RAN device to find the UPF.
[0301] S911, the SMF sends a communication N1N2 message transfer request message to the AMF. Correspondingly, the AMF receives the communication N1N2 message transfer request message from the SMF.
[0302] The communication N1N2 message transfer request message includes a PDU session establishment accept message, which can correspond to the second message or the third message described above.
[0303] It should be understood that the embodiments of the present application do not limit the execution order of S910 and S911.
[0304] S912, the AMF increments the count value by one.
[0305] In the case that the count value is a newly added session count value (session COUNT value) and the AMF uses the count value COUNT1 as 0 or N-1, the K session The count value used is 0 or N-1, and the AMF can increment the count value by one according to the received PDU session establishment accept message, that is, the count value changes from 0 to 1 or from N-1 to N.
[0306] S913, the AMF sends an AN-specific resource setup message to the UE. Correspondingly, the UE receives the AN-specific resource setup message from the AMF.
[0307] The AN-specific resource setup message includes the PDU session setup accept message.
[0308] S914, the UE determines K AMF based on ID1, COUNT1 and K session .
[0309] In the case that the COUNT value is a newly added session COUNT value, corresponding to S907, if the PDU session establishment request in the first message is the first PDU session establishment request sent by the UE after the completion of primary authentication, the COUNT value COUNT1 used to determine K session may be 0 or 1. The UE can input K AMF , the current PDU session identifier ID1 and the COUNT value 0 into a key derivation algorithm to obtain K session , for example, K session = KDF(K AMF , ID1, 0 / 1).
[0310] If the PDU session establishment request in the first message is the Nth (N≠1) PDU session establishment request sent by the UE after the completion of primary authentication, the COUNT value used to determine K session may be N-1 or N. The UE can input K AMF , the current PDU session identifier ID1 and the COUNT value N-1 / N into a key derivation algorithm to obtain K session , for example, K session = KDF(K AMF , ID1, N-1 / N).
[0311] In the case that the COUNT value is 1 or N, the UE first increments the COUNT value by 1 after sending the PDU session establishment request and then performs key derivation. In the case that the COUNT value is 0 or N-1, the UE first performs key derivation after sending the PDU session establishment request and then increments the COUNT value by 1.
[0312] In the case that the COUNT value is a NAS COUNT value, COUNT1 is obtained by the UE counting the NAS messages sent by the UE, and is used to generate K session, the UE can add one to the NAS COUNT value for each NAS message sent by the UE, to generate K for the PDU session requested by the UE for the current sent PDU session establishment request session The NAS COUNT value can be the number of uplink NAS messages counted until the PDU session establishment request is sent, and can or can not include the NAS message carried by the PDU session establishment request, which is not limited.
[0313] S915, the UE adds one to the count value.
[0314] In the case of a new session count value (session COUNT value), the UE uses the count value of 0 or N-1, that is, generates the above K session The count value used is 0 or N-1, and the UE completes the K session derivation, and then adds one to the count value, that is, the count value changes from 0 to 1 or from N-1 to N.
[0315] It should be understood that in the case of a NAS count value (NAS COUNT value), the UE can add one to the count value before or after sending the PDU session establishment request, and accordingly, the AMF can also add one to the count value after receiving the NAS message carrying the PDU session establishment request or sending the K session , which is not limited.
[0316] In the case that the count value of the AMF reaches the maximum value, the AMF can also perform the following S916:
[0317] S916, the AMF sends first indication information to the AUSF. Correspondingly, the AUSF receives the first indication information from the AMF.
[0318] The first indication information is used to indicate that the UE is re-performed primary authentication, and the first indication information can include the SUPI of the UE.
[0319] S917, the AUSF re-performs primary authentication with the UE.
[0320] After the primary authentication is completed, the count values of the UE and the SMF side are both set to zero, and the K AMF is also updated.
[0321] For the next PDU session establishment request initiated by the UE, by adding one to the count value, it can be ensured that the AMF and the UE use different count values to generate different K session for different PDU sessions. Thus, by assigning different count values to each session, key reuse of different sessions of the same UE is prevented.
[0322] As another example, FIG. 10 is a flow diagram illustrating a communication method provided by the embodiments of the present application, taking the case that the first value is a random value and the random value is generated by the AMF as an example. As shown in FIG. 10, the communication method comprises the following steps:
[0323] S1001, the UE sends a registration request to the AMF. Correspondingly, the AMF receives the registration request from the UE.
