Transmission methods, terminal devices, and network device

By protecting and encrypting messages, the problem of insufficient security in message transmission in multi-carrier shared networks is solved, ensuring the security of messages during transmission.

WO2026025341A1PCT designated stage Publication Date: 2026-02-05GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/108763
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-31
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

In communication networks, the security of message transmission cannot be effectively guaranteed because multiple operators share network equipment.

Method used

By protecting and encrypting messages to ensure they are not modified during transmission, protection and verification are achieved using the transceiver and processing modules in terminal and network devices.

Benefits of technology

It enables secure message transmission in a multi-carrier shared network environment, prevents messages from being modified by intermediate nodes, and improves network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024108763_05022026_PF_FP_ABST
    Figure CN2024108763_05022026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to transmission methods, terminal devices, and a network device. A transmission method comprises: a terminal device sending a protected first message to a first network element. The present application can achieve secure transmission of non-access stratum (NAS) messages.
Need to check novelty before this filing date? Find Prior Art

Description

Transmission methods, terminal equipment and network equipment Technical Field

[0001] This application relates to the field of communications, and more specifically, to transmission methods, terminal equipment, and network equipment. Background Technology

[0002] In communication networks, to reduce investment in new networks, multiple operators share network equipment. This means that different devices involved in communication may belong to different operators, leading to a lack of security in message transmission. Ensuring the security of message transmission is a technical problem that needs to be solved.

[0003] Summary of the Invention

[0004] This application provides a transmission method, a terminal device, and a network device.

[0005] This application provides a transmission method, including:

[0006] The terminal device sends a protected first message to the first network element.

[0007] This application provides a transmission method, including:

[0008] The terminal device receives the protected first message sent by the first network element.

[0009] This application provides a transmission method, including:

[0010] The second network element sends a protected first message to the first network element.

[0011] This application provides a transmission method, including:

[0012] The second network element receives the protected first message sent by the first network element.

[0013] This application provides a transmission method, including:

[0014] The third network element protects the first message based on the request from the second network element.

[0015] This application provides a transmission method, including:

[0016] Based on the request from the second network element, the third network element performs integrity protection verification and / or decryption on the protected first message.

[0017] This application provides a terminal device, including:

[0018] The first transceiver module is used to send the protected first message to the first network element.

[0019] This application provides a terminal device, including:

[0020] The second transceiver module is used to receive the protected first message sent by the first network element.

[0021] This application provides a second network element, including:

[0022] The third transceiver module is used to send the protected first message to the first network element.

[0023] This application provides a second network element, including:

[0024] The fourth transceiver module is used to receive the protected first message sent by the first network element.

[0025] This application provides a third network element, including:

[0026] The fourth processing module is used to protect the first message based on the request from the second network element.

[0027] This application provides a third network element, including:

[0028] The fifth processing module is used to perform integrity protection verification and / or decryption on the protected first message based on the request from the second network element.

[0029] This application provides a terminal device, including a transceiver, a processor, and a memory. The memory stores a computer program, the transceiver communicates with other devices, and the processor calls and runs the computer program stored in the memory to enable the terminal device to perform the aforementioned transmission method.

[0030] This application provides a network device, including a transceiver, a processor, and a memory. The memory stores a computer program, the transceiver communicates with other devices, and the processor calls and runs the computer program stored in the memory to enable the network device to perform the aforementioned transmission method.

[0031] This application provides a chip for implementing the above-described transmission method.

[0032] Specifically, the chip includes a processor for retrieving and running a computer program from memory, causing a device equipped with the chip to perform the aforementioned transmission method.

[0033] This application provides a computer-readable storage medium for storing a computer program, which, when run by a device, causes the device to perform the aforementioned transmission method.

[0034] This application provides a computer program product, including computer program instructions that cause a computer to execute the above-described transmission method.

[0035] This application provides a computer program that, when run on a computer, causes the computer to perform the above-described transmission method.

[0036] In this embodiment of the application, by sending a protected first message to a first network element through a terminal device, the message sent by the terminal device can be prevented from being modified by the first network element during transmission, thus ensuring the secure transmission of the first message. Attached Figure Description

[0037] Figure 1 illustrates a communication system 100 as an example.

[0038] Figure 2 illustrates a schematic diagram of a 5G architecture.

[0039] Figure 3 is a schematic diagram of a shared network of multiple operators.

[0040] Figure 4 is a schematic flowchart of a transmission method 400 according to an embodiment of this application.

[0041] Figure 5 is a schematic flowchart of a transmission method 500 according to an embodiment of this application.

[0042] Figure 6 is a schematic flowchart of a transmission method 600 according to an embodiment of this application.

[0043] Figure 7 is a schematic flowchart of a transmission method 700 according to an embodiment of this application.

[0044] Figure 8 is a schematic flowchart of a transmission method 800 according to an embodiment of this application.

[0045] Figure 9 is a schematic flowchart of a transmission method 900 according to an embodiment of this application.

[0046] Figure 10 is a flowchart of the implementation according to Embodiment 1-1 of this application.

[0047] Figure 11 is a flowchart of the implementation according to embodiments 1-2 of this application.

[0048] Figure 12 is a flowchart of the implementation according to Embodiment 2 of this application.

[0049] Figure 13 is a flowchart of the implementation according to Embodiment 3 of this application.

[0050] Figure 14 is a flowchart of the implementation according to Embodiment 4 of this application.

[0051] Figure 15 is a flowchart of the implementation according to Embodiment 5 of this application.

[0052] Figure 16 is a flowchart of the implementation according to Embodiment 6 of this application.

[0053] Figure 17 is a schematic block diagram of a terminal device 1700 according to an embodiment of this application.

[0054] Figure 18 is a schematic block diagram of a terminal device 1800 according to an embodiment of the present application.

[0055] Figure 19 is a schematic block diagram of a terminal device 1900 according to an embodiment of this application.

[0056] Figure 20 is a schematic block diagram of a second network element 2000 according to an embodiment of this application.

[0057] Figure 21 is a schematic block diagram of a second network element 2100 according to an embodiment of the present application.

[0058] Figure 22 is a schematic block diagram of a second network element 2200 according to an embodiment of this application.

[0059] Figure 23 is a schematic block diagram of a third network element 2300 according to an embodiment of this application.

[0060] Figure 24 is a schematic block diagram of a third network element 2400 according to an embodiment of this application.

[0061] Figure 25 is a schematic structural diagram of a communication device 2500 according to an embodiment of this application.

[0062] Figure 26 is a schematic structural diagram of a chip 2600 according to an embodiment of this application. Detailed Implementation

[0063] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0064] The technical solutions of this application embodiment can be applied to various communication systems, such as: Long Term Evolution (LTE) systems, Advanced Long Term Evolution (LTE-A) systems, New Radio (NR) systems, evolution systems of NR systems, LTE-based access to unlicensed spectrum (LTE-U) systems, NR-based access to unlicensed spectrum (NR-U) systems, Non-Terrestrial Networks (NTN) systems, Universal Mobile Telecommunication System (UMTS), Wireless Local Area Networks (WLAN), Wireless Fidelity (WiFi), 5th-Generation (5G) systems, or other communication systems.

[0065] Traditional communication systems typically support a limited number of connections and are easy to implement. However, with the development of communication technology, mobile communication systems will not only support traditional communication but also, for example, device-to-device (D2D) communication, machine-to-machine (M2M) communication, machine-type communication (MTC), vehicle-to-vehicle (V2V) communication, or vehicle-to-everything (V2X) communication. The embodiments of this application can also be applied to these communication systems.

[0066] In one implementation, the communication system in this application embodiment can be applied to a carrier aggregation (CA) scenario, a dual connectivity (DC) scenario, or a standalone (SA) network deployment scenario.

[0067] In one embodiment, the communication system in this application can be applied to unlicensed spectrum, wherein the unlicensed spectrum can also be considered as shared spectrum; or, the communication system in this application can also be applied to licensed spectrum, wherein the licensed spectrum can also be considered as non-shared spectrum.

[0068] This application describes various embodiments in conjunction with network devices and terminal devices. The terminal device may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user device, etc.

[0069] Terminal devices can be stations (STAION, ST) in WLANs, cellular phones, cordless phones, Session Initiation Protocol (SIP) phones, Wireless Local Loop (WLL) stations, Personal Digital Assistant (PDA) devices, handheld devices with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, in-vehicle devices, wearable devices, terminal devices in next-generation communication systems such as NR networks, or terminal devices in future evolved Public Land Mobile Network (PLMN) networks, etc.

[0070] In the embodiments of this application, the terminal device can be deployed on land, including indoor or outdoor, handheld, wearable or vehicle-mounted; it can also be deployed on water (such as ships); and it can also be deployed in the air (such as airplanes, balloons and satellites).

[0071] In the embodiments of this application, the terminal device may be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical care, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, or a wireless terminal device in a smart home, etc.

[0072] By way of example and not limitation, in this embodiment, the terminal device can also be a wearable device. Wearable devices, also known as wearable smart devices, are a general term for devices that utilize wearable technology to intelligently design and develop everyday wearables, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices that are worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not merely hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are feature-rich, large in size, and can achieve complete or partial functions without relying on a smartphone, such as smartwatches or smart glasses, as well as those that focus on a specific type of application function and require the use of other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.

[0073] In the embodiments of this application, the network device can be a device for communicating with mobile devices, such as an access point (AP) in a WLAN, an evolved Node B (eNB or eNodeB) in LTE, a relay station or access point, or a vehicle-mounted device, a wearable device, a network device (gNB) in an NR network, or a network device in a future evolved PLMN network or an NTN network, etc.

[0074] By way of example and not limitation, in this embodiment, the network device may have mobility characteristics; for example, the network device may be a mobile device. Optionally, the network device may be a satellite or a balloon station. For example, the satellite may be a low Earth orbit (LEO) satellite, a medium Earth orbit (MEO) satellite, a geostationary earth orbit (GEO) satellite, a high elliptical orbit (HEO) satellite, etc. Optionally, the network device may also be a base station located on land, water, or other similar locations.

[0075] In this embodiment, the network device can provide services to a cell. The terminal device communicates with the network device through the transmission resources (e.g., frequency domain resources, or spectrum resources) used by the cell. The cell can be the cell corresponding to the network device (e.g., a base station). The cell can belong to a macro base station or to a base station corresponding to a small cell. The small cell can include: metro cell, micro cell, pico cell, femto cell, etc. These small cells have the characteristics of small coverage area and low transmission power, and are suitable for providing high-speed data transmission services.

[0076] Figure 1 illustrates an exemplary communication system 100. The communication system includes a network device 110 and two terminal devices 120. In one embodiment, the communication system 100 may include multiple network devices 110, and the coverage area of ​​each network device 110 may include other numbers of terminal devices 120; this embodiment does not limit the scope of the present application.

[0077] In one embodiment, the communication system 100 may further include other network entities such as a Mobility Management Entity (MME), an Access and Mobility Management Function (AMF), a 6G-AMF, and a 6G-SMF, but this application embodiment does not limit this.

[0078] Network equipment can be further divided into access network equipment and core network equipment. That is, the wireless communication system also includes multiple core networks used to communicate with the access network equipment. Access network equipment can be evolved Node Bs (eNBs or e-NodeBs) in Long-Term Evolution (LTE), Next-Generation Radio (NR), or Authorized Auxiliary Access Long-Term Evolution (LAA-LTE) systems, such as macro base stations, micro base stations (also called "small base stations"), pico base stations, access points (APs), transmission points (TPs), new generation Node Bs (gNodeBs), or 6G NodeBs, etc.

[0079] It should be understood that devices with communication functions in the network / system of this application embodiment can be referred to as communication devices. Taking the communication system shown in Figure 1 as an example, the communication device may include network devices and terminal devices with communication functions. The network devices and terminal devices can be specific devices in this application embodiment, which will not be described in detail here. The communication device may also include other devices in the communication system, such as network controllers, mobility management entities, and other network entities. This application embodiment does not limit this.

[0080] It should be understood that the terms "system" and "network" are often used interchangeably in this document. The term "and / or" in this document merely describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Furthermore, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.

[0081] It should be understood that the term "instruction" mentioned in the embodiments of this application can be a direct instruction, an indirect instruction, or an indication of a relationship. For example, A instructing B can mean that A directly instructs B, such as B being able to obtain information through A; it can also mean that A indirectly instructs B, such as A instructing C, so B can obtain information through C; or it can mean that there is a relationship between A and B.

[0082] In the description of the embodiments of this application, the term "correspondence" may indicate that there is a direct or indirect correspondence between two things, or that there is an association between two things, or that there is a relationship of instruction and being instructed, configuration and being configured, etc.

[0083] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.

[0084] Figure 2 illustrates an exemplary 5G architecture. In Figure 2, the UE connects to the AN via the Uu interface to establish an access layer connection, exchanging access layer messages and radio data transmissions. The UE connects to the AMF via the N1 interface to establish a non-access layer (NAS) connection, exchanging NAS messages. The AMF is the mobility management function in the core network, and the SMF is the session management function in the core network. In addition to managing the UE's mobility, the AMF is also responsible for forwarding session management-related messages between the UE and the SMF. The PCF is the policy management function in the core network, responsible for formulating policies related to UE mobility management, session management, and charging. The UPF is the user plane function in the core network, transmitting data with the external data network via the N6 interface and with the AN via the N3 interface. After the UE accesses the 5G network via the Uu interface, it establishes a PDU session for data transmission under the control of the SMF.