[0324] S1002, the AMF sends an authentication request to the UDM. Correspondingly, the UDM receives the authentication request from the AMF.
[0325] S1003, the UDM obtains the SUPI according to the SUCI.
[0326] S1004, the UDM sends the SUPI to the AUSF. Correspondingly, the AUSF receives the SUPI from the UDM.
[0327] The specific description of the registration procedure of S1001-S1004 can be referred to the related description in S901-S904 described above, and will not be repeated here.
[0328] S1005, the AUSF and the UE perform a primary authentication procedure.
[0329] In the primary authentication procedure, K AMF will be generated, and the UE and the AMF will clear all the stored random values. The specific description of the primary authentication procedure between the AUSF and the UE can be referred to the related description in S904 described above, and will not be repeated here.
[0330] S1006, the UE sends a NAS message to the AMF. Correspondingly, the AMF receives the NAS message from the UE.
[0331] The specific description of S1006 can be referred to the related description in S906 described above, and will not be repeated here.
[0332] S1007, the AMF determines K AMF according to ID1, the random value R1 and K session .
[0333] The random value R1 is used for the AMF to generate K sessionAMF stores the correspondence between ID1 and R1 after generating R1 randomly. The AMF needs to ensure that the generated R1 is different from the random value generated for the PDU session requested by the PDU session establishment request received before the main authentication is completed. Alternatively, the AMF needs to check whether the PDU session ID selected this time has been used after the main authentication, and if it has been used, ensure that the random value R1 generated this time is different from the random value R1' corresponding to the PDU session ID used last time.
[0334] In this way, the AMF can obtain K AMF , the current PDU session ID ID1, and the random value R1 as inputs, and input them into a key derivation algorithm to obtain K session , for example, K session = KDF(K AMF , ID1, R1).
[0335] S1008, the AMF sends a PDU session creation session management context request (Nsmf_PDUSession_CreateSMContext request) message to the SMF. Correspondingly, the SMF receives the PDU session creation session management context request message from the AMF.
[0336] S1009, the SMF selects a UPF.
[0337] S1010, the SMF sends an N4 session establishment request (N4 session establishment request) message to the UPF. Correspondingly, the UPF receives the N4 session establishment request message from the SMF.
[0338] S1011, the SMF sends a communication N1N2 message transfer request (Namf_commination_N1N2messageTransfer request) message to the AMF. Correspondingly, the AMF receives the communication N1N2 message transfer request message from the SMF.
[0339] The specific implementation process of S1008-S1011 can be referred to the related description of S908-S911 described above, and will not be described here.
[0340] S1012, the AMF sends an AN-specific resource setup message to the UE. Correspondingly, the UE receives the AN-specific resource setup message from the AMF.
[0341] The AN-specific resource setup message includes a PDU session establishment acceptance message and the random value R1 described above.
[0342] S1013, the UE derives K according to ID1, random value R1 and K AMF derives K session .
[0343] The UE can derive K according to the random value R1 in the specific resource establishment message, input ID1, random value R1 and K AMF in the input key derivation algorithm session , for example, K session = KDF(K AMF , ID1, R1). Thus, the UE and the AMF side can generate the key K session for data security processing for the session identified by ID1.
[0344] For the next PDU session establishment request initiated by the UE, the AMF can generate a different random value from the session previously requested to establish, generate K session used by the session currently requested to establish, and execute the above steps again. Thus, when deriving the key for the PDU session, the random value is randomly selected as the input parameter, ensuring that the PDU session ID is not only used as the derivation parameter, and then the random number is sent to the UE in the PDU session acceptance message to ensure that the session key is not repeated.
[0345] Another example, FIG. 11 is a flow diagram of a communication method provided by an embodiment of the application, taking the first value as the random value and the random value as an example generated by the UE. As shown in FIG. 11, the communication method comprises:
[0346] S1101, the UE sends a registration request to the AMF. Correspondingly, the AMF receives the registration request from the UE.
[0347] S1102, the AMF sends a registration request to the UDM. Correspondingly, the UDM receives the registration request from the AMF.
[0348] S1103, the UDM obtains SUPI according to SUCI.
[0349] S1104, the UDM sends SUPI to the AUSF. Correspondingly, the AUSF receives the SUPI from the UDM.
[0350] The specific description of the registration process of S1101-S1104 can be referred to the related description in S901-S904 described above, which will not be repeated here.
[0351] S1105, the AUSF and the UE perform a primary authentication process.
[0352] In the primary authentication process, K AMF, the UE and the AMF will clear all the random values stored by them. The specific description of the primary authentication procedure between the AUSF and the UE can refer to the description in S904 above, and will not be described here.
[0353] S1106, the UE sends a NAS message to the AMF. Correspondingly, the AMF receives the NAS message from the UE.
[0354] The NAS message includes a PDU session establishment request, a PDU session identifier ID1, and a random value R1. That is, when the UE initiates a request to establish a PDU session with the PDU session identifier ID1, the UE can randomly generate a random value R1 for the requested session, and save the correspondence between ID1 and R1. At the same time, the UE needs to ensure that the generated R1 is different from the random value generated for the PDU session requested by the PDU session establishment request sent before the primary authentication is completed. Alternatively, the UE needs to check whether the PDU session ID selected this time has been used after the primary authentication, and if it has been used, the UE needs to ensure that the random value R1 generated this time is different from the random value R1' corresponding to the PDU session ID used last time.
[0355] S1107, the AMF determines K AMF based on ID1, the random value R1, and K session .
[0356] The AMF can input the obtained K AMF , the current PDU session identifier ID1, and the random value R1 as inputs, and input the key derivation algorithm to obtain K session , for example, K session = KDF(K AMF , ID1, R1).
[0357] S1108, the AMF sends a PDU session creation session management context request (Nsmf_PDUSession_CreateSMContext request) message to the SMF. Correspondingly, the SMF receives the PDU session creation session management context request message from the AMF.
[0358] S1109, the SMF selects a UPF.
[0359] S1110, the SMF sends an N4 session establishment request message to the UPF. Correspondingly, the UPF receives the N4 session establishment request message from the SMF.
[0360] S1111, the SMF sends a communication N1N2 message transfer request (Namf_commination_N1N2messageTransfer request) message to the AMF. Correspondingly, the AMF receives the communication N1N2 message transfer request message from the SMF.
[0361] The specific implementation process of S1108-S1111 can be referred to the related description of S908-S911, and details are not described herein.
[0362] S1112, the AMF sends an AN-specific resource setup message to the UE. Correspondingly, the UE receives the AN-specific resource setup message from the AMF.
[0363] The AN-specific resource setup message includes a PDU session setup accept message.
[0364] S1113, the UE determines K AMF according to ID1, a random value R1, and K session .
[0365] The UE can input ID1, the random value R1, and K AMF as input parameters into a key derivation algorithm to obtain K session , for example, K session = KDF(K AMF , ID1, R1). Thus, the UE and the AMF side can generate a key K session for data security processing for the session identified by ID1.
[0366] It should be understood that the embodiments of the present application do not limit the execution order of S1113 and S1106. For example, S1113 can be executed after S1106, or can be executed after S1112, and the present application is not limited in this regard.
[0367] For the next PDU session establishment request initiated by the UE, the UE can generate a random value different from the random value used for the session previously requested to be established, generate K session used for the session currently requested to be established, and execute the above steps again. Thus, when deriving the key for the PDU session, the UE side generates a random number, which is directly sent to the network side when sending the PDU session establishment request, and the network side does not need to maintain the corresponding random value state. The random value is randomly selected as an input parameter, which ensures that the PDU session ID is not used as the derivation parameter, thereby ensuring that the session key is not repeated.
[0368] In any of the implementations of FIGS. 9-11, in the implementation, after receiving the PDU session establishment request, the AMF can not derive the first key first, but send the PDU session establishment request to the SMF, and after the SMF determines that the PDU session can be established, the AMF can derive the key according to the request of the SMF and send the first key to the SMF. For example, the AMF sends the PDU session establishment request and the PDU session identifier to the SMF, and correspondingly, after the SMF receives the PDU session establishment request and the PDU session identifier, it can determine whether to establish the PDU session, and if so, send a message (such as a PDU session establishment acceptance message) to the AMF to request the first key, so that the AMF can derive the first key according to the message and send the first key to the SMF, and further, the first key is sent to the UPF by the SMF.