[0085] To reduce investment in new networks (including 5G and future 6th-generation (6G) networks), multiple operators share network equipment. Figure 3 is a schematic diagram of a shared network among multiple operators. As shown in Figure 3, operator X will deploy NR or 6G base stations and AMF in the 5G network or 6G-AMF in the 6G network (in the 6G network, the centralized control point may also be 6G-CP NF, 6G-control plane NF, or 6G MM NF-6G mobility management NF). In this way, the participating operator in Figure 3 can deploy only network equipment other than NR, AMF in the 5G network or 6G base stations and 6G-AMF in the 6G network (in the 6G network, the centralized control point may also be 6G-CP NF, 6G-control plane NF, or 6G MM NF-6G mobility management NF) in a certain area. The shared operator or hosting operator network deploys NR, AMF in the 5G network or 6G base stations and 6G-AMF in the 6G network (in the 6G network, the centralized control point may also be 6G-CP NF, 6G-control plane NF, or 6G MM NF-6G mobility management NF). In 5G networks of shared operators or 6G networks of hosting operators, NR base stations need to broadcast the PLMN ID of the participating operator so that UEs of the participating operator can select this network for access.

[0086] In existing 5G networks, Session Management messages (SM messages) are sent from the SMF to the UE via the AMF, and the UE also sends SM messages from the AMF to the SMF. The PCF sends UE policies to the UE via the AMF, and the UE returns confirmation or support status of the UE policy to the PCF via the AMF. The UE sends an uplink NAS transfer (UL NAS TRANSPORT) message to the AMF, carrying a payload container and payload type. The payload type indicates whether the payload container is an SM container or a UE policy container. The payload container carries the specific SM message or UE policy confirmation or support status. The AMF then forwards the SM container and UE policy container to the SMF and PCF. For PCF or SMF, a similar method is used to send the UE policy container or SM container to AMF. AMF sends the UE policy container or SM container to the UE in a downlink NAS transport (DL NAS TRANSPORT) message. The DL NAS TRANSPORT message carries the payload container and payload type; the payload type can be used to indicate whether the carried payload container is an SM container or a UE policy container. Session management messages are carried in the SM container.

[0087] For the AMF (Active Message Provider) in 5G or 6G systems, although the UE Policy container or SM container does not need to be parsed, the AMF can arbitrarily add, delete, or tamper with the container's content, and the UE, SMF, or PCF cannot know whether the AMF has added, deleted, or tampered with the container's content during transmission. When the AMF and SMF or PCF are within the same operator, the AMF and SMF, PCF, or other NFs that need to send data information to the UE through the AMF can be considered to have a trust relationship. However, with increasing co-construction and sharing among operators, the UE, SMF, or PCF cannot know whether the AMF has added, deleted, or tampered with the message content during transmission. To address this issue, this application proposes a method for secure NAS (Network Attached Message) transmission.

[0088] This application applies to mobile communication networks, and the following description uses 5G and 6G networks. However, this application is not limited to 5G or 6G networks and can also be used in future mobile networks.

[0089] This application proposes a method for secure data transfer in a 6G NAS. In general, it includes the following aspects:

[0090] The UE performs integrity protection and / or encryption on uplink messages (such as SM container or UE policy container), and the core network elements (such as SMF, PCF, etc.) perform integrity verification and / or decryption on the received uplink messages.

[0091] Core network elements (such as SMF, PCF, etc.) perform integrity protection and / or encryption on downlink messages (such as SM container or UE policy container), and the UE performs integrity verification and / or decryption on the received downlink messages.

[0092] In this way, when the SMF / PCF and AMF belong to different operators (as shown in Figure 3 or when the UE is roaming), the content sent between the UE's home network and the UE (such as the SM container or UE policy container) can be prevented from being modified or known by intermediate nodes (such as AMFs from other operators), thereby further improving network security.

[0093] The following details this application.

[0094] Figure 4 is a schematic flowchart of a transmission method 400 according to an embodiment of this application. This method can optionally be applied to the systems shown in Figures 1, 2, or 3, but is not limited thereto. The method includes at least a portion of the following:

[0095] S410, The terminal device sends the protected first message to the first network element.

[0096] The first network may include an AMF.

[0097] The protected first message includes a first message that is integrity protected and / or encrypted by the terminal device. That is, the terminal device performs integrity protection and / or encryption on the first message and sends the integrity-protected and / or encrypted first message to the first network element.

[0098] The first message may include at least one of the following:

[0099] SM message;

[0100] UE Policy message or UE policy information.

[0101] The UE Policy message can also be called the UE Policy container, UE Policy container message, etc.

[0102] In some examples, the terminal device sends a protected first message to the first network element via an uplink NAS transfer (UL NAS TRANSPORT) message, for example:

[0103] The terminal device sends a first NAS transmission message to the first network element, which carries a protected first message.

[0104] Specifically, the first NAS transmission message may carry an SM container containing the protected first message; or, the first NAS transmission message may carry a UE policy container containing the protected first message.

[0105] In some examples, the first NAS transport message includes an uplink NAS transport message.

[0106] In other examples, the terminal device completes the message in a secure mode and sends a protected first message to the first network element. For example, the terminal device sends a secure mode completion message to the first network element, which carries a registration request message; the registration request message carries the protected first message.

[0107] The registration request message may carry an SM container containing the protected first message; or, the registration request message may carry a UE policy container containing the protected first message.

[0108] In the above embodiments, the SM container may further include at least one of the following:

[0109] Message verification code generated by the terminal device;

[0110] The SM counter value generated by the terminal device or a portion of the SM counter value.

[0111] In the above embodiments, the UE policy container may further include at least one of the following:

[0112] The message verification code generated by the terminal device;

[0113] The UE policy counter value or part of the UE policy counter value generated by the terminal device.

[0114] The first terminal receives the protected first message and sends it to the second network element (such as SMF or PCF). The second network element can use the message verification code to verify the protected first message. The SM count value or UE policy count value generated by the terminal device can be used by the second network element to determine whether the first message (i.e., SM message / UE policy) has been replayed.

[0115] In some implementations, the protected first message (such as an SM message) includes: a message after the terminal device has performed integrity protection and / or encrypted the first message according to the AUSF key (Kausf) or the SM key (Ksm); wherein, Ksm is generated by the terminal device according to the Kausf or AMF key (Kamf);

[0116] In some implementations, the protected first message (such as a UE policy) includes: a message after the terminal device has performed integrity protection and / or encrypted the first message according to the Kausf or the key (Kuepolicy) of the UE policy; wherein the Kuepolicy is generated by the terminal device according to the Kausf or Kamf.

[0117] In this way, when the terminal device sends an uplink message, it can perform integrity protection and / or encryption on the uplink message (such as SM container or UE policy container), so that the network element (such as AMF) that receives the uplink message cannot modify the message, thus ensuring the security of message transmission.

[0118] This application also proposes a transmission method. FIG5 is a schematic flowchart of a transmission method 500 according to an embodiment of this application. This method can optionally be applied to the systems shown in FIG1, FIG2, or FIG3, but is not limited thereto. The method includes at least a portion of the following:

[0119] S510, The terminal device receives the protected first message sent by the first network element.

[0120] The first network element may include an AMF.

[0121] The protected first message includes a first message whose integrity is protected and / or encrypted by a second network element. This second network element can be an SMF or a PCF.

[0122] In some implementations, the protected first message (such as an SM message) includes: a message after the second network element has performed integrity protection and / or encrypted the first message according to the AUSF key (Kausf) or the SM key (Ksm); wherein, Ksm is generated by the second network element according to the Kausf or AMF key (Kamf);

[0123] In some implementations, the protected first message (such as a UE policy) includes: a message after the second network element performs integrity protection and / or encryption on the first message according to the Kausf or the key (Kuepolicy) of the UE policy; wherein the Kuepolicy is generated by the second network element according to the Kausf or Kamf.

[0124] That is, the second network element performs integrity protection and / or encryption on the first message and sends the integrity-protected and / or encrypted first message to the first network element; the first network element then sends the integrity-protected and / or encrypted first message to the terminal device, and the terminal device receives the integrity-protected and / or encrypted first message. In this way, when the first message is transmitted through the first network element, because it has already undergone integrity protection and / or encryption, the first network element cannot modify the integrity-protected and / or encrypted first message, thus ensuring the secure transmission of the first message.

[0125] Upon receiving a first message that has been protected and / or encrypted, the terminal device can decipher and / or perform integrity protection checks on the protected first message.

[0126] The first message may include at least one of the following:

[0127] SM message;

[0128] UE Policy message or UE policy information.

[0129] In some examples, the terminal device receives the protected first message via a second NAS transfer (DL NAS TRANSPORT) message, for example:

[0130] The terminal device receives a second NAS transmission message sent by the first network element, which carries a protected first message.

[0131] Specifically, the second NAS transmission message may carry an SM container containing the protected first message; or, the second NAS transmission message may carry a UE policy container containing the protected first message.

[0132] In some examples, the second NAS transport message includes a downlink NAS transport message.

[0133] In other examples, the terminal device receives a protected first message via a registration acceptance message. For example, the terminal device receives a registration acceptance message sent by a first network element, which carries the protected first message.

[0134] Specifically, the registration acceptance message may carry an SM container containing the protected first message; or, the registration acceptance message may carry a UE policy container containing the protected first message.

[0135] In the above embodiments, the SM container may further include at least one of the following:

[0136] The message verification code (SM MAC) generated by the second network element UE );

[0137] The second network element generates an SM counter or a portion of the SM counter value.

[0138] In the above embodiments, the UE policy container may further include at least one of the following:

[0139] The message verification code (UE Policy MAC) generated by the second network element;

[0140] The UE policy counter value generated by the second network element or a portion of the UE policy counter value.

[0141] Among them, the message verification code allows the terminal device to verify the integrity of the first message received.

[0142] In some examples, after performing integrity protection verification on the protected first message, the terminal device can also store the SM count value or UE policy count value. In this way, if the SM count value or UE policy count value in the first message received again is less than or equal to the previously stored SM count value or UE policy count value, the message is ignored.

[0143] In this way, the downlink messages (such as SM container or UE policy container) received by the terminal device are downlink messages that have been protected for integrity and / or encrypted. When the message is transmitted through the first network element (such as AMF), the intermediate network element cannot modify the message, thus ensuring the security of message transmission.

[0144] This application also proposes a transmission method. FIG6 is a schematic flowchart of a transmission method 600 according to an embodiment of this application. This method can optionally be applied to the systems shown in FIG1, FIG2, or FIG3, but is not limited thereto. The method includes at least a portion of the following:

[0145] S610, the second network element sends the protected first message to the first network element.

[0146] The first network element may include an AMF, and the second network element may be an SMF or a PCF.

[0147] That is, the second network element sends a first message that has been protected and / or encrypted to the first network element; the first network element then sends the first message that has been protected and / or encrypted to the terminal device, and the terminal device receives the first message that has been protected and / or encrypted. In this way, when the first message is transmitted through the first network element, because it has been protected and / or encrypted, the first network element cannot modify the first message that has been protected and / or encrypted, thus ensuring the secure transmission of the first message.

[0148] The first message may include at least one of the following:

[0149] SM message;

[0150] UE Policy message or UE policy information.

[0151] In some implementations, the second network element sending a protected first message to the first network element includes: the second network element sending a PDU session establishment SM context response message (Nsmf_PDU session_CreateSMContext_Response) to the first network element, the PDU session establishment SM context response message carrying an SM container, the SM container containing the protected first message; or,

[0152] The second network element sends a communication N1N2 message transfer message (Namf_Communication_N1N2MessageTransfer) to the first network element. The communication N1N2 message transfer message carries an SM container, which contains the protected first message.

[0153] In one example, the SM container may also contain at least one of the following:

[0154] The message verification code generated by the second network element;

[0155] The second network element generates the SM count value or a portion of the SM count value.

[0156] In other embodiments, the second network element sends a protected first message to the first network element, including: the second network element sends a UE Policy Association establishment response message to the first network element, the UE Policy Association establishment response message carrying a UE policy container, the UE policy container containing the protected first message.

[0157] In one example, the UE policy container also contains at least one of the following:

[0158] The message verification code generated by the second network element;

[0159] The second network element generates the UE policy count value or a portion of the UE policy count value.

[0160] In some implementations, the protected first message includes a first message that is integrity protected and / or encrypted.

[0161] In some examples, the first message is protected for integrity and / or encrypted by a third network element. For example, before the second network element sends the protected first message to the first network element, the following steps are also included:

[0162] The second network element sends the first message to the third network element;

[0163] The second network element receives the protected first message sent by the third network element.

[0164] The third network element may include AUSF. After receiving the first message sent by the second network element, the third network element performs integrity protection and / or encryption on the first message, and feeds back the integrity-protected and / or encrypted first message to the second network element.

[0165] In one example, the second network element sending a first message to the third network element includes: the second network element sending an SM protection message (Nausf_SM_Protection) or a UE policy protection message (Nausf_UEPolicy_protection) to the third network element, wherein the SM protection message or UE policy protection message carries the first message.

[0166] In one example, the second network element receiving the protected first message sent by the third network element includes: the second network element receiving an SM protection response message (Nausf_SM_Protection_Response) or a UE policy protection response message (Nausf_UEPolicy_protection_Response) sent by the third network element, wherein the SM protection response message or the UE policy protection response message carries the protected first message.

[0167] In other implementations, a third network element or a first network element provides a key to the second network element for protecting the first message, and the second network element uses this key to protect the first message. For example, before the second network element sends the protected first message to the first network element, the process further includes:

[0168] The second network element sends an authentication request message (Nausf_smf_authenticate Request message) to the third network element or the first network element;

[0169] The second network element receives an authentication response message (Nausf_smf_authenticate Response message) sent by the third network element or the first network element. This authentication response message carries a key.

[0170] The second network element uses this key to perform integrity protection and / or encryption on the first message.

[0171] In some implementations, the protected first message (such as an SM message) includes: a message that has been protected for integrity and / or encrypted according to the AUSF key (Kausf) or the SM key (Ksm); wherein, Ksm is generated according to the Kausf or AMF key (Kamf);

[0172] In some implementations, the protected first message (such as a UE policy) includes: a message that has been integrity protected and / or encrypted according to a Kausf or a key (Kuepolicy) of the UE policy; wherein the Kuepolicy is generated according to Kausf or Kamf.

[0173] In this way, when the second network element sends a downlink message to the first network element, it can perform integrity protection and / or encryption on the downlink message (such as SM container or UE policy container), so that the first network element (such as AMF) that receives the downlink message cannot modify the message, thus ensuring the security of message transmission.

[0174] This application also proposes a transmission method. FIG7 is a schematic flowchart of a transmission method 700 according to an embodiment of this application. This method can optionally be applied to the systems shown in FIG1, FIG2, or FIG3, but is not limited thereto. The method includes at least a portion of the following:

[0175] S710, the second network element receives the protected first message sent by the first network element.

[0176] The first network element may include an AMF, and the second network element may be an SMF or a PCF.

[0177] The protected first message includes a first message that is integrity protected and / or encrypted by the terminal device.

[0178] In some implementations, the protected first message (such as an SM message) includes: a message after the terminal device has performed integrity protection and / or encrypted the first message according to the AUSF key (Kausf) or the SM key (Ksm); wherein, Ksm is generated by the terminal device according to the Kausf or AMF key (Kamf);

[0179] In some implementations, the protected first message (such as a UE policy) includes: a message after the terminal device has performed integrity protection and / or encrypted the first message according to the Kausf or the key (Kuepolicy) of the UE policy; wherein the Kuepolicy is generated by the terminal device according to the Kausf or Kamf.

[0180] That is, the terminal device performs integrity protection and / or encryption on the first message and sends the integrity-protected and / or encrypted first message to the first network element; the first network element then sends the integrity-protected and / or encrypted first message to the second network element, and the second network element receives the integrity-protected and / or encrypted first message. In this way, when the first message is transmitted through the first network element, because it has already undergone integrity protection and / or encryption, the first network element cannot modify the integrity-protected and / or encrypted first message, thus ensuring the secure transmission of the first message.

[0181] Upon receiving a first message that has been protected and / or encrypted, the second network element can decrypt and / or verify the integrity of the protected first message.

[0182] The first message may include at least one of the following:

[0183] SM message;

[0184] UE Policy message or UE policy information.

[0185] In some examples, the second network element receives the protected first message via a PDU session create or update SMContext request message (Nsmf_PDU session_CreateSMContext_Request / Nsmf_PDU session_UpdateSMContext_Request), for example:

[0186] The second network element receives a PDU session establishment or SM context update request message sent by the first network element, which carries the protected first message.

[0187] Specifically, the PDU session establishment or SM context update request message carries an SM container containing the protected first message; or...

[0188] The PDU session establishment or SM context update request message carries a UE policy container, which contains the protected first message.

[0189] In other examples, the second network element receives the protected first message via a UE Policy Association Establishment Request message, for example:

[0190] The second network element receives a UE policy association establishment request message sent by the first network element, which carries the protected first message.

[0191] Specifically, the UE policy association establishment request message may carry an SM container, which contains the first message of the protection; or...

[0192] The UE policy association establishment request message may carry a UE policy container, which contains a protected first message.

[0193] In the above embodiments, the SM container may further include at least one of the following:

[0194] Message Verification Code (SM MAC) generated by the terminal device UE );

[0195] The SM counter value generated by the terminal device or a portion of the SM counter value.

[0196] In the above embodiments, the UE policy container may further include at least one of the following:

[0197] The message verification code (UE Policy MAC) generated by the terminal device;

[0198] The UE policy counter value generated by the terminal device or a portion of the UE policy counter value.

[0199] The message verification code allows the second network element to perform integrity verification on the received first message.

[0200] In some examples, after performing integrity protection verification on the protected first message, the second network element can also store the SM count value or UE policy count value. In this way, if the SM count value or UE policy count value in the first message received again is less than or equal to the previously stored SM count value or UE policy count value, the message is ignored.

[0201] After receiving the first message that has been protected and / or encrypted, the second network element may also request the third network element or the first network element to perform integrity protection verification and / or decryption on the protected first message.

[0202] The third network element may include AUSF.

[0203] For example, the second network element sends a protection verification request message (Nausf_SM_Protection Check request message or Nausf_UEPolicy_Protection Check request message) to the third network element. This protection verification message carries the first message that has been protected.

[0204] After receiving the protected first message, the third network element performs integrity protection verification and / or decryption on the protected first message, and sends back the first message that has not been integrity protected and / or not encrypted to the second network element.

[0205] The second network element receives a protection verification response message (Nausf_SM_Protection Check Response message or Nausf_UEPolicy_Protection Check Response message) sent by the third network element. This protection verification response message carries a first message that is not protected by integrity and / or is not encrypted.

[0206] In this way, the first message received by the second network element (such as the SM container or UE policy container) is a message that has been protected for integrity and / or encrypted. This message cannot be modified during transmission, thus ensuring the security of message transmission.

[0207] This application also proposes a transmission method. FIG8 is a schematic flowchart of a transmission method 800 according to an embodiment of this application. This method can optionally be applied to the systems shown in FIG1, FIG2, or FIG3, but is not limited thereto. The method includes at least a portion of the following:

[0208] S810 and the third network element protect the first message based on the request from the second network element.

[0209] The second network element can be an SMF or a PCF, and the third network element can include an AUSF.

[0210] In some implementations, the third network element receives the first message sent by the second network element; the third network element performs integrity protection and / or encryption on the first message; and the third network element sends the first message, which has been protected and / or encrypted, to the second network element.

[0211] In other implementations, the third network element receives an authentication request message sent by the second network element; the third network element sends an authentication response message to the second network element, the authentication response message carrying a key, the key being used for integrity protection and / or encryption of the first message.

[0212] After receiving the key, the second network element uses the key to perform integrity protection and / or encryption on the first message.

[0213] In some implementations, the first message is protected for integrity and / or encrypted based on the AUSF key (Kausf) or the SM key (Ksm); wherein the Ksm is generated based on the Kausf or AMF key (Kamf).

[0214] In some implementations, the first message is protected for integrity and / or encrypted according to a key (Kuepolicy) of Kausf or UE policy; wherein the Kuepolicy is generated according to Kausf or Kamf.

[0215] In this way, the third network element can protect the first message that the second network element is about to send, thereby preventing the first message from being modified during transmission and ensuring the security of information transmission.

[0216] This application also proposes a transmission method. FIG9 is a schematic flowchart of a transmission method 900 according to an embodiment of this application. This method can optionally be applied to the systems shown in FIG1, FIG2, or FIG3, but is not limited thereto. The method includes at least a portion of the following:

[0217] S910 and the third network element perform integrity protection verification and / or decryption on the protected first message based on the request of the second network element.

[0218] The second network element can be an SMF or a PCF, and the third network element can include an AUSF.

[0219] In one example, the protected first message may include a first message that is integrity protected and / or encrypted by the terminal device. The terminal device performs integrity protection and / or encryption on the first message, and transmits the integrity-protected and / or encrypted first message to the second network element through a first network element (such as AMF); after receiving the integrity-protected and / or encrypted first message, the second network element sends it to a third network element, which performs integrity protection verification and / or decryption on the protected first message, and then feeds back the first message to the second network element.

[0220] In some implementations, the integrity protection verification and / or decryption of the protected first message (such as an SM message) is performed using the AUSF key (Kausf) or the SM key (Ksm); wherein, Ksm is generated based on the Kausf or AMF key (Kamf);

[0221] In some implementations, the integrity protection verification and / or decryption of the protected first message (such as the UE policy) is performed using a key of Kausf or UE policy (Kuepolicy); wherein the Kuepolicy is generated based on Kausf or Kamf.

[0222] In this way, the third network element can perform integrity protection verification and / or decryption on the first message that has been protected during transmission, and provide it to the network element that receives the first message.

[0223] The present application will now be described in detail with reference to the accompanying drawings and specific embodiments. In the following embodiments, the first network element is described as AMF, the second network element as SMF or PCF, and the third network element as AUSF; the first message transmitted between the network element and the terminal device (UE) includes an SM message or a UE policy message (UE Policy container).

[0224] Example 1-1:

[0225] In this embodiment, the UE encrypts and protects the integrity of the uplink SM message (the SM message sent from the UE to the SMF) through Kausf, and the SMF decrypts and checks the integrity of the uplink SM message through Kausf.

[0226] Figure 10 is a flowchart of the implementation according to Embodiment 1-1 of this application, including the following steps:

[0227] Step 1001: The UE sends a registration request message to the 6G-AMF on the network side. The message carries the UE ID, registration type or UE security capabilities. The UE ID can be a Subscription Concealed Identifier (SUCI) or a Globally Unique Temporary UE Identity (GUTI). The registration type includes initial registration or mobility update registration.

[0228] Step 1002: After receiving the registration request message, 6G-AMF triggers the authentication process.

[0229] Step 1003: The 6G-AMF sends a Security Mode Command message to the UE. This Security Mode Command message carries ngKSI, the UE security capabilities for replay, the integrity algorithm, the ciphering algorithm, and a request for a complete Initial NAS message.

[0230] Step 1004: The UE returns a Security Mode Complete message to the 6G-AMF. This Security Mode Complete message carries a complete registration request message. In addition to the content in step 1001, the complete registration request message may also include the requested slice information, UE capability information, etc.

[0231] Step 1005: 6G-AMF returns a registration acceptance message to the UE, which carries the new GUTI and registration area.

[0232] Step 1006: The UE returns a registration completion message to the 6G-AMF to confirm that the new GUTI has taken effect.

[0233] In step 1007, the UE needs to establish a PDU session. The UE uses Kausf to perform integrity protection and / or encryption on the SM message and calculates the message verification code (denoted as SM-MACue). Simultaneously, the SM header field needs to indicate whether the SM message has been integrity protected or has been integrity protected and encrypted. The UE generates an SM counter (which can be denoted as Counter). SM This SM counter enables the SMF to determine whether an SM message has been replayed. The SM counter is also used as a parameter to generate the SM-MACue, and the SMF uses this SM counter to verify the SM_MACue. Table 1A shows one possible configuration of the SM container, which can contain an SM header, a message verification code (SM-MACue), and an SM counter (SM counter or Counter value). SM The message verification code (SM-MACue) is either 128 bits or 32 bits long, and the SM counter (SM counter or Counter) is also included. SM The length of the SM message is 16 bits, and the length of the SM message part depends on the specific content it contains.

[0234] Alternatively, for more efficient transmission, only a portion of the SM Counter's content can be transmitted within the message. Table 1B shows another possible form of the SM container, which can include the SM header, Message Authentication Code (SM-MACue), and SM counter value (SM counter or Counter). SMThe sequence number (or Sequence Number) in ) SM The SM counter consists of two parts: a high-order part and a low-order part. The high-order part is called SM counter_Part 1, and the low-order part is called the sequence number.

[0235] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0236] Table 1A

[0237] Table 1B

[0238] In step 1008, the UE sends an uplink NAS transport (UL NAS TRANSPORT) message to the 6G-AMF. This uplink NAS transport message carries the PDU session ID, Single Network Slice Selection Assistance Information (S-NSSAI), Data Network Name (DNN), and a PDU session establishment request message. The PDU session establishment request message carries the PDU session ID, the type of PDU session establishment, the PDU session type (e.g., IPv4, IPv6, IPv4v6, Ethernet, or Unstructure), S-NSSAI, DNN, etc. The PDU session establishment request message is carried using an SM container and is protected for integrity as described in step 1007, or it is protected for integrity and encrypted. One possible method for using the SM container is shown in Table 1A or Table 1B.

[0239] The SM message portion carries a PDU session establishment request message.

[0240] Step 1009: The 6G-AMF sends a PDU session establishment SM context response request (Nsmf_PDU session_CreateSMContext_Request) message to the SMF. This message carries the PDU session ID, S-NSSAI, and an SM container that is either integrity-protected or integrity-protected and encrypted. The integrity-protected or integrity-protected and encrypted SM container includes the SM header, SM-MACue, and Counter. SM The SM message portion; that is, the content included in Table 1A above. Alternatively, the SM container that has been protected for integrity, or protected for integrity and encrypted, includes the SM header, SM-MACue, Sequence Number, and SM message portion; that is, the content included in Table 1B above.

[0241] Step 1010: The SMF looks up the AUSF based on the user's SUPI and sends an SM protection verification request message (Nausf_SM_Protection Check request message) to the AUSF. This message carries the SM container. The AUSF performs an integrity check on the SM container. If the check passes, the AUSF stores the SM container. Subsequently, the AUSF only accepts SM containers with a Counter value greater than this stored value. The AUSF directly ignores SM containers with a Counter value less than or equal to this stored value.