[0369] Alternatively, after the SMF determines that the PDU session can be established according to the received PDU session establishment request and PDU session identifier, and completes the N4 session establishment with the UPF, the SMF requests the first key from the AMF triggered by the UPF, so that the AMF can derive the first key according to the message and send the first key to the SMF, and then the SMF sends the first key to the UPF. For example, after the UPF and the SMF complete the N4 session establishment, the UPF can request the first key from the SMF, so that the SMF requests the first key from the AMF according to the request of the UPF, to trigger the AMF to derive the first key and feed back the first key to the SMF, and then the SMF feeds back the first key to the UPF.
[0370] Alternatively, after the UPF and the SMF complete the N4 session establishment, the UPF can directly request the first key from the AMF, so that the AMF can trigger the derivation of the first key according to the request of the UPF and send the first key to the UPF.
[0371] The embodiments of the present application do not limit the way in which the UPF or the SMF obtains the first key.
[0372] In the above embodiments, the methods and / or steps implemented by the first network element can also be implemented by components (such as processors, chips, chip systems, circuits, logic modules, or software) available to the first network element; the methods and / or steps implemented by the terminal device can also be implemented by components (such as processors, chips, chip systems, circuits, logic modules, or software) available to the terminal device; and the methods and / or steps implemented by the session management network element can also be implemented by components (such as processors, chips, chip systems, circuits, logic modules, or software) available to the session management network element.
[0373] The above mainly introduces the schemes provided in the application. Correspondingly, the application further provides a communication apparatus, which is used to implement various methods in the above method embodiments. The communication apparatus can be the first network element in the above method embodiments, or an apparatus containing the first network element, or a component (for example, a chip or a chip system) that can be used for the first network element. Alternatively, the communication apparatus can be a terminal device in the above method embodiments, or an apparatus containing the terminal device, or a component (for example, a chip or a chip system) that can be used for the terminal device. Alternatively, the communication apparatus can be a session management network element in the above method embodiments, or an apparatus containing the session management network element, or a component (for example, a chip or a chip system) that can be used for the session management network element.
[0374] In some embodiments, the communication apparatus contains hardware structures and / or software modules corresponding to various functions in order to implement the above functions. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of the examples described in combination with the embodiments disclosed in the present application, the application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is implemented in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0375] The embodiments of the present application can divide the functions of the communication apparatus according to the above method embodiments, for example, each function module can be divided according to each function, or two or more functions can be integrated into one processing module. The integrated module can be implemented in the form of hardware or software function module. It should be noted that the division of the modules in the embodiments of the present application is illustrative, and is only a logical function division. There can be another division manner when actually implemented.
[0376] Taking the communication apparatus as the first network element or the terminal device or the session management network element in the above method embodiments for example, FIG. 12 is a structure schematic diagram of a communication apparatus provided in an embodiment of the present application. As shown in FIG. 12, the communication apparatus 1200 includes a processing module 1201 and a transceiver module 1202. The processing module 1201 is used to perform the processing functions of the first network element or the terminal device or the session management network element in the above method embodiments. The transceiver module 1202 is used to perform the communication functions of the first network element or the terminal device or the session management network element in the above method embodiments.
[0377] Wherein, all related contents of each step involved in the above method embodiments can be cited to the function description of the corresponding function module, which will not be repeated here.
[0378] In a possible design, the transceiver module 1202 can include a receiving module and a sending module (not shown in FIG. 12). The sending module and the receiving module are respectively used to implement the sending function and the receiving function of the communication apparatus 1200.
[0379] In a possible design, the communication apparatus 1200 can further include a storage module (not shown in FIG. 12), which stores programs or instructions. When the processing module 1201 executes the programs or instructions, the communication apparatus 1200 can perform the function of the first network element or the terminal device or the session management network element in any of the methods shown in FIGS. 8-11.
[0380] In some embodiments, the processing module 1201 involved in the communication apparatus 1200 can be implemented by a processor or a processor-related circuit component, and can be a processor or a processing unit; and the transceiver module 1202 can be implemented by a transceiver or a transceiver-related circuit component, and can be a transceiver or a transceiving unit.
[0381] For example, FIG. 13 is a structural schematic diagram of another communication apparatus provided by an embodiment of the present application. The communication apparatus can be the first network element or the terminal device or the session management network element in the above method embodiments, or can be a chip (system) or other component or assembly that can be arranged in the first network element or the terminal device or the session management network element. As shown in FIG. 13, the communication apparatus 1300 can include a processor 1301, a bus 1302, a communication interface 1303, and a memory 1304. The processor 1301, the memory 1304, and the communication interface 1303 communicate through the bus 1302. It should be understood that the number of processors and memories in the communication apparatus 1300 is not limited by the present application.