[0242] When the received SM container contains only part of the SM counter, such as only the sequence number, AUSF needs to deduce the SM counter based on the sequence number and the high-order part of the stored SM counter. AUSF performs an integrity check on the SM container. If the check passes, AUSF stores the SM container. Subsequently, AUSF only accepts SM containers whose estimated counter value is greater than this stored value. AUSF directly ignores SM containers whose estimated counter value is less than or equal to this stored value.

[0243] Step 1011: AUSF returns an SM protection verification response message (Nausf_SM_Protection Check response message) to SMF, which carries an SM message that has not been protected for integrity or is not encrypted (called a clean SM message).

[0244] Step 1012: The SMF accepts the PDU session establishment. The SMF sends the PDU session establishment acceptance message to the AUSF for integrity protection, or performs integrity protection and encryption. The PDU session establishment acceptance message carries information such as PDU session ID, authorized QoS rules, UE IP address, and S-NSSAI. As shown in Figure 10, this PDU session establishment acceptance message is carried in the SM protection (Nausf_SM_Protection) message.

[0245] Step 1013: AUSF returns an SM Protection Response (Nausf_SM_Protection Response) message to SMF. This message carries a PDU session establishment acceptance message that has been integrity protected, or has been integrity protected and encrypted. Specifically, the PDU session establishment acceptance message contains an SM container, which contains the integrity protected, or integrity protected and encrypted PDU session establishment acceptance message. The SM container contains an SM header field, a message authentication code (denoted as MAC-I or SM-MACausf), and a counter value (denoted as Counter). SM The SM container consists of an integrity-protected PDU session establishment and acceptance message, or an integrity-protected and encrypted PDU. One possible format for this SM container is shown in Table 2A. In one example, the message verification code is 128 bits or 32 bits long, the count value is 16 bits long, and the length of the SM message portion depends on its specific content. In the example shown in Table 2A, the SM message portion contains the integrity-protected or encrypted PDU session establishment and acceptance message.

[0246] Table 2A

[0247] Alternatively, for more efficient transmission, Counter SM Only a portion of the content is transmitted within the message. Table 2B shows another possible method for the SM container, involving only Counter. SM The sequence number is transmitted in the message, while other parts are not transmitted. This can be done using a Counter. SM It is divided into two parts: the high-order part and the low-order part. The high-order part is called SM counter_Part 1, and the low-order part is called the Sequence number.

[0248] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0249] Table 2B

[0250] Step 1014: The 6G-SMF returns a PDU session establishment SM context response message (Nsmf_PDU session_CreateSMContext_Response) to the 6G-AMF. This message carries the PDU session ID and the SM container. The SM container is an SM container that has been protected for integrity or has been protected for integrity and encrypted.

[0251] If the 6G-SMF has already returned the Nsmf_PDU session_CreateSMContext_Response message to the 6G-AMF before this step, then this step can use the Communication N1N2 Message Transfer message (Namf_Communication_N1N2MessageTransfer) to send the SM container to the SMF.

[0252] Step 1015: The 6G-AMF sends a downlink NAS transfer (DL NAS TRANSPORT) message to the UE, which carries the SM container and PDU session ID.

[0253] Step 1016: The UE performs integrity protection verification on the SM container according to Kausf. If the verification passes, the UE stores the Counter. SM ,

[0254] Subsequently, the UE will only accept SM containers with a Counter value greater than this storage value. For SM containers with a Counter value less than or equal to this storage value, the UE will directly ignore the SM container.

[0255] When the received SM container contains only part of the SM counter, such as only the sequence number, the UE needs to deduce the SM counter based on the sequence number and the high-order part of the stored SM counter. The UE performs an integrity check on the SM container. If the check passes, the UE stores the SM counter. Subsequently, the UE only accepts SM containers whose estimated counter value is greater than this stored value. The UE directly ignores SM containers whose estimated counter value is less than or equal to this stored value.

[0256] The steps in the diagram omit steps that are not related to the scheme of this application, such as the process of AMF and UDM obtaining user subscription data, and the process of establishing data radio bearer between UE and 6G-NB.

[0257] In this embodiment, the transmitted message is an example of an SM message. It is also applicable to the transmission of UE policy. If it is a newly added NF in a 5G or 6G network, it is also applicable to other newly added message containers.

[0258] Examples 1-2:

[0259] The UE uses Kausf to encrypt and protect the integrity of the uplink Policy container (which is sent from the UE to the PCF). The PCF uses Kausf to decrypt and check the integrity of the uplink Policy container message.

[0260] Figure 11 is a flowchart of the implementation according to embodiments 1-2 of this application, including the following steps:

[0261] Step 1101: The UE sends a registration request message to the network side 6G-AMF. The message carries the UE ID, registration type or UE security capabilities. The UE ID can be SUCI or GUTI, and the registration type includes initial registration or mobility update registration.

[0262] Step 1102: After receiving the registration request message, 6G-AMF triggers the authentication process.

[0263] Step 1103: The 6G-AMF sends a Security Mode Command message to the UE. This Security Mode Command message carries ngKSI, the UE security capabilities for replay, the integrity algorithm, the ciphering algorithm, and a request for a complete Initial NAS message.

[0264] Step 1104: The UE returns a Security Mode Complete message to the 6G-AMF. This message carries a complete registration request message. This complete registration request includes not only the content from step 1101, but may also include requested slice information, UE capability information, and the UE policy container. The UE policy container can carry stored UE policies, including the UE policy ID, or it can carry UE policy requests. The UE uses Kausf to perform integrity protection and / or encryption on the UE policy and calculates a message verification code (denoted as UE_Policy-MACue). Simultaneously, the UE policy header needs to indicate whether the UE policy message or information portion has been integrity protected, or has been integrity protected and encrypted. The UE generates a UE policy counter value (denoted as UE_policy counter or Counter). UEPolicy This UE_policy counter is used by the PCF to determine whether a UE policy message or information has been replayed. The UE_policy counter is also used as a parameter to generate the UE_Policy-MACue, and the PCF uses this UE_policy counter to verify the UE_policy-MACue. One possible form of the UE policy container is shown in Table 3A below, including the UE policy header field and the message verification code (denoted as UE_policy-MAC). ue ), count value (denoted as UE_policy counter or Counter) UEPolicy The message verification code is either 128 bits or 32 bits long, the count value is 16 bits long, and the length of the UE_policy information section depends on the specific content it contains.

[0265] Table 3A

[0266] Alternatively, for more efficient transmission, a UE_policy counter or counter can be used. UEPolicy Only a portion of the content is transmitted within the message. Table 3B shows another possible method for the UE policy container, which only includes UE policy counters or counters. UEPolicy The sequence number (or sequence number) UEPolicy The message is transmitted in the message itself, while other parts are not transmitted. This can be done using a UE policy counter or counter. UEPolicy It is divided into two parts: the high-order part and the low-order part. The high-order part is called UE policy counter_Part 1, and the low-order part is called the Sequence number.

[0267] When the sequence number changes from all 1s to all 0s, UE policy counter_Part 1 needs to be incremented by 1. For example, the high-order part of UE policy counter_Part 1 is 24 bits long, and the low-order part of the sequence number is 8 bits long. The sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the sequence number changes back to "00000000", and the value of UE policy counter_Part 1 is incremented by 1.

[0268] Table 3B

[0269] Step 1105: The AMF selects the PCF and sends a UE Policy Association Establishment Request message to the PCF. This message carries the UE Policy container, which is either already integrity-protected or already integrity-protected and encrypted, including the UE_Policy header, UE_Policy-MACue, and Counter. UEPolicyThe UE Policy message or information section. Alternatively, this UE Policy container may be an integrity-protected or encrypted UE Policy container, including the UE_Policy header, UE_Policy-MACue, and Sequence number. UEPolicy UE Policy messages or information section.

[0270] Step 1106: The PCF locates the AUSF based on the user's SUPI and sends a UE Policy Protection Check (Nausf_UEPolicy_Protection Check) request message to the AUSF. This message carries the UE Policy container. The AUSF performs an integrity check on the UE Policy container. If the check passes, the AUSF stores the Counter. UEPolicy Subsequently, AUSF will only accept UE Policy containers with Counter values ​​greater than this stored value, and will directly ignore UE Policy containers with Counter values ​​less than or equal to this stored value.

[0271] When the received UE Policy container contains only part of the UE Policy counter, such as only the Sequence number, AUSF needs to deduce the UE Policy counter based on the Sequence number and the high-order part of the stored UE Policy counter. AUSF performs an integrity check on the UE Policy container. If the check passes, AUSF stores the UE Policy counter. Subsequently, AUSF only accepts UE Policy containers whose estimated Counter value is greater than this stored value. AUSF directly ignores UE Policy containers whose estimated Counter value is less than or equal to this stored value.

[0272] Step 1107: AUSF returns a UE Policy Protection Check Response (Nausf_UEPolicy_Protection Check Response) message to PCF. This message carries UE Policy messages or information that are not protected by integrity or are not encrypted (referred to as clean UE Policy messages or information).

[0273] Step 1108: The PCF accepts the UE Policy Association Establishment Request message. The SMF sends the UE policy message or information to the AUSF for integrity protection, or performs integrity protection and encryption. The UE policy message or information carries information such as URSP. As shown in Figure 11, the UE policy message or information is carried in the UE Policy Protection (Nausf_UEPolicy_Protection) message.

[0274] Step 1109: AUSF returns a UE Policy Protection Response (Nausf_UEPolicy_Protection Response) message to PCF, which carries a UE Policy message that has been integrity protected or has been integrity protected and encrypted.

[0275] One possible form of the UE policy container is shown in Table 4A below, including the UE policy header field and the message verification code (denoted as UE Policy-MAC). ausf ), count value (denoted as Counter) UEPolicy The message verification code is either 128 bits or 32 bits long, the count value is 16 bits long, and the length of the UE Policy message or information section depends on the specific content it contains.

[0276] Table 4A

[0277] Alternatively, for more efficient transmission, Counter UEPolicy Only a portion of the content is transmitted in the message. Table 4B shows another possible method for the UE policy container, which only includes the sequence number (or sequence number in the UE policy counter). UEPolicy The UE policy counter is transmitted in the message, while other parts are not transmitted. The UE policy counter can be divided into two parts: the high-order part and the low-order part. The high-order part is called UE policy counter_Part 1, and the low-order part is called the Sequence number.

[0278] When the sequence number changes from all 1s to all 0s, UE policy counter_Part 1 needs to be incremented by 1. For example, the high-order part of UE policy counter_Part 1 is 24 bits long, and the low-order part of the sequence number is 8 bits long. The sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the sequence number changes back to "00000000", and the value of UE policy counter_Part 1 is incremented by 1.

[0279] Table 4B

[0280] Step 1110: The PCF returns a UE Policy Association establishment response message to the 6G-AMF. The message carries the UE Policy container, which is either an integrity-protected UE Policy container or an integrity-protected and encrypted UE Policy container.

[0281] In step 1111, the 6G-AMF returns a registration acceptance message to the UE, which carries the new GUTI, the registration area, and may also carry the UE Policy Container.

[0282] In step 1112, the UE returns a registration completion message to the 6G-AMF to confirm that the new GUTI has taken effect.

[0283] Step 1113: If the UE Policy Container was not carried in step 1111, the 6G-AMF sends an uplink NAS transfer (DL NAS TRANSPORT) message to the UE, which carries the UE Policy Container.

[0284] After receiving the UE Policy Container, the UE performs an integrity protection check on the UE Policy Container according to Kausf. If the check passes, the UE stores the Counter. UEPolicy Subsequently, the UE will only accept UE Policy containers with a Counter value greater than this stored value. For UE Policy containers with a Counter value less than or equal to this stored value, the UE will directly ignore the UE Policy container.

[0285] When the received UE Policy container contains only part of the UE Policy counter, such as only the Sequence number, the UE needs to deduce the UE Policy counter based on the Sequence number and the high-order part of the stored UE Policy counter. The UE performs an integrity check on the UE Policy container. If the check passes, the UE stores the UE Policy counter. Subsequently, the UE only accepts UE Policy containers whose estimated Counter value is greater than this stored value. The UE directly ignores UE Policy containers whose estimated Counter value is less than or equal to this stored value.

[0286] The steps in the diagram omit steps that are not related to the scheme of this application, such as the process of obtaining user subscription data between AMF and UDM, and the process of establishing data radio bearer between UE and 6G-NB.

[0287] Examples 1-2 use the UE Policy container as an example, and are also applicable to SM messages. If a new NF is added in a 5G-A or 6G network, the new message container is also applicable.

[0288] Example 2:

[0289] In this embodiment, the SMF encrypts and protects the integrity of downlink SM messages (sent from the SMF to the UE) using Kausf, and the UE decrypts and checks the integrity of downlink SM messages using Kausf.

[0290] Figure 12 is a flowchart of the implementation according to Embodiment 2 of this application, including the following steps:

[0291] Steps 1201 to 1206 are the same as steps 1001 to 1006 in Example 1-1.

[0292] Step 1207: The SMF initiates the PDU session modification process. The SMF locates the AUSF based on the UE SUPI and sends the PDU session modification request message to the AUSF for integrity protection, or performs integrity protection and encryption. The PDU session modification request message carries information such as the PDU session ID and updated QoS rules. As shown in Figure 11, this PDU session modification request message is carried in the SM protection (Nausf_SM_Protection) message.

[0293] Step 1208: AUSF returns an SM Protection Response (Nausf_SM_Protection Response) message to SMF. This message carries an SM container that has been integrity protected, or has been integrity protected and encrypted. The SM container contains an SM header field, a message authentication code (denoted as MAC-I or SM-MACausf), and a counter value (denoted as Counter). SM The SM container consists of the CAPTCHA and the SM message portion. One possible configuration for the SM container is shown in Table 5A below. In one example, the message verification code is 128 bits or 32 bits long, the count value is 16 bits long, and the length of the SM message portion depends on the specific content it contains.

[0294] Alternatively, for more efficient transmission, only a portion of the SM Counter's content can be transmitted in the message. Table 5B shows another possible approach for the SM container, where only the sequence number in the SM counter is transmitted, while other parts are not. The SM counter can be divided into two parts: a high-order part called SM counter_Part1 and a low-order part called the sequence number.

[0295] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0296] Table 5A

[0297] Table 5B

[0298] Step 1209: The 6G-SMF sends a Namf_Communication_N1N2MessageTransfer message to the 6G-AMF. The message carries the PDU session ID and SM container. The SM container is an SM container that has been protected for integrity or has been protected for integrity and encrypted.

[0299] Step 1210: The 6G-AMF sends a DL NAS TRANSPORT message to the UE, which carries the SM container that has been integrity protected or has been integrity protected and encrypted, and the PDU session ID.

[0300] Step 1211: The UE performs integrity protection verification on the SM container according to Kausf. If the verification passes, the UE stores the SM counter. Subsequently, the UE only accepts SM containers with a counter value greater than this stored value. For SM containers with a counter value less than or equal to this stored value, the UE directly ignores the SM container.

[0301] Alternatively, when the received SM container only contains part of the SM counter, such as only the sequence number, the UE needs to deduce the SM counter based on the sequence number and the high-order part of the stored SM counter. The UE performs an integrity check on the SM container. If the check passes, the UE stores the SM counter. Subsequently, the UE only accepts SM containers whose estimated counter value is greater than this stored value, and directly ignores SM containers whose estimated counter value is less than or equal to this stored value.

[0302] After the integrity verification is successful, the UE returns a UL NAS TRANSPORT message to the AMF, which carries the SM container.

[0303] The UE uses Kausf to perform integrity protection and / or encryption on SM messages and calculates the SM-MACue. The SM header needs to indicate whether the SM message has been integrity protected or integrity protected and encrypted. The UE generates an SM counter, which enables the SMF to determine whether the SM message has been replayed. The SM counter is also used as a parameter to generate the SM-MACue, and the SMF uses this SM counter to verify the SM-MACue. One possible form of the SM container is shown in Table 6A below, including the SM header field and the Message Authentication Code (SM-MAC). ue ), count value (denoted as Counter) SM The message verification code is either 128 bits or 32 bits long, the count value is 16 bits long, and the length of the SM message portion depends on the specific content it contains.

[0304] Table 6A

[0305] Alternatively, for more efficient transmission, only a portion of the SM Counter's content is transmitted within the message. Table 6B shows another possible approach for the SM container, where only the sequence number (or sequence number in the SM counter) is transmitted. SM The SM counter is transmitted in the message, while other parts are not transmitted. The SM counter can be divided into two parts: the high-order part and the low-order part. The high-order part is called SM counter_Part 1, and the low-order part is called the Sequence number.

[0306] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0307] Table 6B

[0308] The SM message portion carries a PDU session modification confirmation message.

[0309] Step 1212: The 6G-AMF sends a PDU session update SM context request (Nsmf_PDU session_UpdateSMContext_Request) message to the SMF. This message carries the PDU session ID, the SM container that has been protected for integrity or has been protected for integrity and encrypted, including the SM header, SM-MACue, SM counter or part of the SM counter information, and the SM message part.

[0310] Step 1213: The SMF returns a PDU session update SM context response (Nsmf_PDU session_UpdateSMContext_Response) message to the 6G-AMF.

[0311] Step 1214: SMF locates AUSF based on user SUPI and sends an SM protection check (Nausf_SM_Protection Check) request message to AUSF, which carries the SM container.

[0312] AUSF performs integrity checks on SM containers. If the check passes, AUSF stores the SM counter. Subsequently, AUSF only accepts SM containers with a counter value greater than this stored value, and directly ignores SM containers with a counter value less than or equal to this stored value.

[0313] Alternatively, when the received SM container only contains part of the SM counter, such as only the sequence number, AUSF needs to deduce the SM counter based on the sequence number and the high-order part of the stored SM counter. AUSF performs an integrity check on the SM container. If the check passes, AUSF stores the SM counter. Subsequently, AUSF only accepts SM containers whose estimated counter value is greater than this stored value. AUSF directly ignores SM containers whose estimated counter value is less than or equal to this stored value.

[0314] Step 1215: AUSF returns a Nausf_SM_Protection Check response message to SMF. The message carries an SM message that is not protected for integrity or is not encrypted (called a clean SM message). Here, the SM message refers to the PDU session modification confirmation message.

[0315] The steps in the diagram omit steps that are not related to the scheme of this application, such as the process of obtaining user subscription data between AMF and UDM, and the process of establishing data radio bearer between UE and 6G-NB.

[0316] Example 2 uses SM messages as an example, and it also applies to UE policies. If new NFs are added in 5G or 6G networks, the new message container also applies.

[0317] Example 3:

[0318] In this embodiment, the UE generates Ksm through Kausf and uses Ksm to encrypt and protect the integrity of uplink SM messages (sent from the UE to the SMF). The SMF generates Ksm through Kausf and uses Ksm to decrypt and check the integrity of uplink SM messages.

[0319] Figure 13 is a flowchart of the implementation according to Embodiment 3 of this application, including the following steps:

[0320] Steps 1301 to 1306 are the same as steps 1001 to 1006 in Example 1-1.

[0321] In step 1307, the UE needs to establish a PDU session. The UE uses Kausf and generates a Ksm through the Key Derivation Function (KDF), uses the Ksm to perform integrity protection and / or encryption on the SM message, and calculates the SM-MACue. Simultaneously, the SM header needs to indicate that the SM message has been integrity protected, or has been integrity protected and encrypted. The UE generates an SM counter, which enables the SMF to determine whether the SM message has been replayed. The SM counter is also used as a parameter to generate the SM-MACue, and the SMF also uses this SM counter to verify the SM-MACue.

[0322] Step 1308: The UE sends an uplink NAS transfer (UL NAS TRANSPORT) message to the 6G-AMF. This message carries the PDU session ID, S-NSSAI, DNN, and a PDU session establishment request message. The PDU session establishment request message carries the PDU session ID, the type of PDU session establishment, the PDU session type (e.g., IPv4, IPv6, IPv4v6, Ethernet, or Unstructure), S-NSSAI, DNN, etc. The PDU session establishment request message is carried using an SM container and is protected for integrity as described in step 1307, or it is protected for integrity and encrypted. One possible form of the SM container is shown in Table 7A below, including the SM header field and the Message Authentication Code (SM-MAC). ue ), count value (denoted as Counter) SM The message verification code is either 128 bits or 32 bits long, the count value is 16 bits long, and the length of the SM message portion depends on the specific content it contains.

[0323] Table 7A

[0324] Alternatively, for more efficient transmission, only a portion of the SM Counter's content is transmitted within the message. Table 7B shows another possible approach for the SM container, where only the sequence number (or sequence number in the SM counter) is transmitted. SM The SM counter is transmitted in the message, while other parts are not transmitted. The SM counter can be divided into two parts: the high-order part and the low-order part. The high-order part is called SM counter_Part 1, and the low-order part is called the Sequence number.

[0325] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0326] Table 7B

[0327] Step 1309: The 6G-AMF sends a PDU session establishment SM context request (Nsmf_PDU session_CreateSMContext_Request) message to the SMF. This message carries the PDU session ID, S-NSSAI, an SM container that has been integrity protected, or an SM container that has been integrity protected and encrypted. The SM container includes the SM header, SM-MACue, SM counter or part of the SM counter information, and the SM message part.

[0328] Step 1310: SMF looks up AUSF based on user SUPI and sends an SMF authentication request (Nausf_smf_authenticate request) message to AUSF, which carries the PDU session ID.

[0329] Step 13011: AUSF generates Ksm based on KDF and sends an SMF authentication request response (Nausf_smf_authenticate Response) message to SMF, which carries the Ksm.

[0330] Step 1312: The SMF accepts the PDU session establishment request. The SMF performs integrity protection on the PDU session establishment request message using KSM, or performs integrity protection and encryption. The PDU session establishment request message carries information such as the PDU session ID, authorized QoS rules, UE IP address, and S-NSSAI. One possible format is shown in Table 8A below, including the SM header field and the Message Authentication Code (SM-MAC). smf ), count value (denoted as Counter) SM The message verification code is either 128 bits or 32 bits long, the count value is 16 bits long, and the length of the SM message portion depends on the specific content it contains.

[0331] Table 8A

[0332] Alternatively, for more efficient transmission, Counter SM Only a portion of the content is transmitted within the message. Table 8B shows another possible method for the SM container, involving only Counter. SMThe sequence number (or sequence number) SM The Counter is transmitted in the message, while other parts are not transmitted. SM It is divided into two parts: the high-order part and the low-order part. The high-order part is called SM counter_Part 1, and the low-order part is called Sequence number.

[0333] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0334] Table 8B

[0335] The 6G-SMF returns a PDU session establishment SM context response (Nsmf_PDU session_CreateSMContext_Response) message to the 6G-AMF. This message carries the PDU session ID and the SM container. The SM container is either an SM container that has been protected for integrity or an SM container that has been protected for integrity and encrypted.

[0336] If the 6G-SMF has already returned the Nsmf_PDU session_CreateSMContext_Response message to the 6G-AMF before this step, then this step can use the N1N2 Message Transfer message to send the SM container to the SMF.

[0337] Step 1313: The 6G-AMF sends a downlink NAS TRANSPORT message to the UE. This message carries the integrity protection information, or the integrity protection information and the encrypted SM container, and the PDU session ID.

[0338] Step 1314: The UE performs integrity protection verification on the SM container according to Ksm. If the verification passes, the UE stores the SM counter. Subsequently, the UE only accepts SM containers with a counter value greater than this stored value. For SM containers with a counter value less than or equal to this stored value, the UE directly ignores the SM container.

[0339] Alternatively, when the received SM container only contains part of the SM counter, such as only the sequence number, the UE needs to deduce the SM counter based on the sequence number and the high-order part of the stored SM counter. The UE performs an integrity check on the SM container. If the check passes, the UE stores the SM counter. Subsequently, the UE only accepts SM containers whose estimated counter value is greater than this stored value, and directly ignores SM containers whose estimated counter value is less than or equal to this stored value.

[0340] The steps in the diagram omit steps that are not related to the scheme of this application, such as the process of obtaining user subscription data between AMF and UDM, and the process of establishing data radio bearer between UE and 6G-NB.

[0341] Example 3 uses SM messages as an example, and it also applies to UE policies. If new NFs are added in 5G or 6G networks, the new message container also applies.

[0342] Example 4:

[0343] In this embodiment, the SMF generates a Ksm through Kausf and uses the Ksm to encrypt and protect the integrity of downlink SM messages (sent from the SMF to the UE). The UE generates a Ksm through Kausf and uses the Ksm to decrypt and check the integrity of downlink SM messages.

[0344] Figure 14 is a flowchart of the implementation according to Embodiment 4 of this application, including the following steps:

[0345] Steps 1401 to 1406 are the same as steps 1001 to 1006 in Example 1-1.

[0346] Step 1407: The SMF initiates the PDU session modification process. The SMF locates the AUSF based on the user's SUPI and sends an SMF authentication request (Nausf_smf_authenticate Request) message to the AUSF, which carries the PDU session ID.

[0347] Step 1408: AUSF generates Ksm based on KDF and returns an SMF authentication response (Nausf_smf_authenticate Response) message to SMF, which carries the Ksm.

[0348] Step 1409: The SMF performs integrity protection on the PDU session modification request message according to the KSM, or performs integrity protection and encryption; the PDU session modification command message carries information such as the PDU session ID and updated QoS rules; a possible format is shown in Table 9A below, including the SM header field and the Message Authentication Code (SM-MAC). smf ), count value (denoted as Counter) SM The message verification code is either 128 bits or 32 bits long, the count value is 16 bits long, and the length of the SM message portion depends on the specific content it contains.

[0349] Table 9A

[0350] Alternatively, for more efficient transmission, Counter SM Only a portion of the content is transmitted within the message. Table 9B shows another possible method for the SM container, involving only Counter. SM The sequence number (or sequence number) SM The Counter is transmitted in the message, while other parts are not transmitted. SM It is divided into two parts: the high-order part and the low-order part. The high-order part is called SM counter_Part 1, and the low-order part is called the Sequence number.

[0351] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0352] Table 9B

[0353] The 6G-SMF sends a communication N1N2 message transfer message (Namf_Communication_N1N2MessageTransfer) to the 6G-AMF. This message carries the PDU session ID and the SM container. The SM container is an SM container that has been protected for integrity or has been protected for integrity and encrypted.

[0354] In step 1410, the 6G-AMF sends a DL NAS TRANSPORT message to the UE, which carries the SM container and PDU session ID.

[0355] Step 1411: The UE generates Ksm based on Kausf and performs integrity protection verification on the SM container. If the verification passes, the UE stores the SM counter. Subsequently, the UE only accepts SM containers with a counter value greater than this stored value. For SM containers with a counter value less than or equal to this stored value, the UE directly ignores the SM container.