[0382] The bus 1302 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one line is shown in FIG. 13, but it does not mean that there is only one bus or only one type of bus. The bus 1302 can include a path for transmitting information between various components (for example, the memory 1304, the processor 1301, and the communication interface 1303) of the communication apparatus 1300.
[0383] The processor 1301 can include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP), among other processors.
[0384] The memory 1304 can include volatile memory, such as random access memory (RAM), and non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid-state drive (SSD), among others.
[0385] The communication interface 1303 uses a transceiver module, such as but not limited to a network interface card, a transceiver, among others, to enable communication between the communication apparatus 1300 and other devices or communication networks.
[0386] The memory 1304 stores executable program code that the processor 1301 executes to implement the functionality of the first network element or the terminal device or the session management network element in the method embodiments described above. That is, the memory 1304 stores instructions for performing the methods described above.
[0387] In yet another aspect, the embodiments of the present application also provide a computer program product containing instructions, which, when executed on a communication apparatus, cause the communication apparatus to perform the methods described in any of the embodiments above.
[0388] In yet another aspect, the embodiments of the present application also provide a computer readable storage medium. The computer readable storage medium stores computer programs or instructions, which, when executed on a communication apparatus, cause the communication apparatus to perform the methods described in any of the embodiments above.
[0389] In yet another aspect, the embodiments of the present application also provide a communication system, which includes the first network element, the terminal device, and the session management network element for implementing the method embodiments described above.
[0390] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (for example, coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (for example, infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be accessed by a computer or data storage device such as one or more servers, data centers, etc. integrated with one or more media. The available media can be magnetic media (for example, floppy disk, hard disk, magnetic tape), optical media (for example, digital video disc (DVD)), or semiconductor media (for example, SSD), etc.
[0391] Those skilled in the art can appreciate that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. A person skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0392] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here.
[0393] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the described device embodiments are merely schematic. The division of the units is merely logical function division. There can be other division manners in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0394] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0395] In addition, each functional unit in the various embodiments of the present application can be integrated into one processing unit, or each unit can exist physically, or two or more units can be integrated into one unit.
[0396] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application can be embodied in the form of a software product in essence or in the part that contributes to the prior art, or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or an access network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a ROM, a random access memory RAM, a magnetic disk or an optical disk, and various media that can store program codes.
[0397] Although the present application is described herein in conjunction with various embodiments, other variations of the disclosed embodiments can be understood and implemented by those skilled in the art with reference to the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality. A single processor or other unit can implement several functions listed in the claims. Some measures described in mutually different dependent claims can be combined and produce good results.
[0398] Although the present application has been described in connection with certain specific features and embodiments thereof, it is to be understood that it is provided as an example to the best of the applicant's knowledge and that various modifications and combinations of the described features and embodiments are possible and are within the spirit and scope of the application. Accordingly, the specification and drawings are to be regarded in an illustrative rather than a restrictive sense, and all such modifications and variations are considered within the scope of the present application as defined by the following claims and their equivalents. Obviously, many modifications and variations of the present application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the claims and their equivalents, the present application can be practiced otherwise than as specifically described.