[0356] Alternatively, when the received SM container only contains part of the SM counter, such as only the sequence number, the UE needs to deduce the SM counter based on the sequence number and the high-order part of the stored SM counter. The UE performs an integrity check on the SM container. If the check passes, the UE stores the SM counter. Subsequently, the UE only accepts SM containers whose estimated counter value is greater than this stored value. AUSF directly ignores SM containers whose estimated counter value is less than or equal to this stored value.

[0357] After the integrity verification is successful, the UE returns a UL NAS TRANSPORT message to the AMF, which carries the SM container.

[0358] The UE uses KSM to perform integrity protection and / or encryption on SM messages and calculates the SM-MACue. The SM header needs to indicate whether the SM message has been integrity protected or has been both integrity protected and encrypted. The UE generates an SM counter, which enables the SMF to determine whether the SM message has been replayed. The SM counter is also used as a parameter to generate the SM-MACue, and the SMF uses this SM counter to verify the SM-MACue. One possible approach is shown in Table 10A below, including the SM header field and the Message Authentication Code (SM-MACue). ue ), count value (denoted as Counter) SM The message verification code is either 128 bits or 32 bits long, the count value is 16 bits long, and the length of the SM message portion depends on the specific content it contains.

[0359] Table 10A

[0360] Alternatively, for more efficient transmission, Counter SM Only a portion of the content is transmitted within the message. Table 10B shows another possible method for the SM container, involving only Counter. SM The sequence number (or sequence number) SM The Counter is transmitted in the message, while other parts are not transmitted. SM It is divided into two parts: the high-order part and the low-order part. The high-order part is called SM counter_Part 1, and the low-order part is called the Sequence number.

[0361] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0362] Table 10B

[0363] The SM message portion carries a PDU session modification confirmation message.

[0364] Step 1412: The 6G-AMF sends a PDU session update SM context request (Nsmf_PDU session_UpdateSMContext_Request) message to the SMF. This message carries the PDU session ID, an SM container that has been protected for integrity, or an SM container that has been protected for integrity and encrypted. The SM container includes the SM header, SM-MACue, SM counter or part of the SM counter information, and the SM message part.

[0365] Step 1413: The SMF returns a PDU session update SM context response (Nsmf_PDU session_UpdateSMContext_Response) message to the 6G-AMF.

[0366] The steps in the diagram omit steps that are not related to the scheme of this application, such as the process of obtaining user subscription data between AMF and UDM, and the process of establishing data radio bearer between UE and 6G-NB.

[0367] Example 4 uses SM messages as an example, and it also applies to UE policies. If new NFs are added in 5G or 6G networks, the new message container also applies.

[0368] Example 5:

[0369] In this embodiment, the UE generates Ksm through Kamf and uses Ksm to encrypt and protect the integrity of uplink SM messages (sent from SMF to UE). The UE generates Ksm through Kausf and uses Ksm to decrypt and check the integrity of downlink SM messages.

[0370] Figure 15 is a flowchart of the implementation according to Embodiment 5 of this application, including the following steps:

[0371] Steps 1501 to 1506 are the same as steps 1001 to 1006 in Example 1-1.

[0372] In step 1507, the UE needs to establish a PDU session. The UE uses Kausf and generates a Ksm through the Key Derivation Function (KDF), uses the Ksm to perform integrity protection and / or encryption on the SM message, and calculates the SM-MACue. Simultaneously, the SM header needs to indicate that the SM message has been integrity protected, or has been integrity protected and encrypted. The UE generates an SM counter, which enables the SMF to determine whether the SM message has been replayed. The SM counter is also used as a parameter to generate the SM-MACue, and the SMF also uses this SM counter to verify the SM-MACue.

[0373] S1508, the UE sends an uplink NAS transfer (UL NAS TRANSPORT) message to the 6G-AMF. This message carries the PDU session ID, S-NSSAI, DNN, and a PDU session establishment request message. The PDU session establishment request message carries the PDU session ID, the type of PDU session establishment, the PDU session type (e.g., IPv4, IPv6, IPv4v6, Ethernet, or Unstructure), S-NSSAI, DNN, etc. The PDU session establishment request message is carried using an SM container and is protected for integrity as described in step 1507, or it is protected for integrity and encrypted. One possible form of the SM container is shown in Table 11A below, including the SM header field and the Message Authentication Code (SM-MAC). ue ), count value (denoted as Counter) SMThe message verification code is either 128 bits or 32 bits long, the count value is 16 bits long, and the length of the SM message portion depends on the specific content it contains.

[0374] Table 11A

[0375] Alternatively, for more efficient transmission, Counter SM Only a portion of the content is transmitted within the message. Table 11B shows another possible method for the SM container, involving only Counter. SM The sequence number (or sequence number) SM The Counter is transmitted in the message, while other parts are not transmitted. SM It is divided into two parts: the high-order part and the low-order part. The high-order part is called SM counter_Part 1, and the low-order part is called the Sequence number.

[0376] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0377] Table 11B

[0378] Step 1509: The 6G-AMF sends a PDU session establishment SM context request (Nsmf_PDU session_CreateSMContext_Request) message to the SMF. This message carries the PDU session ID, S-NSSAI, an SM container that has been integrity protected, or an SM container that has been integrity protected and encrypted. The SM container includes the SM header, SM-MACue, SM counter or part of the SM counter information, and the SM message part.

[0379] Step 1510: The SMF sends an SM authentication request (Namf_smf_authenticate Request) message to the AMF, which carries the PDU session ID.

[0380] Step 1511: AMF generates Ksm based on KDF and returns an SM authentication response (Namf_smf_authenticate Response) message to SMF, which carries the Ksm.

[0381] Another approach is to directly include Ksm in step 1509, which eliminates the need for steps 1510-1511.

[0382] Step 1512: The SMF accepts the PDU session establishment. The SMF uses KSM to perform integrity protection on the PDU session establishment acceptance message, or performs integrity protection and encryption. The PDU session establishment acceptance message carries information such as PDU session ID, authorized QoS rules, UE IP address, and S-NSSAI.

[0383] One possible format is shown in Table 12A below, including the SM header and the Message Authentication Code (SM-MAC). smf ), count value (denoted as Counter) SM The message verification code is either 128 bits or 32 bits long, the count value is 16 bits long, and the length of the SM message portion depends on the specific content it contains.

[0384] Table 12A

[0385] Alternatively, for more efficient transmission, Counter SM Only a portion of the content is transmitted within the message. Table 12B shows another possible method for the SM container, involving only Counter. SM The sequence number (or sequence number) SM The Counter is transmitted in the message, while other parts are not transmitted. SM It is divided into two parts: the high-order part and the low-order part. The high-order part is called SM counter_Part 1, and the low-order part is called the Sequence number.

[0386] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0387] Table 12B

[0388] The 6G-SMF returns an Nsmf_PDU session_CreateSMContext_Response message to the 6G-AMF. The message carries the PDU session ID and the SM container. The SM container is either an SM container that has been protected for integrity or an SM container that has been protected for integrity and encrypted.

[0389] If the 6G-SMF has already returned the Nsmf_PDU session_CreateSMContext_Response message to the 6G-AMF before this step, then this step can use the Namf_Communication_N1N2MessageTransfer message to send the SM container to the SMF.

[0390] In step 1513, the 6G-AMF sends a DL NAS TRANSPORT message to the UE, which carries the SM container and PDU session ID.

[0391] Step 1514: The UE performs integrity protection verification on the SM container according to Ksm. If the verification passes, the UE stores the SM counter. Subsequently, the UE only accepts SM containers with a counter value greater than this stored value. For SM containers with a counter value less than or equal to this stored value, the UE directly ignores the SM container.

[0392] Alternatively, when the received SM container only contains part of the SM counter, such as only the sequence number, the UE needs to deduce the SM counter based on the sequence number and the high-order part of the stored SM counter. The UE performs an integrity check on the SM container. If the check passes, the UE stores the SM counter. Subsequently, the UE only accepts SM containers whose estimated counter value is greater than this stored value, and directly ignores SM containers whose estimated counter value is less than or equal to this stored value.

[0393] The steps in the diagram omit steps that are not related to the scheme of this application, such as the process of obtaining user subscription data between AMF and UDM, and the process of establishing data radio bearer between UE and 6G-NB.

[0394] Example 5 uses SM messages as an example, and it also applies to UE policies. If new NFs are added in 5G or 6G networks, the new message container also applies.

[0395] Example 6:

[0396] In this embodiment, the SMF generates a Ksm through Kamf and uses the Ksm to encrypt and protect the integrity of downlink SM messages (sent from the SMF to the UE). The UE generates a Ksm through Kamf and uses the Ksm to decrypt and check the integrity of downlink SM messages.

[0397] Figure 16 is a flowchart of the implementation according to Embodiment 6 of this application, including the following steps:

[0398] Steps 1601 to 1606 are the same as steps 1001 to 1006 in Example 1-1.

[0399] Step 1607: The SMF initiates the PDU session modification process. The SMF sends an SM authentication request (Namf_smf_authenticate Request) message to the AMF, which carries the PDU session ID.

[0400] Step 1608: AMF generates Ksm based on KDF and returns an SM authentication response (Namf_smf_authenticate Response) message to SMF, which carries the Ksm.

[0401] Step 1609: The SMF performs integrity protection on the PDU session modification request message according to the KSM, or performs integrity protection and encryption; the PDU session modification command message carries information such as the PDU session ID and updated QoS rules; a possible format is shown in Table 13A below, including the SM header field and the Message Authentication Code (SM-MAC). smf ), count value (denoted as Counter) SM The message verification code is either 128 bits or 32 bits long, the count value is 16 bits long, and the length of the SM message portion depends on the specific content it contains.

[0402] Table 13A

[0403] Alternatively, for more efficient transmission, Counter SM Only a portion of the content is transmitted within the message. Table 13B shows another possible method for the SM container, involving only Counter. SM The sequence number (or sequence number) SM The Counter is transmitted in the message, while other parts are not transmitted. SM It is divided into two parts: the high-order part and the low-order part. The high-order part is called SM counter_Part 1, and the low-order part is called the Sequence number.

[0404] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0405] Table 13B

[0406] The 6G-SMF sends a Namf_Communication_N1N2MessageTransfer message to the 6G-AMF. This message carries the PDU session ID and the SM container. The SM container is an SM container that has been protected for integrity or has been protected for integrity and encrypted.

[0407] Step 1610: The 6G-AMF sends a DL NAS TRANSPORT message to the UE, which carries the SM container and PDU session ID.

[0408] Step 1611: The UE generates Ksm based on Kamf and KDF, and performs integrity protection verification on the SM container. If the verification passes, the UE stores the SM counter. Subsequently, the UE only accepts SM containers with a counter value greater than this stored value. For SM containers with a counter value less than or equal to this stored value, the UE directly ignores the SM container.

[0409] Alternatively, when the received SM container only contains part of the SM counter, such as only the sequence number, the UE needs to deduce the SM counter based on the sequence number and the high-order part of the stored SM counter. The UE performs an integrity check on the SM container. If the check passes, the UE stores the SM counter. Subsequently, the UE only accepts SM containers whose estimated counter value is greater than this stored value, and directly ignores SM containers whose estimated counter value is less than or equal to this stored value.

[0410] After the integrity verification passes, the UE returns a UL NAS TRANSPORT message to the AMF, which carries the SM container.

[0411] The UE uses KSM to perform integrity protection and / or encryption on SM messages and calculates the SM-MACue. The SM header needs to indicate whether the SM message has been integrity protected or has been both integrity protected and encrypted. The UE generates an SM counter, which enables the SMF to determine whether the SM message has been replayed. The SM counter is also used as a parameter to generate the SM-MACue, and the SMF uses this SM counter to verify the SM-MACue. One possible approach is shown in Table 14A below, including the SM header field and the Message Authentication Code (SM-MACue). ue ), count value (denoted as Counter) SM The message verification code is either 128 bits or 32 bits long, the count value is 16 bits long, and the length of the SM message portion depends on the specific content it contains.

[0412] Table 14A

[0413] Alternatively, for more efficient transmission, Counter SM Only a portion of the content is transmitted within the message. Table 14B shows another possible method for the SM container, involving only Counter. SM The sequence number (or sequence number) SM The Counter is transmitted in the message, while other parts are not transmitted. SM It is divided into two parts: the high-order part and the low-order part. The high-order part is called SM counter_Part 1, and the low-order part is called the Sequence number.

[0414] When the sequence number changes from all 1s to all 0s, SM counter_Part 1 needs to be incremented by 1. For example, the length of the high-order part of SM counter_Part 1 is 24 bits, and the length of the low-order part of the sequence number is 8 bits. The value of the sequence number starts from "00000000" and increases sequentially. When it increases to "11111111", the value of the sequence number changes back to "00000000", and at this time, the value of SM counter_Part 1 is incremented by 1.

[0415] Table 14B

[0416] The SM message portion carries a PDU session modification confirmation message.

[0417] Step 1612: The 6G-AMF sends a PDU session update SM context request (Nsmf_PDU session_UpdateSMContext_Request) message to the SMF. This message carries the PDU session ID, an SM container that has been protected for integrity, or an SM container that has been protected for integrity and encrypted. The SM container includes the SM header, SM-MACue, SM counter or part of the SM counter information, and the SM message part.

[0418] Step 1613: The SMF returns a PDU session update SM context response (Nsmf_PDU session_UpdateSMContext_Response) message to the 6G-AMF.

[0419] The steps in the diagram omit steps that are not related to the scheme of this application, such as the process of obtaining user subscription data between AMF and UDM, and the process of establishing data radio bearer between UE and 6G-NB.

[0420] Example 6 uses SM messages as an example, and it also applies to UE policies. If new NFs are added in 5G or 6G networks, new message containers also apply.

[0421] This application also proposes a terminal device. FIG17 is a schematic block diagram of a terminal device 1700 according to an embodiment of this application. The terminal device 1700 may include:

[0422] The first transceiver module 1710 is used to send a protected first message to the first network element.

[0423] In some implementations, the protected first message includes a first message that is integrity protected and / or encrypted by the terminal device.

[0424] In some implementations, the first message includes at least one of the following:

[0425] SM message;

[0426] UE policy message or UE policy information.

[0427] In some implementations, the first transceiver module 1710 is used to send a first NAS transmission message to a first network element, the first NAS transmission message carrying a protected first message.

[0428] In some implementations, the first NAS transmission message carries a protected first message, including:

[0429] The first NAS transmission message carries an SM container, which contains a protected first message; or...

[0430] The first NAS transmission message carries a UE policy container, which contains a protected first message.

[0431] In one example, the first NAS transmission message includes an uplink NAS transmission message.

[0432] In some implementations, the first transceiver module 1710 is used to send a security mode completion message to the first network element, the security mode completion message carrying a registration request message; the registration request message carrying a protected first message.

[0433] In some implementations, the registration request message carries a protected first message, including:

[0434] The registration request message carries an SM container, which contains a protected first message; or,

[0435] The registration request message carries a UE policy container, which contains a protected first message.

[0436] In some implementations, the SM container or the UE policy container further includes at least one of the following:

[0437] Message verification code generated by the terminal device;

[0438] The SM count value generated by the terminal device or a portion of the SM count value.

[0439] In some implementations, the UE policy container also includes at least one of the following:

[0440] Message verification code generated by the terminal device;

[0441] The UE policy count value generated by the terminal device or a portion of the UE policy count value.

[0442] In some implementations, the protected first message (SM) includes:

[0443] The terminal device performs integrity protection and / or encryption on the message based on Kausf or Ksm; the terminal device generates Ksm based on Kausf or Kamf.

[0444] In some implementations, the protected first message (UE policy) includes:

[0445] The terminal device performs integrity protection and / or encryption on the message based on Kausf or Kuepolicy; the terminal device generates Kuepolicy based on Kausf or Kamf.

[0446] In some implementations, the first network element includes an AMF.

[0447] The terminal device 1700 of this application embodiment can realize the corresponding functions of the terminal device in the foregoing method embodiments. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in the terminal device 1700 can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the terminal device 1700 of the application embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).

[0448] Figure 18 is a schematic block diagram of a terminal device 1800 according to an embodiment of the present application. The terminal device 1800 may include:

[0449] The second transceiver module 1810 is used to receive the protected first message sent by the first network element.

[0450] In some implementations, the protected first message includes a first message that is integrity protected and / or encrypted by a second network element.

[0451] This application also proposes a terminal device. FIG19 is a schematic block diagram of a terminal device 1900 according to an embodiment of this application. The terminal device 1900 may include: a second transceiver module 1810 and a first processing module 1920: wherein,

[0452] The first processing module 1920 is used to decrypt and / or verify the integrity of the protected first message.

[0453] In some implementations, the first message includes at least one of the following:

[0454] SM message;

[0455] UE policy message or UE policy information.

[0456] In some implementations, the second transceiver module 1810 is used to receive a second NAS transmission message sent by the first network element, the second NAS transmission message carrying a protected first message.

[0457] In some implementations, the second NAS transmission message carries a protected first message, including:

[0458] The second NAS transmission message carries an SM container, which contains a protected first message; or...

[0459] The second NAS transmission message carries a UE policy container, which contains a protected first message.

[0460] In one example, the second NAS transport message includes a downlink NAS transport message.

[0461] In some implementations, the second transceiver module 1810 is used to receive a registration acceptance message sent by the first network element, the registration request message carrying a protected first message.

[0462] In some implementations, the registration request message carries a protected first message, including:

[0463] Register to accept messages carrying an SM container, which contains a protected first message; or...

[0464] The registration accept message carries a UE policy container, which contains a protected first message.

[0465] In some implementations, the SM container or the UE policy container further includes at least one of the following:

[0466] The message verification code generated by the second network element;

[0467] The second network element generates the SM count value or a portion of the SM count value.

[0468] In some implementations, the first processing module 1920 is further configured to store the SM count value after performing an integrity protection check on the protected first message.

[0469] In some implementations, the UE policy container also includes at least one of the following:

[0470] The message verification code generated by the second network element;

[0471] The second network element generates the UE policy count value or a portion of the UE policy count value.

[0472] In some implementations, the first processing module 1920 is further configured to store the UE policy count value after performing integrity protection verification on the protected first message.

[0473] In some implementations, the first network element includes an SMF or a PCF.

[0474] In some implementations, the second network element includes an AMF.

[0475] Terminal devices 1800 and 1900 in this application embodiment can implement the corresponding functions of the terminal devices in the aforementioned method embodiments. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in terminal devices 1800 and 1900 can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described in the various modules (sub-modules, units, or components, etc.) of terminal devices 1800 and 1900 in the application embodiments can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).

[0476] Figure 20 is a schematic block diagram of a second network element 2000 according to an embodiment of the present application. The second network element 2000 may include:

[0477] The third transceiver module 2010 is used to send the protected first message to the first network element.

[0478] In some implementations, the first message includes at least one of the following:

[0479] SM message;

[0480] UE policy message or UE policy information.

[0481] In some implementations, the third transceiver module 2010 is also used to send a first message to a third network element and receive a protected first message sent by the third network element.

[0482] In some implementations, the third transceiver module 2010 is used to send an SM protection message or a UE policy protection message to a third network element, wherein the SM protection message or the UE policy protection message carries a first message.

[0483] In some implementations, the third transceiver module 2010 is used to receive an SM protection response message or a UE policy protection response message sent by a third network element, wherein the SM protection response message or the UE policy protection response message carries a protected first message.

[0484] This application also proposes a second network element. Figure 21 is a schematic block diagram of a second network element 2100 according to an embodiment of this application. The second network element 2100 may include: a third transceiver module 2010 and a second processing module 2120: wherein,

[0485] The third transceiver module 2010 is also used to send authentication request messages to the third network element or the first network element; and to receive authentication response messages sent by the third network element or the first network element, wherein the authentication response messages carry a key.

[0486] The second processing module 2120 is used to perform integrity protection and / or encryption on the first message using a key.

[0487] In some implementations, the third transceiver module 2010 is used to send a PDU session establishment SM context response message to the first network element, the PDU session establishment SM context response message carrying an SM container containing a protected first message; or, to send a communication N1N2 message transmission message to the first network element, the communication N1N2 message transmission message carrying an SM container containing a protected first message.

[0488] In some implementations, the SM container further includes at least one of the following:

[0489] The message verification code generated by the second network element;

[0490] The second network element generates the SM count value or a portion of the SM count value.

[0491] In some implementations, the third transceiver module 2010 is used to send a UE policy association establishment response message to the first network element. The UE policy association establishment response message carries a UE policy container, and the UE policy container contains a protected first message.

[0492] In some implementations, the UE policy container also includes at least one of the following:

[0493] The message verification code generated by the second network element;

[0494] The second network element generates the UE policy count value or a portion of the UE policy count value.

[0495] In some implementations, the first network element includes an SMF or a PCF.

[0496] In some implementations, the second network element includes an AMF.

[0497] In some implementations, the third network element includes AUSF.

[0498] The second network element 2000 and the second network element 2100 in this application embodiment can realize the corresponding functions of the second network element in the aforementioned method embodiment. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in the second network element 2000 and the second network element 2100 can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the second network element 2000 and the second network element 2100 in this application embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).

[0499] Figure 22 is a schematic block diagram of a second network element 2200 according to an embodiment of the present application. The second network element 2200 may include:

[0500] The fourth transceiver module 2210 is used to receive the protected first message sent by the first network element.

[0501] In some implementations, the protected first message includes a first message that is integrity protected and / or encrypted by the terminal device.

[0502] In some implementations, the first message includes at least one of the following:

[0503] SM message;

[0504] UE policy message or UE policy information.

[0505] In some implementations, the fourth transceiver module 2210 is used to receive a PDU session establishment or SM context update request message sent by the first network element, the PDU session establishment or SM context update request message carrying a protected first message.

[0506] In some implementations, the PDU session establishment or SM context update request message carries a protected first message, including:

[0507] The PDU session establishment or SM context update request message carries an SM container, which contains a protected first message; or...

[0508] The PDU session establishment or SM context update request message carries a UE policy container, which contains a protected first message.

[0509] In some implementations, the fourth transceiver module 2210 is used to receive a UE policy association establishment request message sent by the first network element, the UE policy association establishment request message carrying a protected first message.

[0510] In some implementations, the UE policy association establishment request message carries a protected first message, including:

[0511] The UE policy association establishment request message carries an SM container, which contains a protected first message; or...

[0512] The UE policy association establishment request message carries a UE policy container, which contains a protected first message.

[0513] In some implementations, the SM container further includes at least one of the following:

[0514] Message verification code generated by the terminal device;

[0515] The SM count value generated by the terminal device or a portion of the SM count value.

[0516] In some implementations, the UE policy container also includes at least one of the following:

[0517] Message verification code generated by the terminal device;

[0518] The UE policy count value generated by the terminal device or a portion of the UE policy count value.

[0519] In some implementations, the fourth transceiver module 2210 is used to request the third network element or the first network element to perform integrity protection verification and / or decryption on the protected first message.

[0520] In some implementations, the fourth transceiver module 2210 is used to send a protection verification request message to the third network element, the protection verification message carrying a protected first message; and to receive a protection verification response message sent by the third network element, the protection verification response message carrying a first message that has not been integrity protected and / or is not encrypted.

[0521] In some implementations, the first network element includes an SMF or a PCF.

[0522] In some implementations, the second network element includes an AMF.

[0523] In some implementations, the third network element includes AUSF.

[0524] The second network element 2200 in this embodiment can realize the corresponding function of the second network element in the aforementioned method embodiment. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in the second network element 2200 can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the second network element 2200 of this embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).

[0525] Figure 23 is a schematic block diagram of a third network element 2300 according to an embodiment of the present application. The third network element 2300 may include:

[0526] The fourth processing module 2310 is used to protect the first message based on the request from the second network element.

[0527] In some implementations, the fourth processing module 2310 is used to perform integrity protection and / or encryption on the first message;

[0528] The third network element 2300 also includes a fifth transceiver module 2320, which is used to receive the first message sent by the second network element and send the first message to the second network element after integrity protection and / or encryption.

[0529] In some implementations, the fifth transceiver module 2320 is used to receive an authentication request message sent by the second network element, and send an authentication response message to the second network element. The authentication response message carries a key, which is used to protect the integrity of the first message and / or encrypt it.

[0530] In some implementations, the second network element includes an AMF.

[0531] In some implementations, the third network element includes AUSF.

[0532] The third network element 2300 in this embodiment can realize the corresponding function of the third network element in the aforementioned method embodiment. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in the third network element 2300 can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the third network element 2300 of this embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).

[0533] Figure 24 is a schematic block diagram of a third network element 2400 according to an embodiment of the present application. The third network element 2400 may include:

[0534] The fifth processing module 2410 is used to perform integrity protection verification and / or decryption on the protected first message based on the request of the second network element.

[0535] In some implementations, the protected first message includes a first message that is integrity protected and / or encrypted by the terminal device.

[0536] In some implementations, the second network element includes an AMF.

[0537] In some implementations, the third network element includes AUSF.

[0538] The third network element 2400 in this application embodiment can realize the corresponding function of the third network element in the foregoing method embodiment. The processes, functions, implementation methods, and beneficial effects of each module (sub-module, unit, or component, etc.) in the third network element 2400 can be found in the corresponding descriptions in the above method embodiments, and will not be repeated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the third network element 2400 of the application embodiment can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.).

[0539] Figure 25 is a schematic structural diagram of a communication device 2500 according to an embodiment of this application. The communication device 2500 includes a processor 2510, which can call and run computer programs from memory to enable the communication device 2500 to implement the methods in the embodiments of this application.

[0540] In one embodiment, the communication device 2500 may further include a memory 2520. The processor 2510 can retrieve and run computer programs from the memory 2520 to enable the communication device 2500 to implement the methods described in the embodiments of this application.

[0541] The memory 2520 can be a separate device independent of the processor 2510, or it can be integrated into the processor 2510.

[0542] In one embodiment, the communication device 2500 may further include a transceiver 2530, and the processor 2510 may control the transceiver 2530 to communicate with other devices. Specifically, it may send information or data to other devices or receive information or data sent by other devices.

[0543] The transceiver 2530 may include a transmitter and a receiver. The transceiver 2530 may further include an antenna, which may be one or more.

[0544] In one embodiment, the communication device 2500 may be a network device in the embodiments of this application, and the communication device 2500 may implement the corresponding processes implemented by the network device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0545] In one embodiment, the communication device 2500 may be a terminal device in the embodiments of this application, and the communication device 2500 may implement the corresponding processes implemented by the terminal device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0546] Figure 26 is a schematic structural diagram of a chip 2600 according to an embodiment of this application. The chip 2600 includes a processor 2610, which can call and run computer programs from memory to implement the methods in the embodiments of this application.