Claims
A communication method characterized by comprising: The method comprises: receiving a first message from a terminal device, the first message comprising a session establishment request and a session identifier corresponding to the session establishment request; sending the session establishment request, the session identifier and a first key, the first key being used for security processing of data in a session corresponding to the session identifier, wherein the first key is determined according to the session identifier and a first value, the first value being a counting value or a random value, and different session establishment requests corresponding to different first values. The method of claim 1, wherein The counting value is obtained by counting a counter, and the counter is used for counting the number of session establishment requests requested by the terminal device, or the counter is used for counting the number of non-access stratum (NAS) messages sent by the terminal device, or the counter is used for counting the number of NAS messages sent to the terminal device. The method according to claim 1 or 2, characterized in that In a case where the first value is the counting value and the counter corresponding to the counting value is used for counting the number of session establishment requests requested by the terminal device, the method further comprises: receiving a second message, the second message being used for indicating that the counting value is incremented by one; incrementing the counting value by one according to the second message. The method according to claim 3, characterized in that The method further comprises: in a case where the counting value reaches a maximum value, sending first indication information, the first indication information being used for indicating that the terminal device is re-performed with primary authentication; after the primary authentication is completed, setting the counting value to zero. The method according to claim 1 or 2, characterized in that In a case where the first value is the random value, the method further comprises: storing a correspondence between the random value and the session identifier; sending the random value to the terminal device. The method according to claim 5, characterized in that The method further comprises: after the terminal device is performed with primary authentication, clearing all stored random values. The method according to claim 1 or 2, characterized in that In a case where the first value is the random value, the method further comprises: receiving the random value from the terminal device. The method of claim 7, wherein The random value is carried in the first message. The method according to any one of claims 1-8, characterized in that The different session establishment requests corresponding to different first values comprise: different session establishment requests corresponding to different first values, and different session establishment requests corresponding to different first values. A communication method characterized by comprising: The method comprises: sending a first message, the first message comprising a session establishment request and a session identifier corresponding to the session establishment request; determining a first key according to the session identifier and a first value, the first key being used for security processing of data in a session corresponding to the session identifier, the first value being a counting value or a random value, and different session establishment requests corresponding to different first values. The method of claim 10, wherein The counting value is obtained by counting a counter, and the counter is used for counting the number of session establishment requests requested by the terminal device, or the counter is used for counting the number of NAS messages sent by the terminal device, or the counter is used for counting the number of NAS messages sent to the terminal device. The method according to claim 10 or 11, characterized in that In a case where the first value is the counting value and the counter corresponding to the counting value is used for counting the number of session establishment requests requested by the terminal device, the method further comprises: incrementing the count value after sending the first message or receiving a session establishment accept message. The method of claim 12, wherein The method further comprises: setting the count value to zero after completing primary authentication. The method according to claim 10 or 11, characterized in that In a case where the first value is the random value, the method further comprises: receiving the random value. The method of claim 14, wherein The random value is carried in a session establishment accept message. The method according to claim 14 or 15, characterized in that The method further comprises: clearing all stored random values after completing primary authentication. The method according to claim 10 or 11, characterized in that In a case where the first value is the random value, the method further comprises: storing a correspondence between the session identity and the random value; sending the random value. The method of claim 17, wherein The random value is carried in the first message. The method according to any one of claims 10-18, characterized in that The different session establishment requests correspond to different first values, including that session establishment requests of different session identities correspond to different first values, and session establishment requests of the same session identity correspond to different first values. The method according to any one of claims 10-19, characterized in that The method further comprises: performing security processing on data in a session corresponding to the session identity according to the first key. A communication method characterized by comprising: The method comprises: receiving a session establishment request, a session identity corresponding to the session establishment request, and a first key, the first key being used for security processing on data in a session corresponding to the session identity, the first key being determined according to the session identity and a first value, the first value being a count value or a random value, different session establishment requests corresponding to different first values; sending the session identity and the first key to a user plane network element. The method of claim 21, wherein The count value is obtained by counting by a counter, the counter being used for counting a number of session establishment requests requested by a terminal device, or the counter being used for counting a number of NAS messages sent by the terminal device, or the counter being used for counting a number of NAS messages sent to the terminal device. The method according to claim 21 or 22, characterized in that In a case where the first value is the count value, the method further comprises: sending a second message, the second message being used for indicating that the count value is incremented by one. The method according to claim 21 or 22, characterized in that In a case where the first value is the random value, the method further comprises: sending a third message, the third message being used for indicating that the random value is sent to a terminal device. A communication device, characterized by comprising means for performing the method of any of claims 1-9, or 10-20, or 21-24. A communication device characterized by comprising: comprising: a processor; the processor is configured to run computer programs or instructions to cause the method of any of claims 1-9, or 10-20, or 21-24 to be implemented. A communication chip, characterized in that, instructions stored therein, when the chip is run on a communication device, cause the method of any of claims 1-9, or 10-20, or 21-24 to be implemented. A computer-readable storage medium, characterized by, The computer readable storage medium has computer programs or instructions stored therein, when the computer programs or instructions are executed by a communication device, implement the method of any of claims 1-9, or 10-20, or 21-24. A computer program product, characterized in that including computer program code to implement the method of any of claims 1-9, or 10-20, or 21-24 when the computer program code is run on a communications device.
Citation Information
Patent Citations
Secure session method and device
CN110830991A
Session configuration method and device thereof
CN111464572A
Session establishment method and related device
CN115942305A