[0547] In one embodiment, chip 2600 may further include memory 2620. Processor 2610 can retrieve and run computer programs from memory 2620 to implement the methods executed by the terminal device or network device in this embodiment.

[0548] The memory 2620 can be a separate device independent of the processor 2610, or it can be integrated into the processor 2610.

[0549] In one embodiment, the chip 2600 may further include an input interface 2630. The processor 2610 can control the input interface 2630 to communicate with other devices or chips; specifically, it can acquire information or data sent by other devices or chips.

[0550] In one embodiment, the chip 2600 may further include an output interface 2640. The processor 2610 can control the output interface 2640 to communicate with other devices or chips; specifically, it can output information or data to other devices or chips.

[0551] In one implementation, the chip can be applied to the network device in the embodiments of this application, and the chip can implement the corresponding processes implemented by the network device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0552] In one embodiment, the chip can be applied to the terminal device in the embodiments of this application, and the chip can implement the corresponding processes implemented by the terminal device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0553] The chips used in network equipment and terminal equipment can be the same chip or different chips.

[0554] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0555] The processors mentioned above can be general-purpose processors, digital signal processors (DSPs), field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), or other programmable logic devices, transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processors mentioned above can be microprocessors or any conventional processor.

[0556] The aforementioned memory can be volatile memory or non-volatile memory, or a combination of both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM).

[0557] It should be understood that the above-described memory is exemplary and not a limiting description. For example, the memory in the embodiments of this application may also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DR RAM), etc. That is to say, the memory in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.

[0558] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. This computer program product includes one or more computer instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, Digital Subscriber Line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).

[0559] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0560] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0561] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A transmission method, comprising: sending, by a terminal device, a protected first message to a first network element.

2. The method of claim 1, wherein, The protected first message comprises a first message that is integrity protected and / or encrypted by the terminal device.

3. The method of claim 1 or 2, wherein, The first message comprises at least one of: a session management (SM) message; a user equipment (UE) policy message or UE policy information.

4. The method of any one of claims 1-3, wherein, The sending, by the terminal device, of the protected first message to the first network element comprises: sending, by the terminal device, a first non-access stratum (NAS) transport message to the first network element, the first NAS transport message carrying the protected first message.

5. The method of claim 4, wherein, The carrying, by the first NAS transport message, of the protected first message comprises: the first NAS transport message carrying an SM container, the SM container containing the protected first message; or the first NAS transport message carrying a UE policy container, the UE policy container containing the protected first message.

6. The method of any one of claims 1-3, wherein, The sending, by the terminal device, of the protected first message to the first network element comprises: sending, by the terminal device, a security mode complete message to the first network element, the security mode complete message carrying a registration request message; The carrying, by the registration request message, of the protected first message comprises:

7. The method of claim 6, wherein, the registration request message carrying an SM container, the SM container containing the protected first message; or the registration request message carrying a UE policy container, the UE policy container containing the protected first message. The SM container further contains at least one of:

8. The method of claim 5 or 7, wherein, a message authentication code generated by the terminal device; an SM count value or part of the SM count value generated by the terminal device. The UE policy container further contains at least one of:

9. The method of claim 5 or 7, wherein, a message authentication code generated by the terminal device; a UE policy count value or part of the UE policy count value generated by the terminal device. The protected first message comprises:

10. The method of claim 1, wherein, a message that is integrity protected and / or encrypted by the terminal device according to a key of an authentication server function (AUSF) or a key of an SM, the key of the SM being generated by the terminal device according to a key of the AUSF or a key of an access and mobility management function (AMF). The protected first message comprises:

11. The method of claim 1, wherein, a message that is integrity protected and / or encrypted by the terminal device according to a key of an AUSF or a key of a UE policy, the key of the UE policy being generated by the terminal device according to a key of the AUSF or a key of an AMF. The first network element comprises an AMF.

12. The method of any one of claims 1-11, wherein, 13.A transmission method, comprising: receiving, by a terminal device, a protected first message sent by a first network element. The protected first message comprises a first message that is integrity protected and / or encrypted by a second network element.

14. The method of claim 13, wherein, 15.The method of claim 13 or 14, further comprising decrypting and / or integrity protection checking, by the terminal device, the protected first message. The first message comprises at least one of:

16. The method of claim 13 or 14, wherein, an SM message; ​ The UE policy message or the UE policy information.

17. The method of any one of claims 13-16, wherein, The terminal device receives the protected first message sent by the first network element, including: The terminal device receives the second NAS transport message sent by the first network element, and the second NAS transport message carries the protected first message.

18. The method of claim 17, wherein, The second NAS transport message carries the protected first message, including: The second NAS transport message carries an SM container, and the SM container contains the protected first message; or The second NAS transport message carries a UE policy container, and the UE policy container contains the protected first message.

19. The method of any one of claims 13-16, wherein, The terminal device receives the protected first message sent by the first network element, including: The terminal device receives the registration accept message sent by the first network element, and the registration request message carries the protected first message.

20. The method of claim 19, wherein, The registration request message carries the protected first message, including: The registration accept message carries an SM container, and the SM container contains the protected first message; or The registration accept message carries a UE policy container, and the UE policy container contains the protected first message.

21. The method of claim 18 or 20, wherein, The SM container further contains at least one of the following: A message verification code generated by the second network element; An SM count value or part of the SM count value generated by the second network element.

22. The method of claim 21, further comprising, The terminal device stores the SM count value after the integrity protection check on the protected first message.

23. The method of claim 18 or 20, wherein, The UE policy container further contains at least one of the following: A message verification code generated by the second network element; A UE policy count value or part of the UE policy count value generated by the second network element.

24. The method of claim 23, further comprising, The terminal device stores the UE policy count value after the integrity protection check on the protected first message.

25. The method of any one of claims 13-24, wherein, The first network element includes a session management function (SMF) or a policy control function (PCF).

26. The method of claim 14, wherein, The second network element includes an AMF.

27. A transmission method, comprising: The second network element sends a protected first message to the first network element.

28. The method of claim 27, wherein, The first message includes at least one of the following: An SM message; A UE policy message or UE policy information.

29. The method of claim 27 or 28, before the second network element sends the protected first message to the first network element, further comprising: The second network element sends the first message to a third network element; The second network element receives the protected first message sent by the third network element.

30. The method of claim 29, wherein, The second network element sends the first message to the third network element, including: The second network element sends an SM protection message or a UE policy protection message to the third network element, and the SM protection message or the UE policy protection message carries the first message.

31. The method of claim 29, wherein, The second network element receives the protected first message sent by the third network element, including: The second network element receives an SM protection response message or a UE policy protection response message sent by the third network element, and the SM protection response message or the UE policy protection response message carries the protected first message.

32. The method of claim 27 or 28, before the second network element sending the protected first message to the first network element, further comprising: the second network element sending an authentication request message to a third network element or the first network element; the second network element receiving an authentication response message sent by the third network element or the first network element, the authentication response message carrying a key; the second network element performing integrity protection and / or encryption on the first message by using the key.

33. The method of any one of claims 27-32, wherein, the second network element sending the protected first message to the first network element, comprising: the second network element sending a PDU session establishment SM context response message to the first network element, the PDU session establishment SM context response message carrying an SM container, the SM container containing the protected first message; or the second network element sending a communication N1N2 message transfer message to the first network element, the communication N1N2 message transfer message carrying an SM container, the SM container containing the protected first message.

34. The method of claim 33, wherein, the SM container further containing at least one of: a message authentication code generated by the second network element; an SM sequence value or part of the SM sequence value generated by the second network element.

35. The method of any one of claims 27-32, wherein, the second network element sending the protected first message to the first network element, comprising: the second network element sending a UE policy association establishment response message to the first network element, the UE policy association establishment response message carrying a UE policy container, the UE policy container containing the protected first message.

36. The method of claim 35, wherein, the UE policy container further containing at least one of: a message authentication code generated by the second network element; a UE policy sequence value or part of the UE policy sequence value generated by the second network element.

37. The method of any one of claims 27-36, wherein, the first network element comprising an SMF or a PCF.

38. The method of any one of claims 27-36, wherein, the second network element comprising an AMF.

39. The method of any one of claims 29-32, wherein, the third network element comprising an AUSF.

40. A transmission method, comprising: a second network element receiving a protected first message sent by a first network element.

41. The method of claim 40, wherein, the protected first message comprising a first message that is integrity protected and / or encrypted by a terminal device.

42. The method of claim 40 or 41, wherein, the first message comprising at least one of: an SM message; a UE policy message or UE policy information.

43. The method of any one of claims 40-42, wherein, the second network element receiving the protected first message sent by the first network element, comprising: the second network element receiving a PDU session establishment or update SM context request message sent by the first network element, the PDU session establishment or update SM context request message carrying the protected first message.

44. The method of claim 43, wherein, the PDU session establishment or update SM context request message carrying the protected first message, comprising: the PDU session establishment or update SM context request message carrying an SM container, the SM container containing the protected first message; or the PDU session establishment or update SM context request message carrying a UE policy container, the UE policy container containing the protected first message.

45. The method of any one of claims 40-42, wherein, the second network element receiving the protected first message sent by the first network element, comprising: The second network element receives a UE policy association establishment request message sent by the first network element, and the UE policy association establishment request message carries the protected first message.

46. The method of claim 45, wherein, The UE policy association establishment request message carries the protected first message, including: The UE policy association establishment request message carries an SM container, and the SM container contains the protected first message; or The UE policy association establishment request message carries a UE policy container, and the UE policy container contains the protected first message.

47. The method of claim 44 or 46, wherein, The SM container further contains at least one of: A message verification code generated by the terminal device; An SM count value or part of the SM count value generated by the terminal device.

48. The method of claim 44 or 46, wherein, The UE policy container further contains at least one of: A message verification code generated by the terminal device; A UE policy count value or part of the UE policy count value generated by the terminal device.

49. The method of any one of claims 40-48, further comprising, The second network element requests the third network element or the first network element to perform integrity protection verification and / or decryption on the protected first message.

50. The method of claim 49, wherein, The second network element requests the third network element to perform integrity protection verification and / or decryption on the protected first message, including: The second network element sends a protection verification request message to the third network element, and the protection verification message carries the protected first message; The second network element receives a protection verification response message sent by the third network element, and the protection verification response message carries the first message that is not subjected to integrity protection and / or encryption.

51. The method of any one of claims 40-50, wherein, The first network element includes an SMF or a PCF.

52. The method of any one of claims 40-50, wherein, The second network element includes an AMF.

53. The method of claim 49 or 50, wherein, The third network element includes an AUSF.

54. A transmission method, comprising: The third network element protects the first message based on a request of the second network element.

55. The method of claim 54, wherein, The third network element protects the first message based on a request of the second network element, including: The third network element receives a first message sent by the second network element; The third network element performs integrity protection and / or encryption on the first message; The third network element sends the first message subjected to integrity protection and / or encryption to the second network element.

56. The method of claim 54 or 55, wherein the third network element protects the first message based on a request of the second network element, including: The third network element receives an authentication request message sent by the second network element; The third network element sends an authentication response message to the second network element, and the authentication response message carries a key used for integrity protection and / or encryption on the first message.

57. The method of any one of claims 54-56, wherein, The second network element includes an AMF.

58. The method of any one of claims 54-56, wherein, The third network element includes an AUSF.

59. A transmission method, comprising: The third network element performs integrity protection verification and / or decryption on a protected first message based on a request of the second network element.

60. The method of claim 59, wherein, The protected first message includes a first message subjected to integrity protection and / or encryption by a terminal device.

61. The method of claim 59 or 60, wherein, The second network element includes an AMF.

62. The method of claim 59 or 60, wherein, The third network element includes an AUSF.

63. A terminal device, comprising: A first transceiver module, configured to send a protected first message to a first network element.

64. A terminal device, comprising: The second transceiver module is used to receive the protected first message sent by the first network element.

65. A second network element, comprising: The third transceiver module is used to send the protected first message to the first network element.

66. A second network element, comprising: The fourth transceiver module is used to receive the protected first message sent by the first network element.

67. A third network element, comprising: The fourth processing module is used to protect the first message based on the request from the second network element.

68. A third network element, comprising: The fifth processing module is used to perform integrity protection verification and / or decryption on the protected first message based on the request from the second network element.

69. A terminal device comprising: A transceiver, a processor, and a memory, wherein the memory is used to store a computer program, the transceiver is used to communicate with other devices, and the processor is used to invoke and run the computer program stored in the memory to cause the terminal device to perform the method as described in any one of claims 1 to 26.

70. A network device comprising: A transceiver, a processor, and a memory, wherein the memory is used to store a computer program, the transceiver is used to communicate with other devices, and the processor is used to invoke and run the computer program stored in the memory to cause the network device to perform the method as described in any one of claims 27 to 62.

71. A chip comprising: A processor for retrieving and running a computer program from memory, causing a device on which the chip is mounted to perform the method as described in any one of claims 1 to 62.

72. A computer-readable storage medium for storing a computer program that, when run by a device, causes the device to perform the method as claimed in any one of claims 1 to 62.

73. A computer program product comprising computer program instructions that cause a computer to perform the method as described in any one of claims 1 to 62.

74. A computer program that causes a computer to perform the method as described in any one of claims 1 to 62.

Citation Information

Patent Citations

  • Method and device for managing security context

    CN116074828A

  • Parameter Protection Method And Device, And System

    US20200228977A1

  • Security context for target amf

    US20230262453A1

  • Key generation method, device, and system

    WO2020087286A1